Danmec Bot, Fast-Flux networks and recruitment of Zombies PCs

Danmec or Asprox, is the name of a trojan designed to recruit zombie machines while collecting confidential information from each of the victims it infects.

While the emergence of this trojan isn't new, now uses more complex strategies than those usually used by other malicious code, including its early variants, as techniques Fast-Flux to avoid detection by blocking programs and infect as many computers aspossible.

Currently, the networks Fast-Flux and massively exploited actively by thousands of Russian origin domains, activating again as that created by botnets Danmec.

google-analitycs.lijg. ru
fmkopswuzhj. biz
fnygfr. com

fvwugekf. info

fwkbt. info

gbrpn. org

gbxpxugx. org

ghtileh. biz

gnyluuxneo. com

fuougcdv. org

www. dbrgf. ru

www. bnmd. kz

www. nvepe. ru

www. mtno. ru

www. wmpd. ru

www. msngk6. ru

www. vjhdo. com

www. aspx37. I
google-analitycs.dbrgf. ru

www. advabnr. com

www. lijg. ru

www. dft6s. kz

Each of these domains hosting the following script, written in JavaScript, called script.js (MD5:ccec2c026a38ce139c16ae97065ccd91), from which runs a Drive-by-Download:

This call through the iframe tag is made to a URL that is part of a network active Fast-Flux.

; IN A

;; ANSWER SECTION: 600 IN A 600 IN A 600 IN A 600 IN A 600 IN A 600 IN A 98,194,180,179 600 IN A 600 IN A 151,118,186,131 600 IN A 600 IN A 600 IN A 600 IN A 24,107,209,119 600 IN A 24,170,188,201 600 IN A

;; AUTHORITY SECTION: 339,897 IN NS 339,897 IN NS 339,897 IN NS 339,897 IN NS 339,897 IN NS

;; Query time: 263 msec
;; SERVER: # 53 (
;; WHEN: Sun Jan 25 20:31:57 2009
;; MSG SIZE rcvd: 356

While each of the lines set out above web addresses are a new farm networks Fast-Flux with IP group mirrors.

Fast-Flux is an advanced technique used for malicious purposes, together with others, for the propagation of hazards. This forces them to be cautious at all times.

