Welcome 微信登录
编程资源 图片资源库 蚂蚁家优选 PDF转换器

首页 / 操作系统 / Linux / [注意]亚马逊云服务中发现Zeus僵尸网络

云计算服务正成为黑客的新疆域。安全研究人员发现,Zeus僵尸网络在亚马逊的EC2云服务中运行着一个未授权的命令和控制中心。这是首次发现亚马逊云计算被用于此类非法活动。安全研究员Don DeBolt称,黑客是通过入侵一个使用EC2云服务的网站后,悄悄的在亚马逊的服务器上安装了一个命令和控制程序。A new wave of a Zeus bot (Zbot) variant was spotted taking advantage of Amazon EC2’s cloud-based services for its C&C (command and control) functionalities.This notable scheme is a highlight from the latest spammed executable “xmas2.exe” (63,488 bytes), for which we have recently published blog titled "Christmas is knocking on the door, so does the malware".[Figure 01 – Zeus displays cyber-criminal activities][Figure 02  – Zeus bot variant communication]As shown in Figure 03, the Zeus bot variant injects code into the system processes (such as svchost.exe) and connects to its cloud-server [Figure 02] for configuration (config.bin) of the master for it’s criminal activity.Figure 03 – Injects code and waits for user to enter bank credentialsThe group behind this criminal activity is obviously doing it for financial gain –  stealing both your identity and your money.In this variant, we have learned how cloud on-demand (pay-as-you-use) offerings could be used to fuel such online cyber-crimes.Please Note:The legitimate hacked website was contacted and informed about its participation in the Zeus bot activity and accordingly has stopped serving the malicious variant.Furthermore, we also reported the observed abuse activities to Amazon Web Service. For future reference, this page explains how to report AWS suspicious activities.Thanks to Zarestel for his valuable contribution in the code analysis.Linux Kernel ip_frag_reasm()函数空指针引用拒绝服务漏洞Ruby 1.9.1升级,修正堆溢出问题相关资讯      黑客  云计算 
  • 甲骨文被控夸大云计算业务收入  (06月07日)
  • 黑客控制 Dridex 服务器 用杀毒软  (02月07日)
  • 黑客是如何入侵和控制物联网设备的  (12/31/2015 10:14:35)
  • 黑客透露他如何入侵Hacking Team的  (04月18日)
  • 影响历史的四个黑客故事  (01月24日)
  • 黑客利用 Wi-Fi 攻击你的七种方法  (12/28/2015 19:43:01)
本文评论 查看全部评论 (0)
表情: 姓名: 字数


评论声明
  • 尊重网上道德,遵守中华人民共和国的各项有关法律法规
  • 承担一切因您的行为而直接或间接导致的民事或刑事法律责任
  • 本站管理人员有权保留或删除其管辖留言中的任意内容
  • 本站有权在网站内转载或引用您的评论
  • 参与本评论即表明您已经阅读并接受上述条款