{"id":565,"date":"2009-05-09T16:26:15","date_gmt":"2009-05-09T20:26:15","guid":{"rendered":"http:\/\/rbachnet.wwwmi3-ss40.a2hosted.com\/?p=565"},"modified":"2022-12-30T12:11:35","modified_gmt":"2022-12-30T17:11:35","slug":"lessons-from-botnet-demise","status":"publish","type":"post","link":"https:\/\/rbach.net\/index.php\/lessons-from-botnet-demise\/","title":{"rendered":"Lessons From Botnet Demise"},"content":{"rendered":"<p><a href=\"http:\/\/www.theemailadmin.com\/2012\/07\/do-you-have-zombies-sending-spam\/\" target=\"_blank\" rel=\"noopener noreferrer\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignleft wp-image-100940\" title=\"Lessons From Botnet Demise\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/computer_zombies.jpg?resize=120%2C110&#038;ssl=1\" alt=\"Lessons From Botnet Demise\" width=\"120\" height=\"110\" srcset=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/computer_zombies.jpg?resize=150%2C138&amp;ssl=1 150w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/computer_zombies.jpg?resize=75%2C69&amp;ssl=1 75w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/computer_zombies.jpg?w=400&amp;ssl=1 400w\" sizes=\"auto, (max-width: 120px) 100vw, 120px\" \/><\/a>Brian Krebs on the <em><a href=\"http:\/\/www.washingtonpost.com\" target=\"_blank\" rel=\"noopener noreferrer\">Washington Post<\/a><\/em> blog <a href=\"http:\/\/voices.washingtonpost.com\/securityfix\/2009\/05\/zeustracker_and_the_nuclear_op.html\" target=\"_blank\" rel=\"noopener noreferrer\">Security Fix<\/a> profiled a case where a <a href=\"http:\/\/en.wikipedia.org\/wiki\/Bot_herder\" target=\"_blank\" rel=\"noopener noreferrer\">bot-herder<\/a> killed 100,000 <a href=\"http:\/\/en.wikipedia.org\/wiki\/Zombie_computer\" target=\"_blank\" rel=\"noopener noreferrer\">zombie clients<\/a> in his <a href=\"http:\/\/en.wikipedia.org\/wiki\/Botnet\" target=\"_blank\" rel=\"noopener noreferrer\">botnet<\/a>. The bot-herder implemented a &#8220;kill operating system&#8221; or kos command resident in the Zeus bot-net crimeware. The kos command caused the infected PCs to <a href=\"http:\/\/en.wikipedia.org\/wiki\/Blue_Screen_of_Death\" target=\"_blank\" rel=\"noopener noreferrer\">Blue Screen of Death<\/a> (BSOD). The Madrid-based security services firm S21sec reports that invoking the kos command only results in a blue screen and subsequent difficulty booting the OS. There appears to be no significant data loss and neither the Trojan binaries nor the start-up registries are removed, In this post, they look at what happens to an infected computer when it receives a Zeus kos.<\/p>\n<h3>Russian botnet<\/h3>\n<p>The Zeus crimeware was designed by the <a href=\"https:\/\/web.archive.org\/web\/20120713235513\/http:\/\/www.usatoday.com:80\/tech\/news\/computersecurity\/2008-08-04-hacker-cybercrime-zeus-identity-theft_N.htm\" target=\"_blank\" rel=\"noopener noreferrer\">Russian A-Z<\/a> to harvest financial and personal data from PCs with a Trojan. UK Computer security firm <a href=\"http:\/\/www.prevx.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">Prevx<\/a> found the Zeus crimeware available for just $4,000. The fee includes a DIY &#8220;exe builder&#8221; which incorporates a kernel-level rootkit. According to the <a href=\"https:\/\/web.archive.org\/web\/20130203214851\/http:\/\/www.prevx.com\/blog\/112\/ZEUS-steals-information-from-home-and-business-PCs.html\" target=\"_blank\" rel=\"noopener noreferrer\">Prevx<\/a> this means it can hide from even the most advanced home or corporate security software. RSA detailed the capabilities of Zeus crimeware in 2008. Zeus also includes advanced &#8220;form injection capabilities&#8221; that allows it to change web pages displayed by websites as they are served on the user&#8217;s PC. For example, criminals can add an extra field or fields to a banking website asking for credit card numbers, social security numbers, etc. The bogus field makes it look like the bank is asking you for this data after you have logged on and you believe you are securely connected to your bank.