StudentShare
Contact Us
Sign In / Sign Up for FREE
Search
Go to advanced search...
Free

Mariposa Botnet: What are They and How do They Work - Literature review Example

Cite this document
Summary
This paper 'Mariposa Botnet: What are They and How do They Work' discusses that the Mariposa Botnet malware program is also defined a group of computers that are under control of a single entity, a group of criminal leaders of the Mariposa Botnet malware. The name Mariposa is the name of the botnet…
Download full paper File format: .doc, available for editing
GRAB THE BEST PAPER95.1% of users find it useful
Mariposa Botnet: What are They and How do They Work
Read Text Preview

Extract of sample "Mariposa Botnet: What are They and How do They Work"

? Mariposa Botnet: What are They and How do They Work. October 12, Mariposa Botnet: What are They and How do They Work. INTRODUCTION Mariposa botnet is a malware that infiltrates computers. The research delves on the botnets, viruses, and malware. The research delves on the with Mariposa Botnet malware program’s damaging functions. Mariposa Botnet malware program focuses on identity theft, DDos attacks, and stealing confidential information. BODY Mariposa Botnet malware program is also defined a group of computers that are under control of a single entity, a group of criminal leaders of the Mariposa Botnet malware. The name Mariposa is the name of the botnet. Mariposa Botnet malware program is not a virus. The program is definitely not a worm. The Mariposa malware program is called a botnet. Botnet means control. The owners of the botnet take control of the infected computers’ functions. While under control, the criminal leaders of the Mariposa Botnet malware can do whatever they want with the files stored in the hacked computers’ database. Malware program constantly change to avoid being noticed the attacked computers’ warning systems. The criminal leaders of the Mariposa Botnet malware masterminds use software strategies and social engineering procedures to find ways to pass on the malware into targeted victims’ computers. Malwares send information to their crime headquarters. To understand the Mariposa Botnet malware program, the botnet term should first be discussed. A botnet normally occurs in a P2P environment. Several computers connect to each other to engage in file sharing activities. One computer can connect to a botnet in order to get files located in another botnet member’s computer. Some individuals volunteer to join the peer to peer environment. They feel that the benefits from the botnet environment because they can retrieve files from other botnet environment members (Stamp, 2010). Understanding the Mariposa Botnet malware program, malware is discussed here. Malware means malicious codes. The infecting malware code acts like an agent. The agent, malware code, does the bidding or obeys the instructions of the malware manufacturer, creator. When infected by the malware, the computer is now like a zombie of the malware creator. The malware culprit obeys the malware creator’s instructions to hand in the personal data or information of the computer unit’s owner or user. When the computer owner gives instructions to the computer, the computer refuses to comply with the computer owner’s instructions (Thompson, 2009). Further, a computer virus normally differs from a botnet. A virus is a program that is set to activate on a scheduled time, usually some time in the future. When the date arrives, the virus unloads all its debilitating effects on the computer. Viruses were created to make pranks on the computer owners. Many viruses do not intend to harm the computer owners. The viruses are normally not designed to steal confidential credit card numbers. Viruses are normally not created to steal confidential personal information concerning the computer users. Viruses include the 1992 Michaelangelo virus, the Win32.Hatred virus, polymorphic virus, the unforgettable horrors of the iloveyou virus, Sunday virus, and Jerusalem virus (Shelly, 2011). Furthermore, the malware takes the place of a physical threat. A thief who tries to steal a victim’s credit card information from your computer would have to barge into your home or office. When reaching inside the computer owner’s home or office, the invader has to locate where the computer owner hides his computer. This will take lots of roaming around time. When the thief reaches the victim’s computer, the intruder will have to locate where the computer owner hid his coveted passwords (Thompson, 2009). If the computer has no login password, the computer owner is giving confidential information openly to the data thief. When this happens, the thief’s chances of stealing confidential information are very greater. The intruder must be able to the thief must be able to pass through the security guards stationed in front of your home or office. When the intruder is able to pass through your security guards, the intruder has to avoid being detected by people inside your home or office. The physical stealing of confidential information is more difficult to accomplish, when compared to using malware to steal the computer users’ confidential information. The malicious malware codes will wreak havoc to the lives of all infected computer owners (Skoudis, 2004). Further, one website cache connects all the computers registered with the p2p botnet. Usually, the botnet uses the Gnutella Web cache that keeps all the botnet computers connected to each other. The same cache is set in the client’s code. Consequently, any new botnet member can join the botnet group. Once accepted, the new computer can update its computer with the latest files stored in another botnet member’s hard disk (Skoudis, 2004). Consequently, when one computer requests another botnet member for updates or access to a file, the other computer replies by sending the requesting file to the requesting computer’s hard disk. To increase communication between two botnet computers, the two computers the power of algorithm to speed up the request and send peer to peer process. One popular peer to peer site is Napster. Most p2p setups indicate the central server is the only location where one or more botnet computer members can make P2P file request and file sending (Skoudis, 2004). Likewise, the Mariposa Botnet malware program constantly changes the program structure. The criminal leaders of the Mariposa Botnet malware constantly update the botnet. Consequently. Mariposa Botnet malware program has many variants. The variants has already reached the 1,500 variants level. Because of the continuing change, the malware is both a dynamic as well as insistent botnet. It is one of the largest botnets in the world used by its creators to steal money from its victims and implementing DDos infections (Ottis, 2011). In addition, Matt Thompson emphasized that Mariposa Botnet is a malware program (2009). The malware’s command and control center implements custom encrypted UDP datagrams to acquire and send hacked or stolen computer information. The Mariposa Botnet