MalwareIntelligence is a site dedicated to research on all matters relating to anti-malware security, criminology computing and information security in general, always from a perspective closely related to the field of intelligence.

30.6.11

JAVA Drive-by [infection] On Demand

JAVA is one of the largest computer technology integration in the field of cybercrime because of its status as a "hybrid". This transforms Java platform in a highly exploited vector for the spread of all types of malicious code.

Even the modern crimeware includes a battery of exploits created to exploit vulnerable versions of JAVA through Exploit Packs, and in fact, together with the PDF files, exploits for JAVA are those with higher success rate.

Now, Drive-by is one of the most widely used techniques to propagate and automate the process of infection via the web. Especially through websites that promise via streaming video display or visual social engineering strategies similar. Combining this methodology with JAVA simply results a Java Drive-by; that is technically the same but using JAVA language and resources. Did you ever see some of these templates?...


...Probably many times!

Every day we see these websites are usually hosted on sites that offer free file storage, but they conceal the necessary instructions to "streamline" the process of infection, simply using a Java applet. In chronological order, the images correspond to the options of: Photo Gallery, Camera Chat and Video Streaming respectively. All, created an automated way through iJAVA.

iJAVA is a On Demand generator (Java Drive-by Generator) of Arab origin, since its first version had a very good acceptance in the area of ​​cybercrime because it allows in just a few clicks, create a simple web page, link to this site a customized malware and automatically upload the page, for example, to one of these services free storage. A dose of visual trivial social engineering but unfortunately extremely effective.

iJAVA Version 1. In just three steps propagators of malware pose a threat personalized accompanying the action with a dose of social engineering.

iJAVA Version 2. Adding a series of "extras", like the previous version, the creation of the strategy is defined in only three basic steps.
Some examples in the wild:

Unlike the first version, the second generation to customize a template itself, which the design is used to "capture" of victims is limited only to the imagination of the attacker being able to achieve infection strategies such as:


Saving time is also an important factor for cybercriminals. And with applications of this style, get the automation necessary to cost savings in terms of time and of course, profits also in economic terms, since in spite of the triviality of the maneuver, cybercriminals often use them in campaigns related to business type of PPI (Pay-per-Install) to boost the economy through affiliate programs.

Related information:
Automatización en la creación de exploits
Automation in creating exploits II
Automating processes anti-analysis through of crimeware
Process Automation anti-analysis II

Ver más

15.6.11

The Art of the Cyberwar

The development of new technologies, in catching up with military interests and dependence on existing technology by developed countries, sets up a scenario where the cyber war, or war in cyberspace, is becoming more important.

All countries aware of the risks of such dependence developed defense programs against attacks that could jeopardize critical national infrastructure.

On the other hand, developing countries and major world powers are training computer security experts in various techniques of hacking, cracking, virology, etc.., forming true experts in cyber warfare, called cyberwarriors.

That does not fit anyone doubt that the future wars will not be determined or land or sea or air, but in cyberspace. The soldiers do not carry weapons or shields, but knowledge and deploy applications that war virus, disabling the enemy's critical systems that are technologically dependent.

This is the scenario where the world is moving now, a scenario of technological dependence, where countries with more traditional military strength will be losing ability to war for countries with highly qualified in computer security and cyber techniques.

This essay is intended as a point of reflection and knowledge about cyber warfare, on the present philosophy of Sun Tzu in the Art of War, and adapt their knowledge to technological scenario which we live and live, so we can get a modern compendium: The Art of Cyberwar.

Version in english
Version in spanish

Ver más

3.4.11

Gangsterware. Stealth Shield of the Malware

A few days ago I watched one of the training of BlackHat Webcast whose title is the same as used for this post, where people of M86Security was assigned to conduct a superficial talking about the main vectors of infection today. Putting focus primarily on Exploit Packs, and emphasizing time on the modus operandi of Phoenix Kit Exploit, Neosploit and Open Source Exploit Kit (a lot of impact between the "would-be criminals" because of his condition "free").


The training was very good for those who want to begin investigating the characterization of this type of crimeware, in this case through the criminal crannies that hide three Exploit Packs that are active criminal living in the ecosystem. So... a bravo! to the authors of the brief training. The slide can be viewed from the BlackHat Media.