<\/p>\n<p><strong><em>rb-<\/em><\/strong><\/p>\n<p><em>The reason for BSODing 100,000 machines isn&#8217;t quite clear. Several security experts have offered up their opinions including S21sec and Zeustracker (currently down due to an apparent DDOS). What is clear are the implications of this action.<\/em><\/p>\n<p><em> Botnets and their related crimeware are dangerous for more and more reasons. They can steal massive amounts of personal data. They can launch denial-of-service attacks and they can execute code. I agree with Krebs that the scarier reality about malicious software is that these programs leave ultimate control over victim machines in the hands of the attacker.<\/em><\/p>\n<h3><em>Politically motivated attackers<\/em><\/h3>\n<p><em>For the time being, it is still in the best interests of the attackers to leave the compromised systems in place. They can plunder more information. However, imagine the social chaos created if <\/em><em><a href=\"https:\/\/web.archive.org\/web\/20120408100202\/http:\/\/www.pcworld.com\/businesscenter\/article\/157858\/downadup_worm_bores_into_9_million_pcs.html?tk=rel_news\" target=\"_blank\" rel=\"noopener noreferrer\">9 million<\/a> PCs infected with <\/em><em><a href=\"http:\/\/en.wikipedia.org\/wiki\/Conflicker\" target=\"_blank\" rel=\"noopener noreferrer\">Conflicker<\/a> including hospitals from <a href=\"https:\/\/web.archive.org\/web\/20090503003516\/http:\/\/www.siliconvalley.com:80\/news\/ci_12257206?nclick_check=1\" target=\"_blank\" rel=\"noopener noreferrer\">Utah<\/a> to the <a href=\"http:\/\/www.theregister.co.uk\/2009\/01\/20\/sheffield_conficker\/\" target=\"_blank\" rel=\"noopener noreferrer\">UK<\/a> were under the control of Al-Queda or other similarly minded groups. These politically motivated attackers could order all the infected machines to BSOD, creating computer-enhanced chaos. One of the forgotten lessons of 9-11 is that our technology can be hi-jacked and turned against us.\u00a0 This could be the opening into a new type of cyber warfare.<\/em><\/p>\n<p>&nbsp;<\/p>\n<p><em><a title=\"Ralph Bach\" href=\"https:\/\/rbach.net\/index.php\/new-resume\/\" target=\"_blank\" rel=\"noopener noreferrer\">Ralph Bach<\/a>\u00a0has been in IT long enough to know better and has blogged from his\u00a0<a title=\"Bach Seat\" href=\"https:\/\/rbach.net\/\" target=\"_blank\" rel=\"noopener noreferrer\">Bach Seat<\/a> about IT, careers, and anything else that catches his attention since 2005. You can follow him on <a class=\"broken_link\" href=\"http:\/\/www.linkedin.com\/in\/rb48334\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">LinkedIn<\/a>,\u00a0<a href=\"https:\/\/www.facebook.com\/ralph.bach.14\" target=\"_blank\" rel=\"noopener noreferrer\">Facebook<\/a>,\u00a0and\u00a0<a href=\"https:\/\/twitter.com\/rbach48334\" target=\"_blank\" rel=\"noopener noreferrer\">Twitter<\/a>. Email the Bach Seat\u00a0<a href=\"mailto:\/\/bach.seat@gmail.com\" target=\"_blank\" rel=\"noopener noreferrer\">here<\/a>.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Brian Krebs profiled a case where a bot-herder killed or kos command resident in the Zeus botnet crimeware that made the infected PC&#8217;s BSOD<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[3216,58,761,605,768,2920,23,2835,4,127],"class_list":["post-565","post","type-post","status-publish","format-standard","hentry","category-security","tag-3216","tag-botnet","tag-brian-krebs","tag-cyberwarfare","tag-denial-of-service-attack","tag-dos","tag-malware","tag-russia","tag-security","tag-zeus"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 4.9.9 - aioseo.com -->\n\t<meta name=\"description\" content=\"Brian Krebs profiled a case where a bot-herder killed or kos command resident in the Zeus botnet crimeware that made the infected PC&#039;s BSOD\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"RB\"\/>\n\t<meta name=\"keywords\" content=\"botnet,malware,security,zeus,brian krebs,denial-of-service attack,cyberwarfare,2009,dos,russia\" \/>\n\t<link