<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: crimeware]]></title>
    <link>http://securityratty.com/tag/crimeware</link>
    <description></description>
    <pubDate>Thu, 02 Oct 2008 03:33:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Yet Another Web Malware Exploitation Kit in the Wild]]></title>
      <link>http://securityratty.com/article/5caa05f53942f1ddb87a74f20c2c3599</link>
      <guid>http://securityratty.com/article/5caa05f53942f1ddb87a74f20c2c3599</guid>
      <description><![CDATA[With business-minded malicious attackers embracing basic marketing practices like branding, it is becoming increasingly harder, if not pointless to keep track of all XYZ-Packs currently in...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/STR4MhsqHZI/AAAAAAAACfY/EnFEn5S9XMY/s1600-h/5Qqp497mdd.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/STR4MhsqHZI/AAAAAAAACfY/EnFEn5S9XMY/s200/5Qqp497mdd.png" /></a>With business-minded malicious attackers embracing basic marketing practices like branding, it is becoming increasingly harder, if not pointless to keep track of all XYZ-Packs currently in circulation. How come? Due to their open source nature allowing modifications, claiming copyright over the modified and re-branded kit, the source code of core web malware exploitation kits continue representing the foundation source code for each and every newly released kit.<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/STSLw4XodgI/AAAAAAAACfg/0WZInEH3pD4/s1600-h/gPdiZb9b7u_.PNG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/STSLw4XodgI/AAAAAAAACfg/0WZInEH3pD4/s200/gPdiZb9b7u_.PNG" /></a>In fact, the practice is becoming so evident, that anecdotal evidence in the form of monitoring ongoing communications between sellers and buyers reveals actual attempts of intellectual property enforcement in the form of&nbsp; exchange of flames between an author of a original kit, and a newly born author who seems to have copied over 80% of his source code, changed the layout, re-branded it, added several more exploits and started pitching it as the most exclusive kit there is available in the underground marketplace.<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/STSL6Yo0fFI/AAAAAAAACfo/7OQAGGmvwHg/s1600-h/9CtxtBWp6S_.PNG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/STSL6Yo0fFI/AAAAAAAACfo/7OQAGGmvwHg/s200/9CtxtBWp6S_.PNG" /></a>What's new about this particular kit anyway? Changed iframe and js obfuscation techniques, doesn't require MySQL to run, with several modified Adobe Acrobat and Flash exploits - all patched and publicly obtainable. This is precisely where the marketing pitch ends for the majority of malware kits released during the last quarter. <br />
<br />
As always, there are noticable exceptions to the common wisdom that time-to-underground market isn't allowing them to innovate, but thankfully, these exceptions aren't yet going mainstream. What is going to change in the upcoming 2009? Web malware exploitation kits are slowly maturing into multi-user cybercrime platforms, where traffic management coming from the SQL injected or malware embedded sites is automatically exploited with access to the infected hosts or to the traffic volume in general offered for sale under a flat rate, or on a volume basis.<br />
<br />
Converging traffic management with drive-by exploitation and offering the output for sale, all from a single web interface, is precisely what <a href="http://ddanchev.blogspot.com/2007/07/malware-embedded-sites-increasing.html">malicious economies of scale</a> is all about.<br />
<br />
<b>Related posts:</b><br />
<a href="http://blogs.zdnet.com/security/?p=2217">Cybercriminals release Christmas themed web malware exploitation kit</a><cite></cite><b></b><br />
<a href="http://ddanchev.blogspot.com/2008/11/new-web-malware-exploitation-kit-in.html">New Web Malware Exploitation Kit in the Wild</a><b></b><br />
<a href="http://ddanchev.blogspot.com/2008/11/modified-zeus-crimeware-kit-gets.html">Modified Zeus Crimeware Kit Gets a Performance Boost</a><b>&nbsp;</b><br />
<a href="http://ddanchev.blogspot.com/2008/11/zeus-crimeware-kit-gets-carding-layout.html">Zeus Crimeware Kit Gets a Carding Layout</a><br />
<a href="http://ddanchev.blogspot.com/2008/10/web-based-malware-emphasizes-on-anti.html">Web Based Malware Emphasizes on Anti-Debugging Features</a><br />
<a href="http://ddanchev.blogspot.com/2008/10/copycat-web-malware-exploitation-kit.html">Copycat Web Malware Exploitation Kit Comes with Disclaimer</a><br />
<a href="http://ddanchev.blogspot.com/2008/10/web-based-malware-eradicates-rootkits.html">Web Based Malware Eradicates Rootkits and Competing Malware</a><br />
<a href="http://ddanchev.blogspot.com/2008/09/two-copycat-web-malware-exploitation.html">Two Copycat Web Malware Exploitation Kits in the Wild</a><br />
<a href="http://ddanchev.blogspot.com/2008/09/copycat-web-malware-exploitation-kits.html">Copycat Web Malware Exploitation Kits are Faddish</a><br />
<a href="http://ddanchev.blogspot.com/2008/08/web-based-botnet-command-and-control.html">Web Based Botnet Command and Control Kit 2.0</a> <br />
<a href="http://ddanchev.blogspot.com/2008/02/blackenergy-ddos-bot-web-based-c.html">BlackEnergy  DDoS Bot Web Based</a><br />
<a href="http://ddanchev.blogspot.com/2007/09/new-ddos-malware-kit-in-wild.html">A  New DDoS Malware Kit in the Wild</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/small-pack-web-malware-exploitation-kit.html">The  Small Pack Web Malware Exploitation Kit</a><br />
<a href="http://ddanchev.blogspot.com/2006/11/nuclear-grabber-toolkit.html">The  Nuclear Grabber Kit</a><br />
<a href="http://ddanchev.blogspot.com/2008/02/rbns-phishing-activities.html">The  Apophis Kit</a><br />
<a href="http://ddanchev.blogspot.com/2007/08/nuclear-malware-kit.html">Nuclear  Malware Kit</a><br />
<a href="http://ddanchev.blogspot.com/2008/01/random-js-malware-exploitation-kit.html">The  Random JS Malware Exploitation Kit</a><br />
