Showing posts with label Malware. Show all posts
Showing posts with label Malware. Show all posts

What is Zeus - Technical paper

Zeus or Zbot is one of the most notorious and widely-spread information stealing Trojans in existence. Zeus is primarily targeted at financial data theft; its effectiveness has lead to the loss of millions worldwide. The spectrum of those impacted by Zbot infections ranges from individuals who have had their banking details compromised, to large public order departments of prominent western governments.

We will explore the various components of the Zeus kit from the Builder through to the configuration file; examine in detail the functionality and behaviour of the Zbot binary; and assess emerging and future trends in the Zeus world.


Download: PDF

YARA v.1.5 released

A malware identification and classification tool

YARA is a tool aimed at helping malware researchers to identify and classify malware samples. With YARA you can create descriptions of malware families based on textual or binary patterns contained on samples of those families. Each description consists of a set of strings and a Boolean expression which determines its logic.
YARA is multi-platform, running on Windows, Linux and Mac OS X, and can be used through its command-line interface or from your own Python scripts with the yara-python extension.

This version provides some new features, including:
* Process memory scanning
* Support for ELF files
* Faster regular expressions by using RE2 instead of PCRE

Download and more info: http://code.google.com

Botnets: Measurement, Detection, Disinfection and Defence


�Botnets: Measurement, Detection, Disinfection and Defence� is a comprehensive report on how to assess botnet threats and how to neutralise them. It is survey and analysis of methods for measuring botnet size and how best to assess the threat posed by botnets to different stakeholders. It includes a comprehensive set of 25 different types of best-practices to measure, detect and defend against botnets from all angles. The countermeasures are divided into 3 main areas: neutralising existing botnets, preventing new infections and minimising the profitability of cybercrime using botnets. The recommendations cover legal, policy and technical aspects of the fight against botnets and give targeted recommendations for different groups.

Download: PDF

Symantec Report on Attack Kits and Malicious Websites

Attack toolkits are bundles of malicious code tools used to facilitate the launch of concerted and widespread attacks on networked computers. Also known as crimeware, these kits are usually composed of prewritten malicious code for exploiting vulnerabilities along with various tools to customize, deploy, and automate widespread attacks, such as command-and-control (C&C) server administration tools.

As with a majority of malicious code in the threat landscape, attack kits are typically used to enable the theft of sensitive information or to convert compromised computers into a network of zombie bots (botnet) in order to mount additional attacks. These kits are advertised and sold in the online underground economy�a black market of servers and forums used to advertise and trade stolen information and services.
Symantec has found that attack kits are significantly advancing the evolution of cybercrime into a self-sustaining, profitable, and increasingly organized economic model worth millions of dollars.


Download: PDF

Attack Toolkits and Malicious Websites SlideShare

Symantec Attack Kit Evolution Timeline

PandaLabs Annual Report 2010


In 2010, cyber-criminals have created and distributed a third of all existing viruses. That is, in just 12 months, they have created 34 percent of all malware that has ever existed and has been classified by the company. Furthermore, the Collective Intelligence system, which automatically detects, analyzes and classifies 99.4 percent of all malware received, currently stores 134 million unique files, out of which 60 million are malware (viruses, worms, Trojans and other computer threats).

Trojans still dominate the ranking of new malware that has appeared in 2010 (56 percent of all samples), followed by viruses and worms. It is interesting to note that 11.6 percent of all the malware gathered in the Collective Intelligence database is rogueware or fake antivirus software, a malware category that despite appearing only four years ago is creating much havoc among users.


Download: PDF

Koobface: Inside a Crimeware Network

Introduction
There are numerous computer systems around the world that are under the control of malicious actors.These compromised computers,often known as zombies,form a botnet that receives and executes commands from botnet operators who harvest passwords,credit card numbers,and sensitive information from the zombies.Botnet operators also put the �zombies� to work by forcing them to send spam messages,create fraudulent accounts,and host malicious files.Rather than relying on sophisticated technical exploits,some botnet operators simply trick users into compromising themselves.Through fake Web sites,users are encouraged to download malicious software masquerading as benign.Sometimes,these fake,malicious Web sites are sent to users by their contacts on social networking sites.The rise of social networking tools has given attackers a platform to exploit the trust that individuals have in one another.People are much more likely to execute a malicious file if it has been sent to them by someone they know and trust.The information that individuals post online and the interests contained within their profile information can also be used to lure individuals into executing malicious software.Koobface is a botnet that leverages social networking platforms to propagate.

