Court order cripples Coreflood botnet, says FBI
But Microsoft re-releases Coreflood scrubber
Computerworld - Although the Federal Bureau of Investigation (FBI) said a federal temporary restraining order has crippled the Coreflood botnet in the U.S., Microsoft today took the unusual step of pushing a second version of its monthly malware cleaner to Windows users to again quash the botnet.
Coreflood made the news earlier this month when the U.S. Department of Justice (DOJ) and FBI obtained an unprecedented temporary restraining order that allowed them to seize command-and-control servers that managed the botnet's estimated 2.3 million compromised PCs.
Those servers were replaced by government-controlled systems.
The court order also allowed the DOJ and FBI to issue commands using those replacement servers that disabled, but did not uninstall, Coreflood on infected PCs that asked for new commands.
In an affidavit filed in a Connecticut federal court last Saturday, FBI Special Agent Briana Neumiller said that the server seizure and "kill-switch" instructions issued to the malware have crippled the botnet.
On April 13, the day after the DOJ and FBI seized the Coreflood servers, the government replacements received nearly 800,000 command requests, or "beacons," from Coreflood-infected machines in the U.S. A week later, the number of beacons had plummeted to less than 100,000.
"Two possible reasons why the Coreflood Botnet is getting smaller are as follows: (i) because Coreflood has not been able to update itself on infected computers, anti-virus vendors have been able to release virus signatures capable of detecting the latest versions of Coreflood," Neumiller said in her affidavit. "And (ii) as victims of Coreflood are notified of their infected computers, they may be disconnecting the infected computers from the Internet or taking other measures to disable or remove Coreflood."
The restraining order, which was transformed from "temporary" to "preliminary" this week by U.S. District Court Judge Vanessa Bryant, allows the DOJ and FBI to identify infected computers using IP addresses. The agencies then notify the ISPs (Internet service providers) responsible for those addresses; the ISPs are to send the owners of those PCs a form letter telling them that their computer is infected and urging them to run tools to delete the malware.
While the volume of beacons from U.S. PCs has fallen to one-tenth of the number prior to the takedown, Neumiller noted that beacons from foreign machines -- which haven't received instructions to stop running the bot -- have not dropped as rapidly. As of last Friday, beacons from foreign PCs were about a quarter that of April 13.
Neumiller also said that the FBI has identified "seventeen state or local government agencies, including one police department; three airports; two defense contractors; five banks or financial institutions; approximately thirty colleges or universities; approximately twenty hospital or health care companies; and hundreds of businesses" infected with Coreflood.
Microsoft today said it was releasing another edition of its Malicious Software Removal Tool (MSRT) to bolster the cleaning process.
"This edition includes variants of Afcore released by the criminals behind it at approximately the same time as the previous edition of MSRT." said Jeff Williams, a principal group program manager with the Microsoft Malware Protection Center.
Typically, Microsoft ships a new version of its Malicious Software Removal Tool (MSRT) only once each month as part of its Patch Tuesday package. The free MSRT, which targets a limited number of malware families, scrubs PCs of attack code. Microsoft feeds the tool to users through the same Windows Update mechanism that serves up security patches.
Microsoft said earlier this month that it added Coreflood detection to the April 13 version "at the request of the FBI and the Department of Justice." Today the company declined to confirm whether it re-released the tool at the request of the DOJ and FBI.
Neumiller's affidavit included a chart that showed a resurgence in Coreflood beacons on April 18. That spike may have prompted the DOJ and FBI to ask Microsoft to reissue MSRT.
Microsoft's newest version of the MSRT can be manually downloaded from the company's Web site. Windows PCs should receive the revised tool shortly via the Windows Update service.
Gregg Keizer covers Microsoft, security issues, Apple, Web browsers and general technology breaking news for Computerworld. Follow Gregg on Twitter at
@gkeizer or subscribe to Gregg's RSS feed
. His e-mail address is gkeizer@computerworld.com.
Read more about Security in Computerworld's Security Topic Center.


- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Driving Secure Enterprise File Sharing and Syncing in the Enterprise
- GroupLogic's new activEcho is the industry's only secure Enterprise File Sharing and Synching solution that balances the need for simplicity for the end...
- The Enterprise File Sharing Option
- Enterprises and IT departments need to address several critical security issues when considering file sharing and syncing products. Many of today's solutions do...
- Security Strategies to Virtualizing Internet-Facing Applications
- The IT organization at Intel has set a goal to transition their enterprise to a private cloud for their Office and Enterprise applications....
- Cloud Security Planning Guide
- Cloud security considerations span protecting hardware and platform technologies in the data center to enabling regulatory compliance and defending cloud access through different...
- Cloud Security Vendor Round Table
- This vendor round table guide will help you to evaluate different cloud technology vendors and service providers based on a series of questions... All Security White Papers
- Live Webcast
Data Privacy and Protection in Production Environments: New Research from Ponemon Institute - Date: Wednesday, June 13, 2012, 1:00 PM EDT / 10:00 AM PDT
In a recent study conducted by Ponemon Institute, fifty-five percent of respondents... - Data Privacy and Protection in Production Environments: New Research from Ponemon Institute
- Date: Wednesday, June 13, 2012, 1:00 PM EDT / 10:00 AM PDT
In a recent study conducted by Ponemon Institute, fifty-five percent of respondents... - Security Certifications 101 - BlackBerry and all those acronyms what do they mean and why they matter?
- FIPS, Common Criteria, CAPS, AISEP, NFC, NIST, Fraunhofer SIT, CESG, DSD - these are just some of the government and industry certifications which...
- BlackBerry PlayBook OS 2.0 Security Overview
- The presentation provides an overview of BlackBerry PlayBook OS 2.0 security capabilities and features, including: BlackBerry® Balance™ technology, BlackBerry® Bridge, data-at-rest protection, and...
- BlackBerry NFC Security Overview
- The presentation on NFC security will provide an overview of the security protections built into the BlackBerry platform to protect users, application developers...
- Playing Defense: Staying on Top of Your Disaster Recovery Game
- When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing... All Security Webcasts