<a href="http://ddanchev.blogspot.com/2007/11/metaphisher-malware-kit-spotted-in-wild.html">Metaphisher  Malware Kit Spotted in the Wild</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=gqSxO"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=gqSxO" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=kPWXO"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=kPWXO" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=IWaVo"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=IWaVo" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=AQnUo"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=AQnUo" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=z4nXO"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=z4nXO" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=f162O"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=f162O" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=zFrIo"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=zFrIo" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/472427816" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 02 Dec 2008 03:24:43 +0000</pubDate>
      <category domain="http://securityratty.com/tag/kit">kit</category>
      <category domain="http://securityratty.com/tag/malware exploitation kit">malware exploitation kit</category>
      <category domain="http://securityratty.com/tag/nuclear malware kit">nuclear malware kit</category>
      <category domain="http://securityratty.com/tag/zeus crimeware kit">zeus crimeware kit</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/exclusive kit">exclusive kit</category>
      <category domain="http://securityratty.com/tag/nuclear grabber kit">nuclear grabber kit</category>
      <category domain="http://securityratty.com/tag/apophis kit">apophis kit</category>
      <category domain="http://securityratty.com/tag/ddos malware kit">ddos malware kit</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/472427816/yet-another-web-malware-exploitation.html">Yet Another Web Malware Exploitation Kit in the Wild</source>
    </item>
    <item>
      <title><![CDATA[New Web Malware Exploitation Kit in the Wild]]></title>
      <link>http://securityratty.com/article/b14bf267debe94a6c65be57f5460b9a5</link>
      <guid>http://securityratty.com/article/b14bf267debe94a6c65be57f5460b9a5</guid>
      <description><![CDATA[Oops, they keep doing it, again and again - trying to cash-in on the biased exclusiveness of web malware exploitation kits in general, which when combined with active branding is supposed to make them...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SSM95r20KJI/AAAAAAAACd8/zSHqY21iofM/s1600-h/XYZ_web_exploitation_malware_kit_1.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SSM95r20KJI/AAAAAAAACd8/zSHqY21iofM/s200/XYZ_web_exploitation_malware_kit_1.JPG" /></a>Oops, they keep doing it, again and again - trying to cash-in on the biased exclusiveness of web malware exploitation kits in general, which when combined with active branding is supposed to make them rich. However, despite the low price of $300 in this particular case, this copycat kit is once again lacking any signification differentiation factors besides perhaps the 20+ exploits targeting Opera and Internet Explorer included within.<br />
<br />
<div style="text-align: left;"><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SSNBwwoW4tI/AAAAAAAACeE/TafqAoH3ohM/s1600-h/XYZ_web_exploitation_malware_kit_2.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SSNBwwoW4tI/AAAAAAAACeE/TafqAoH3ohM/s200/XYZ_web_exploitation_malware_kit_2.JPG" /></a> Marketed for novice users, despite lacking any key features worth being worried about, it's still managing to maintain a steady infection rate of unpatched Opera browsers. Such statistics obtained in an OSINT fashion always provide a realistic perspective on publicly known facts, like the one where millions of end users continue getting exploited due to their overall misunderstanding of today's threatscape driven by the ubiquitous web exploitation kits.<b>&nbsp;</b></div><div style="text-align: left;"></div><div style="text-align: left;"></div><div style="text-align: left;"></div><div style="text-align: left;"></div><div style="text-align: left;"></div><div style="text-align: left;"></div><div style="text-align: left;"><br />
<b>Related posts:</b></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://ddanchev.blogspot.com/2008/11/modified-zeus-crimeware-kit-gets.html">Modified Zeus Crimeware Kit Gets a Performance Boost</a><b>&nbsp;</b><br />
<a href="http://ddanchev.blogspot.com/2008/11/zeus-crimeware-kit-gets-carding-layout.html">Zeus Crimeware Kit Gets a Carding Layout</a><br />
<a href="http://ddanchev.blogspot.com/2008/10/web-based-malware-emphasizes-on-anti.html">Web Based Malware Emphasizes on Anti-Debugging Features</a><br />
<a href="http://ddanchev.blogspot.com/2008/10/copycat-web-malware-exploitation-kit.html">Copycat Web Malware Exploitation Kit Comes with Disclaimer</a><br />
<a href="http://ddanchev.blogspot.com/2008/10/web-based-malware-eradicates-rootkits.html">Web Based Malware Eradicates Rootkits and Competing Malware</a><br />
<a href="http://ddanchev.blogspot.com/2008/09/two-copycat-web-malware-exploitation.html">Two Copycat Web Malware Exploitation Kits in the Wild</a><br />
<a href="http://ddanchev.blogspot.com/2008/09/copycat-web-malware-exploitation-kits.html">Copycat Web Malware Exploitation Kits are Faddish</a><br />
<a href="http://ddanchev.blogspot.com/2008/08/web-based-botnet-command-and-control.html">Web Based Botnet Command and Control Kit 2.0</a> <br />
<a href="http://ddanchev.blogspot.com/2008/02/blackenergy-ddos-bot-web-based-c.html">BlackEnergy  DDoS Bot Web Based</a><br />
<a href="http://ddanchev.blogspot.com/2007/09/new-ddos-malware-kit-in-wild.html">A  New DDoS Malware Kit in the Wild</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/small-pack-web-malware-exploitation-kit.html">The  Small Pack Web Malware Exploitation Kit</a><br />
<a href="http://ddanchev.blogspot.com/2006/11/nuclear-grabber-toolkit.html">The  Nuclear Grabber Kit</a><br />
<a href="http://ddanchev.blogspot.com/2008/02/rbns-phishing-activities.html">The  Apophis Kit</a><br />
<a href="http://ddanchev.blogspot.com/2007/08/nuclear-malware-kit.html">Nuclear  Malware Kit</a><br />
<a href="http://ddanchev.blogspot.com/2008/01/random-js-malware-exploitation-kit.html">The  Random JS Malware Exploitation Kit</a><br />
<a href="http://ddanchev.blogspot.com/2007/11/metaphisher-malware-kit-spotted-in-wild.html">Metaphisher  Malware Kit Spotted in the Wild</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=8y1lN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=8y1lN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=IOKKN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=IOKKN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=uqbmn"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=uqbmn" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=jfHFn"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=jfHFn" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=FJVwN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=FJVwN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=BxLfN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=BxLfN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=zWfkn"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=zWfkn" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/458244891" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 19 Nov 2008 01:15:01 +0000</pubDate>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/malware exploitation kit">malware exploitation kit</category>
