Simda, as the botnet was known, infected an additional 128,000 new
computers each month over the past half year, a testament to the stealth
of the underlying backdoor trojan and the organization of its creators.
The backdoor morphed into a new, undetectable form every few hours,
allowing it to stay one step ahead of many antivirus programs. Botnet
operators used a variety of methods to infect targets, including
exploiting known vulnerabilities in software such as Oracle Java, Adobe Flash, and Microsoft Silverlight.
The exploits were stitched into websites by exploiting SQL injection
vulnerabilities and exploit kits such as Blackhole and Styx. Other
methods included sending spam and other forms of social engineering.
Countries most affected by Simda included the US, with 22 percent of the
infections, followed by the UK, Turkey with five percent, and Canada
and Russia with four percent.
The malware modified the HOSTS file Microsoft Windows machines use to
map specific domain names to specific IP addresses. As a result,
infected computers that attempted to visit addresses such as
connect.facebook.net or google-analytics.com were surreptitiously
diverted to servers under the control of the attackers. Often the
booby-trapped HOSTS file remains even after the Simda backdoor has been
removed. Security researchers advised anyone who may have been infected
to inspect their HOSTS file, which is typically located in the directory
%SYSTEM32%\drivers\etc\hosts. People who want to discover if they have
been infected by Simda can check this page
provided by AV provider Kaspersky Lab.
The page is effective as long as
a person's IP address hasn't changed from when the infection was
detected.
The takedown involved the seizing of
14 command-and-control servers that were located n the Netherlands, US,
Luxembourg, Poland, and Russia. The highly coordinated takedown occurred
simultaneously all over the world last Thursday and Friday and was
organized by the Interpol Global Complex for Innovation in Singapore.
It
included officers from the Dutch National High Tech Crime Unit, the US
FBI, the Police Grand-Ducale Section Nouvelles Technologies in
Luxembourg, and the Russian Ministry of the Interior’s Cybercrime
Department “K." INTERPOL also worked with Microsoft, Kaspersky Lab,
Trend Micro, and Japan’s Cyber Defense Institute for technical
assistance.
Last week's takedown is only the latest international operation to
shut down a botnet that indiscriminately menaced huge numbers of people
around the world. Last week a separate takedown targeted Beebone,
a highly elusive botnet that provided a captive audience of backdoored
PCs to criminals who were looking for an easy way to quickly install
malware on large numbers of computers. Get Latest Setup and Botnet configuration contact me on skype nitro_9ice or Ymessenger- nitro_ice9 for more insight.
Friday, January 8, 2016
Tuesday, April 14, 2015
RAMNIT Botnet that Infected 3.2 Million Computers
Alike GameOver Zeus, RAMNIT is also a 'botnet'
- a network of zombie computers which operate under criminal control
for malicious purposes like spreading viruses, sending out spam
containing malicious links, and carrying out distributed denial of service attacks (DDoS) in order to bring down target websites.
RAMNIT believes to spread malware via trustworthy links sent through
phishing emails or social networking sites, and mainly target people
running Windows operating systems in order to steal money from victims
bank accounts. Moreover, public FTP servers have also been found
distributing the malware.
Once installed, the infected computer
comes under the control of the botnet operators. The module
inadvertently downloads a virus onto the victim’s computer which could
be used by operators to access personal or banking information, steal
passwords and disable anti-virus protection.
NASTY FEATURES OF RAMNIT BOTNET
Symantec says
that Ramnit has been around for over four years, first originating as a
computer worm. According to the anti-virus firm, Ramnit is a
"fully-featured cybercrime tool, featuring six standard modules that
provide attackers with multiple ways to compromise a victim." The
features are:
- SPY MODULE - This is one of the most powerful Ramnit features, as it monitors the victim’s web browsing and detects when they visit online banking sites. It can also inject itself into the victim’s browser and manipulate the bank’s website in such a way that it appears legitimate and easily grab victim’s credit card details.
- COOKIE GRABBER - This steals session cookies from web browsers and send them back to the Ramnit operators, who can then use the cookies to authenticate themselves on websites and impersonate the victim. This could allow an attacker to hijack online banking sessions.
- DRIVE SCANNER - This scans the computer’s hard drive and steals files from it. The scanner is configured in such a way that it searches for specific folders which contain sensitive information such as victims’ passwords.
- ANONYMOUS FTP SERVER - By connecting to this server, the malware lets attackers remotely access the infected computers and browse the file system. The server can be used to upload, download, or delete files and execute commands.
