Wednesday, 17 June 2009

FireEye: Killing the beast .... Part II

These articles were published back in December 2008 but most of the details are still valid for the newer versions.

Back to the CnC structure ... Koobface relies mostly on domain names to locate its CnC servers, instead of using hard coded IPs like Pushdo. As a matter of fact, I observed that it tends to change its CnC domains more often than the IPs behind those domains change. Based on my lab data (for the last 3 months or so) I see Koobface connecting to 23 unique domains.

Here is the complete list:

Surprisingly, when I count the collective IPs behind all these domains, I hardly find 4 unique IPs. Multiple domains have been resolving to these fixed IPs over the period I examined.