      <category domain="http://securityratty.com/tag/web based malware">web based malware</category>
      <category domain="http://securityratty.com/tag/nuclear malware kit">nuclear malware kit</category>
      <category domain="http://securityratty.com/tag/ddos malware kit">ddos malware kit</category>
      <category domain="http://securityratty.com/tag/zeus crimeware kit">zeus crimeware kit</category>
      <category domain="http://securityratty.com/tag/wild">wild</category>
      <category domain="http://securityratty.com/tag/key features worth">key features worth</category>
      <category domain="http://securityratty.com/tag/metaphisher malware kit">metaphisher malware kit</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/458244891/new-web-malware-exploitation-kit-in.html">New Web Malware Exploitation Kit in the Wild</source>
    </item>
    <item>
      <title><![CDATA[Will Code Malware for Financial Incentives]]></title>
      <link>http://securityratty.com/article/30eebfa1383ce3a671879e2f1f0af37d</link>
      <guid>http://securityratty.com/article/30eebfa1383ce3a671879e2f1f0af37d</guid>
      <description><![CDATA[A couple of hundred dollars can indeed get you state of the art undetectable piece of malware with post-purchase service in the form of automatic lower detection rate for sure, but what happens when...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><div class="separator" style="clear: both; text-align: center;"></div><div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SSLQOaWm71I/AAAAAAAACdM/nHHgxqAJn-4/s1600-h/malware_hire_sample_1.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SSLQOaWm71I/AAAAAAAACdM/nHHgxqAJn-4/s200/malware_hire_sample_1.JPG" /></a>A couple of hundred dollars can indeed get you state of the art <a href="http://ddanchev.blogspot.com/2008/07/coding-spyware-and-malware-for-hire.html">undetectable piece of malware with post-purchase service</a> in the form of automatic lower detection rate for sure, but what happens when the vendors of such releases start vertically integrating just like everyone else, and start offering OS-independent spamming, flooding, modifications and tweaking of popular crimeware kits in the very same fashion? The quality assurance process gets centralized into the hands of experienced programmers that have been developing cybercrime facilitating tools for years.<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SSLcUHXGAoI/AAAAAAAACdU/wnzsUHFHSrg/s1600-h/malware_hire_sample_2.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SSLcUHXGAoI/AAAAAAAACdU/wnzsUHFHSrg/s200/malware_hire_sample_2.JPG" /></a>It's interesting to monitor the pricing schemes that they implement. For instance, the modularity of a particular malware, that is the additional functions that a buyer may want or not want, increase or decrease the price respectively. Others, tend to leave the price open topic by only mentioning the starting price for their services and they increasing it again in open topic fashion.<br />
<br />
Let's take look at some recently advertised (translated) "malware coding for hire" propositions, highlighting some of the latest developments in their pricing strategies :<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SSMEwnRgU6I/AAAAAAAACdc/bFEBpsTalQQ/s1600-h/malware_hire_sample_3.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SSMEwnRgU6I/AAAAAAAACdc/bFEBpsTalQQ/s200/malware_hire_sample_3.JPG" /></a><b>Proposition 1</b> : <br />
"<i>Programs and scripts under the following categories are accepted : </i><br />
<i>grabbers; spamming tools for forums, spamming tools for social networking sites, modifications of admin panels for (popular crimeware kits), phishing pages</i><br />
<br />
<i>Platform: software running on MAC OS to Windows  </i><br />
<i>Multitasking: have the capacity to work on multiple projects</i><br />
<i>Speed and responsibility: at the highest level  </i><br />
<i>Pre-payment for new customers: 50% of the whole price, 30% pre-pay of the whole price for repreated customers  </i><br />
<i>Support: Paid  </i><br />
<i>Rates: starting from 100 euros</i><br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SSMGg5E49_I/AAAAAAAACds/lWtlV3eYu4s/s1600-h/malware_hire_sample_4.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SSMGg5E49_I/AAAAAAAACds/lWtlV3eYu4s/s200/malware_hire_sample_4.JPG" /></a><i>If, after speaking ultimate price, you decide to add to your order something else - the price change. Prepare the job immediately, which will understand what to do and how much it will cost you, if you have any suggestions for a price, then lays them immediately and not after the work is completed. If you order something that requires parsing your logs, and their continued use, you agree to provide "a significant portion of the logs, so that after putting the project did not raise misunderstandings due to the fact that some logs are no longer "fresh", because of their "uniqueness". In this case, for the finalization of the project will be charged an additional fee.</i>"<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SSMKeg8y5SI/AAAAAAAACd0/ekeV4Us8PwY/s1600-h/malware_hire_sample_5.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SSMKeg8y5SI/AAAAAAAACd0/ekeV4Us8PwY/s200/malware_hire_sample_5.JPG" /></a>This is an example of an "open topic pricing scheme" with the vendor offering the possibility to code the malware or the tool for any price above 100 euro based on what he perceives as features included within worth the price.<br />
<br />
<b>Proposition 2</b>:<br />
"<i>Starting price for my malware is 250 EUR. Additional modules like P2P features, source code for a particular module go for an additional 50 EUR. If you're paying in another currency the price is 200 GBP or 395 dollars. I sell only ten copies of the builder so hurry up. The trading process is simple - a password protected file with the malware is sent to you so you can see the files inside. You then sent the money and I mail you back the password. If you don't like this way you lose.&nbsp;</i><br />
