Information About

Rbot.cbq




''"The Zotob worm and several variations of it, known as Rbot.cbq, SDBot.bzh and Zotob.d, infected computers at companies such as ABC , CNN , The Associated Press , The New York Times , and Caterpillar Inc. " — Business Week, August 16 , 2005 .


Zotob is a vulnerability. This worm has been known to spread on microsoft-ds or TCP Port 445.

It was declared that the Zotob worms cost an average of $97,000 as well as 80 hours of cleanup per every company affected. {Link without Title}


RBOT VARIANT

Zotob was derived from the Rbot worm. Rbot can force an infected computer to continuously Restart . Its outbreak on August 16 , 2005 was covered "live" on CNN television, as the network's own computers got infected.


SEQUENCE OF EVENTS


  • August 9 , 2005 : Security advisory
    "On 9 August, Microsoft released critical security advisory MS05-039 which revealed a vulnerability in the Plug-and-Play component of Windows 2000. Code to patch the loophole was also made available." {Link without Title}


  • Virus writing
    "In the days since Microsoft's announcement, virus writers have released several variants of both Zotob and RBot, along with updated versions of older worms named SD-Bot and IRC-Bot, designed to take advantage of the newly discovered flaw." {Link without Title}


  • August 13 , 2005 : Emerged on Saturday
    "The worms, called Zotob and Rbot, and variants of them, started emerging Saturday, computer security specialists said, and continued to propagate as corporate networks came to life at the beginning of the week." {Link without Title}



  • August 17 , 2005 : CIBC and other banks, companies affected
    "CIBC says the Zotob worm caused some isolated outages, but did not affect ATMs, Internet or phone banking. The virus also hit other Canadian businesses but has not caused widespread shutdowns." {Link without Title}




ARREST OF THE CODERS

On August 26 , 2005 , Farid Essebar and Attila Ekici were arrested in Morocco and Turkey , respectively. They are believed to be the men behind the coding of the worm.

A signature in the Zotob worm code suggested it was coded by Diabl0 and the IRC server it connects to is the same used in previous version of Mytob. Diabl0 is believed to have incorporated the code of a Russia n nicknamed houseofdabus whose journal has been shut down by authorities [http://www.livejournal.com/users/houseofdabus/ , just after the arrest of Diabl0. The coder (Ekici) probably paid Diabl0 (Essebar) to write the code.

"''He says it's all about making money, and that he doesn't care if people remove the worm because it's the spyware stuff that he installs that's making him the money,'' Taylor said in a conversation with me."
{Link without Title}

In August 30 , 2005 , controversial reports emerged from different Anti-virus firms. Sophos declared that several people had access to the Mytob source code (a variant of the worm). On the other hand, F-Secure declared that it has found multiple variants of Mytob that were coded after the arrest of Essebar. Those declarations suggest that Essebar is only a part of a larger group of Dark-side Hacker s behind the spread of the Malware . {Link without Title}


SEE ALSO



EXTERNAL LINKS AND SOURCES


Security vulnerability information

  • [http://www.microsoft.com/technet/security/bulletin/MS05-039.mspx Microsoft Security Bulletin MS05-039] (Microsoft)

  • [http://www.microsoft.com/technet/security/advisory/899588.mspx Microsoft Security Advisory (899588)] (Microsoft)

  • [http://www.kb.cert.org/vuls/id/998653 US Cert Vulnerability Note VU#998653] (US-CERT)

  • Secunia Advisory SA16372 (Secunia)

  • CAN-2005-1983 (Common Vulnerabilities and Exposures)

  • Bugtraq ID 14513 (SecurityFocus)



Worm information



News coverage

  • BBC News Windows 2000 worm hits US firms

  • BBC News Windows 2000 bug starts virus war

  • BBC News Two detained for US computer worm

  • BBC News Money motive drove virus suspects

  • New York Times Virus Attacks Windows Computers at Companies

  • CNN Worm strikes down Windows 2000 systems

  • MSNBC Computer worms strike media outlets

  • Reuters Computer virus hits U.S media outlets

  • Slashdot Zotob Worm Hits CNN and Goes Global

  • Information Week Zotob Proves Patching "Window" Non-Existent