- VIRTUAL NETWORK COMPUTING (VNC) MODULE - This feature provides the attackers with another means to gain remote access to the compromised computers.
- FTP GRABBER - This feature allows the attackers to gather login credentials for a large number of FTP clients.
WHY BOTNET RE-EMERGE AFTER TAKEDOWNS ?
According to the authorities, Ramnit botnet has been taken down, but is
it guaranteed that the botnet will not re-emerged again? We have seen
the took down of GameOver Zeus botnet by FBI and Europol as well, but
what happened at last? Just after a month, GameOver Zeus botnet again came into operation with more nasty features.
Thursday, June 5, 2014
Carbon Form Grabber BOTNET - All Browser Intrusion !
I bring to you a brand new product! This is really very cool! This form grabber was written from scratch with the
customer in mind.
we have made a web panel that is very intuitive, easy to use and sleek! This product was made for new comers and for pros,
it will suit the needs of any user with our easy to use panel and our advance features, this product is the best of both worlds.
The Carbon Form Grabber created by AlexHF runs on 32-bit and 64-bit platforms and exhibits some semi-persistence. the Carbon Grabber is composed of a Builder and an intuitive PHP Panel.
The Carbon Grabber is able to capture logins and passwords from SSL & HTTP webpages in Chrome, Firefox and Internet Explorer.
The kit contains the following features :
* Startup ( Hidden)
* Userkit(x86 & x64 )
* Injection
* Chrome SSL & HTTP Grabber
* Firefox SSL & HTTP Grabber
* Internet Explorer SSL & HTTP Grabber
* Intuitive PHP Panel
* Escalate to Administrator Privileges.
Contact NitRo on Ymessenger for SETUP files or SETUPS - Ymessenger ID- nitro_ice9@yahoo.com
we have made a web panel that is very intuitive, easy to use and sleek! This product was made for new comers and for pros,
it will suit the needs of any user with our easy to use panel and our advance features, this product is the best of both worlds.
The Carbon Form Grabber created by AlexHF runs on 32-bit and 64-bit platforms and exhibits some semi-persistence. the Carbon Grabber is composed of a Builder and an intuitive PHP Panel.
The Carbon Grabber is able to capture logins and passwords from SSL & HTTP webpages in Chrome, Firefox and Internet Explorer.
The kit contains the following features :
- Startup (Hidden) - Meaning the process doesn’t appear in the Windows Task Manager.
- Userkit (x86 & x64 )
- Injection
- Chrome SSL & HTTP Grabber
- Firefox SSL & HTTP Grabber
- Internet Explorer SSL & HTTP Grabber
- Intuitive PHP Panel
- Escalate to Administrator Privileges - Apparently performed via runas
* Startup ( Hidden)
* Userkit(x86 & x64 )
* Injection
* Chrome SSL & HTTP Grabber
* Firefox SSL & HTTP Grabber
* Internet Explorer SSL & HTTP Grabber
* Intuitive PHP Panel
* Escalate to Administrator Privileges.
Contact NitRo on Ymessenger for SETUP files or SETUPS - Ymessenger ID- nitro_ice9@yahoo.com
Tuesday, April 1, 2014
Newest Zeus banking Trojan is Born, ZeusVM
NOTORIOUS BANKING TROJAN Zeus is back in another variant, security firm Malwarebytes has warned.
Dubbed ZeusVM, the modded version of the infamous Trojan is being distributed in many different ways, but typically through phishing emails or web-based attacks, including "malvertising", whereby people are infected by visiting websites containing malicious ads.
"The Zeus/Zbot Trojan is one the most notorious banking Trojans ever created; it's so popular it gave birth to many offshoots and copycats,"
"The particularity of Zeus is that it acts as a 'man in the browser', allowing cyber-crooks to collect personal information from its victims as well as to surreptitiously perform online transactions.
"A new variant of this Trojan, dubbed ZeusVM, is using images as a decoy to retrieve its configuration file, a vital piece for its proper operation."
Malwarebytes senior security researcher Jerome Segura explained that there are various parts to this piece of malware. While the main executable - the bot - will bury itself into your computer and ensure it is reactivated every time you reboot, at regular intervals it also checks with its command and control server for new instructions while monitoring user activity.
"The JPG contains the malware configuration file which is essentially a list of scripts and financial institutions - but doesn't need to be opened by the victim themselves," Segura said.
