Trojan Analysis Leads To Russian Data Hoard
Stolen Identity writes "An attack by a single Trojan variant compromises thousands, circumvents SSL, and uploads the results to a Russian dropzone server. A unique blow-by-blow analysis reveals evidence of cooperation between groups of malware specialists acting as service providers and points to the future of malware's growing underground economy."
how's that for having your tables turned on you ?
:)
In soviet Russia you invade the trojans
Pixie Rank ? WTF ??
- Steals SSL data using advanced Winsock2 functionality
- State-of-the-art, modularized trojan code
- Spread through IE browser exploits
- etc
...
When I read the Slashdot summary, I was initially concerned that I may be at risk. But then I noticed the above three lines and realized there was no risk since I don't use IE.But, in the end, if this is an exploit utilizing the very basic network DLL that windows provides for socket connections (Winsock2--which is what I assume all network applications eventually link against in Windows) then why aren't other browsers at risk?
I know Firefox is awesome & more secure & all that jazz but I haven't done enough network programming to know the nitty gritty details of it. Does anyone know why, if this trojan is exploiting the basic socket connection library that the Windows API provides, all browsers aren't potential victims?
I mean, it makes sense to introduce some sort of security that never ever lets anything but the browser's code access the interfaces to these libraries
My work here is dung.
Can't you just do a traceroute on the IP that this info is being sent to? Seems this would be a nice way of figuring out where the info is going. Then blacklist it or possibly a range router side.
...to the problem of AV companies not picking them up; offer a large-ish reward for information, and have someone involved tell the AV companies about the trojan as soon as possible. It only needs one relatively unimportant person (coder peon?) to blab and give the game away, so long as they're assured of having their identity kept secret.
I'm sure there are a million flaws in this idea, but it's a start.
"Slashdot - News and Chat Sites Deviant". (Click "homepage" link above for details).
You need IE to install the trojan, once it is running it will compromise all SSL traffic.
I thought the US was responsible for this? Which is it people.
2 7215
http://it.slashdot.org/article.pl?sid=07/03/20/01
Libertarian Leaning Political Discussion Forum.
Trojan Analysis Leads To Russian Data Hoard
So the analysis led the the hoarding? Everybody stop analyzing NOW!
TFA mentions 81.15.146.42, which apparently is a42.skierniewice.mediaclub.pl, which is Poland.
Where Russia came from?
But is this software supported on Linux?
reading that article is like looking at the blueprint for a neutron bomb: beautiful, magnificent, and pure evil
the mind boggles at what these men (or women) of such high craft could achieve were they to devote their genius to good efforts rather than bad. as it is, in the business they are in, they will probably very rapidly come under the thumb of the russian mafia, if they aren't already. then their life will be on a short leash, that, if they attempt to tug, will land them with a swift reprimand from guys you don't want to know what a swift reprimand from is like
sad. these are no script kiddies here. these are smart blokes. and they are also doomed to a life under the thumb of men a thousand times more evil than their devilish and brillaint exploits ever could be
intellectual property law is philosophically incoherent. it is your moral duty to ignore it or sabotage it
In soviet russia, the Horde owns YOU !
or is that
In World of Warcraft, the Horde owns YOU !
I am so confused....
Guns are for wimps... Use a crossbow.. this way you can pin them to their chair when you go postal.
What frustrates me a bit about TFA is where they stopped. They identified what the malware is, does, where it comes from, etc. They seem to have left out the 'why' part of the equation. Who would buy the data, and for what purpose? Dig a little deeper here. What we are defending against becomes a lot clearer when the motives of the attacker are known. This exploit is sophisticated and mature. It appears to be a viable business. This is not the action of an individual bent on personal gain, rather a true-world example of organized crime. This is much more serious than we're being led to believe. This is what gives me pause: What kind of customer would pay for access to such a broad set of data?
Very pro deconstruction though. I usually just whipe the little buggers.
I'll just use my special getting high powers one more time...
slashdotted?
here is an effective way to make a Trojan useless: just post it on slashdot
The further away you get from M$, the better off you are. IE is the pits but other browsers on the platform will use M$'s flawed underlying code at times for compatibility. There are lots of IE specific bones on this one but once the machine is compromised anything is possible. You keep IE around for that one page that needs it, right? All it takes is a rotten banner ad to blow you out that one time you use it. M$'s internet services are starting to mirror their PC performance when it comes handing out malware. The more you use M$, the worse off you are.
