On UrbanBaby: What is a Helicopter Mom?
BNET Business Network:
BNET
TechRepublic
ZDNet

September 24th, 2007

Storm Worm botnet numbers, via Microsoft

Posted by Ryan Naraine @ 7:40 am

Categories: Botnets, Browsers, Data theft, Exploit code, Hackers, Microsoft, Passwords, Patch Watch, Pen testing, Rootkits, Spam and Phishing, Spyware and Adware, Viruses and Worms, Vulnerability research

Tags: Microsoft Corp., Worm, Machine, MSRT, Productivity, Microsoft Windows, Cyberthreats, Spyware, Adware & Malware, Viruses And Worms, Security

If the statistics from Microsoft’s MSRT (malicious software removal tool) are anything to go by, the Storm Worm botnet is not quite the world’s most powerful supercomputer.

The tool — which is updated and shipped once a month on Patch Tuesday — removed malware associated with Storm Worm from 274,372 machines in the first week after September 11. In all the tool scanned more about 2.6 million Windows machines.

These numbers, released by Microsoft anti-virus guru Jimmy Kuo, puts the size of the botnet on the low end of speculation that Storm Worm has commandeered between 1 million and 10 million Windows machines around the world.

[ SEE: Storm Worm botnet could be world’s most powerful supercomputer ]

The MSRT numbers, though helpful, shouldn’t be relied on as gospel. For starters, the tool targets a very specific known malware (it only finds exactly what it’s looking for) and attackers constantly tweak malware files to get around detection. In addition, it is only delivered to Windows machines that have automatic updates turned on, which means there are liely tons and tons of hijacked machines that never gets a copy of the MSRT.

Still, Kuo claims that the September version of MSRT made a dent in the botnet.

Another antimalware researcher who has been tracking these recent attacks has presented us with data that shows we knocked out approximately one-fifth of Storm’s Denial of Service (DoS) capability on September 11th. Unfortunately, that data does not show a continued decrease since the first day. We know that immediately following the release of MSRT, the criminals behind the deployment of the Storm botnet immediately released a newer version to update their software. To compare, one day from the release of MSRT, we cleaned approximately 91,000 machines that had been infected with any of the number of Nuwar components. Thus, the 180,000+ additional machines that have been cleaned by MSRT since the first day are likely to be home user machines that were not notably incorporated into the daily operation of the Storm botnet. Machines that will be cleaned by MSRT in the subsequent days will be of similar nature.

The September release of the MSRT probably cleaned up approximately one hundred thousand machines from the active Storm botnet. Such numbers might project that the strength of that botnet possibly stood at almost half a million machines with an additional few hundred thousand infected machines that the Storm botnet perhaps were not actively incorporating.

Kuo also confirmed fears that the botnet will slowly regain its strength once those cleaned machines become reinfected because those machines are likely unpatched and not equipped with any security software.

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 6 Talkback(s)
2.6 million machines had malware removed
NOT "scanned". Sorry, don't have the "Scanned" number handy.

Also, because the computation is based on taking out 1/5 of the active botnet, the computation is "accurate" regardless of the perc... (Read the rest)
Posted by: cjkuo Posted on: 09/24/07 You are currently: a Guest | | Terms of Use
Something to fear  aceofspades1217@... | 09/24/07
What makes you think government...  bjbrock | 09/24/07
RE: Storm Worm botnet numbers, via Microsoft  cmosentine@... | 09/24/07
My thoughts exactly  swoopee | 09/24/07
2.6 million machines had malware removed  cjkuo | 09/24/07
How "clean" are the cleaned machines?  gtvr | 09/24/07

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors
advertisement
Click Here

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here