malware program gathers confidential information from the computer users’ computers. The malware is tasks to retrieve bank accounts, credit card information, and other confidential information. Likewise, the malware gathers the personal profile of the infected computers’ users. The malware’s owners can use the stolen personal information for identity theft purposes. Further, the Mariposa Botnet malware program’s illegal activities are financially disastrous. In October 2009 alone, one malware update cropped up. Two malicious Mariposa Botnet programs were downloaded into the victims’ computers. The downloaded malware took control of the computer owner’s software and hardware functions. The malware renamed the ASCII commands and stole Google Adsense collections. Moreover, the Mariposa Botnet malware program cropped up its massive theft feelers in May of 2009. The program cause many computers to send traffic to the criminal leaders’ server headquarters. The Mariposa Botnet malware program’s evil functions included compromising computers that were infected by the spreading malware. The botnet master or creator can infinitely increase and extend the ill effects of the program far beyond the damage inflicted when the computers were first infected. The computer’s massive stealing activities grew in strength and activities. In addition, the Mariposa Botnet malware program constantly updates itself. The program sends constant messages to the criminal leaders’ main servers. The updates created a metamorphosis of the original characteristics of the malware to a new binary form, like a chameleon. The chameleon effect reduces the infected computer’s anti-virus programs to detect the ever-changing Mariposa Botnet malware program (Thompson, 2009). Further, the Mariposa Botnet malware program attacked many computers in several countries. Usually the criminal leaders of the program chose which country to infect. In addition, the criminal leaders of the criminal leaders of the Mariposa Botnet malware chose which individual computers to infect, control, and steal confidential information. Research that was conducted showed the servers of the intruding malware included lalundelau.sinip.es, bf2bc.sinip.es, and thejacksonfive.us, tamiflux.net, binaryfeed.in, and booster.estr.es (Thompson, 2009). What's more, the Mariposa Botnet malware program was finally shut down. Panda Security antivirus Corporation contributed its significant share to deleting the annoying trespasser, Mariposa Botnet malware program. In addition, Georgia Tech Information Security Center (GTISC) jumped into the debacle to help in wiping out the Mariposa Botnet malware program from the face of the earth (Thompson, 2009). In addition, an analysis of the damages was very financially hurting. The Mariposa Botnet malware program was able to infiltrate, control, and execute its illegal activities on an estimated 13 million computers. The computers included those owned by government agencies. The sidelined computers included those owned by business and other corporations or entities. The infected computers include those in the hands of individuals. The malware-hit computers include those used in schools and other learning facilities. The Mariposa Botnet malware program was able to steal confidential bank information and credit card details from individuals and groups living in more than 189 countries around the world (Thompson, 2009). What's more, the computer literally stole vital confidential information. The stolen information included passwords. The hacked data included bank details. Consequently, the malware was able to stealing computer users’ names, addresses, phone numbers, and other personal identification details. The criminal leaders of the Mariposa Botnet malware successfully withdraw money using the stolen credit card information and stolen bank details (Thompson, 2009). Moreover, the research showed that the malware was very active. The researchers used different methods to diffuse the damages done by the uninvited guest, Mariposa Botnet malware program. The counter attacks used against the Mariposa Botnet malware program included obfuscation. Another anti- Mariposa Botnet malware program strategy was to use anti-debugging programs. The computer defenders used a third tool to combat the dreaded malware. The tool was a packing program process. The MD5 has of the original Mariposa Botnet malware program sample is f4e2c305ef2d38b6d4e4be9d19de16ed. Of the 41 anti-virus programs that were used to detect and defeat the malware, only 36 out of 41 antivirus software programs were able to detect the malware. This is the reason why the malware continues to successful enter the targeted computers without being noticed and swept away, cleaned (Thompson, 2009). In terms of computer antivirus parlance, the obfuscation and packing takes place. The program’s entry point starts with the obfuscated loop. The loop includes a mixture of meaningless SIMD and FPU commands. As the loop reaches its terminal end, the code transfers to an address that starts with XOR of the .text part of the image in random access memory with the corresponding 0x0CB2DC4AA constant. The decoded .text part is pressed towards the stack. Consequently, the RETN command transfers management of the Mariposa Botnet malware program to the decoded code. The code begins its magnanimous job of debugging the giant malware software program (Thompson, 2009). CONCLUSION Summarizing the above discussion, Mariposa botnet is a malware that infiltrates computers. The research delves on the botnets, viruses, and malware. The research delves on the with Mariposa Botnet malware program’s damaging functions. Evidently, Mariposa Botnet malware program focuses on unlawful identity theft, DDos attacks, and stealing confidential information, and credit card theft. REFERENCES: Ottis, R. (2011). The Proceedings of the 10th European Conference on Information Warfare and Security. New York: Academic Conference Press. Shelly, G. (2011). Discovering Computers 2011. New York: Cengage Learning Press. Skoudis, E. (2004). Malware: Fighting Malicious Code. New York: Prentice Hall Press. Stamp, M. (2010). Handbook of Information and Communication Strategy. New York: Springer Press. Thompson, M. (2009). Mariposa Botnet. retrieved October 12, 2012 from Read More
Cite this document
  • APA
  • MLA
  • CHICAGO
(“Mariposa botnet: what are they and how do they work Research Paper”, n.d.)
Mariposa botnet: what are they and how do they work Research Paper. Retrieved from https://studentshare.org/information-technology/1458769-mariposa-botnet-what-are-they-and-how-do-they-work
(Mariposa Botnet: What Are They and How Do They Work Research Paper)
Mariposa Botnet: What Are They and How Do They Work Research Paper. https://studentshare.org/information-technology/1458769-mariposa-botnet-what-are-they-and-how-do-they-work.
“Mariposa Botnet: What Are They and How Do They Work Research Paper”, n.d. https://studentshare.org/information-technology/1458769-mariposa-botnet-what-are-they-and-how-do-they-work.
  • Cited: 0 times