However, know that the evolution of these crimeware is very fast, that the offer is very broad and very specific demand. Then leave the links of some of the Exploit Pack that somehow have been exposed through MalwareIntelligence along a good few years:

[6.10.10] Eleonore Exploit Pack. New version
[1.10.10] Phoenix Exploit’s Kit v2.3 Inside
[30.9.10] Black Hole Exploits Kit. Another crimeware in addition to criminal supply
[8.9.10] Phoenix Exploit’s Kit v2.1 Inside
[18.8.10] State of the art in Phoenix Exploit's Kit
[9.8.10] Campaign infection through Phoenix Exploit's Pack
[11.7.10] YES Exploit System and Crimeware-as-a-Service
[3.7.10] BOMBA Botnet. New alternative crimeware fuel the economy criminal
[24.6.10] State of the art in Eleonore Exploit Pack II
[28.5.10] Intelligence and operational level by Siberia Exploit Pack
[19.5.10] State of the art in CRiMEPACK Exploit Pack
[28.3.10] iPack y GOLOD. New on the scene crimeware criminal
[16.1.10] YES Exploit System. Official Business Partner’s
[9.1.10] Napoleon Sploit. Frameware Exploit Pack
[3.1.10] State of the art in Eleonore Exploit Pack
[25.12.09] Siberia Exploit Pack. Another package of explois In-the-Wild
[3.12.09] A brief glance inside Fragus
[29.11.09] JustExploit. New Exploit kit that uses vulnerabilities in Java
[26.9.09] Nueva versión de Eleonore Exploits Pack In-the-Wild
[15.8.09] Fragus. New botnet framework In-the-Wild
[14.8.09] Liberty Exploit System. Alternatively crimeware to control botnets
[4.8.09] Eleonore Exploits Pack. New crimeware In-the-Wild
[29.6.09] ElFiesta. Recruitment zombie across multiple threats
[14.6.09] Mirando de cerca la estructura de Unique Sploits Pack
[27.5.09] Unique Sploits Pack. Manipulando la seguridad del atacante II
[21.5.09] YES Exploit System. Manipulando la seguridad del atacante
[12.4.09] YES Exploit System. Otro crimeware made in Rusia
[6.3.09] Unique Sploits Pack. Crimeware to automate the exploitation of vulnerabilities
[27.2.09] LuckySploit, the right hand of ZeuS

Alejandro Cantis
Crimeware Research

Ver más

22.2.11

See you soon Jorge Mieres!

As many readers know, this means of information read at this time, was founded by Jorge Mieres in 2006. What you may not know is that several months ago, Jorge has decided to move away from the front of MalwareIntelligence, leaving us with complete confidence (one of the many qualities and characteristics of Jorge) the command of his legacy.

For this reason, and through these few words, we want to thank not only the possibility of allowing us to continue with its philosophy that is the essence of MalwareIntelligence, which no doubt has become a means of informing local and uncontested global on everything related to crimeware and botnets activities, but also by the amount of information who selflessly shared with the community safety through this forever your blog :D, its quality as a person and, above all things, for his admirable humility.

Surely Jorge will continue to share things from their personal blog or catharsis as he always called :D, so I'm sure you will find it there :)

Thank you Jorge!
MalwareIntelligence Team

Ver más

18.2.11

Inside Carberp Botnet

In early 2010, from MalwareIntelligence started researching a new botnet designed to agglutination of sensitive information relating to bank accounts, and theft of credentials to exploit a disturbing list of programs.

NOTE: At the bottom of this article may find the link to download the complete white paper, called "Inside Carberp Botnet", which describes the various internal components that make up Carberp.

Carberp, unlike SpyEye and ZeuS, was not (and neither is today) a crimeware mass marketed, but rather to a small group of people. Proof of this were (and are) a few C&C to operate the botnet. Also, to implement, require use licenses to use the constructor and the administration panel.

After a while with high levels of activity through these C&C, we are surprised when we noticed that gradually disappeared and even more so when the vast majority upgraded to the new version for less than two months. Still had a few C&C refused to disappear, although we believe that in fact the operating botmaster refused to set aside this malware.

During January this year Seculert published an article which talks about the new version of Carberp, with an entirely new panel and developments in the bot.

In MalwareIntelligence found only one C&C with these features, and we have several indications for which we believe is not an "official" version of Carberp, but a modification of the bot original interface and some features of crimeware.

These unique signs also be evidence of a possible breakup of the group behind the development, commercialization and exploitation of crimeware.

In recent weeks we have begun to notice an increased activity of new C&C Carberp. However, these do not correspond to the earlier version discussed in "Inside Carberp Botnet" but they are the same crimeware activity ceased in December 2010. This reinforces our theory that in fact the administration panel referenced by Seculert, it is not really the new Carberp.

Decided to resume research for more information about this "resurrection" of Carberp and, based on the knowledge we had of this botnet, publish our internal report. But also exposed through this the first results of the second part of the investigation.

Carberp has begun to be announced from the crimeware community, which until now had not happened and no doubt this is precisely why this has again become popular in the media.

Change of business model? Actually we can not guarantee yet, but it may be that this botnet is beginning to be marketed to expand coverage of the bid, or that some other criminal group (perhaps made by any member of the original group Carberp developer) has taken the opportunity to take a new version inspired by the original and try to commercialize it.

