via a link from exler — an article by a Kaspersky Lab expert *We do not know exactly how many botnets are involved in carrying out the attack, but we know for certain of at least one such botnet. It is built on the Darkness/Optima DDoS bot, which is currently quite popular on the Russian-language cybercrime black market. What is being offered for sale includes not only Trojan programs (bots), but also networks of infected machines built on their basis, as well as services for carrying out DDoS attacks against a specified internet resource. One such Optima botnet has been under our observation for some time. Analysis of the monitoring data showed that the first DDoS attack on LJ (LiveJournal) was carried out as early as March 24. The botnet owners issued a command to attack the blog address of Alexei Navalny: http://navalny.livejournal.com. On March 26, the bots received a command to begin an attack on another resource belonging to the well-known anti-corruption campaigner — http://rospil.info, and on April 1 the site http://www.rutoplivo.ru came under attack. The following table lists the links received by the bots to launch DDoS attacks during the period from March 24 to April 1: 24.03.2011 http://navalny.livejournal.com 25.03.2011 http://navalny.livejournal.com 25.03.2011 http://navalny.livejournal.com/569737.html 25.03.2011 http://www.livejournal.com/ratings/posts 26.03.2011 http://navalny.livejournal.com 26.03.2011 http://rospil.info 29.03.2011 http://rospil.info 30.03.2011 http://www.kredo-m.ru 30.03.2011 http://navalny.livejournal.com 01.04.2011 http://www.rutoplivo.ru It is worth noting that LiveJournal representatives first announced the DDoS attack on March 30. On that day, we recorded an attack via the Optima botnet only against navalny.livejournal.com. But on April 4, the bots received an impressive list that included links to the blogs of many popular users of this service: http://www.livejournal.com http://www.livejournal.ru http://sergeydolya.livejournal.com http://shpilenok.livejournal.com http://tema.livejournal.com http://radulova.livejournal.com http://marta_ketro.livejournal.com http://pesen_net.livejournal.com http://doctor_livsy.livejournal.com http://pushnoy_ru.livejournal.com http://navalny.livejournal.com http://dolboeb.livejournal.com http://olegtinkov.livejournal.com http://mi3ch.livejournal.com http://belonika.livejournal.com http://mzadornov.livejournal.com http://tebe_interesno.livejournal.com http://tanyant.livejournal.com http://eprst2000.livejournal.com http://drugoi.livejournal.com http://stillavinsergei.livejournal.com http://kitya.livejournal.com http://vero4ka.livejournal.com http://zhgun.livejournal.com http://zyalt.livejournal.com http://fritzmorgen.livejournal.com http://miss-tramell.livejournal.com http://sadalskij.livejournal.com http://becky-sharpe.livejournal.com http://roizman.livejournal.com http://alex-aka-jj.livejournal.com http://alphamakaka.livejournal.com http://borisakunin.livejournal.com http://kungurov.livejournal.com http://plucer.livejournal.com http://twower.livejournal.com It should be obvious to specialists in the Russian-language blogosphere that the list contains blogs by very different people writing about completely different things, all of them among the platform’s most popular authors — the so-called “thousanders” (bloggers with over 1,000 followers, in LiveJournal parlance). Whether this was an attempt to “blur” the real target of the attack, which was clearly indicated in the earliest DDoS attempts, or whether the list of unwanted blogs had simply grown broader, we do not know. ..... W**e are very surprised that LiveJournal representatives still have not contacted law enforcement regarding the attack: “We have not filed a request with Russian law enforcement agencies to open criminal cases, although we do not rule out such a possibility,” said Svetlana Ivannikova, head of LiveJournal Russia. Moreover, media outlets have carried statements claiming that “such a criminal case has no prospects.” From our point of view, this attack clearly shows all the signs of a crime classified under Article 273 of the Criminal Code of the Russian Federation, “Creation and distribution of malicious software.” Russian law enforcement agencies and courts have already accumulated solid experience in applying this article. ** *in full

Original

Tags