CHECK THESE SAMPLES OF Mariposa Botnet: What are They and How do They Work

Analysis of Biography of a Runaway Slave by M. Barnet

It wasn't a place for merriment or after-work parties, instead, it was a prison for the hundred or so slaves who must be guarded lest they escape their masters.... His memories were poignant of a free life, where African children can play about in the sugar plantations without worrying of being whipped and punished by their masters He also explained why so many of them do not seek for escape.... He talked about how Africans knew about healing through natural herbs and potions....
4 Pages (1000 words) Assignment

WiMax for Amford

Indoors is useful for setting up the network, especially for the equipment provider, they should not have to send an installer, as the installation process is simple enough for the householder to do.... This assignment "WiMax for Amford" discusses Amford that has a need for improved communications....
12 Pages (3000 words) Assignment

Mariposa Botnet and How It Works

This coursework "Mariposa Botnet and how It Works" delves into the botnets, viruses and malware, Mariposa Botnet malware program's damaging functions.... mariposa botnet malware program focuses on identity theft, DDoS attacks, and stealing confidential information.... hellip; mariposa botnet malware program has also defined a group of computers that are under the control of a single entity, a group of criminal leaders of the mariposa botnet malware....
7 Pages (1750 words) Coursework

Malware Management in the Enterprise

A rather recent work known as the Koobface surfaced, its purpose was to target people on social networks and it's created profited by making 2 million dollars in one year.... what the worm did was drop spyware that stole susceptible information from the individuals who suffered, which includes bank account numbers and credit card credentials.... A worm known as the mariposa has been known to create the largest network of zombie machines on the entire planet....
7 Pages (1750 words) Case Study

Analysis of Hacking Attacks

This entire act they do without the system owner's authority.... his term is normally used to describe the type of hackers who do not express the seriousness and lack the ethics in principals as practiced by professional hackers.... Professional hackers do so with lots of knowledge, respect for skills and a sense of self-mentorship.... To gain access to computers, these hackers put into practice programs that were developed by different individuals which they have less idea about how they function....
24 Pages (6000 words) Coursework

Types of Hacking

The paper "Types of Hacking" discusses that recent years have seen the development of a number of interesting developments which detail how the techniques of cyber intrusions and attacks may be used on a national level, executing of host applications, and specific malicious actions.... how a particular “hacker” would be rated would depend upon the motivations and causes behind their behavior (Post, 1996)....
24 Pages (6000 words) Coursework

Indian Emigration to Great Britain After 1947

Recent government policies have also seen the character of this policy undergo some radical changes to its now being defined by entry to work and study programs.... The flow of Indians moving into Great Britain is seen to mainly comprise of young males who either come to work through the country's work permit system or to be reunified with their families.... This coursework "Indian Emigration to Great Britain After 1947" highlights how after 1947 Great Britain had a great labor shortage, and with the 1948 British Nationality Act, Indian Immigrants started flowing into Britain, created a large working-class and had a profound effect on the British economy....
10 Pages (2500 words) Coursework

What Are Bonnets and How They Work

This paper "What Are Bonnets and How they work" explores more on bonnet, their classification, how the security threat they pose has changed over the past five years.... How they work Bonnets are formed by an assortment of bots, which are controlled by one command and control (C & C) network.... These attacks include click fraud, keylogging, spamming shipping, and distributed denial of services and they are carried out using botnet (Banday, Qadri & Shah 2009, p....
9 Pages (2250 words) Report
sponsored ads
We use cookies to create the best experience for you. Keep on browsing if you are OK with that, or find out how to manage cookies.
Contact Us