<br />
<i>I can also offer you another deal, I will share the complete source code in exchange to access to a botnet with at least 4000 infected hosts because I don't have time to play around with me bot right now.</i> <br />
<br />
This proposition is particularly interesting because the seller is introducing basic understanding of exchange rates, but most of all because he's in fact offering a direct bargain in the form of access to a botnet in exchange for a complete source code of his malware bot. Both propositions are also great examples that vendors engage by keeping their current and potential customers up-to-date with <a href="http://ddanchev.blogspot.com/2008/04/botnet-masters-to-do-list.html">TODO lists of features to come</a> next to the usual CHANGELOGS, and, of course,&nbsp; establish trust by allowing potential customers to take a peek at the source code of the malware they're about to purchase.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2008/07/coding-spyware-and-malware-for-hire.html">Coding Spyware and Malware for Hire </a><br />
<a href="http://ddanchev.blogspot.com/2007/03/underground-economys-supply-of-goods.html">The Underground Economy's Supply of Goods and Services</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/dynamics-of-malware-industry.html">The Dynamics of the Malware Industry - Proprietary Malware Tools</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/using-market-forces-to-disrupt-botnets.html">Using Market Forces to Disrupt Botnets</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/multiple-firewalls-bypassing.html">Multiple Firewalls Bypassing Verification on Demand</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/managed-spamming-appliances-future-of.html">Managed Spamming Appliances - The Future of Spam</a><br />
<a href="http://ddanchev.blogspot.com/2008/02/localizing-cybercrime-cultural.html">Localizing Cybercrime - Cultural Diversity on Demand</a><br />
<a href="http://ddanchev.blogspot.com/2008/01/e-crime-and-socioeconomic-factors.html">E-crime and Socioeconomic Factors</a><br />
<a href="http://ddanchev.blogspot.com/2007/12/russias-fsb-vs-cybercrime.html">Russia's FSB vs Cybercrime</a><br />
<a href="http://ddanchev.blogspot.com/2007/08/malware-as-web-service.html">Malware as a Web Service</a><br />
<a href="http://ddanchev.blogspot.com/2007/09/localizing-open-source-malware.html">Localizing Open Source Malware</a><br />
<a href="http://ddanchev.blogspot.com/2008/04/quality-and-assurance-in-malware.html">Quality and Assurance in Malware Attacks</a><br />
<a href="http://ddanchev.blogspot.com/2006/09/benchmarking-and-optimising-malware.html">Benchmarking and Optimising Malware</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=a8huN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=a8huN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=sEoBN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=sEoBN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Rj24n"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Rj24n" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=W4aen"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=W4aen" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=7YAqN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=7YAqN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=rEDhN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=rEDhN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=rpNUn"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=rpNUn" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/457569401" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 18 Nov 2008 10:57:55 +0000</pubDate>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/code">code</category>
      <category domain="http://securityratty.com/tag/source malware">source malware</category>
      <category domain="http://securityratty.com/tag/malware attacks">malware attacks</category>
      <category domain="http://securityratty.com/tag/malware bot">malware bot</category>
      <category domain="http://securityratty.com/tag/proprietary malware tools">proprietary malware tools</category>
      <category domain="http://securityratty.com/tag/source code">source code</category>
      <category domain="http://securityratty.com/tag/complete source code">complete source code</category>
      <category domain="http://securityratty.com/tag/tools">tools</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/457569401/will-code-malware-for-financial.html">Will Code Malware for Financial Incentives</source>
    </item>
    <item>
      <title><![CDATA[Zeus Crimeware Kit Gets a Carding Layout]]></title>
      <link>http://securityratty.com/article/2dadca90df89c26f3f517a1e2b237afd</link>
      <guid>http://securityratty.com/article/2dadca90df89c26f3f517a1e2b237afd</guid>
      <description><![CDATA[With cybercriminals clearly expressing their nostalgia for several notorious and already shut down credit card fraud communities, they seem to have found a way to once again give their self-esteem a...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SRgXkf4easI/AAAAAAAACbU/eTHcGM--Oww/s1600-h/zeus_new_layout_22.GIF" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SRgXkf4easI/AAAAAAAACbU/eTHcGM--Oww/s200/zeus_new_layout_22.GIF" /></a>With cybercriminals clearly expressing their nostalgia for several notorious and already shut down credit card fraud communities, they seem to have found a way to once again give their self-esteem a boost. Following the <a href="http://ddanchev.blogspot.com/2008/11/modified-zeus-crimeware-kit-gets.html">ongoing modification</a> of open source <a href="http://ddanchev.blogspot.com/2008/09/modified-zeus-crimeware-kit-comes-with.html">crimeware kits</a> and the inevitable innovation introduced <a href="http://ddanchev.blogspot.com/2008/06/zeus-crimeware-kit-vulnerable-to.html">by third parties</a>, last week a new layout was introduced for Zeus, once again courtesy of a group that's piggybacking on Zeus popularity.<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div>It's particularly interesting to see how a one-man operation evolves into a group of third-party developers starting to claim ownership rights over the modified versions despite that they're basically brandjacking the Zeus brand and building business models on the top of it.<br />
<br />
