Friday, July 31, 2009

Botnet Analytics


We are still working our way to release Botnet Analytics. The first project in this site would be trend analysis of the botnet IPs fed from EmergingThreats.net website. We are almost 80% done. But we have 1 issue. When we see an opportunity to extend the tool, we do it. Hence, the tool so far expanded to a analytics engine that will crunch every possible relation with the IP listed in the backend.

If you wish to contribute or if you have some ideas for us, feel free to contact us at any time: contact.fingers @ gmail.com

- EF

DC 571 Meeting




Hey guys,

The previous meeting went very well. It would definitely be a great time to launch DC571.com very soon. I was wondering if you guys were cool in having our next meeting on a Friday [Aug 7th, 2009]. I promise you, there wont be many weekday meetings. This time alone I would like to have this one before going to India for a month, so that you guys can meet up even when I am not around. Zak or Uber will be running the future meetings when I am not around. Contact us @ contact.fingers@gmail.com if you wish to join. The reason is because, we do not have a standard/fixed location yet. Hence, we are trying to find a spot that works out well[suitable] for everyone.

- EF

Sunday, July 26, 2009

Software as a Service on the malware industry

Several years ago we have the ability to interact with different resources that are offered via web without using the resources at local level, our teams, for example, an operating system memory (eyeOS) that applied at the time, and applies this concept, as well as others we routinely use as Google Apps.

However, at present this concept responds to a name that is setting a trend under the name of Cloud Computing offers a wide range of services that use Internet as a central infrastructure (the cloud). Where services are offered programs, is known by the acronym SaaS (Software as a Service).

The point is that under this new phenomenon, the developers of malware were not on the sidelines and give rise to a new nomenclature that accompanies the concept of Cloud Computing, MaaS - Malware as a Service.

Some months ago I mentioned an online payment service that allows malicious code to create polymorphic capabilities based on the famous trojan PoisonIvy called PoisonIvy Polymorphic Online Builder.

Adding to this trend of offering services over the HTTP protocol, there are several alternatives as a service similar to the above, but free, called FUDSOnly Online Crypter, which channels its activity in the handling of malicious code in line with the intent to avoid detection by the antivirus companies, contributing to the cause pursued by malware developers to implement their creative processes anti-analysis.

Basically it's a Crypter. One type of program normally used to encrypt the binaries used in the distribution of malicious code. This "service" has the advantage of not needing to download or run the Crypter of locally on the PC, but the entire process is carried out via web.

At the end of the process, the application returns the following legend "Your file has been encrypted without errors, Service offered by FUDSOnly. Click HERE to download." that has the link to download the file handling.

As "extra", the "service" has the potential to insert into the encrypted file with the EOF crypter data (information server which is located at the end of file) for malicious code that doesn't support it, through a small program called ReEoF.

This service offered to handle malware, has had a previous version that demonstrates that the concept had already been adopted by cyber criminals for quite some time.

In fact, many services of this style that have been uploaded to the wave.

The malware industry adds to the notion that agglomeration online services offered by the Cloud Computing, extending the possibility of danger and threats to continue with the daily bombardment that information against environments, seeking to broaden the offering criminal .

Related Information
Creación Online de malware polimórfico basado en PoisonIvy

# Jorge Mieres

Wednesday, July 22, 2009

DC 571: Meeting Schedule



Venue: http://www.shoptysons.com/location.asp [Directions Available Here]

We are meeting up once again at the 2nd floor coffee shop at Barnes & Noble, in Tysons Corner Shopping center at around 5 PM on July 25th 2009[Coming Saturday]. You are most welcome to join us. This weekend, we will decide on how we would like to meet in future, venue and other stuff.

EF

Saturday, July 18, 2009

DC 571: Change of Plans

Change of plans: Call us at 213-210-1031 or meet us at the Barnes&Nobles 2nd floor coffee shop at the Tysons Corner shopping center. DC 571 meeting starts at 5:30 PM EST July 18 2009.

EF

Thursday, July 16, 2009

Special!!! ZeuS Botnet for Dummies

After dealing with some emphasis on the activities of the most active botnets now, ZeuS, let's see a more detailed description of their crime.

If we talk about malware and botnets, no doubt ZeuS has a particular advantage due to the amount of zombies that are part of its campus. ZeuS is designed to steal any information that is stored on the computers of victims remotely and carry out other attacks aimed at stealing information such as phishing.

Therefore, we could say that ZeuS is a spyware, but also has capabilities for other types of malware such as backdoors, trojans and viruses. However, the author mentions in the installation manual that you don't like to call any of these forms in this crimeware, but will refer to it as a "bot software".

Although we know the external face of ZeuS (the web interface management and control of zombies), has certain features that are constantly evolving and professionalize achieving greater flexibility and adaptability to ensure operation on different versions of Windows. This makes ZeuS a latent threat and very dangerous for any information system.