"In fact, the JPEG itself has very little visibility to the user and is largely a cloaking technique to ensure it is undetected from a security software standpoint."
This enables a "man in the browser' attack where everything the victim does while browsing can be intercepted and modified at will.
"Visiting certain URLs, such as a bank website, will trigger an alert and the Trojan will start interacting in real-time. For example, it will alter the login page and ask for additional personal details, which it does using a technique known as 'webinjects', where code is injected directly into the browser, changing the webpage in real time," he added.
It can also perform wire transfers while the victim is logged in, Segura said, and even alter the appearance of the current account balance to ensure that it remains unnoticed.
although most anti-malware products should detect banking Trojans, traditional anti-virus software products might not.
"It only matters if the detection is timely. There's little use if you have been infected for two days and your account has already been depleted," the firm said, advising that observing basic security tips like "not opening email attachments unless you are absolutely sure it is safe" will help.
However, while Malwarebytes recorded a new variant of the popular Zeus trojan, security firm Fireeye has said that hackers are dropping standard malware like Zeus in favour of more advanced but harder to use remote access Trojans (RATs) such as Xtreme RAT.
Xtreme RAT is a notorious RAT that has been freely available on a number of cyber black markets since June 2010. The RAT is dangerous as it can be used for a variety of purposes, including interacting with the victim machine via a remote shell, uploading and downloading files, interacting with the registry and manipulating running processes and services
Dubbed ZeusVM, the modded version of the infamous Trojan is being distributed in many different ways, but typically through phishing emails or web-based attacks, including "malvertising", whereby people are infected by visiting websites containing malicious ads.
"The Zeus/Zbot Trojan is one the most notorious banking Trojans ever created; it's so popular it gave birth to many offshoots and copycats,"
"The particularity of Zeus is that it acts as a 'man in the browser', allowing cyber-crooks to collect personal information from its victims as well as to surreptitiously perform online transactions.
"A new variant of this Trojan, dubbed ZeusVM, is using images as a decoy to retrieve its configuration file, a vital piece for its proper operation."
Malwarebytes senior security researcher Jerome Segura explained that there are various parts to this piece of malware. While the main executable - the bot - will bury itself into your computer and ensure it is reactivated every time you reboot, at regular intervals it also checks with its command and control server for new instructions while monitoring user activity.
"The JPG contains the malware configuration file which is essentially a list of scripts and financial institutions - but doesn't need to be opened by the victim themselves," Segura said.
"In fact, the JPEG itself has very little visibility to the user and is largely a cloaking technique to ensure it is undetected from a security software standpoint."
This enables a "man in the browser' attack where everything the victim does while browsing can be intercepted and modified at will.
"Visiting certain URLs, such as a bank website, will trigger an alert and the Trojan will start interacting in real-time. For example, it will alter the login page and ask for additional personal details, which it does using a technique known as 'webinjects', where code is injected directly into the browser, changing the webpage in real time," he added.
It can also perform wire transfers while the victim is logged in, Segura said, and even alter the appearance of the current account balance to ensure that it remains unnoticed.
although most anti-malware products should detect banking Trojans, traditional anti-virus software products might not.
"It only matters if the detection is timely. There's little use if you have been infected for two days and your account has already been depleted," the firm said, advising that observing basic security tips like "not opening email attachments unless you are absolutely sure it is safe" will help.
However, while Malwarebytes recorded a new variant of the popular Zeus trojan, security firm Fireeye has said that hackers are dropping standard malware like Zeus in favour of more advanced but harder to use remote access Trojans (RATs) such as Xtreme RAT.
Xtreme RAT is a notorious RAT that has been freely available on a number of cyber black markets since June 2010. The RAT is dangerous as it can be used for a variety of purposes, including interacting with the victim machine via a remote shell, uploading and downloading files, interacting with the registry and manipulating running processes and services
Neverquest banking malware Partners Zeus trojan
New Neverquest malware steals bank account logins
and lets attackers access accounts through victims' computers.
For over five years, Zeus has been the undisputed king of banking malware. Once this trojan was loaded onto a victim's machine, it could:- Detect when the owner entered banking information into a web browser.
- Steal passwords and other pertinent login information.
- Encrypt the stolen information and send it to the attacker's specified servers.
Zeus remains active today, but its source code was published online in 2011 and this cyberscourge has about run its course. Unfortunately, Security experts are already sounding the alarm about a new piece of malware that makes Zeus look like a simpleton. Neverquest significantly raises the bar for online banking malware.