<a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SRgZzIlf-eI/AAAAAAAACbc/YsBowySVmSk/s1600-h/zeus_new_layout_11.GIF" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SRgZzIlf-eI/AAAAAAAACbc/YsBowySVmSk/s200/zeus_new_layout_11.GIF" /></a>Open source crimeware and web malware exploitation kits on the other hand undermine the business model of a great number of "<a href="http://ddanchev.blogspot.com/2008/07/coding-spyware-and-malware-for-hire.html">malware/spyware for hire</a>" vendors, which surprisingly doesn't stop them from continuing offering their services and products which are often using the de facto crimeware kits as the foundations for their propositions. Are the buyers even aware of this fact? From a buyer's perspective in times when most of the output is sold in bulk form, or access to the botnet rented for a specific period of time, the buyer doesn't care about the cybercrime platform of use, but is looking for transparent ways to justify the investment he's made into renting the service.<br />
<br />
Now that Zeus administrators and their cybercrime clerks in the face of those managing the campaigns knowingly or unknowingly knowing the type of campaigns and the data that they manage, can <a href="http://ddanchev.blogspot.com/2008/09/modified-zeus-crimeware-kit-comes-with.html">listen to their favorite music within Zeus</a> and choose different layouts for the command and control interfaces while commiting cybercrime, what's next?<br />
<br />
<a href="http://ddanchev.blogspot.com/2008/08/web-based-botnet-command-and-control.html">Convergence</a> and improved monetization.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=fQb6N"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=fQb6N" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Rhj0N"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Rhj0N" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=9MADn"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=9MADn" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Kqtmn"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Kqtmn" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Cqo2N"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Cqo2N" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=pkhEN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=pkhEN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=i9tYn"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=i9tYn" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/448333234" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 10 Nov 2008 02:53:52 +0000</pubDate>
      <category domain="http://securityratty.com/tag/zeus">zeus</category>
      <category domain="http://securityratty.com/tag/zeus administrators">zeus administrators</category>
      <category domain="http://securityratty.com/tag/zeus popularity">zeus popularity</category>
      <category domain="http://securityratty.com/tag/source crimeware kits">source crimeware kits</category>
      <category domain="http://securityratty.com/tag/cybercrime">cybercrime</category>
      <category domain="http://securityratty.com/tag/cybercrime clerks">cybercrime clerks</category>
      <category domain="http://securityratty.com/tag/source crimeware">source crimeware</category>
      <category domain="http://securityratty.com/tag/zeus brand">zeus brand</category>
      <category domain="http://securityratty.com/tag/cybercrime platform">cybercrime platform</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/448333234/zeus-crimeware-kit-gets-carding-layout.html">Zeus Crimeware Kit Gets a Carding Layout</source>
    </item>
    <item>
      <title><![CDATA[Modified Zeus Crimeware Kit Gets a Performance Boost]]></title>
      <link>http://securityratty.com/article/206d70045cec21b7f158d2fdc041b855</link>
      <guid>http://securityratty.com/article/206d70045cec21b7f158d2fdc041b855</guid>
      <description><![CDATA[Oops, they did it again - modifying an open source crimeware kit like Zeus in order to improve its performance, fix previously known bugs, and release the improved administration script for free at...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SQ8K2EKd8NI/AAAAAAAACaE/UGYKyEUZBKs/s1600-h/modified_zeus_performance_admin.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SQ8K2EKd8NI/AAAAAAAACaE/_DEokn56Kdo/s200-R/modified_zeus_performance_admin.png" /></a>Oops, they did it again - <a href="http://ddanchev.blogspot.com/2008/09/modified-zeus-crimeware-kit-comes-with.html">modifying an open source crimeware kit like Zeus</a> in order to improve its performance, fix previously known bugs, and release the improved administration script for free at the end of October.<br />
<br />
It's important to point out that both of these modifications haven't been released by <a href="http://www.usatoday.com/tech/news/computersecurity/2008-08-04-hacker-cybercrime-zeus-identity-theft_N.htm">the original author of Zeus</a>, but by third parties filling in the gaps he has left open. The very nature of open source web based malware exploitation kits is one of the key factors for the ongoing <a href="http://ddanchev.blogspot.com/2008/08/web-based-botnet-command-and-control.html">convergence of traffic management, exploits serving, ddos, and cybercrime as a service</a> features into a simplified cybercrime platform available on demand.<br />
<br />
Following the discovery of <a href="http://ddanchev.blogspot.com/2008/06/zeus-crimeware-kit-vulnerable-to.html">a remotely exploitable flaw within Zeus in June</a> -- a <a href="http://ddanchev.blogspot.com/2008/08/pinch-vulnerable-to-remotely.html">flaw affecting Pinch</a> leaked out two months later -- allowing cyberciminals to inject their own credentials and hijack the botnet of other cybercriminals, this modified version claims to have fixed three vulnerabilities within the original Zeus release, namely, a remote file inclusion flaw and two SQL injections within the administration panel. Here's the new CHANGELOG :<br />
<br />
"<i>- code improvements and optimizations<br />
- internal data checkings added<br />
- exit() function instead of die()<br />
- echo() function instead of print()<br />
- mysql_affected_rows () changed to mysql_num_rows () everywhere<br />
- all queries are fixed in system or mod .php files<br />
- no text password in the database and clear text password in $_SESSION, cookies authentication is gone and md5 hashes are everywhere<br />
- Geo IP support has been added <br />
- umask () bug fixed, the file has been created (chmoded) with different permissions<br />
