MalwareIntelligence is a site dedicated to research on all matters relating to anti-malware security, criminology computing and information security in general, always from a perspective closely related to the field of intelligence.

12.8.09

Prices of Russian crimeware. Part 2

Criminal activities of which are fed daily cyber criminals through a business model implemented by themselves, are channeled through the underground market that offer "services" more professionals to suit the needs of cyber -organized crime.

Consequently, every day there are new crimeware applications to enhance the economics of cyber-criminals, whatever the role in the criminal chain. Some of these crimeware is reflected below, highlighting the costs are within the illegal market.

CRUM Cryptor Polymorphic v2.6
This is an application type crypter. Its main feature is the ability to generate polymorphic malware encrypts every file created with a random key of 256 bytes. It also offers the possibility of the anti-malware analysis processes such as the detection of virtual machines. Your cost is USD 200 and includes updates for free.

CRUM Joiner Polymorphic v3.1
In this case, the main function is the ability to merge files without any limit on the amount. Like the previous binary can refer to a 256-byte encryption, polymorphic and detection capabilities of virtual machines. The price is USD 100 and upgrades are free.

More information about this family of crimeware

Eleonore Exploits Pack v1.2
Eleonore is a package of exploiting vulnerabilities and network control zombies. The cost of the latest version is USD 700. For an additional cost of USD 50 provides access to their crypter.

By default, the crimeware is linked to a number of domains, but there is the possibility of leaving it disconnected but its value is free to USD 1500, including Crypter. It's designed to exploit the following vulnerabilities: MDAC, MS009-02, Telnet - Opera, Font tags - FireFox, PDF collab.getIcon, PDF Util.Printf, PDF collab.collectEmailInfo, DirectX DirectShow and Spreadsheet.

Eleonore Exploits Pack v1.1
The previous version has a cost of USD 500 and unlike the version 1.2, the module hasn't exploit Spreadsheet.

More information about Eleonore Exploits Pack

Unique Sploits Pack v2.1
One of the botnets applications designed for managing web via HTTP. Current value is USD 750 and includes free updates and Crypter. For those who have older versions, the upgrade to this version has an aggregate value of USD 200.

The ability to exploit vulnerabilities that are: MDAC for IE 6, PDF exploit for IE 7, Opera and Firefox, PDF exploit for Adobe Acrobat 9, PDF Doble. Download simultaneously two exploits in PDF, MS Office Snapshot for IE 6 y 7, IE 7 XML SPL, Firefox Embed, IE 7 Uninitialized Memory Corruption Exploit, SPL Amaya 11, Foxit Reader 3.0. PDF Buffer Overflow Exploit.

More information about Unique Sploits Pack

Adrenaline
Another of the many crimeware designed to exploit vulnerabilities and to control botnets via http. Among the features that has highlighted the possibility of using local pharming, keylogging, theft of digital certificates, encryption of information, anti-detection techniques, cleaning of fingerprints, injection of viral code, among others. Its value is USD 3000.

More on Adrenaline Pack

YES Exploit System v2.0.1
One of the most used operating kits. Has an interface that resembles that of an operating system with a "Start" menu from which you access the various features of it. The cost of the latest version to date (August 2009) is USD 800.

YES Exploit System v1.2.0
Some packages of the first generation, still very active, the price varies depending on the versions. In the case of version 1.2.0, the cost is around USD 700.

More information about Exploit System YES

Barracuda Botnet v3.0
Latest version of this web application that, despite having several years of existence, it still has a relatively high cost compared to their peers. This is a crimeware with two versions of marketing, the Full version at a cost of USD 1600 and the Lite version at USD 1000.

In addition, this package is modular, meaning that you can add modules to meet the needs of the botmaster buy or rent. Modules that can be acquired are:

  • Module DDoS (HTTP GET / POST flood, UDP flood, ICMP flood, TCP flood, IP Spoofing) at a cost of USD 900.
  • Email Grabber module that collects email addresses stored on the zombie. Its value is USD 600.
  • Proxy Module, allows to increase the number of simultaneous connections for a more "efficient" sending spam. Its value is USD 500.
  • Module PWDGRAB. Clearly oriented to the theft of private information. The value is USD 500.
  • Module SSLSOCKS. This module is in its beta stage and can build a VPN "through the botnet. The price is USD 500.
With respect to previous versions, the 2.2 is sold for USD 600 and USD 300 to version 2.0.

