Black Hole Exploits Kit. Another crimeware in addition to criminal supply
Crimeware industry continues to grow through the development and implementation of new marketing packages pre-compiled exploits add to the supply of alternatives to facilitate criminal maneuvers over the Internet.
In this case, it's Black Hole Exploits Kits, a web application developed in Russia but also incorporates for the English language interface, and the first version (beta at the moment) is trying to fit into the black market since early September 2010. Its cost is determined based on a number of features that attempt to differentiate from the rest.
In this case, it's Black Hole Exploits Kits, a web application developed in Russia but also incorporates for the English language interface, and the first version (beta at the moment) is trying to fit into the black market since early September 2010. Its cost is determined based on a number of features that attempt to differentiate from the rest.
Black Holes Exploits Kit statistical module
This module offers a quick view of the most relevant information for a botmaster: number of computers that are part of the network and their respective countries, exploits with higher success rates and other information processing.
This module offers a quick view of the most relevant information for a botmaster: number of computers that are part of the network and their respective countries, exploits with higher success rates and other information processing.
Unlike many other crimeware of this style, Black Hole Exploits Kit uses a licensing system costed time. For example, purchasing this crimeware for 1 year (currently the maximum time) costs $ 1500, while a semi-annual and quarterly license, costing $ 1000 and $ 700 respectively.
Statistics on the affected operating systems
The trend marks a slight but gradual increase in committed operating systems that do not belong to the family of Microsoft. This includes crimeware *NIX based platforms such as GNU/Linux and Mac OS. Others, such as Siberia Exploit Pack and Eleonore Exploits Kit includes platforms for high-end mobile devices and gaming consoles.
The trend marks a slight but gradual increase in committed operating systems that do not belong to the family of Microsoft. This includes crimeware *NIX based platforms such as GNU/Linux and Mac OS. Others, such as Siberia Exploit Pack and Eleonore Exploits Kit includes platforms for high-end mobile devices and gaming consoles.
It also has costs of $ 50 for the alternative of using the encryption system. This feature is a pattern for the service "extras" offered by the developers of crimeware, like the ability to verify the integrity of malware (AVChecker) spread through crimeware.
To carry out this verification, is used more often VirTest, the private service of Russian origin that has become a favorite of criminals to control the reputation not only malware but also spread exploits of the pack. There are several crimeware packages that have recently joined VirTest module, including the latest version of SpyEye.
As for the exploits, which incorporates all of the time are public and widely used by most current crimeware. However, these exploits have the highest rate of success in exploitation.
To carry out this verification, is used more often VirTest, the private service of Russian origin that has become a favorite of criminals to control the reputation not only malware but also spread exploits of the pack. There are several crimeware packages that have recently joined VirTest module, including the latest version of SpyEye.
As for the exploits, which incorporates all of the time are public and widely used by most current crimeware. However, these exploits have the highest rate of success in exploitation.
Statistics exploits
Through this module displays the statistical data on the ability of success that has every one of the exploits that are part of crimeware.
Through this module displays the statistical data on the ability of success that has every one of the exploits that are part of crimeware.
Black Hole Exploits Kit includes a TDS (Traffic Direction Script) that allows independence from another web application that allows arbitrarily manipulate web traffic, and probably this feature will catch the attention of criminals.
Also has a self-defensive module means which can block access to certain security websites by URL or IP address ranges. In the next image is set to block access to websites Kaspersky Antivirus:
Also has a self-defensive module means which can block access to certain security websites by URL or IP address ranges. In the next image is set to block access to websites Kaspersky Antivirus:
Self-defense module
Through this module can also import or export a list of addresses to block.
Through this module can also import or export a list of addresses to block.
Black Hole Exploits Kit joins the portfolio of offerings and little more than a month since its launch in underground environments no more activity In-the-Wild, perhaps due to its initial cost. However, security professionals should pay special attention to this crimeware as their characteristics and cost (probably decrease slightly for the next version) will be well accepted within the criminal community and therefore in demand by of offenders.
Related information
Servicio ruso en línea para comprobar la detección de malware
Crimeware-as-a-Service and antivirus evasion schemes
Crimeware-as-a-Service and antivirus evasion schemes
myLoader. Base C&C to manage Oficla/Sasfis Botnet [Whitepaper]
Criminal activities from BKCNET “SIA” IZZI / ATECH-SAGADE - Part one [Whitepaper]
Criminal activities from BKCNET “SIA” IZZI / ATECH-SAGADE - Part one [Whitepaper]
Founder & Director of MalwareIntelligence
Crimeware & Intelligence Analyst Researcher