rel=\"canonical\" href=\"https:\/\/rbach.net\/index.php\/lessons-from-botnet-demise\/\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 4.9.9\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"Bach Seat | The view from where I am sitting\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"Lessons From Botnet Demise\" \/>\n\t\t<meta property=\"og:description\" content=\"Brian Krebs profiled a case where a bot-herder killed or kos command resident in the Zeus bot-net crimeware that which made the infected PC&#039;s BSOD\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/rbach.net\/index.php\/lessons-from-botnet-demise\/\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/rbach.net\/wp-content\/uploads\/computer_zombies-150x138.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/rbach.net\/wp-content\/uploads\/computer_zombies-150x138.jpg\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2009-05-09T20:26:15+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2022-12-30T17:11:35+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/ralph.bach.14\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:site\" content=\"@rbach48334\" \/>\n\t\t<meta name=\"twitter:title\" content=\"Lessons From Botnet Demise\" \/>\n\t\t<meta name=\"twitter:description\" content=\"Brian Krebs profiled a case where a bot-herder killed or kos command resident in the Zeus bot-net crimeware that which made the infected PC&#039;s BSOD\" \/>\n\t\t<meta name=\"twitter:creator\" content=\"@rbach48334\" \/>\n\t\t<meta name=\"twitter:image\" content=\"http:\/\/rbach.net\/wp-content\/uploads\/computer_zombies-150x138.jpg\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/rbach.net\\\/index.php\\\/lessons-from-botnet-demise\\\/#article\",\"name\":\"Lessons From Botnet Demise | Bach Seat\",\"headline\":\"Lessons From Botnet Demise\",\"author\":{\"@id\":\"https:\\\/\\\/rbach.net\\\/index.php\\\/author\\\/administrator\\\/#author\"},\"publisher\":{\"@id\":\"https:\\\/\\\/rbach.net\\\/#person\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"http:\\\/\\\/rbach.net\\\/wp-content\\\/uploads\\\/computer_zombies-150x138.jpg\",\"@id\":\"https:\\\/\\\/rbach.net\\\/index.php\\\/lessons-from-botnet-demise\\\/#articleImage\"},\"datePublished\":\"2009-05-09T16:26:15-04:00\",\"dateModified\":\"2022-12-30T12:11:35-05:00\",\"inLanguage\":\"en-US\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/rbach.net\\\/index.php\\\/lessons-from-botnet-demise\\\/#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/rbach.net\\\/index.php\\\/lessons-from-botnet-demise\\\/#webpage\"},\"articleSection\":\"Security, 2009, Botnet, Brian Krebs, Cyberwarfare, Denial-of-service attack, DoS, Malware, Russia, Security, Zeus\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/rbach.net\\\/index.php\\\/lessons-from-botnet-demise\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/rbach.net#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/rbach.net\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/rbach.net\\\/index.php\\\/category\\\/security\\\/#listItem\",\"name\":\"Security\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/rbach.net\\\/index.php\\\/category\\\/security\\\/#listItem\",\"position\":2,\"name\":\"Security\",\"item\":\"https:\\\/\\\/rbach.net\\\/index.php\\\/category\\\/security\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/rbach.net\\\/index.php\\\/lessons-from-botnet-demise\\\/#listItem\",\"name\":\"Lessons From Botnet Demise\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/rbach.net#listItem\",\"name\":\"Home\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/rbach.net\\\/index.php\\\/lessons-from-botnet-demise\\\/#listItem\",\"position\":3,\"name\":\"Lessons From Botnet