<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Another Big Botnet</title>
	<atom:link href="http://blog.eset.com/2009/04/22/another-big-botnet/feed" rel="self" type="application/rss+xml" />
	<link>http://blog.eset.com/2009/04/22/another-big-botnet</link>
	<description></description>
	<lastBuildDate>Sun, 12 Feb 2012 22:29:08 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: David Harley</title>
		<link>http://blog.eset.com/2009/04/22/another-big-botnet/comment-page-1#comment-44742</link>
		<dc:creator>David Harley</dc:creator>
		<pubDate>Mon, 27 Apr 2009 08:14:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.eset.com/threat-center/blog/?p=995#comment-44742</guid>
		<description>I couldn&#039; t possibly comment. Though according to Finjan I already have. ;-)</description>
		<content:encoded><![CDATA[<p>I couldn&#8217; t possibly comment. Though according to Finjan I already have. <img src='http://blog.eset.com/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jcanto</title>
		<link>http://blog.eset.com/2009/04/22/another-big-botnet/comment-page-1#comment-44725</link>
		<dc:creator>jcanto</dc:creator>
		<pubDate>Mon, 27 Apr 2009 06:13:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.eset.com/threat-center/blog/?p=995#comment-44725</guid>
		<description>this situation indeed deserves the holy trinity of acronyms</description>
		<content:encoded><![CDATA[<p>this situation indeed deserves the holy trinity of acronyms</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: VITALIKG</title>
		<link>http://blog.eset.com/2009/04/22/another-big-botnet/comment-page-1#comment-44466</link>
		<dc:creator>VITALIKG</dc:creator>
		<pubDate>Fri, 24 Apr 2009 16:43:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.eset.com/threat-center/blog/?p=995#comment-44466</guid>
		<description>!)</description>
		<content:encoded><![CDATA[<p>!)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: David Harley</title>
		<link>http://blog.eset.com/2009/04/22/another-big-botnet/comment-page-1#comment-44443</link>
		<dc:creator>David Harley</dc:creator>
		<pubDate>Fri, 24 Apr 2009 10:52:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.eset.com/threat-center/blog/?p=995#comment-44443</guid>
		<description>Indeed you&#039;re not. :-D</description>
		<content:encoded><![CDATA[<p>Indeed you&#8217;re not. <img src='http://blog.eset.com/wp-includes/images/smilies/icon_biggrin.gif' alt=':-D' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Atif Mushtaq</title>
		<link>http://blog.eset.com/2009/04/22/another-big-botnet/comment-page-1#comment-44408</link>
		<dc:creator>Atif Mushtaq</dc:creator>
		<pubDate>Fri, 24 Apr 2009 03:04:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.eset.com/threat-center/blog/?p=995#comment-44408</guid>
		<description>Today, I visited RSA and got a chance to talk to Finjan&#039;s representatives there. I talked to them about the same confusion but they refused to comment on this topic saying, they are working with law enforcement agencies so they cannot reveal more information at this moment. When I asked them at least tell me the name of this mysterious botnet. They said we have already mentioned botnet name in our article...I said I am asking about malware which downloaded Hexzone not hexzone itself ..as stated by you guysâ€¦. 

Guy there thought for a second and said again..
We are working with law enforcement agencies, so cannot release more information at this :)

I am relieved now; I am not the only one who is confused here...;)</description>
		<content:encoded><![CDATA[<p>Today, I visited RSA and got a chance to talk to Finjan&#8217;s representatives there. I talked to them about the same confusion but they refused to comment on this topic saying, they are working with law enforcement agencies so they cannot reveal more information at this moment. When I asked them at least tell me the name of this mysterious botnet. They said we have already mentioned botnet name in our article&#8230;I said I am asking about malware which downloaded Hexzone not hexzone itself ..as stated by you guysâ€¦. </p>
<p>Guy there thought for a second and said again..<br />
We are working with law enforcement agencies, so cannot release more information at this <img src='http://blog.eset.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>I am relieved now; I am not the only one who is confused here&#8230;;)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: David Harley</title>
		<link>http://blog.eset.com/2009/04/22/another-big-botnet/comment-page-1#comment-44325</link>
		<dc:creator>David Harley</dc:creator>
		<pubDate>Thu, 23 Apr 2009 15:55:54 +0000</pubDate>
		<guid isPermaLink="false">http://www.eset.com/threat-center/blog/?p=995#comment-44325</guid>
		<description>Thanks for that. Yes, I think that&#039;s probably a more accurate way of looking at it.</description>
		<content:encoded><![CDATA[<p>Thanks for that. Yes, I think that&#8217;s probably a more accurate way of looking at it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Atif Mushtaq</title>
		<link>http://blog.eset.com/2009/04/22/another-big-botnet/comment-page-1#comment-44323</link>
		<dc:creator>Atif Mushtaq</dc:creator>
		<pubDate>Thu, 23 Apr 2009 15:32:08 +0000</pubDate>
		<guid isPermaLink="false">http://www.eset.com/threat-center/blog/?p=995#comment-44323</guid>
		<description>I think we are mis-reading the Finjan&#039; article here , here is what Finjan said... 