In this sense, ZeuS also ensures performance "working" on the privilege level 3 (where the applications are) the operating system to avoid incompatibilities between the implementation of equipment and devices (which operate at lower levels). Though it may seem an irrelevant fact, this allows greater flexibility and hence a higher yield at the time of the fraudulent and criminal activities for which it was conceived.

The latest version of ZeuS is written with version 9 of the C + + language, and among the features that have this web application (malicious), we can mention:
  • Monitor network traffic (sniffer) TCP.
  • Intercepts the FTP and POP3 connections from any port.
  • Intercepts HTTP and HTTPS requests from all applications that work with the library wininet.dll (eg IE). This demystifies the myth in which ZeuS uses a BHO to intercept applications through IE.
  • Functions server (socks4/4a/5).
  • Backconnect for all of the infected computer services (RDP, Socks, FTP, etc.).
  • Get screenshots in real time.
  • Ability to conduct phishing attacks.
  • Incorporates anti-analysis mechanisms.
  • Constructor of the trojan that spreads and configuration file.
  • Polymorphic encryption.
Another technical detail is that all communication is done by ZeuS through a symmetric encryption algorithm (RC4).

The server is the heart of ZeuS, and any botnet, and who is to obtain all records of infected computers that are part of the botnet and execute commands remotely.

On the other hand, many botnets using virtual servers to their criminal operations. However, this plays against the botnet when is very large, if ZeuS, as usually, the virtual servers don't have too many resources, so it's customary for botmaster using dedicated servers to host the bot. This is an important fact to keep in mind during the research side.

Accordingly, and as every application requires a minimum of resources to run satisfactorily, in the case of this botnet, the requirements are just to have 2GB of RAM and 2x frequency of 2 GHz CPU. As we see, the minimum requirements aren't at all a constraint VIP. Anyone can implement ZeuS, even without these minimum requirements.

Furthermore, it's assumed that the computer is running an HTTP server with PHP (the language is generally develop these crimeware) and MySQL (to create the database with statistical information that shows your activity). Another requirement is Zend Optimizer, which is necessary to protect and optimize the scripts.

With regard to updates, ZeuS is also can be "groomed" by newer versions without too much effort. During the last six months have been released five versions (based on each one approx. 35 days) with correction of errors, changes and new features, not the versions with smaller arrangements.

After looking at the diagram, many wonder what the number of each version. A teaching mode could say that if we have the "A.B.C.D" ...

A means a complete package of crimeware.
B represents changes that cause total or partial incompatibility with earlier versions.
C specifies error correction, added functionality, improvements, etc..
D is the number of refuds (changes) to the current version.

This is just a screenshot of what can and ZeuS represents in terms of skills and maneuvers that have an environment within which criminal crimeware applications are the main actors.

Related Information
Botnet. Securización en la nueva versión de ZeuS
ZeuS Carding World Template. Jugando a cambiar la cara de la botnet
Entidades financieras en la mira de la botnet ZeuS. Segunda parte
Entidades financieras en la mira de la botnet ZeuS. Primera parte
ZeuS Botnet. Masiva propagación de su troyano. Segunda parte
ZeuS Botnet. Masiva propagación de su troyano. Primera parte
LuckySploit, la mano derecha de ZeuS

# Jorge Mieres

Sunday, July 12, 2009

BruCON, Brussels 16-19 September 2009



BruCON is an annual security and hacker conference providing two days of an interesting atmosphere for open discussions of critical infosec issues, privacy, information technology and its cultural/technical implications on society.

Organized in Brussels, BruCON offers a high quality line up of speakers, security challenges and interesting workshops. It's affordable, accessible and entertaining. BruCON is a conference by and for the security and hacker community.

Two day trainings are available before the conference by some industry experts:

  • Crash course in Penetration Testing (By Joe McCray, and Chris Gates)


  • Former speaker at SOURCE Boston 09, NotACon ,Toorcon X and ChicagoCon. He is scheduled to speak BlackHat USA 2009 and Defcon 17


  • Web 2.0 Hacking – Attacks and Defense (By Shreeraj Shah)


  • Author of Hacking Web Services (Thomson 06) and Web Hacking: Attacks and Defense


  • Social Engineering testing for IT Security professionals (By Sharon Conheady)


  • Sharon Conheady is a social engineer/penetration tester at First Defence Information Security in the UK. She has social engineered her way into dozens of organisations across the UK and abroad, including company offices, sports stadiums, government facilities and more. Former speaker at Deepsec, Recon, CONFidence, ISSE, ISF, SANS Secure Europe and more.


    Why should people attend this event?

  • These are renowned speakers, international experts and book authors which you will seldom meet at other events.

  • It's affordable and accessible.

  • With 400 seats, it's an ideal occasion to network with others and exchange knowledge.

  • Lightning talks will give possibilities for visitors to present their own projects, tools or website

  • Various workshops on wireless security, digital ID, lockpicking, VOIP,....

  • The Hex Factor: a contest where people can learn the basics of web application security, forensics,… both fun and challenging for both absolute beginners as well as experts.



  • More info? How to register? Visit http://www.brucon.org/