More information on this crimeware

ZeuEsta Exploit Pack v7.0
This is an "adaptation" which consists of private combination of two very active crimeware: ZeuS v1.2.4.6 and SPack Kit. The cost is USD 600 and USD 100 per month to access a more hosting. Originally composed by the merger between Zeus and ElFiesta up during April this year (2009) was updated replacing ElFiesta by SPack Kit

While this fusion of crimeware isn't an original creation developed entirely by Russians, the different versions of it are ZeuS and therefore was considered to reflect its cost.

ZeuEsta Exploit Pack v5.0
This version is obtained in the illegal market at a cost of USD 150 the "unofficial", ie sold by third parties and not by the author himself. This version is composed by ZeuS v1.1.2.2 and ElFiesta.

ElFiesta v3
One of the most exploited by crimeware botmasters. In this case it's version 3 at a cost of USD 800. The application has modules that exploit vulnerabilities over twenty of which those with higher levels of efficiency are the exploits to PDF and SWF.

More information about ElFiesta

Liberty Exploit System v1.0.5
A new crimeware package that has recently emerged a number of characteristics that make it according to its author, an ideal application for its price/quality.

Preinstalled by default has the following exploits: MS06-014 Internet Explorer (MDAC) Remote Code Execution Exploit, PDF util.printf(), PDF collab.collectEmailInfo(), PDF collab.getIcon(), Flash 9 y MS DirectShow. Its cost is USD 500.

Neon Exploit System v2.0.5
Neon suffered a slight cut of USD 100. Now, the cost is USD 400 and USD 500 no. Among the modules of exploits that are preinstalled and preconfigured include: IE7 MC, PDF collab, PDF util.printf, PDF foxit reader, MDAC, Snapshot and Flash 9.

Limbo Trojan Kit
Limbo is one of the least popular crimeware illegal market in Russian market. However, this does not mean that your risk is lower. At a cost below other crimeware much more popular, their cost is USD 300.

Among its features are the binary update, cleaning of tracks (cache, cookies, etc..), Reboot the operating system (Windows) and destruction if necessary. It also has ability to capture keyloggin all passwords are accessed through Internet Explorer and that are stored in the browser, among others.

Fragus v1.0
A very new Web applications that access the crimeware industry at a cost of USD 800. Its characteristics are that the multilingual support (english and russian), statistical system on the browser and operating systems (including versions) and countries, the ability to customize modules exploits and incorporate new injection of iframe tags, file encryption, Crypter is a part of that package, however, you can add a personal.


As we can see, the malicious process automation, services and offerings relevant to making the purchase, sale and rental of effective "weapon" software designed purely for criminal purposes and profit.

In this sense, the costs generated from crimeware Russia moves depending on what the market dictates, even creating alternative business models such as loss of focus on providing technical support through professional services and maintenance and custom Update crimeware, feedback and the black market. 

Related information this Blog
Los precios del Crimeware ruso
Comercio Ruso de versiones privadas de crimeware...
Automatización de procesos anti-análisis II
Eleonore Exploits Pack. Nuevo crimeware In-the-Wild
Mirando de cerca la estructura de Unique Sploits Pack
Adrenaline botnet: zona de comando. El crimeware ruso...
YES Exploit System. Otro crimeware made in Rusia
Barracuda Bot. Botnet activamente explotada
ElFiesta. Reclutamiento zombi a través de múltiples amenazas

Jorge Mieres

Ver más

8.8.09

TRiAD Botnet III. Remote administration of multi-platform zombies

TRIAD is a web application designed to monitor and manage botnets by using GNU/Linux and MS Windows via the http protocol and of which we have discussed recently. It's part of an even more ambitious project by its author (who calls himself "cross"), called Hybrid Remote Administration System and which we will talk soon ;P

This time, it's version 3 TRIAD botnet. This web application is still in "infancy" but that nevertheless is in constant development and from version 2 has become a multi-platform crimeware. His full name is actually TRIAD HTTP Control System v0.3.

This latest version of crimeware has slight differences (improvements would say the creator) with respect to its predecessor. At first glance, highlights in its new interface, something we might say, characterizes the application.

Like its predecessors, is written in C ++ and compiled with GCC.

