Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - Not All Botnets Are Treated Equally: Brobot in Action
News & Analysis

Not All Botnets Are Treated Equally: Brobot in Action

ISBuzz TeamBy ISBuzz TeamJuly 3, 2014Updated:July 10, 20144 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
botnet
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Last week, DOSarrest had a run in with the notorious Brobot Botnet. If the name sounds familiar, it’s because this bot was responsible for sporadic outages on a number of large US based financial institutions in 2013. It is said to be operated by al-Qassam Cyber Fighters (AKA QCF).

Botnets are born, die, grow, shrink, and morph on a daily, if not hourly, basis and it is extremely hard to keep track of them all. There are particularly nasty ones that are large, powerful and sophisticated. To keep track of them, they will have some of their zombies or bots corralled off for research purposes by a number of organizations, including private Botnet hunters, government cyber surveillance departments and other large law enforcement agencies.

The attack

A large media outlet specializing in Middle Eastern news was attacked last week.

With all the conflict over there these days, it is suspected that it has written a few stories that the attackers were not in agreement with.

Using Brobot, the attackers threw millions of TCP port 80 requests at the website.

Unlike a SYN attack that tries to exhaust the TCP open sessions table buffers, this attack would open and close each session/request:

1)   Request a TCP connection

2)   Once established they would send one character

3)   Then request the TCP session to close.

The major problem arose when they started receiving approximately 50 million of these per second.

This botnet is comprised of infected webservers using PHP, hosted on various webhosting companies around the globe.

One notable observation of the Brobot is that it’s US centric; while not all of the bots are based in the US, approximately 40% are, which makes filtering based on countries very difficult.

When under a large TCP port 80 attack, it usually is not evenly divided across DOSarrest’s scrubbing nodes in the US and Europe. This attack was different; virtually all of the upstream links in every city had pretty much the same amount of Packets Per Second and Bandwidth. This is extremely unusual.

Brobot Botnet

All links appeared almost exactly like the graph above

The upshot

DOSarrest was able to successfully defend against this attack and within a couple of hours of the attack starting it was contacted by a private Botnet hunter that knew the company was dealing with Brobot. This was soon followed by visits to the DOSarrest website from two US federal Law enforcement agencies. This proves for certain that not all botnets are equal, as not all of them would attract this much attention.

By Mark Teolis, General Manager for DOSarrest

About DOSarrest

DOSarrest is the result of seven years of research, experimentation and mitigation of malicious traffic. In the last seven years, we have formed a dedicated team of network security specialists, network engineers and developers focused on mitigating DoS/DDoS attacks. Solving the DDoS problem is like a never ending cat and mouse game with attackers.

– See more at: http://www.dosarrest.com/company/#sthash.FgPkMnVJ.dpuf

DOSarrest is the result of seven years of research, experimentation and mitigation of malicious traffic. In the last seven years, we have formed a dedicated team of network security specialists, network engineers and developers focused on mitigating DoS/DDoS attacks. Solving the DDoS problem is like a never ending cat and mouse game with attackers.

– See more at: http://www.dosarrest.com/company/#sthash.FgPkMnVJ.dpuf

DOSarrest is the result of seven years of research, experimentation and mitigation of malicious traffic. In the last seven years, we have formed a dedicated team of network security specialists, network engineers and developers focused on mitigating DoS/DDoS attacks. Solving the DDoS problem is like a never ending cat and mouse game with attackers. – See more at: http://www.dosarrest.com/company/#sthash.FgPkMnVJ.dpuf

DOSarrestDOSarrest is a true, cloud-based fully managed DDoS protection service specializing in DDoS Protection. Its layered protection strategy evaluates complex attacks on a request-by-request basis, so there is never a false positive. Also, its proprietary mitigation methods and techniques have successfully and instantly stopped thousands of real-world DDoS attacks since 2007.

DOSarrest is the result of seven years of research, experimentation and mitigation of malicious traffic. In the last seven years, we have formed a dedicated team of network security specialists, network engineers and developers focused on mitigating DoS/DDoS attacks. Solving the DDoS problem is like a never ending cat and mouse game with attackers.

– See more at: http://www.dosarrest.com/company/#sthash.FgPkMnVJ.dpuf

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

How to Protect Your VoIP System from DDoS Attacks

September 9, 20258 Mins Read

Pro-Russian Cybercrime Group NoName057(16) Hit Hard in Global Takedown

July 18, 20255 Mins Read

Roundcube RCE Vulnerability Disclosed Early Amid Active Exploitation

June 10, 20255 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}