The next time you end up wiping and reloading because of problems like this, why not save time and install something that just works?
Friends don't help friends install M$ junk.
you seem to have some problems understanding how the world works. the programmers who do these things are not untouchable, nor do they go to the great lengths you describe to make themselves untouchable. why? because no one can do business and also be a puff of smoke at the same time. it's a balance you have to strike between being hard to find by the authorities and easy to find by your business interests. it easy to be hard to find by the authorities. even when they see you, their hands are tied
however, it is those very business interests i describe above whom you have to worry about more than the authorities
you cannot do business with the underworld, and not also be made part of the underworld in the process. you fail to understand the dynamics of the situation these programmers are in. you fail to understand the mafia. if you deal with the mafia, and you yourself are doing something shady, the mafia simply moves into your turf. they will simply come to own you, one way or another, and there is absolutely nothing you can do about it
get someone to protect you from them? who? the authorities? you're already illegal yourself. another mafia group? ok, fine: you're not dealing with the original evil a**holes who were threatening to coopt your life, but now you are dealing with another group of evil a**holes who have the same methodologies and goals, so you have the same problem. protect yourself? ok, now you have become the evil a**hole yourself. you have the stomach to threaten loved ones, put innocents in harms way, deal in murder? it's a big step up from internet crime my friend. it's one thing to pilfer a moron's bank account. it's another thing to kill the 9 year old daughter of the mafia tycoon who won't leave your business alone
in other words, deal with the devil, and the devil owns you, no matter what. you are not untouchable when you deal with the mafia and you also make money shady like they do and you do business with them. you have no relatives who can be threatened? you love no one in this world who can't be hurt or found?
in short, you're rather naive about the subject matter you are commenting on. you really haven't the faintest clue about how vile these people are, the mafias of the world
and, therefore, in a way, you are lucky, in your naivete, to be so blissfully unawares of these monsters in your midst. pray you stay that way, naive and clueless about how these type of organizations really operate. it's the best way to live your life. you really don't want to know about these guys, nor boadly boast about how untouchable you would make yourself from them via a few proxies. right, yeah. if you are doing shady work, and you are in business with them, and you are making a nice amount of cash, consider yourself pwned
intellectual property law is philosophically incoherent. it is your moral duty to ignore it or sabotage it
tell me something, as you appear to be russian: is it merely a hollywood stereotype that the russian mafia exerts so much influence in russia? i mean even putin seems to be playing the authoritarian game of "do as i say or you're going down". is it a stereotype? or is it true that the underworld seems to have an especially strong grasp on russia? why? hangover from the collapse of the soviet union? filling some sort of power void?
i ask in complete innocence, but sitting here in new york city, where we are no stranger to organized crime, but russia seems to me to be caught in the especially strong underworld net as compared to other locales. fact or fiction? if so, why?
intellectual property law is philosophically incoherent. it is your moral duty to ignore it or sabotage it
the NPG electrode was replaced with carbon blac
# create object associated with price list
$price = 'pesdato!'; The correct translation of 'pesdato!' would be 'fukken-A!'.
I passed the Turing test.
Check this out: The malware opened the named pipe "\\.\PIPE\lsarpc" and the "C:\autoexec.bat" file, but the tools did not log any writes. The tools were "a Windows XP VMware virtual machine with tools designed for behavioral analysis". A little further down: Upack stub code is executed from the memory allocated for the executable's PE header. However, as it executes, that code changes, making normal breakpoints -- those set for certain code at certain addresses -- ineffective. Whoever wrote that binary also knew quite a bit about the way the overall architecture of the x86 series running the Windows kernel can be used to hide between the cracks. SecureWorks Senior Security Researcher Joe Stewart wrote OllyBonE (Break on Execute), a plug-in for OllyDbg that would be very useful. To use it, the malware executable would have to be moved out of the virtual machine and debugged on native hardware. A 750 MHz Pentium III and 512 MB RAM was loaded with a default install of Windows XP Professional SP2 in an isolated environment. OllyDbg, Joe's OllyBone plug-in, and the malware executable were copied to the system. Now we're getting to the point: After dismissing the error, execution is paused in ntdll.dll code. Upack must go back to the PE header for the working EXE file at some point, so bringing up the memory map (ALT+M) and right-clicking on that memory range brings up a context menu, where "Set breakpoint on execute" can be selected. Single stepping.