Demise\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/rbach.net\\\/index.php\\\/category\\\/security\\\/#listItem\",\"name\":\"Security\"}}]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/rbach.net\\\/#person\",\"name\":\"RB\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/rbach.net\\\/index.php\\\/lessons-from-botnet-demise\\\/#personImage\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/277b077a94c848430275fca45f1992aa413a6acb98e489f0d4ea5771d8cd99f1?s=96&d=mm&r=r\",\"width\":96,\"height\":96,\"caption\":\"RB\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/rbach.net\\\/index.php\\\/author\\\/administrator\\\/#author\",\"url\":\"https:\\\/\\\/rbach.net\\\/index.php\\\/author\\\/administrator\\\/\",\"name\":\"RB\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/rbach.net\\\/index.php\\\/lessons-from-botnet-demise\\\/#authorImage\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/277b077a94c848430275fca45f1992aa413a6acb98e489f0d4ea5771d8cd99f1?s=96&d=mm&r=r\",\"width\":96,\"height\":96,\"caption\":\"RB\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/rbach.net\\\/index.php\\\/lessons-from-botnet-demise\\\/#webpage\",\"url\":\"https:\\\/\\\/rbach.net\\\/index.php\\\/lessons-from-botnet-demise\\\/\",\"name\":\"Lessons From Botnet Demise | Bach Seat\",\"description\":\"Brian Krebs profiled a case where a bot-herder killed or kos command resident in the Zeus botnet crimeware that made the infected PC's BSOD\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/rbach.net\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/rbach.net\\\/index.php\\\/lessons-from-botnet-demise\\\/#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/rbach.net\\\/index.php\\\/author\\\/administrator\\\/#author\"},\"creator\":{\"@id\":\"https:\\\/\\\/rbach.net\\\/index.php\\\/author\\\/administrator\\\/#author\"},\"datePublished\":\"2009-05-09T16:26:15-04:00\",\"dateModified\":\"2022-12-30T12:11:35-05:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/rbach.net\\\/#website\",\"url\":\"https:\\\/\\\/rbach.net\\\/\",\"name\":\"Bach Seat\",\"description\":\"The view from where I am sitting\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/rbach.net\\\/#person\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"Lessons From Botnet Demise | Bach Seat","description":"Brian Krebs profiled a case where a bot-herder killed or kos command resident in the Zeus botnet crimeware that made the infected PC's BSOD","canonical_url":"https:\/\/rbach.net\/index.php\/lessons-from-botnet-demise\/","robots":"max-image-preview:large","keywords":"botnet,malware,security,zeus,brian krebs,denial-of-service attack,cyberwarfare,2009,dos,russia","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/rbach.net\/index.php\/lessons-from-botnet-demise\/#article","name":"Lessons From Botnet Demise | Bach Seat","headline":"Lessons From Botnet Demise","author":{"@id":"https:\/\/rbach.net\/index.php\/author\/administrator\/#author"},"publisher":{"@id":"https:\/\/rbach.net\/#person"},"image":{"@type":"ImageObject","url":"http:\/\/rbach.net\/wp-content\/uploads\/computer_zombies-150x138.jpg","@id":"https:\/\/rbach.net\/index.php\/lessons-from-botnet-demise\/#articleImage"},"datePublished":"2009-05-09T16:26:15-04:00","dateModified":"2022-12-30T12:11:35-05:00","inLanguage":"en-US","mainEntityOfPage":{"@id":"https:\/\/rbach.net\/index.php\/lessons-from-botnet-demise\/#webpage"},"isPartOf":{"@id":"https:\/\/rbach.net\/index.php\/lessons-from-botnet-demise\/#webpage"},"articleSection":"Security, 2009, Botnet, Brian Krebs, Cyberwarfare, Denial-of-service attack, DoS, Malware, Russia, Security, Zeus"},{"@type":"BreadcrumbList","@id":"https:\/\/rbach.net\/index.php\/lessons-from-botnet-demise\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/rbach.net#listItem","position":1,"name":"Home","item":"https:\/\/rbach.net","nextItem":{"@type":"ListItem","@id":"https:\/\/rbach.net\/index.php\/category\/security\/#listItem","name":"Security"}},{"@type":"ListItem","@id":"https:\/\/rbach.net\/index.php\/category\/security\/#listItem","position":2,"name":"Security","item":"https:\/\/rbach.net\/index.php\/category\/security\/","nextItem":{"@type":"ListItem","@id":"https:\/\/rbach.net\/index.php\/lessons-from-botnet-demise\/#listItem","name":"Lessons From Botnet