Posted on Thursday, April 17th, 2008 | Bookmark on del.icio.us

Loads.CC Bot Still Live, Still Targeted

by Jose Nazario

Enough has been written about the Loads.CC team to probably give you enough of a picture that you need to know. Some reports suggested they went away, but they didn’t. They’re still active. See these reports by RBN exploit, CIO magazine, 2-viruses.com, this PC Week article by Scott B, and Adam T for a good background. The team is still quite active.

They came up in some analysis earlier this week when we looked at an infection chain. I started digging and found that they’re still churning out new malware install sites with great regularity:

loads.cc new URLs since jan 1 2008

Loads.CC URLs (manda.php) since Jan 1, 2008

They’re spreading their efforts around the world, which makes sense. Some of these countries have become hotbeds of malicious website activity, as they have lax controls and ISPs don’t respond to takedown requests.

loads.cc activity by malicious website hosting country since jan 1 2008

Loads.CC activity by website hosting country

Here’s the kicker: someone really wants these guys out of business. Still. Even though the Loads.CC domain name now points to nowhere. Here’s DDoS attacks we’ve been tracking against their domain name this year alone.

ddos attacks commanded against loads.cc over time
DDoS attacks targeting Loads.CC this year so far

It’s interesting to watch these ’skirmishes’ in the malware communities.

2 Responses | Add your own



Comment Post by: Ruslan Stoyanov — April 18th, 2008 @ 8:54 am EST  Reply

Contact Interface of load.cc team:

http://zaebal-ddos.com/
and ICQ UIN for conformation: 100155

Comment Post by: Andrew Hay » Blog Archive » Suggested Blog Reading - Sunday April 20th, 2008 — April 20th, 2008 @ 9:53 pm EST  Reply

[...] Loads.CC Bot Still Live, Still Targeted - More info about the Loads.CC bot that you should probably check out. Enough has been written about the Loads.CC team to probably give you enough of a picture that you need to know. Some reports suggested they went away, but they didn’t. They’re still active. See these reports by RBN exploit, CIO magazine, 2-viruses.com, this PC Week article by Scott B, and Adam T for a good background. The team is still quite active. [...]

Leave a Comment