The operators of the botnet(known as Ali Baba and 40 LLC)have developed a system that uses social networking platforms,such as Bebo,Facebook,Friendster,Fubar,Hi5,MySpace,Netlog,Tagged,Twitter,and Yearbook,to send messages containing malicious links.These links are often concealed using the URL shortening service bit.ly and sometimes redirects to Blogspot blogs that redirect users to false YouTube pages hosted on compromised Web servers. These pages encourage users to download malicious software masquerading as a video codec or a software upgrade.Koobface also uses search engine optimization (SEO) techniques that allow these malicious sites to be listed highly in search engine results for popular search terms.


Download: PDF

The Zeus malware R&D program

Trusteer captured and analyzed a new version (2.1) of the Zeus financial malware and found that it has added sophisticated new mechanisms to commit online fraud and remain the Trojan of choice for criminals.

Zeus has not only improved its business logic but also its ability to avoid detection and automatic analysis by antivirus vendors. Zeus is under the spotlight of security vendors, banks, and law enforcement, which forces its developers to continually improve it to avoid losing business to competing malware like Bugat, Clampi, and SpyEye.Just like commercial application developers, the creators of Zeus run an R&D program to ensure it can avoid detection and side-step the growing number of IT security mechanisms designed to detect, block and eliminate it.

More about Zeus v2.1: http://www.net-security.org

Mumba Botnet Disclosed

The Mumba botnet, so called because of some funky attributes our researchers found on the server, was created by one of the most sophisticated group of cybercriminals on the internet known as the Avalanche Group.

This group has perfected a mass-production system for deploying phishing sites and data stealing malware. Mumba uses the latest version of Zeus, currently one of the most common malwares and infected 55,000 computers worldwide.Of course, the longer cyber criminals can keep their botnets out in the open the more money they make, so they invest a great deal of time and resources in protecting their systems and hiding their servers from detection by security researchers and law enforcement officials.

This was certainly the case with the Mumba botnet, which was extremely effective at harvesting web users data. The full report, which can be downloaded from this blog, shows that the Mumba botnet was responsible for stealing more than 60 gigabytes of personal data from people, including their details from social networking websites, bank account details, credit card numbers and emails.
The United States had the highest share of PCs infected by the Mumba botnet (33 percent), followed by Germany (17 percent), Spain (7 percent), United Kingdom (6 percent), Mexico and Canada (both 5 percent).

Download Revised Mumba Botnet Whitepaper

Botnet with integrated copy protection

The current version of the ZeuS botnet uses classical copy protection mechanisms to prevent the use of unlicensed pirate copies. ZeuS is a malware toolkit used, for instance, to steal online banking data. The basic version currently costs about $3,000 to $4,000.

Security firm SecureWorks has discovered that the ZeuS server only works with a system specific key. Similar to the Windows OS, the malware creates a kind of fingerprint of the respective hardware configuration when first started. The vendor then provides the user with a personalised licence key for this configuration.

The ZeuS server is responsible for controlling the botnet. It communicates with the infected computers � the bots �, it receives the data they provide and issues commands, etc. The client software injected on victims' systems of course does not require a licence key. Extensive division of labour has existed in the malware scene for some time. Many gangs use the professional ZeuS software which is modular and can � for a fee � be extended to include, for instance, different Windows versions or browsers. By using a licence management system, the product has reached a new level of professionalism.

Source: h-online

iPhone Botnet Analysis

SRI's Malware Threat Center has published an excellent analysis of the iPhone botnet that we covered in a diary a few weeks ago. Here is the abstract:

We present an analysis of the iKee.B (duh) Apple iPhone bot client, captured on 25 November 2009. The bot client was released throughout several countries in Europe, with the initial purpose of coordinating its infected iPhones via a Lithuanian botnet server. This report details the logic and function of iKee's scripts, its configuration files, and its two binary executables, which we have reverse engineered to an approximation of their C source code implementation. The iKee bot is one of the latest offerings in smartphone malware, in this case targeting jailbroken iPhones. While its implementation is simple in comparison to the latest generation of PC-based malware, its implications demonstrate the potential extension of crimeware to this valuable new frontier of handheld consumer devices.


Source: http://isc.sans.org

Zbot Targets Major Banks Across the World

At Virus Bulletin, we presented on some of the nastiest families of 2009, and zbot was one of them. Early Sunday morning was the first that the ThreatFire community started seeing a newer variant of the banking password stealing family "Zbot" in fairly high prevalence, served on a system hosted in Sweden (83.140.191.170). This variant is interesting in that it indiscriminately targets banks all over the world -- the U.S., Germany, Italy, Spain, Russia, England, Ireland, etc. (the ThreatExpert report lists the banking sites here), but the users being attacked appear to be concentrated within the U.S. for now.

