Update Protection against the Kneber/Zeus Botnet
| Check Point Reference: | CPAI-2010-038 | |
| Date Published: | ||
| Severity: | ||
| Source: | NetworkWorld | |
| Protection Provided by: |
Security Gateway
|
|
| Who is Vulnerable? Microsoft Windows machines | ||
| Vulnerability Description Kneber (Zbot, BTN1) is a form of malware which is reported to have affected more than 74,000 PCs in 2,400 business and government systems around the world. Kneber, named after the username linking the infected computers worldwide (Hilary Kneber), is related to the ZeuS botnet, a malware botnet package that is readily available for sale and also traded in underground cybercriminal forums. The Kneber/Zeus botnet gathers login credentials to online financial systems, social networking sites and e-mail systems from infested computers and reports the information back to botnet owners and their clients. They, in turn, use the information to break into accounts, steal corporate and government information as well as personal and financial identities. |
||
|
Vulnerability Details According to the researcher who discovered Kneber, Alex Cox from NetWitness, more than half of the computer systems in the Kneber botnet also have the Waledac Trojan, a worm known to create email spam botnets that was recently associated with conficker. |
Protection Overview
The protection will detect and block attempts to connect to the Kneber/Zeus botnet.
In order for the protection to be activated, update your Security Gateway/VPN-1 product to the latest IPS/SmartDefense update. For information on how to update IPS/SmartDefense, go to SBP-2006-05, Protection tab and select the version of your choice.
To configure the defense, select your product from the list below and follow the related protection steps.