New Cridex Malware Copies Tactics From GameOver Zeus
Trailrunner7 writes The GameOver Zeus malware had a nice run for itself, making untold millions of dollars for its creators. But it was a run that ended with a multi-continent operation from law enforcement and security researchers to disassemble the infrastructure. Now researchers have identified a new variant of the Cridex malware that has adopted some of the techniques that made GOZ so successful in its day.
Researchers at IBM's X-Force research team have seen a new version of Cridex, which is also known as Bugat and Feodo, using some of the same techniques that GOZ used to such good effect. Specifically, the new strain of malware has adopted GOZ's penchant for using HTML injections, and the researchers say the technique is nearly identical to the way that GOZ handled it.
"There are two possible explanations for this. First, someone from the GOZ group could have moved to the Bugat team. This would not be the first time something like this has happened, which we've witnessed in other cases involving Zeus and Citadel; however, it is not very likely in this case since Bugat and GOZ are essentially competitors, while Zeus and Citadel are closely related. The second and more likely explanation is that the Bugat team could have analyzed and perhaps reversed the GOZ malware before copying the HTML injections that made GOZ so highly profitable for its operators," Etay Maor, a senior fraud prevention strategist at IBM, wrote in an analysis of the new malware.
Researchers at IBM's X-Force research team have seen a new version of Cridex, which is also known as Bugat and Feodo, using some of the same techniques that GOZ used to such good effect. Specifically, the new strain of malware has adopted GOZ's penchant for using HTML injections, and the researchers say the technique is nearly identical to the way that GOZ handled it.
"There are two possible explanations for this. First, someone from the GOZ group could have moved to the Bugat team. This would not be the first time something like this has happened, which we've witnessed in other cases involving Zeus and Citadel; however, it is not very likely in this case since Bugat and GOZ are essentially competitors, while Zeus and Citadel are closely related. The second and more likely explanation is that the Bugat team could have analyzed and perhaps reversed the GOZ malware before copying the HTML injections that made GOZ so highly profitable for its operators," Etay Maor, a senior fraud prevention strategist at IBM, wrote in an analysis of the new malware.
Of course IBM found this, they have relocated to China where all this shite comes from. I personally wouldn't doubt that eventually they will work with the Chinese government on these sorts of things. A little you wash my back I'll wash yours, and Bob's your uncle, a nice fat contract. Take that for what it's worth from an AC.
... plus a third, in that no lessons were learned from those two.
It little behooves the best of us to comment on the rest of us.
And here I though I knew english.
Looks like the djerkoff had it WAY wrong!
Please post how to make a million us dollars off this program easy step by step please
United States 58.4% spam king. China 5.6%. The United States is the leading malware-hosting nation. U.S. hosted 44 percent of all malware. Even the U.S. government is doing it: "After failing to infect targets with malware in spam emails, the U.S. National Security Agency has reportedly turned to Facebook. According to a report by The Intercept, the NSA “disguises itself as a fake Facebook server” to perform “man-in-the-middle” and “man-on-the-side” attacks and spreads malware. The Intercept is the first in a series of publications created by Pierre Omidyar‘s First Look Media." The U.S. has overtaken India and Russia to become the biggest producer of viruses, according to Network Box. The U.S. is now responsible for 12.05 per cent of the world’s viruses, up from 4.03 per cent from August. GCHQ prefers to put child porn on people's computers according to the Guardian newspaper.
Zeus variants are too with this data (& security community reports) -> https://zeustracker.abuse.ch/m... + this:
APK Hosts File Engine 9.0++ 32/64-bit:
http://start64.com/index.php?o...
(Details of benefits in link)
Summary:
---
A.) Hosts do more than:
1.) AdBlock ("souled-out" 2 Google/Crippled by default)
2.) Ghostery (Advertiser owned) - "Fox guards henhouse"
3.) Request Policy -> http://yro.slashdot.org/commen...
B.) Hosts add reliability vs. downed/redirected dns (& overcome redirects on sites, /. beta as an example).
C.) Hosts secure vs. malicious domains too -> http://tech.slashdot.org/comme... w/ less added "moving parts" complexity/room 4 breakdown,
D.) Hosts files yield more:
1.) Speed (adblock & hardcodes fav sites - faster than remote dns)
2.) Security (vs. malicious domains serving malcontent + block spam/phish & trackers)
3.) Reliability (vs. downed or Kaminsky redirect vulnerable dns, 99% = unpatched vs. it & worst @ isp level + weak vs Fastflux + dynamic dns botnets)
4.) Anonymity (vs. dns request logs + dnsbl's).
---
* Hosts do more w/ less (1 file) @ faster levels (ring 0) vs redundant inefficient addons (slowing slower ring 3 browsers) via filtering 4 the IP stack (coded in C, loads w/ os, & 1st net resolver queried w\ 45++ yrs.of optimization).
* Addons = more complex + slow browsers in message passing (use a few concurrently & see) & are nullified by native browser methods - It's how Clarityray is destroying Adblock.
* Addons slowup slower usermode browsers layering on more - & bloat RAM consumption too + hugely excessive cpu use (4++gb extra in FireFox https://blog.mozilla.org/nneth...)
Work w/ a native kernelmode part - hosts files (An integrated part of the ip stack)
APK
P.S.=> "The premise is quite simple: Take something designed by nature & reprogram it to make it work for the body rather than against it..." - Dr. Alice Krippen: "I am legend"
...apk
It supplies BOTH the botnet's C&C IP addresses + host-domain names to add to firewalls rules tables + custom hosts files-> https://feodotracker.abuse.ch/
(Gotta love those guys over @ abuse.ch... they're the BEST!)
They're indicative (alongside computer security news sites too of course that expose their excellent research) of what I meant by "security reports" helping in my initial post (that ODDLY keeps getting modded down... oh well - I just repost it along with THIS good news of a source to block this botnet out too, specifically, as to another Zeus variant to shutdown on YOUR end, as an end user or network admin!).
APK
P.S.=> They're another great source to use alongside (yes, shameless plug) my APK Hosts File Engine 9.0++ 32/64-bit & firewalls to stop these suckers from even BEGINNING to get ahold of you as a zombie in a botnet or to rip you off personally... & even *IF* you're infected/infested already? Nice part is, this 'cuts off' the botnet client from "communicating back to HQ" @ all, effectively nullifying it... multiple bonus!
... apk
I can't block IP addresses in my hosts file, you lose.
"It supplies BOTH the botnet's C&C IP addresses + host-domain names to add to firewalls rules tables + custom hosts files-> https://feodotracker.abuse.ch/" - by APK on Monday August 18, 2014 @09:32AM
I noted firewall rules tables here dimwit (get your "hooked on phonics" remedial reading aids out) -> http://it.slashdot.org/comment...
* Didn't I? Yes, I did... learn to read, freak. I mean, seriously: YOU have just GOT to be kidding me (or yourself)... or you are massively stupid - take your pick!
APK
P.S.=> See subject-line & "sound it out" IF you *have* to (& apparently, you do, cretin) + I see you've run dry of modpoints to downmod my posts with too (hahaha)...
... apk