- language improvements and pre-installation checks<br />
- checking for php version/safe_mod/open_basedir as you're required to run php 5.1.0 or higher to run it successfully<br />
<b>- fixed sql injection in credentials checking </b><br />
<b>- GetUserData () function has been rewritten - possible sql injection fixed</b><br />
<b>- possible remote file inclusion fixed</b><br />
- socket error definition changed<br />
- gcnt () function has been rewritten so you can use geolication - GeoIP which is free and GeoIPCity which is paid<br />
- ip address checking improved through validIP() function improvement<br />
- all queries are now fixed, input data has been sanitized<br />
- fs () function has been fixed in order to improve the quality of the log names<br />
- formatFilePath () function has been added for file upload purposes<br />
- arbitrary file upload bug has been fixed so that you can now upload only images with original names <br />
- the Log2SQL () function has been changed and stricter data checking/sanitizing is added<br />
- internal file sorting mechanism is improved so that files/dirs are sorted by file modification time</i>"<br />
<br />
As it's becoming increasingly clear that what once used to be a proprietary crimeware kits whose business model got undermined by their open source nature and the fact that they've started leaking for average cybercriminals and script kiddies to take advantage of, are today's "open source projects" - and therefore maintaining static lists of exploits and features included within a particular kit is getting even more irrelevant these days. In the long term, the quality assurance processes applied within crimeware kits courtesy of third party cybercriminals, is prone to shift from performance to <a href="http://ddanchev.blogspot.com/2008/10/quality-and-assurance-in-malware.html">improving the infection rates</a>.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=sKCIN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=sKCIN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=tB0JN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=tB0JN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=1XIkn"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=1XIkn" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=1XWUn"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=1XWUn" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=xmgXN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=xmgXN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=QpufN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=QpufN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=i4Nun"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=i4Nun" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/441336309" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 03 Nov 2008 11:12:30 +0000</pubDate>
      <category domain="http://securityratty.com/tag/fixed">fixed</category>
      <category domain="http://securityratty.com/tag/sql injection fixed">sql injection fixed</category>
      <category domain="http://securityratty.com/tag/zeus">zeus</category>
      <category domain="http://securityratty.com/tag/fixed sql injection">fixed sql injection</category>
      <category domain="http://securityratty.com/tag/upload">upload</category>
      <category domain="http://securityratty.com/tag/file upload purposes">file upload purposes</category>
      <category domain="http://securityratty.com/tag/file">file</category>
      <category domain="http://securityratty.com/tag/function improvement">function improvement</category>
      <category domain="http://securityratty.com/tag/function">function</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/441336309/modified-zeus-crimeware-kit-gets.html">Modified Zeus Crimeware Kit Gets a Performance Boost</source>
    </item>
    <item>
      <title><![CDATA[Crooks can make $5M a year shilling fake security software]]></title>
      <link>http://securityratty.com/article/32391a8062ca2f1d530cfd760b824a25</link>
      <guid>http://securityratty.com/article/32391a8062ca2f1d530cfd760b824a25</guid>
      <description><![CDATA[Criminals can rake in as much as $5 million a year by planting nearly worthless security software on PCs, then badgering users with so many bogus warnings that they pay for the software, a noted...]]></description>
      <content:encoded><![CDATA[Criminals can rake in as much as $5 million a year by planting nearly worthless security software on PCs, then badgering users with so many bogus warnings that they pay for the software, a noted crimeware researcher said today.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:bfbd04044ef6bfce001fbb5d24dfbcfa:624U6%2FlYBIZ4m6zKIU2u4%2B5v3T%2BlVL3iWGlYcRp15AE4ioeVKsd7yJKARriDp7nlduBKJDo%2BiNbf'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:362b0945cbbc7f656f1c895e1b3a34db:5o7caJ5lZnyd3bsqeqiet3Db4mELKQhMRLlFsnlsfy%2BWyUXzG4%2Bi08OfUWYduDpFUagV7LPafOuMDw%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:2ec69255f28d2b35151a70c5d319504b:31WBZb7MSrr21tSusmeI4sbALzAx%2BL1c%2BP9IblgfK6LvTDg%2Bj59n3XGmC3vdLI9UmlqpDGeaY1LgZQ%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:c0bd48b7354f46485230c4dbb8b71b1a:YZZ8SGoi%2FHNquL50ErwHWt25xTwy6%2BaSWgZIl3lbfu40jXkxDOi9giMSitNzAT%2FsDXB5%2FCCmpBDd5w%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>      <a href="http://www.pheedo.com/click.phdo?s=f2be39a259037c6948f13bae7bbda4ad"><img alt="" style="border: 0;" border="0" src="http://www.pheedo.com/img.phdo?s=f2be39a259037c6948f13bae7bbda4ad"/></a>
  <img src="http://www.pheedo.com/feeds/tracker.php?i=f2be39a259037c6948f13bae7bbda4ad" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Fri, 31 Oct 2008 01:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/software">software</category>
      <category domain="http://securityratty.com/tag/worthless security software">worthless security software</category>
      <category domain="http://securityratty.com/tag/noted crimeware researcher">noted crimeware researcher</category>
      <category domain="http://securityratty.com/tag/bogus warnings">bogus warnings</category>
      <category domain="http://securityratty.com/tag/users">users</category>
      <category domain="http://securityratty.com/tag/rake">rake</category>
      <category domain="http://securityratty.com/tag/criminals">criminals</category>
      <category domain="http://securityratty.com/tag/million">million</category>
