Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

In 2013, Poland’s NASK and CERT Polska took control of 43 .pl domains used by the Virut botnet and redirected its command-and-control traffic to a sinkhole. That disrupted a route the criminals used to reach infected computers and allowed researchers to observe connections—but it did not remove Virut from those computers.

What happened to the Virut botnet?

NASK, operator of Poland’s .pl country-code domain registry, and CERT Polska took control of 43 .pl domains used to control Virut and distribute malicious applications. CERT Polska redirected traffic aimed at the botnet’s command-and-control (C&C) infrastructure to a server it controlled. CERT Polska’s 2013 annual report summarized the action: “In January and February 2013 NASK took over 43 .pl domains used to control the Virut botnet and to spread malicious applications.” CERT Polska’s contemporary Virut botnet report and its 2013 annual report describe the operation.

How did the takedown work?

Domain control redirected bot traffic

The operation began with control of domains that Virut-infected systems contacted. NASK’s domain-level action changed where those names led, redirecting the malware’s traffic away from criminal infrastructure. This step interrupted the botmasters’ access through those domains; it did not itself alter or clean files on victims’ computers.

The sinkhole received and emulated C&C traffic

A sinkhole is a server controlled by defenders that receives traffic redirected from malicious infrastructure. CERT Polska prepared one to emulate aspects of Virut’s C&C behavior. The redirection hindered the criminals’ ability to use that route to communicate with bots and gave researchers a way to observe connections and estimate activity. Sinkholing is a network-level disruption and measurement technique, not endpoint disinfection. See CERT Polska’s explanation of sinkholing and its technical account of the domain takeover.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What did CERT Polska observe?

Daily connections and geographic distribution

CERT Polska reported an average of about 270,000 unique IP addresses connecting to the sinkhole each day. This was the organization’s estimate of botnet activity during the 2013 operation, not a precise count of infected computers: multiple devices can share an IP address, and one device’s address can change. The report placed nearly half of the observed infected machines in Egypt, Pakistan, and India combined, while Poland ranked 19th. These are historical observations from CERT Polska’s 2013 reporting, not figures for current infections. The contemporary report gives the estimates.

Why the timeline is not a single uncontested date

The detailed technical account says the first 23 domains were transferred and redirected on 17 January 2013; another 15 were handled on 18 January, with their transfer finalized on 21 January; and the final five were transferred by 6 February. The annual report instead says the takeover started on 23 January. The contemporary summary frames the operation broadly as taking place in January and February. Because the official accounts differ on the start date, the safest description is that the operation unfolded in late January and early February 2013, involving 43 domains. The annual report and the technical account provide the differing chronologies.

Rank #2
FixMeStick Gold Computer Virus Removal Stick for Windows PCs - Unlimited Use on Up to 5 Laptops or Desktops for 2 Years - Works with Your Antivirus
  • WHAT YOU GET: FixMeStick Virus Removal Tool for Windows PCs (Windows XP, Vista, 7, 8, 8.1, 10, and 11. 512 MB RAM required), Getting Started Guide, our virus removal guarantee backed by our friendly Canadian based Customer Support Team.

How Virut infected computers and what it did

Infection routes and communications

CERT Polska’s technical report describes Virut spreading by infecting files, arriving bundled with other malicious software, and using modified HTML to trigger drive-by downloads through vulnerable browsers or browser components. It also documents an attack on an RPC service. Once running, Virut connected to attacker-controlled IRC servers and could receive commands to download and run executables.

The analyzed versions used IRC or IRC-like communications; some traffic was encrypted with a nonstandard stream cipher. The technical report observed C&C-related traffic on TCP ports 80 and 65520. These details describe the samples and infrastructure CERT Polska analyzed, not necessarily every version of Virut. Some versions had fallback domains or a domain generation algorithm; one analyzed version generated 100 six-letter .com names based on the infected system’s date. CERT Polska’s technical report explains these behaviors.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Uses attributed to the botnet

CERT Polska’s reports describe Virut being used for data theft, spam, distributed denial-of-service (DDoS) activity, and activity connected with fake antivirus distribution. The technical report also describes injecting advertisements into displayed content. The 2013 report distinguished more than 20 Virut versions and observed infections across eight Windows versions, from Windows 98 through Windows 8; those are the report’s historical findings, not an assessment of current Windows exposure. The contemporary summary and annual report document the findings.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Did the takedown remove Virut from infected computers?

No. The documented action took control of domains and redirected traffic; CERT Polska’s accounts do not say that the operation cleaned infected machines. A sinkhole can disrupt communications and help defenders observe infected systems, but removing malware from an endpoint is a separate remediation task. The reports establish a domain-level disruption and traffic analysis, not that every host was disinfected or that Virut permanently disappeared.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.