How Neverquest works
Like Zeus, Neverquest is a Trojan. Bad guys introduce Neverquest to the victim’s computer via social media, email, or file transfer. According to the security blog Threat Post, Neverquest replicates in a manner similar to the Bredolab botnet client:"Bredolab malware used the same methods of distribution that Neverquest is currently using. Bredolab would eventually become the third most widely distributed piece of malware on the Internet."Before it was shuttered, the Bredolab botnet consisted of 30 million computers. Why not use something that works?
If the victim’s computer is vulnerable to an exploit targeted by Neverquest’s trojan loader; the malware is installed. Then Neverquest starts paying attention to what the user is typing into their web browser. If a predetermined financial term is recognized, Neverquest checks the website domain name. Since, Neverquest has hundreds of banking and financial institutions in its database; there’s a better than average chance Neverquest will be familiar with the banking website.
Once Neverquest recognizes a banking site, it will relay the login information back to the attackers’ command and control server. Once the victim's credentials are in the hands of the attackers, they will remotely control the victim's computer using VNC, log into the victim's banking website, and do one of the following:
- Transfer money to different accounts
- Change login credentials, locking out account owner
- Write checks to money mules
One capability Neverquest has that Zeus doesn’t, is the ability to cultivate new banking sites for its database. If the malcode recognizes certain financial terms, but not the domain; Neverquest will send the information back to the command and control server which then creates a new identity, and updates every compromised computer under its control.
Neverquest in the wild
One sobering reality is that Neverquest is already for sale. Zeus, being “first of its kind” malware, required skilled controllers. Not so with Neverquest, script kiddies and malware non-experts are able to make use of the potent malware as soon as they buy it.Tuesday, October 22, 2013
Zeus Botnet Overview (Tutorials )
Zeus Botnet Overview
Zeus is a toolkit that provides a malware creator all of the tools required to build and administer a botnet. The Zeus tools are primarily designed for stealing banking information, but they can easily be used for other types of data or identity theft. A Control Panel application is used to maintain/update the botnet, and to retrieve/organize recovered information. A configurable Builder tool allows to create the executables that will be used to infect victim's computers. These executables are usually detected as ZBot by anti-virus software.There is no single Zeus botnet. The toolkit is a commercial product that is sold to many different users, and distributed freely to many more. Each of them can create one or more botnets of their own, so the number of Zeus botnets is likely quite large.
The latest version of the toolkit typically sells for about $700 USD to trusted buyers, with the bot source code possibly available for a much larger sum. After a few months the new toolkit version is released as a free "public" version, which is probably meant to serve as a promotion for the commercial version. The public version may not include all of the latest functions, and the documentation is minimal. Modified versions of the public toolkit have also been offered for sale at lower prices by third party developers, sometimes known as "modders".
Configuration and Bot Creation
The first step in building a bot executable is to edit the configuration file. The configuration tells the bot how to connect to the botnet, and it also contains information on what user data to gather and how to do so. The configuration file is in two parts, as described below.Static Configuration
The StaticConfig is compiled into the bot by the Builder tool. It contains information that the bot will need when it is first executed. To update the StaticConfig the bots must be ordered to download a new bot version.The available settings are:
- The name of the botnet that this bot belongs to.
- The amount of time to wait between dynamic configuration file downloads.
- The time interval between uploads of logs and statistical information to the drop server.
- The URL where the bot can get the dynamic config file.
- A URL where the bot can check its own IP address, to determine if it is behind a router or firewall.
- The encryption key that is used to hide information transmitted within the botnet.
- A language ID list that tells the bot to go into a dormant state if the infected computer's language is on the list.
Dynamic Configuration
The DynamicConfig is downloaded by the bot immediately after it is installed on a victim's computer. This file is downloaded at timed intervals by the bot, and can be used to change the behaviour of the botnet. Most of the entries control how information is collected from the infected computer.Available settings include:
- A URL where the bot can download a new version of itself, if the command to do so is given.
- The URL of the drop server where logs, statistics and files will be uploaded and stored.
- Information used to inject additional fields into web pages viewed from the infected computer.
- A list of URLs where an emergency backup config file can be found.
- A set of URL masks used to cause or prevent logging of information.
- A set of URL masks to indicate that a screen image should be saved if the left mouse button is clicked.
- A list of pairs of URLs that are used to cause redirection from the first URL to the second.