While no statistics as if they have features found in more sophisticated crimeware applications, has a number of options that makes it a danger. For now, its features are:

In GNU/Linux system: 

    Syn Flood con source IP spoofing: [SynStorm]-[Host]-[Port]-[Nr of Packets]-[Delay]   
    Small HTTP Server: [HTTP Server]-[Port]-[Time(minutes)]   
    Bind Shell: [Bind Shell]-[Port]-[Allowed IP Address]

    While the version for Windows platforms includes: 
      UDP Flood: [Reverse Shell]-[Host]-[Port] 
      Small Proxy Server: [UdpStorm]-[Target IP]-[Target Port]-[Nr of Packets]-[Delay] 
      Reverse Shell: [Proxy Server]-[Port]-[Time(minutes)]

      Regardless of the platform, the two have in common the ability to: 
      Sleep  
      Reboot remote machine  
      Shutdown remote machine  
      Delete bot from remote machine

        Through a recent update for now, only the version that runs on GNU/Linux provides the ability to generate the configuration file through a GUI, this way, the process is much simpler.

        The configuration file is generated then compiled to create the bot and getting a new crimeware through some simple steps.

        However, this creates a counter that has to do with an issue of optimization and that when you upgrade the bots, it would make an individual, which is annoying for a botmaster advanced.

        The crimeware this trend has created a style of hard braking, which marks a turning point on the control and administration of botnets represents a major effort by the security community in the fight against organized cyber crime which are in the current state of criminal activities committed through the Internet. 

        Related information this Blog
        TRiAD Botnet II. Administración remota de zombis...
        TRiAD Botnet. Administración remota de zombis en Linux
        Eleonore Exploits Pack. Nuevo crimeware In-the-Wild
        Especial!! ZeuS Botnet for Dummies
        ElFiesta. Reclutamiento zombi a través de múltiples amenazas
        Adrenalin botnet: zona de comando. El crimeware ruso marca...
        Chamaleon botnet. Administración y monitoreo de descargas
        YES Exploit System. Otro crimeware made in Rusia
        Barracuda Bot. Botnet activamente explotada
        Unique Sploits Pack. Crimeware para automatizar...

        Activities botnets
        Fusión. Un concepto adoptado por el crimeware actual
        ZeuS Carding World Template. Jugando a cambiar la cara...
        Unique Sploits Pack. Manipulando la seguridad del atacante...
        Scripting attack II. Conjunción de crimeware para obtener...
        Zeus Botnet. Masiva propagación de su troyano. Segunda parte
        Danmec Bot, redes Fast-Flux y reclutamiento de Zombies PCs

        Jorge Mieres

        Ver más

        7.8.09

        A recent tour of scareware XII

        Considering that the best way to prevent threats is to know them, we provide this new set of domains, along with their respective IP addresses, committed to spread malicious code scareware type, also called rogue.

        As always, the aim of showing these addresses is to be able to block them through mechanisms that are ordinarily used.

        It should be noted that this list represents only a very small proportion of the total volume of malware of this kind that daily bombard the web.


        PC Security 2009
        IP: 72.52.210.131, 72.52.210.132, 72.52.210.133
        United States United States Lansing Liquid Web Inc
        Domains associated
        pcsecurity09.com, pc-security09.com, pcsecurity-09.com, pcsecurity09.com, pcsecurity-2009.com



        Home Antivirus 2010
        MD5: 30d09989020fcb8f12a1aa3f87b4efa9
        IP: 72.52.210.131, 72.52.210.132, 72.52.210.133
        United States United States Lansing Liquid Web Inc
        Domains associated
        homeantivirus2010.com, home-anti-virus2010.com, homeantivirus-2010.com, home-antivirus-2010.com, homeanti-virus-2010.com, home-anti-virus-2010.com, homeav2010.com, home-av2010.com, homeav-2010.com, home-av-2010.com