There's an entire internet full of zero-day trojans which run this deep. I wouldn't be surprised if the same people who know enough to write this rogue code also uses their expertise as a legitimate taxable employee someplace (security writing, security monitoring, detection, forensics, maybe on the LinuxSE team with the government). It's the same knowledgebase.
the NPG electrode was replaced with carbon blac
If you are using Windows, you must use a highly heuristics capable antivirus/security product. No name needed but if you rely on signature based antivirus, you are busted.
Firefox? They would use some Firefox exploit if it was majority.
If viruses appear for Mac, it will be same deal too. There should be a tool watching the behaviour instead of sitting and waiting for pre-defined signatures. Pre defined signatures were given up by serious vendors the first day poly/semi polymorphic DOS virus appeared.
might i ask where it is from? ;-)
the problem with this world is the naive and clueless, yet full of bravado, happily waltzing into a world of crime, extremely confident in their ability to take care of themselves and to handle any bad news guys they encounter
they have no fucking clue
they simply wind up trapped and under the thumb of a guy who has no problem killing their wife or children or girlfriend or parents. and, trapped under that thumb, they sit their silently rueing their younger dumber selves, a younger dumber self who could have just stayed clean, and made a little less money, a little harder, and yet remained free men, not slaves
because that is what you become when you get involved with organized crime: a slave
or dead
take your pick, budding young confident script kiddies
you can't beat the devil
and the devil is not a person, it's a force: evil action begetting more evil action, and severing you from a happy life forever
be warned, mr. young dumb and confident. hopefully you are reading this
intellectual property law is philosophically incoherent. it is your moral duty to ignore it or sabotage it
I don't think so.. this is using the Internet 101:
inetnum: 81.95.144.0 - 81.95.147.255
role: RBusiness Network Registry
address: RBusiness Network
address: The Century Tower Building
address: Ricardo J. Alfari Avenue
address: Panama City
address: Republic of Panama
phone: +1 401 369 8152
e-mail: noc@rbnnetwork.com
admin-c: JK4668-RIPE
tech-c: JI424-RIPE
nic-hdl: RNR4-RIPE
mnt-by: RBN-MNT
route 65.254.48.0/20 Proxy registered route object GNAXNET NET 65 254 32 0 1 GNAXNET NET 65 254 48 0 1 Global Net Access, LLC 55 Marietta St, NW Suite 1720 Atlanta, GA 30303 and as3595 AS GNAXNET AS Global Net Access, LLC 1100 White Street Atlanta, GA 30310 Who ran the Undernet's atlanta.ga.us.undernet.org server? Who worked for GNAX?
the NPG electrode was replaced with carbon blac
The one I'm most familiar with is to get mail from Outlook to Thunderbird. M$'s own interface is terrible and forces the user to save each message as text one at a time with poor control of output location. Mozilla automates the use of the program called, but still uses the program.
You might also look at Mozilla's ActiveX. While I'm sure it's much saner than the controls which were exploited in this threads topic, it's still a use of M$'s unsafe machinery.
Finally, even good code is more dangerous on Windoze then elsewhere. M$ has not yet properly implemented users, permissions and other safety features found in the Unix world. This is one of the reasons it's always been so much easier to break a Windoze box than anything else. The other reason is that most M$ code is poor quality. They bought it and hacked it together and have always shipped with known bugs.
Friends don't help friends install M$ junk.
In Soviet Russia, data hoard leads to you!
Sorry, we'd just gotten well into commenting without a decent Russian reversal yet.
I am officially gone from
Your post was unreadable anyway, but now it has comedic value!
Wow, you really are ignorant. Why do you think SELinux is so hot? Because it copies Microsoft's ACL security model. Why don't you just shut up if you're going to spout worthless ignorant crap like this?
Please, mod parent up for lingustic correctness =) Pesdato (syn. Ohuenno) indeed is better translated like "fckin' awsome" and such =)