Demise"},"previousItem":{"@type":"ListItem","@id":"https:\/\/rbach.net#listItem","name":"Home"}},{"@type":"ListItem","@id":"https:\/\/rbach.net\/index.php\/lessons-from-botnet-demise\/#listItem","position":3,"name":"Lessons From Botnet Demise","previousItem":{"@type":"ListItem","@id":"https:\/\/rbach.net\/index.php\/category\/security\/#listItem","name":"Security"}}]},{"@type":"Person","@id":"https:\/\/rbach.net\/#person","name":"RB","image":{"@type":"ImageObject","@id":"https:\/\/rbach.net\/index.php\/lessons-from-botnet-demise\/#personImage","url":"https:\/\/secure.gravatar.com\/avatar\/277b077a94c848430275fca45f1992aa413a6acb98e489f0d4ea5771d8cd99f1?s=96&d=mm&r=r","width":96,"height":96,"caption":"RB"}},{"@type":"Person","@id":"https:\/\/rbach.net\/index.php\/author\/administrator\/#author","url":"https:\/\/rbach.net\/index.php\/author\/administrator\/","name":"RB","image":{"@type":"ImageObject","@id":"https:\/\/rbach.net\/index.php\/lessons-from-botnet-demise\/#authorImage","url":"https:\/\/secure.gravatar.com\/avatar\/277b077a94c848430275fca45f1992aa413a6acb98e489f0d4ea5771d8cd99f1?s=96&d=mm&r=r","width":96,"height":96,"caption":"RB"}},{"@type":"WebPage","@id":"https:\/\/rbach.net\/index.php\/lessons-from-botnet-demise\/#webpage","url":"https:\/\/rbach.net\/index.php\/lessons-from-botnet-demise\/","name":"Lessons From Botnet Demise | Bach Seat","description":"Brian Krebs profiled a case where a bot-herder killed or kos command resident in the Zeus botnet crimeware that made the infected PC's BSOD","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/rbach.net\/#website"},"breadcrumb":{"@id":"https:\/\/rbach.net\/index.php\/lessons-from-botnet-demise\/#breadcrumblist"},"author":{"@id":"https:\/\/rbach.net\/index.php\/author\/administrator\/#author"},"creator":{"@id":"https:\/\/rbach.net\/index.php\/author\/administrator\/#author"},"datePublished":"2009-05-09T16:26:15-04:00","dateModified":"2022-12-30T12:11:35-05:00"},{"@type":"WebSite","@id":"https:\/\/rbach.net\/#website","url":"https:\/\/rbach.net\/","name":"Bach Seat","description":"The view from where I am sitting","inLanguage":"en-US","publisher":{"@id":"https:\/\/rbach.net\/#person"}}]},"og:locale":"en_US","og:site_name":"Bach Seat | The view from where I am sitting","og:type":"article","og:title":"Lessons From Botnet Demise","og:description":"Brian Krebs profiled a case where a bot-herder killed or kos command resident in the Zeus bot-net crimeware that which made the infected PC's BSOD","og:url":"https:\/\/rbach.net\/index.php\/lessons-from-botnet-demise\/","og:image":"https:\/\/rbach.net\/wp-content\/uploads\/computer_zombies-150x138.jpg","og:image:secure_url":"https:\/\/rbach.net\/wp-content\/uploads\/computer_zombies-150x138.jpg","article:published_time":"2009-05-09T20:26:15+00:00","article:modified_time":"2022-12-30T17:11:35+00:00","article:publisher":"https:\/\/www.facebook.com\/ralph.bach.14","twitter:card":"summary_large_image","twitter:site":"@rbach48334","twitter:title":"Lessons From Botnet Demise","twitter:description":"Brian Krebs profiled a case where a bot-herder killed or kos command resident in the Zeus bot-net crimeware that which made the infected PC's BSOD","twitter:creator":"@rbach48334","twitter:image":"http:\/\/rbach.net\/wp-content\/uploads\/computer_zombies-150x138.jpg"},"aioseo_meta_data":{"post_id":"565","title":"#post_title #separator_sa #site_title&nbsp;","description":"#post_excerpt","keywords":[{"label":"Botnet","value":"Botnet"},{"label":"Malware","value":"Malware"},{"label":"Security","value":"Security"},{"label":"Zeus","value":"Zeus"},{"label":"Brian Krebs","value":"Brian Krebs"},{"label":"Denial-of-service attack","value":"Denial-of-service attack"},{"label":"Cyberwarfare","value":"Cyberwarfare"}],"keyphrases":{"focus":{"keyphrase":"botnet","score":93,"analysis":{"keyphraseInTitle":{"title":"Focus Keyphrase in SEO title","description":"Focus Keyphrase found in SEO title.","score":9,"maxScore":9,"error":0},"keyphraseInDescription":{"title":"Focus keyphrase in meta description","description":"Focus keyphrase found in meta