The following text corresponds to the notice by which this new variant of Carberp is trying to be marketed (plain text):

Carberp. Multi-banking Trojan
Works on any system: Windows XP/Vista/7 with limited accounts.
The bot contains:

  • Loader
  • FTP Grabber
  • Password Grabber
  • Forms Grabber
  • FTP Sniffer 
  • Backconnect (Supports up to 500 connections)
  • Delete cookies in IE and Firefox.
  • Injections in IE and Firefox.
  • Ability to take screenshots directly from the js.
  • % user_id% html insert in the uid.
  • The constructor
  • A sample injection and much more.
  • System plugins. 
  • Command multidownload can simultaneously lose 20 exe
MiniAV
Detects and removes the following malware:
ZeuS, Limbo, Barracuda, Adrenalin, MyLoader, BlackEnergy, SpyEye.



NOTE: Unlike the previous version, this features a "Kill SpyEye" whereby also tries to get rid of this crimeware.

Lock antivirus updates:
vg8, avg9, arca2009, arca2008, avast5, ESET NOD32 Antivirus 3.x/4.x, ESET Smart Security 3.x/4.x, Avira Premium Security Suite, Avira AntiVir Premium, Avira AntiVir Professional, BitDefender Antivirus 2010, McAfee AntiVirus Plus 10, Microsoft Security Essentials, DrWeb     .

Grabber program list:
Messengers, Miranda, ICQ2003, RQ, Trillian, ICQ99b, MSN, Yahoo, AIM, Gaim, QIP, Odigo, IM2, SIM, GTalk, PSI, Faim, LiveMessenger, PalTalk, Excite, Gizmo, Pidgin, AIMPRO, MySpace, Pandion, QIPOnline, JAJC, Digsby, Astra, Post clients, Becky, The_Bat, Outlook, Eudora, Gmail, MRA, IncrediMail, GroupMailFree, VypressAuvis, PocoMail, ForteAgent, Scribe, POPPeeper, MailCommander, Windows_Mail_Live, Windows_Mail_Vista.

FTP Clients:
TotalCommander, Far Manager, WS_FTP, CuteFtp, FlashFXP, FileZilla, FTP Commander, FTP Navigator, BulletProof, SmartFTP, TurboFTP, FFFTP, CoffeCup, CoreFTP, FTP Explorer, Frigate3, UltraFXP, FTPRush, SecureFX, WebPublisher, BitKinex, ExpanDrive, Classic FTP DC, Fling, SoftX FTP Client, Directory Opus, FTP Uploader, Free FTP, DirectFTP, LeapFTP, WinSCP.

Browsers:
Firefox, Safari, Opera, IE, Chrome.

Others:
SysInfo, WinVNC, ScreenSaver, ASPNET, RDP, FreeCall, CamFrog, PCRemoteControl, NetCache, CiscoVPN, Credentials.

Backconnect system:

  • For receipt of bots used win32-appendix.
  • Allows you to use the bots as SOCKS5-Proxy.
  • There are options to configure the ports to stop, number of bots, times, etc.
  • Possibility of authentication proxies.
  • You can disconnect a bot mandatory when required.
    Injections:
    • The injections work in IE and Firefox.
    • A program to configure the injections.
    Builder:
    • Ability to configure 3 domains. 
    • Requires a license.
      Autocrypt system: 
      There is a metamorph cryptor to be checking with the antivirus.
        Browser:
        • Works with the user's session, bot, even if it is unprivileged (limited account).
        • You can get screenshots of the user and other parts of the system.
        • dormant mode, the user will not notice anything strange.
        • The browser is entirely invisible to the user.
        • The browser is not or when filling a form.
        • You can hijack a user's browser and work with. 
        • Look bot files as well as download them.
          License:
          • The license takes a panel + builder.
          • Restrictions on the number of servers under license.
          • To operate more than one botnet requires a second license.
          • It is forbidden to reorient the botnet to another server than the one provided.
          • We looked carefully at all the licenses, any violation will result in the loss of license and a DDoS on the servers and domains offenders.
          • The panel is protected with IonCube.
          • The bot is protected by our security system. In each update changes the way the bot, making it difficult the task that is listed.
          • resale is prohibited.
          Upcoming updates:
          • Bilder (60%).
          • Module DDoS (90%).
          • Shots chrome (50%).
          • Module fakes (70%).
          • p2p (10%).
          • Opera formgrabber (90%)
          • Chrome formgrabber (40%)
          • Grabber for Basic Auth in Firefox and IE (90%).
          Updates:
          • Updates the current modules and small changes are free.
          • Updates on new modules and major changes, require an extra fee.
          Price:
          • Price module browser bot 5k wmz
          • Price with browser module: 8k wmz.
          • Autocrypt System: wmz 1k/month

          Undoubtedly, since the present keep you informed of our progress Carberp and around his botnet.

          Download full whitepaper Inside Carberp Botnet

          Francisco Ruiz
          Crimeware Research of MalwareIntelligence

          Ver más