      <category domain="http://securityratty.com/tag/pcs">pcs</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=f2be39a259037c6948f13bae7bbda4ad">Crooks can make $5M a year shilling fake security software</source>
    </item>
    <item>
      <title><![CDATA[One Sinowal Trojan + One Gang = Hundreds of Thousands of Compromised Accounts ]]></title>
      <link>http://securityratty.com/article/1a4969d994be490ce3b3ac9a5e6ec848</link>
      <guid>http://securityratty.com/article/1a4969d994be490ce3b3ac9a5e6ec848</guid>
      <description><![CDATA[The RSA FraudAction Research Lab would like to share its startling findings based on its tracking and research of the Sinowal Trojan, also known as Torpig and Mebroot . Our findings based on the data...]]></description>
      <content:encoded><![CDATA[The RSA FraudAction Research Lab would like  to share its startling findings based on its tracking and research of the Sinowal  Trojan, also known as <a href="http://en.wikipedia.org/wiki/Torpig">Torpig</a> and <a href="http://www.f-secure.com/weblog/archives/00001510.html">Mebroot</a>.  Our findings based on the data we have collected on this Trojan over the course  of almost three years &ndash; including information regarding its design and its  infrastructure &ndash; indicate that this may be one of the most pervasive and advanced  pieces of crimeware ever created by fraudsters.

We recently discovered that, dating back as  early as February 2006, <B>the Sinowal Trojan has compromised and stolen login  credentials from approximately 300,000 online bank accounts</b>... ]]></content:encoded>
      <pubDate>Thu, 30 Oct 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/sinowal trojan">sinowal trojan</category>
      <category domain="http://securityratty.com/tag/trojan">trojan</category>
      <category domain="http://securityratty.com/tag/findings based">findings based</category>
      <category domain="http://securityratty.com/tag/online bank accounts">online bank accounts</category>
      <category domain="http://securityratty.com/tag/login credentials">login credentials</category>
      <category domain="http://securityratty.com/tag/fraudsters">fraudsters</category>
      <category domain="http://securityratty.com/tag/research">research</category>
      <category domain="http://securityratty.com/tag/design">design</category>
      <category domain="http://securityratty.com/tag/share">share</category>
      <source url="http://www.rsa.com/blog/blog_entry.aspx?id=1378">One Sinowal Trojan + One Gang = Hundreds of Thousands of Compromised Accounts </source>
    </item>
    <item>
      <title><![CDATA[The Shape of Crimeware to Come]]></title>
      <link>http://securityratty.com/article/a1b404ad259e39c1abd23a1671850ad5</link>
      <guid>http://securityratty.com/article/a1b404ad259e39c1abd23a1671850ad5</guid>
      <description><![CDATA[Martin Stytz reviews Crimeware: Understanding New Attacks and...]]></description>
      <content:encoded><![CDATA[Martin Stytz reviews Crimeware: Understanding New Attacks and Defenses.<br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=4271cd8ecaa8de4b57948ef346b21267" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=4271cd8ecaa8de4b57948ef346b21267" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Wed, 08 Oct 2008 00:42:02 +0000</pubDate>
      <category domain="http://securityratty.com/tag/attacks">attacks</category>
      <category domain="http://securityratty.com/tag/defenses">defenses</category>
      <source url="http://www.pheedo.com/click.phdo?i=4271cd8ecaa8de4b57948ef346b21267">The Shape of Crimeware to Come</source>
    </item>
    <item>
      <title><![CDATA[Fake Windows XP Activation Trojan Wants Your CVV2 Code]]></title>
      <link>http://securityratty.com/article/fac8ba92dd4114941015e75bba3149c4</link>
      <guid>http://securityratty.com/article/fac8ba92dd4114941015e75bba3149c4</guid>
      <description><![CDATA[In a self-contradicting social engineering attempt, a malware author is offering to sale a ( updated version of Kardphisher) DIY fake Windows XP activation builder, which despite the fact that it...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SOqbO7J3tvI/AAAAAAAACPg/YNDy4vo817c/s1600-h/fake_windows_xp_activation1.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SOqbO7J3tvI/AAAAAAAACPg/BYpcW4rkU0o/s200-R/fake_windows_xp_activation1.png" /></a>In a self-contradicting social engineering attempt, a malware author is offering to sale a (<a href="http://www.symantec.com/security_response/writeup.jsp?docid=2007-042705-0108-99">updated version</a> of Kardphisher) DIY fake Windows XP activation builder, which despite the fact that it claims "<i>We will ask for your billing details, but your credit card will NOT be charged</i>", is requesting and remotely uploading all the credit card details required for a successfully credit card theft.<br />
<br />
Perhaps among the main reasons why such simplistic social engineering attempts never scaled in a "malicious economies of scale" approach, is because sophisticated crimeware kits capable of obtaining the very same data automatically, started leaking for everyone to start taking advantage of - including yesterday's cybercriminals using such DIY fake message builders. <br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div>Moreover, according to <a href="http://news.ncsu.edu/news/2008/09/wmswogalterfakemessage.php">recently reseased survey results</a>, end users cannot distinguish between fake popups and real ones, and on their way to continue doing what they were doing, click OK on that pesky warning message telling them that they're about to get infected with malware. Taking into consideration the fact that the popup windows the researchers used look like cheap creative compared to the average fake security software's layout high quality GUIs, it is perhaps worth restating your research questions with something in the lines of - <b>What motivates end users to install an antivirus application going under the name of Super Antivirus 2009 or Mega Virus Cleaner 2008?</b> The fact that the fake status bar is telling them that they're infected with 47 spyware cookies, or the fact that they ended up at the fake site while browsing their trusted web services? <br />
<br />