description.","score":9,"maxScore":9,"error":0},"keyphraseInURL":{"title":"Focus Keyphrase in URL","description":"Focus Keyphrase not found in the URL.","score":1,"maxScore":5,"error":1},"keyphraseLength":{"title":"Focus keyphrase length","description":"Good job!","score":9,"maxScore":9,"error":0,"length":1},"keyphraseInIntroduction":{"title":"Focus keyphrase in introduction","description":"Your Focus keyphrase appears in the first paragraph. Well done!","score":9,"maxScore":9,"error":0},"keyphraseInSubHeadings":{"title":"Focus Keyphrase in Subheadings","description":"Your H2 and H3 subheadings reflects the topic of your copy. Good job!","score":9,"maxScore":9,"error":0},"keyphraseInImageAlt":{"title":"Focus keyphrase in image alt attributes","description":"Focus keyphrase found in image alt attribute(s).","score":9,"maxScore":9,"error":0}}},"additional":[]},"primary_term":null,"canonical_url":null,"og_title":"Lessons From Botnet Demise","og_description":"Brian Krebs profiled a case where a bot-herder killed or kos command resident in the Zeus bot-net crimeware that which made the infected PC's BSOD","og_object_type":"article","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":"","og_custom_url":null,"og_article_section":null,"og_article_tags":[],"twitter_use_og":false,"twitter_card":"summary_large_image","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[],"defaultGraph":"Article","defaultPostTypeGraph":""},"schema_type":"default","schema_type_options":"{\"article\":{\"articleType\":\"BlogPosting\"},\"course\":{\"name\":\"\",\"description\":\"\",\"provider\":\"\"},\"faq\":{\"pages\":[]},\"product\":{\"reviews\":[]},\"recipe\":{\"ingredients\":[],\"instructions\":[],\"keywords\":[]},\"software\":{\"reviews\":[],\"operatingSystems\":[]},\"webPage\":{\"webPageType\":\"WebPage\"}}","pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":"-1","robots_max_videopreview":"-1","robots_max_imagepreview":"large","priority":null,"frequency":"default","location":null,"local_seo":{"locations":{"business":{"name":"","businessType":"","image":"","areaServed":"","urls":{"website":"","aboutPage":"","contactPage":""},"address":{"streetLine1":"","streetLine2":"","zipCode":"","city":"","state":"","country":"","addressFormat":"#streetLineOne\n#streetLineTwo\n#city, #state #zipCode"},"contact":{"email":"","phone":"","phoneFormatted":"","fax":"","faxFormatted":""},"ids":{"vat":"","tax":"","chamberOfCommerce":""},"payment":{"priceRange":"","currenciesAccepted":"","methods":""}}},"openingHours":{"useDefaults":true,"show":true,"alwaysOpen":false,"use24hFormat":false,"timezone":"","labels":{"closed":"","alwaysOpen":""},"days":{"monday":{"open24h":false,"closed":false,"openTime":"09:00","closeTime":"17:00"},"tuesday":{"open24h":false,"closed":false,"openTime":"09:00","closeTime":"17:00"},"wednesday":{"open24h":false,"closed":false,"openTime":"09:00","closeTime":"17:00"},"thursday":{"open24h":false,"closed":false,"openTime":"09:00","closeTime":"17:00"},"friday":{"open24h":false,"closed":false,"openTime":"09:00","closeTime":"17:00"},"saturday":{"open24h":false,"closed":false,"openTime":"09:00","closeTime":"17:00"},"sunday":{"open24h":false,"closed":false,"openTime":"09:00","closeTime":"17:00"}}}},"breadcrumb_settings":null,"limit_modified_date":false,"ai":null,"created":"2020-12-21 03:46:49","updated":"2022-09-13 19:17:21","seo_analyzer_scan_date":null},"_links":{"self":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts\/565","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/comments?post=565"}],"version-history":[{"count":6,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts\/565\/revisions"}],"predecessor-version":[{"id":132759,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts\/565\/revisions\/132759"}],"wp:attachment":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/media?parent=565"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/categories?post=565"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/tags?post=565"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}