        Result: 22/41 (53.66%)

        hotlife.us/mediastream/components/SecureLiveVideo.exe (67.212.162.250) - United States Singlehop Inc
        rundaqimao.com/1/installer/Installer.exe?u=1025&...t=2 (74.222.134.20) - United States Orange Vpls Inc. D/b/a Krypt Technologies
        od32qjx6meqos.cn/ue.php (220.196.59.23) - China United Network Communications Corporation Limited
        nextantivirusplus.com/install/AntivirusPlus.grn (195.95.151.176) - Ukraine Kiev Eastnet-ua-net
        explorersecurityhelper.com/block.php (83.133.123.113) - Germany Lncde-greatnet-newmedia
        http://downloadsoftwareserver4.com/xpdeluxe.exe (89.248.168.79) - Netherlands As29073 Ecatel Ltd

        antivirus-quickscanv5.com, antivirusonlinescanv9.com, antivirusscannerv9.com, fastvirusscanv6.com, firstspywarescannerv1.com, folder-antivirus-scanv1.com, mysafecomputerscan.com, onlineantispywarescanv6.com, onlineantivirusscanv4.com, personalfolderscanv2.com, personalonlinescanv3.com, privatevirusscannerv8.com, securefolderscannerv6.com, t370.hc-server.com, totalsecurityscannerv3.com (83.133.126.155) - Germany Lncde-greatnet-newmedia

        212.117.174.14/racing.exe, clean-pc-now.net, clean-pc-now.org, fast-spyware-cleaner.com, fast-spyware-cleaner.net, fast-spyware-cleaner.org, free-spyware-checker.org, free-spyware-cleaner.com, free-spyware-cleaner.net, kill-spyware-now.org, scan-pc-now.com, scan-pc-now.org, spyware-killer.biz, spyware-scaner.com, spyware-scaner.net, spyware-scaner.org (212.117.160.18) Result: 4/41 (9.76%) - Luxembourg Root Esolutions
        core2623.racingmoney-0110.com/d_program_all.cgi?host=host&id=0 (95.169.190.147) Descarga el binario PC_Protect.exe - Russian Federation Keyweb Online Limited Ip Network

        PC Antispyware 2010
        MD5: 30d09989020fcb8f12a1aa3f87b4efa9
        IP: 174.139.243.46, 174.139.5.51, 216.86.144.130, 174.139.243.42, 174.139.243.43, 174.139.243.45, 209.31.180.232, 209.31.180.233, 209.31.180.235, 209.31.180.234, 209.31.180.237, 209.31.180.240
        United States United States Chicago Nozone Inc
        United States United States Orange Vpls Inc. D/b/a Krypt Technologies
        United States United States Austin Supporting Act Technologies Llc
        Domains associated
        pc-anti-spyware-20-10.com, pcantispyware2010.com, pc-antispyware-2010.com, pcanti-spyware-2010.com, pc-anti-spyware-2010.com, pcantispyware20-10.com, pc-antispyware20-10.com, pcantispyware-20-10.com, pcantispyware-2010.com, pc-antispyware-20-10.com, pc-anti-spyware2010.com, pc-anti-spyware20-10.com, pc-antispy2010.com, p-c-anti-spyware-2010.com

        Result: 22/41 (53.66%)

        Windows System Suite
        IP: 64.213.140.69
        United States United States Global Crossing
        Domains associated
        fastantivirpro.com, malwarecatcher.net, mykeepplace.net, pay2.malwarecatcher.net, pay2.malwaresdestructor.com, prestotuneup.com, safe-pay-vault.com, trustshields.cn, update2.virusshieldpro.com, update2.windowspcsuite.com, update2.windowssystemsuite.com, virussweeper-scan.net
        websystemsec.info, windowsprotectionsuite.com, windowssystemsuite.com, www.fastantivirpro.com, www.malwarecatcher.net, www.prestotuneup.com, www.protectsystem.info, www.virussweeper-scan.net

        UnVirex
        MD5: c20478d4f1b10d40831dd3d4cf9ba7a0
        IP: 195.2.253.43
        Russian Federation Russian Federation Madet Ltd
        Domains associated
        unvirex.com



        Result: 30/41 (73.17%) 

        Related information this Blog
        Una recorrida por los últimos scareware XI
        Una recorrida por los últimos scareware X
        Una recorrida por los últimos scareware IX
        Una recorrida por los últimos scareware VIII
        Una recorrida por los últimos scareware VII
        Una recorrida por los últimos scareware VI
        Una recorrida por los últimos scareware V
        Una recorrida por los últimos scareware IV
        Una recorrida por los últimos scareware III
        Una recorrida por los últimos scareware II
        Una recorrida por los últimos scareware

        Jorge Mieres

        Ver más

        4.8.09

        Eleonore Exploits Pack. New Crimeware In-the-Wild

        The business represents the crimeware into the underground world of web applications marketing plays an important role in the business plan of the Russian developers spend much time in creating this style threats.