Source:threatfire.com

The economics of Botnets


In the past ten years, botnets have evolved from small networks of a dozen PCs controlled from a single C&C (command and control center) into sophisticated distributed systems comprising millions of computers with decentralized control. Why are these enormous zombie networks created? The answer can be given in a single word: money.

A botnet, or zombie network, is a network of computers infected with a malicious program that allows cybercriminals to control the infected machines remotely without the users� knowledge. Zombie networks have become a source of income for entire groups of cybercriminals. The invariably low cost of maintaining a botnet and the ever diminishing degree of knowledge required to manage one are conducive to growth in popularity and, consequently, the number of botnets.

So how does one start? What does a cybercriminal in need of a botnet do? There are many possibilities, depending on the criminal�s skills. Unfortunately, those who decide to set up a botnet from scratch will have no difficulty finding instructions on the Internet.

You can simply create a new zombie network. This involves infecting computers with a special program called a bot. Bots are malicious programs that unite compromised computers into botnets. If someone who wants to start a �business� has no programming skills, there are plenty of �bot for sale� offers on forums. Obfuscation and encryption of these programs� code can also be ordered in the same way in order to protect them from detection by antivirus tools. Another option is to steal an existing botnet.

The cybercriminal�s next step is to infect user machines with bot malware. This is done by sending spam, posting messages on user forums and social networks, or via drive-by downloads. Alternatively, the bot itself can include self-replication functionality, like viruses and worms.

Read More on viruslist.com

The Golden Cash Botnet

Security services provider Finjan has released a report from its Malicious Code Research Center analysing a trading platform for botnets. According to the report, the underground trade in infected computers offers a comprehensive menu of botnets at locations all around the world. Some Far Eastern networks can be had for a mere $5 a thousand PCs.

Criminals can buy and sell botnets on the "Golden Cash" platform (tagline: Your Money Making Machine). Prices vary according to the botnet's location. Whilst 1,000 zombie PCs in Japan can be picked up at bargain basement prices, buyers wanting a botnet, for example, in Australia will have to pay up to $100 for 1,000 computers. Criminals can also place orders for specific botnet sizes in specific regions and wait for offers.

Golden Cash also provides its 'partners' with exploit tool kits for infecting PCs and manipulating websites. The functions carried out by Golden Cash bots include collecting FTP access data for websites to allow criminals to obtain access to the sites in order to embed browser exploits. All in all, Finjan's assessment indicates that the platform represents a highly lucrative system. See Finjan's report for further details � Cybercrime Intelligence Report, Issue 2

Source
See Original article: The Golden Cash Botnet

YES Exploit System


YES Exploit System. Another crimeware made in Russia

The suite of applications used to automate different types of attacks via the Web (crimeware), have been transformed into a dangerous trend that clearly shows the inclination and demand criminal automate processes malicious.

I've noticed several of them of which Russia is a paradise for the creative development of crimeware. Also, technical support, in many cases, and the creation of crimeware packages "tailored" ready to implement and need only to know to modify the default password of admin panel via the web.

Which is an extra spice of proliferation of malicious acts performed by persons not familiar with the type of program you are using. Just purchased a modest cost ready to start spreading malicious instructions in bulk.

YES Exploit System, is another of the crimeware package that meets these characteristics of easy implementation and use.

The new version has recently presented a cost of 700 USD in the Russian black market and incorporates a series of "improvements" malicious functions with respect to the previous version, in addition to free updates for life.

Among the new features that are incorporated crimeware:
New exploits.
The possibility to obtain minimum statistical information through a new manager doesn't replace the statistical complete but supplements it.
Notice that no other infections have occurred through YES Exploit System in the victim computer.
Updating the GeoIP database.
Ability to download multiple files from the same page, for example, index.php can be downloaded from abc.exe, def.exe, ghi.exe.
Administration of downloading files via the control panel and not FTP.
Optimizing PHP code.
Elimination of statistics and guest checker FTP.

Control files downloaded through the administration panel.
Optimization of the general control panel for a better performance in loading it.
Added a new level of encryption code iframe.
Encryption binaries to avoid detection by the AV companies.
A new alternative to centralized management and automation of criminal activities using the Internet as a base for attacks.

Source
 

AbheLink Black or White ? Copyright © 2011-2012 | Powered by Blogger