&quot;This command instructs the bot on the infected computers to download and execute a Trojan horse. As indicates on the VirusTotal report below, only 4 out of 39 Anti-Virus products detected this Trojan.&quot; // Hexzone

They did not give any detail about the parent dropper (unnamed botnet of size 1.9 million) which downloaded HexZone. It&#039;s so confusing that all people started thinking this botnet as the HexZone......Hexzone along with other trojan like Win32.AutoIt seems only the secondary download..</description>
		<content:encoded><![CDATA[<p>I think we are mis-reading the Finjan&#8217; article here , here is what Finjan said&#8230; </p>
<p>&#8220;This command instructs the bot on the infected computers to download and execute a Trojan horse. As indicates on the VirusTotal report below, only 4 out of 39 Anti-Virus products detected this Trojan.&#8221; // Hexzone</p>
<p>They did not give any detail about the parent dropper (unnamed botnet of size 1.9 million) which downloaded HexZone. It&#8217;s so confusing that all people started thinking this botnet as the HexZone&#8230;&#8230;Hexzone along with other trojan like Win32.AutoIt seems only the secondary download..</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pierre-Marc Bureau</title>
		<link>http://blog.eset.com/2009/04/22/another-big-botnet/comment-page-1#comment-44313</link>
		<dc:creator>Pierre-Marc Bureau</dc:creator>
		<pubDate>Thu, 23 Apr 2009 13:09:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.eset.com/threat-center/blog/?p=995#comment-44313</guid>
		<description>Thanks for your comments gh and Henk.

I have to clarify the situation regarding the number of detection I have included in my previous blog post.  It appears to bring more confusion than valuable information to our readers.

Instead of total number of detection, I should have used the ratio of detection.  For the Win32/Hexzone family, this ratio is 0.1%, that is very small compared to Conficker which receives almost 20%.</description>
		<content:encoded><![CDATA[<p>Thanks for your comments gh and Henk.</p>
<p>I have to clarify the situation regarding the number of detection I have included in my previous blog post.  It appears to bring more confusion than valuable information to our readers.</p>
<p>Instead of total number of detection, I should have used the ratio of detection.  For the Win32/Hexzone family, this ratio is 0.1%, that is very small compared to Conficker which receives almost 20%.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: David Harley</title>
		<link>http://blog.eset.com/2009/04/22/another-big-botnet/comment-page-1#comment-44301</link>
		<dc:creator>David Harley</dc:creator>
		<pubDate>Thu, 23 Apr 2009 12:50:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.eset.com/threat-center/blog/?p=995#comment-44301</guid>
		<description>Hi, Henk. Virus Radar only measures email-borne malware, and doesn&#039;t generally include malware found on malicious web sites referenced by malicious messages. Malicious attachments have been decreasing dramatically in volume for years now, and very little new malware is disseminated that way. Also, the page you&#039;re looking at is only showing the email-borne malware flagged over the last 24 hours: it doesn&#039;t represent in any way the totality of what we detect. 

I&#039;m afraid the resource Pierre was referring to isn&#039;t publicly available in realtime, though we do use the figures - as percentages and indicators, not absolute figures - in our monthly/annual/semi-annual reports. That&#039;s partly because it is very easy for people to misinterpret.</description>
		<content:encoded><![CDATA[<p>Hi, Henk. Virus Radar only measures email-borne malware, and doesn&#8217;t generally include malware found on malicious web sites referenced by malicious messages. Malicious attachments have been decreasing dramatically in volume for years now, and very little new malware is disseminated that way. Also, the page you&#8217;re looking at is only showing the email-borne malware flagged over the last 24 hours: it doesn&#8217;t represent in any way the totality of what we detect. </p>
<p>I&#8217;m afraid the resource Pierre was referring to isn&#8217;t publicly available in realtime, though we do use the figures &#8211; as percentages and indicators, not absolute figures &#8211; in our monthly/annual/semi-annual reports. That&#8217;s partly because it is very easy for people to misinterpret.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: David Harley</title>
		<link>http://blog.eset.com/2009/04/22/another-big-botnet/comment-page-1#comment-44299</link>
		<dc:creator>David Harley</dc:creator>
		<pubDate>Thu, 23 Apr 2009 12:11:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.eset.com/threat-center/blog/?p=995#comment-44299</guid>
		<description>That 140,000 doesn&#039;t refer to the total number of Hexzone-infected machines. It refers to the number of attempts to infect  machines protected by ESET products. ESET users can opt to allow the software to &quot;call home&quot; when it recognizes malware. In other words, these figures provide some indication of how active a given malicious program is compared to other malicious code, not  overall figures. In this case, they simply suggest that Hexzone is out there in far lower volumes than some of our other detections.

If you check out , you&#039;ll find a likely explanation for the disparity between the dramatic size and rate of spread figures suggested by Finjan compared to the impact that we and others are seeing.</description>
		<content:encoded><![CDATA[<p>That 140,000 doesn&#8217;t refer to the total number of Hexzone-infected machines. It refers to the number of attempts to infect  machines protected by ESET products. ESET users can opt to allow the software to &#8220;call home&#8221; when it recognizes malware. In other words, these figures provide some indication of how active a given malicious program is compared to other malicious code, not  overall figures. In this case, they simply suggest that Hexzone is out there in far lower volumes than some of our other detections.</p>
<p>If you check out , you&#8217;ll find a likely explanation for the disparity between the dramatic size and rate of spread figures suggested by Finjan compared to the impact that we and others are seeing.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

