Information AboutRbot.cbq |
''"The Zotob worm and several variations of it, known as Rbot.cbq, SDBot.bzh and Zotob.d, infected computers at companies such as ABC , CNN , The Associated Press , The New York Times , and Caterpillar Inc. " — Business Week, August 16 , 2005 . Zotob is a vulnerability. This worm has been known to spread on microsoft-ds or TCP Port 445. It was declared that the Zotob worms cost an average of $97,000 as well as 80 hours of cleanup per every company affected. {Link without Title} RBOT VARIANT Zotob was derived from the Rbot worm. Rbot can force an infected computer to continuously Restart . Its outbreak on August 16 , 2005 was covered "live" on CNN television, as the network's own computers got infected. SEQUENCE OF EVENTS
ARREST OF THE CODERS On August 26 , 2005 , Farid Essebar and Attila Ekici were arrested in Morocco and Turkey , respectively. They are believed to be the men behind the coding of the worm. A signature in the Zotob worm code suggested it was coded by Diabl0 and the IRC server it connects to is the same used in previous version of Mytob. Diabl0 is believed to have incorporated the code of a Russia n nicknamed houseofdabus whose journal has been shut down by authorities [http://www.livejournal.com/users/houseofdabus/ , just after the arrest of Diabl0. The coder (Ekici) probably paid Diabl0 (Essebar) to write the code. "''He says it's all about making money, and that he doesn't care if people remove the worm because it's the spyware stuff that he installs that's making him the money,'' Taylor said in a conversation with me." {Link without Title} In August 30 , 2005 , controversial reports emerged from different Anti-virus firms. Sophos declared that several people had access to the Mytob source code (a variant of the worm). On the other hand, F-Secure declared that it has found multiple variants of Mytob that were coded after the arrest of Essebar. Those declarations suggest that Essebar is only a part of a larger group of Dark-side Hacker s behind the spread of the Malware . {Link without Title} SEE ALSO EXTERNAL LINKS AND SOURCES Security vulnerability information
Worm information
News coverage
|
|
|