<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: shark3]]></title>
    <link>http://securityratty.com/tag/shark3</link>
    <description></description>
    <pubDate>Sun, 09 Dec 2007 17:44:58 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[The Shark3 Malware is in the Wild]]></title>
      <link>http://securityratty.com/article/dc725612535174610928742a0567c2aa</link>
      <guid>http://securityratty.com/article/dc725612535174610928742a0567c2aa</guid>
      <description><![CDATA[Life's too short to live in uncertainty, the stakes are too high. A month ago, I indicated the upcoming release of the third version of the script kiddies favorite Shark Malware . Despite that after...]]></description>
      <content:encoded><![CDATA[<a href="http://bp3.blogger.com/_wICHhTiQmrA/R6JGPrWhg3I/AAAAAAAABVo/DYlxaox0bvo/s1600-h/shark3.jpg"><img id="BLOGGER_PHOTO_ID_5161765358069187442" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="" src="http://bp3.blogger.com/_wICHhTiQmrA/R6JGPrWhg3I/AAAAAAAABVo/DYlxaox0bvo/s200/shark3.jpg" border="0" /></a>Life's too short to live in uncertainty, the stakes are too high. A month ago, I indicated the <a href="http://ddanchev.blogspot.com/2007/12/shark-malware-new-versions-coming.html">upcoming release</a> of <a href="http://ddanchev.blogspot.com/2007/08/shark-2-diy-malware.html">the third version</a> of the script kiddies favorite <a href="http://ddanchev.blogspot.com/2007/07/shark2-rat-or-malware.html">Shark Malware</a>. Despite that after the negative publicity of the malware that's actually promotd as a RAT, the authors supposedly abondoned the malware, they seem to have logically resumed its development. And so, the Shark3 <div>malware is continuing its development.</div><div><br />What's new? Anti-debugger capabilities in particural against - VmWare, Norman Sandbox, Sandboxie, VirtualPC, Symantec Sandbox, Virtual Box etc.</div><div><br /><a href="http://bp3.blogger.com/_wICHhTiQmrA/R6JvWrWhg4I/AAAAAAAABVw/-_-r1Sf1qV0/s1600-h/shark3_stealth.jpg"><img id="BLOGGER_PHOTO_ID_5161810558305010562" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="" src="http://bp3.blogger.com/_wICHhTiQmrA/R6JvWrWhg4I/AAAAAAAABVw/-_-r1Sf1qV0/s200/shark3_stealth.jpg" border="0" /></a><strong>Detection rate</strong> : Result: 15/31 (48.39%) - Backdoor.Win32.Shark.if<br /></div><div><strong>File size</strong>: 3104768 bytes</div><div><strong>MD5</strong>: e3a6758f5c90b39b59c6cd7551224d52</div><div><strong>SHA1</strong>: 25f025f31560a28275aab006e04aace828e012ea</div><div><br /><br /><br /></div><div></div><div><a href="http://bp0.blogger.com/_wICHhTiQmrA/R6Jvl7Whg5I/AAAAAAAABV4/dXrLutTpNVw/s1600-h/shark3_advanced.jpg"><img id="BLOGGER_PHOTO_ID_5161810820298015634" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="" src="http://bp0.blogger.com/_wICHhTiQmrA/R6Jvl7Whg5I/AAAAAAAABV4/dXrLutTpNVw/s200/shark3_advanced.jpg" border="0" /></a>Some key points regarding Shark :</div><div><br />- its <a href="http://ddanchev.blogspot.com/2008/01/diy-fake-msn-client-stealing-passwords.html">do-it-yourself</a> nature, <a href="http://ddanchev.blogspot.com/2007/10/diy-german-malware-dropper.html">just</a> like <a href="http://ddanchev.blogspot.com/2007/09/diy-phishing-kit-goes-20.html">many</a> of the <a href="http://ddanchev.blogspot.com/2007/09/diy-exploits-embedding-tools.html">malware</a> tools <a href="http://ddanchev.blogspot.com/2007/09/diy-chinese-passwords-stealer.html">I've</a> covered <a href="http://ddanchev.blogspot.com/2007/06/diy-malware-droppers-in-wild.html">before</a> is <a href="http://ddanchev.blogspot.com/2007/10/empowering-script-kiddies.html">empowering script kiddies</a> with advanced point'n'click capabilities</div><div><br /></div><div>- built-in spyware functionaly, namely "aggressive service" which resets the start-up values when they're delted, yet another indication that what's pitched as a RAT is in fact malware</div><div><br /></div><div>- once released in an open source form, a community emerges around it one that starts innovating and coming up with new