- A set of URL masks used to collect TAN (Transaction Authentication) numbers - used by some banks for online authentication.
- A list of IP/URL pairs that are inserted into the infected computer's hosts file to override DNS lookups.
Building the Bot
Once the configuration file is ready the Builder tool is used to build the encrypted dynamic configuration file and the bot executable file. The Builder first checks the computer it is running on to see if the Zeus bot is installed and gives the user the option to clean the system. This is probably meant to make it easier to test configuration settings. The Builder will then report system information as seen in Figure 1 below:Figure 1: Zeus Builder - Information
Figure 2: Zeus Builder - Compiling configuration
Figure 3: Zeus Builder - Assembling configuration and binary
Bot Distribution and Installation
The Zeus bot has no built-in capability to spread to other computers. In most cases a spam campaign is used to distribute it, either as an attached file or a link. Some type of social engineering within the spam message is used to trick the victims into executing the bot. A wide variety of these tricks have been seen, often in forms that are persuasive and difficult to detect. The large number of social engineering tricks is a result of many individuals attempting to seed their own botnet, using the common Zeus platform.The lack of worm-like spreading capabilities makes the bot suitable for targeted attacks, since the bot is less visible and less likely to be detected. In targeted attacks, it can be sent to the intended victim in various disguises until success is achieved.
When the bot is executed on a victim's computer it goes through a number of steps to install and configure itself, and to connect to the botnet. The filenames given here are for the tested version, and sometimes are changed in new versions. Outlined below are the steps taken upon initial execution:
- The install function searches for the "winlogon.exe" process, allocates some memory within it and decrypts itself into the process.
- The bot executable is written to the hard drive as "C:\WINDOWS\system32\sdra64.exe".
- The directory "C:\WINDOWS\system32\lowsec\" is created. This directory is not visible in Windows Explorer but can be seen from the command line. Its purpose is to contain the following files:
- local.ds: Contains the most recently downloaded DynamicConfig file.
- user.ds: Contains logged information.
- user.ds.lll: Temporarily created if transmission of logs to the drop server fails.
- The Winlogon ("HKLM/SOFTWARE/Microsoft/WindowsNT/CurrentVersion/Winlogon") registry key's value is appended with the path of the bot executable: C:/WINDOWS/system32/sdra64.exe. This will cause the bot to execute when the computer restarts.
- The Windows XP firewall is disabled. This causes a Windows Security Center warning icon to appear in the system tray, the only visible indication that the computer has been infected.
- The bot broadcasts an "M-SEARCH" command to find UPnP network devices. This may be an attempt to access and reconfigure local routers.
- The bot sends an HTTP GET command to the configured botnet server to get the latest DynamicConfig file.
- The bot begins capturing and logging information from the infected computer. The DynamicConfig file largely determines what information is collected.
- The bot sends two HTTP POST commands to upload log (user.ds) and stat information to the botnet drop server.
- Three timers are set to values in the StaticConfig, each executing a function on time-out:
- Get new config file (DynamicConfig) from server (default 60 minutes).
- Post harvested data (user.ds) to server (default 1 minute).
- Post statistics to server (default 20 minutes).
- If a web page that is viewed from the infected computer is on the injection target list in the DynamicConfig, the additional fields from the list are injected into the page.
- If the HTTP "200 OK" reply to a POST contains a hidden script command, the bot executes it and returns a success or failure indication along with any data (see Communication section below).
Friday, July 19, 2013
Understanding How Zeus Botnet Works !
If you are really looking at going into hacking with zeus botnet, you need to know the fundamentals and basic knowledge about Coding and Programming. Then you will need the Zeus Botnet files and builder then the required skills on how to truly go about it. For Support and SETUP contact me on YM = nitro_ice9@yahoo.com
With Zeus Botnet you are able to do the following....
Steal Personal data (Including Bank Details.
All type of Emails+Password
FTP Logins
PoP3 Logins
Web mails Logins
All http &https Logins
Browser Cookies
Almost everything.
Contact for Support on Zeus Botnet SETUP ... Email or YM .. Nitro_ice9@yahoo.com
With Zeus Botnet you are able to do the following....
Steal Personal data (Including Bank Details.
All type of Emails+Password
FTP Logins
PoP3 Logins
Web mails Logins
All http &https Logins
Browser Cookies
Almost everything.
Contact for Support on Zeus Botnet SETUP ... Email or YM .. Nitro_ice9@yahoo.com
Subscribe to:
Posts (Atom)