<a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SOqf_xbxL7I/AAAAAAAACPo/6uvXj2AuS_A/s1600-h/fake_windows_xp_activation2.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SOqf_xbxL7I/AAAAAAAACPo/fa1jUBjFGOU/s200-R/fake_windows_xp_activation2.png" /></a>The increase of <a href="http://ddanchev.blogspot.com/2008/09/diverse-portfolio-of-fake-security_30.html">rogue security software domains</a> is happening due to the high payout affiliation based model, the standardized creative allowing the participants to come up with their own fake names if they want to, and due to the fact that the fake security threats scareware approach seems to be perfectly taking advantage of the overall suspicion on the effectiveness of their legitimate security software.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=mw30M"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=mw30M" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=WJFzM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=WJFzM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=jNfpm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=jNfpm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=9lodm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=9lodm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=6go3M"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=6go3M" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=TLsPM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=TLsPM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=JuYBm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=JuYBm" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/413264124" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 06 Oct 2008 15:01:01 +0000</pubDate>
      <category domain="http://securityratty.com/tag/credit card details">credit card details</category>
      <category domain="http://securityratty.com/tag/credit card">credit card</category>
      <category domain="http://securityratty.com/tag/credit card theft">credit card theft</category>
      <category domain="http://securityratty.com/tag/details">details</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/malware author">malware author</category>
      <category domain="http://securityratty.com/tag/social">social</category>
      <category domain="http://securityratty.com/tag/mega virus cleaner">mega virus cleaner</category>
      <category domain="http://securityratty.com/tag/creative">creative</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/413264124/fake-windows-xp-activation-trojan-wants.html">Fake Windows XP Activation Trojan Wants Your CVV2 Code</source>
    </item>
    <item>
      <title><![CDATA[Monetizing Infected Hosts by Hijacking Search Results]]></title>
      <link>http://securityratty.com/article/30b128b9fa2c48983d32dbcc4818d136</link>
      <guid>http://securityratty.com/article/30b128b9fa2c48983d32dbcc4818d136</guid>
      <description><![CDATA[When logs with accounting data are no longer of interest due to low liquidity on the underground market, monetization of the infected hosts comes into play

This web based malware seems like an early...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SOPovcbgMHI/AAAAAAAACNY/PtnyHCXQm30/s1600-h/pict1.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SOPovcbgMHI/AAAAAAAACNY/kLv97AsLUco/s200-R/pict1.jpg" /></a>When logs with accounting data are no longer of interest due to low liquidity on the underground market, monetization of the infected hosts comes into play.<br />
<br />
This web based malware seems like an early BETA aiming to scale, however it's only unique features are its ability to hijack the infected user's searches and server relevant ads courtesy of the affiliate networks the administrator participates in, and also, an integrated DDoS module that the author simply stole from another kit. Strangely, it's 2008 yet the author also included the ability to turn on the telnet service on an infected host. <br />
<br />
<a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SOQZH-8W6ZI/AAAAAAAACOQ/DVWUfx2tkJg/s1600-h/pict2.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SOQZH-8W6ZI/AAAAAAAACOQ/kSX1geifdWA/s200-R/pict2.jpg" /></a>With the search queries feature easy to duplicate by other kits, this web based malware is a great example of how the time-to-market mentality lacking any kind of personal experience -- the malware cannot intercept SSL sessions compared to the majority of crimeware kits that can -- ends up in a weird hybrid of random features.<br />
&nbsp; <br />
<a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SOQZQQsgnMI/AAAAAAAACOY/f1UOwGyrhSo/s1600-h/pict3.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SOQZQQsgnMI/AAAAAAAACOY/4K4tbpQnUys/s200-R/pict3.jpg" /></a><a href="http://ddanchev.blogspot.com/2008/07/coding-spyware-and-malware-for-hire.html">Customerization</a> will inevitably prevail over the product concept mentality.<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=dgQOM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=dgQOM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=oQzAM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=oQzAM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=1wqEm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=1wqEm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=4U2Mm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=4U2Mm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=DbC0M"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=DbC0M" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=605TM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=605TM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=9wzem"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=9wzem" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/409220865" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 02 Oct 2008 03:33:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/web based malware">web based malware</category>
      <category domain="http://securityratty.com/tag/kits">kits</category>
      <category domain="http://securityratty.com/tag/author simply">author simply</category>
      <category domain="http://securityratty.com/tag/author">author</category>
      <category domain="http://securityratty.com/tag/crimeware kits">crimeware kits</category>
      <category domain="http://securityratty.com/tag/intercept ssl sessions">intercept ssl sessions</category>
      <category domain="http://securityratty.com/tag/product concept mentality">product concept mentality</category>
      <category domain="http://securityratty.com/tag/queries feature easy">queries feature easy</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/409220865/monetizing-infected-hosts-by-hijacking.html">Monetizing Infected Hosts by Hijacking Search Results</source>
    </item>
  </channel>
</rss>