        There are several similar packages that we discussed during the short existence of this blog and every day there are more that come with the intention of enhancing the economy of the authors. In this case, is in "freedom" a new version of Eleonore Exp (shorthand Eleonore Exploits Pack) that the complainant has submitted under the caption "Hello! I now present new exploits russian pack v1.2 Eleonore Exp".

        This new package is designed in the first instance, for exploiting the following vulnerabilities:

        MDAC
        MS009-02
        Telnet - Opera
        Font tags - FireFox
        PDF collab.getIcon
        PDF Util.Printf
        PDF collab.collectEmailInfo
        DirectShow DirectX
        Spreadsheet


        The installation process is very simple and is done through the install.php file, the settings specified in config.php and malware by default is called load.exe (in case of changing the name, modification must be reflected in the configuration file).

        In the next screen capture shows the statistics from which they sprang interesting facts related to the total targeted operating systems, browsers through which exploited a vulnerability with their respective versions, many countries discriminated against zombies and exploits used .


        As for prices, this crimeware is marketed at a cost of USD 700 and this value corresponds only to the kit without extra components as a crypter (whose aggregate value is USD 50). By default, is linked to a domain, ie, bought and used directly without further proceedings.

        However, if the buyer prefers to untie the package of any of the domains with which it's sold, you can do but pay the sum of USD 1500 for the complete kit. On the other hand, it also offers a combo in which buyers purchase the first three plus Eleonore Exp v1.2 crypter worth USD 600.

        For previous versions, the costs are:

        Eleonore Exp v1.0 = USD 300 (originally cost USD 599): it has DirectX DirectShow and Spreadsheet
        Eleonore Exp v1.1 = USD 500: Spreadsheet hasn't


        As usual, the holding botmasters previous versions can update new exploits and malware upload functionality through the admin panel locally (from your computer) or remotely (from a zombie).

        Obviously, the fraudulent services in the acronym CaaS framed, Crimeware as a Service, increasing exponentially as time goes underground world to develop and commercialize various actors involved sonde being the creator of crimeware and botmaster (who generally buy or an initial rent web applications), the most important players. 

        Related information this Blog
        TRiAD Botnet II. Administración remota de zombis multiplataforma
        TRiAD Botnet. Administración remota de zombis en Linux
        Especial!! ZeuS Botnet for Dummies
        Botnet. Securización en la nueva versión de ZeuS
        Los precios del Crimeware ruso
        Comercio Ruso de versiones privadas de crimeware ¡Aproveche la oferta!
        ElFiesta. Reclutamiento zombi a través de múltiples amenazas
        Mirando de cerca la estructura de Unique Sploits Pack
        Adrenalin botnet: zona de comando. El crimeware ruso marca la tendencia
        YES Exploit System. Otro crimeware made in Rusia
        Creación Online de malware polimórfico basado en PoisonIvy

        Jorge Mieres

        Ver más

        3.8.09

        TRIAD Botnet II. Zombie-platform remote administration

        A few days ago we mentioned the creation of a web application created for GNU/Linux platforms that allows to control and manage botnets through http protocol called TRiAD Botnet.

        Despite its short life, the first version was launched on 18 February 2009, existing developments of this crimeware (just two more) designed to operate in both operating systems Linux and Windows. That is, the applicative evolved and became a multi crimeware.

        The catch is presented below represents the second version. As shown, it retains the idea of a minimalist application, without too many demands and a bottom "showy".


        While still maintaining the possibility of attacks distributed denial of service (DDoS), Bindshell, and ReverseShell, it has new features such as: delete bot from remote machine (Remove the bot on the remote machine), shutdown remote machine (turn off the computer remotely) and remote machine reboot (restart your computer remotely).

        The first option, perhaps this conceived with the aim of providing a mechanism for self-defense eliminated zombie control any incident. As for the other two options would seem rather to have been created with the intention of "fun" against the victim machine.

        Although not a complex threat, as if they are other crimeware as ZeuS, ElFiesta, Unique Sploits Pack or YES Sploits System, and its simple functionality is more like a backdoor in PHP, it's still a web application that can become very dangerous due to a problem: is free, open source, which means it can evolve according to the malicious intentions of the person or persons decide to "make up" their source code.


        Related information this Blog
        TRiAD Botnet. Administración remota de zombis en Linux

        Jorge Mieres

        Ver más