features</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=uzpTXBD"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=uzpTXBD" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=XJmYHGD"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=XJmYHGD" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=GymYcgd"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=GymYcgd" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=hIN6aQd"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=hIN6aQd" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=MhvUZtD"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=MhvUZtD" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=AdZKBZD"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=AdZKBZD" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=QaIe6Ud"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=QaIe6Ud" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/226903651" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 31 Jan 2008 16:10:57 +0000</pubDate>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/malware tools">malware tools</category>
      <category domain="http://securityratty.com/tag/built-in spyware functionaly">built-in spyware functionaly</category>
      <category domain="http://securityratty.com/tag/script kiddies">script kiddies</category>
      <category domain="http://securityratty.com/tag/shark">shark</category>
      <category domain="http://securityratty.com/tag/aggressive service">aggressive service</category>
      <category domain="http://securityratty.com/tag/negative publicity">negative publicity</category>
      <category domain="http://securityratty.com/tag/rat">rat</category>
      <category domain="http://securityratty.com/tag/authors supposedly">authors supposedly</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/226903651/shark3-malware-is-in-wild.html">The Shark3 Malware is in the Wild</source>
    </item>
    <item>
      <title><![CDATA[The Shark Malware - New Version's Coming]]></title>
      <link>http://securityratty.com/article/aae2ee8a29293c56cf5a4632cc3a660b</link>
      <guid>http://securityratty.com/article/aae2ee8a29293c56cf5a4632cc3a660b</guid>
      <description><![CDATA[Remember Shark, the DIY malware pitched as a Remote Administration Tool (RAT) , whose publicity among script kiddies, and the press given the easy with which an undetected malware can be build with...]]></description>
      <content:encoded><![CDATA[<div align="left"><p><a href="http://bp1.blogger.com/_wICHhTiQmrA/R1ykNqehXtI/AAAAAAAABOE/pMoFGQi_HG4/s1600-h/shark3_remote_memory_execution.jpg"><img id="BLOGGER_PHOTO_ID_5142165429197823698" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="" src="http://bp1.blogger.com/_wICHhTiQmrA/R1ykNqehXtI/AAAAAAAABOE/pMoFGQi_HG4/s200/shark3_remote_memory_execution.jpg" border="0" /></a></p>Remember Shark, the <a href="http://ddanchev.blogspot.com/2007/08/shark-2-diy-malware.html">DIY malware pitched as a Remote Administration Tool (RAT)</a>, whose publicity among script kiddies, <a href="http://www.theregister.co.uk/2007/08/15/shark_trojan_creation_kit/">and the press</a> given the easy with which an undetected malware can be build with it, prompted the author behind the project to publicly announce that he's shutting down work on the RAT? However, as it looks like, the project is still under development, and the author's recent announcement of the upcoming version of Shark3 further confirms that the shut down announcement was valid by the time the publicity started to fade away. Here're some screenshots of what's to come in the new version :</div><br /><a href="http://bp3.blogger.com/_wICHhTiQmrA/R1yjlKehXrI/AAAAAAAABN0/ZGmRU1c9slM/s1600-h/shark3_windows_info.jpg"><img id="BLOGGER_PHOTO_ID_5142164733413121714" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="" src="http://bp3.blogger.com/_wICHhTiQmrA/R1yjlKehXrI/AAAAAAAABN0/ZGmRU1c9slM/s200/shark3_windows_info.jpg" border="0" /></a>Shark3 Window's Info<br /><br /><br /><br /><p align="left"><br /></p><br /><br /><br /><br /><br /><p align="left"></p><br /><a href="http://bp0.blogger.com/_wICHhTiQmrA/R1yj2aehXsI/AAAAAAAABN8/gGXRjxisqXw/s1600-h/shark3_keylogger.jpg"><img id="BLOGGER_PHOTO_ID_5142165029765865154" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="" src="http://bp0.blogger.com/_wICHhTiQmrA/R1yj2aehXsI/AAAAAAAABN8/gGXRjxisqXw/s200/shark3_keylogger.jpg" border="0" /></a><br />Shark3 Keylogger<br /><br /><br /><br /><p></p><p></p><p></p><p><br /></p><p><br /></p><p></p><p><a href="http://bp1.blogger.com/_wICHhTiQmrA/R1ykNqehXtI/AAAAAAAABOE/pMoFGQi_HG4/s1600-h/shark3_remote_memory_execution.jpg"></a></p><p><br /><br /></p><p><a href="http://bp1.blogger.com/_wICHhTiQmrA/R1ykNqehXtI/AAAAAAAABOE/pMoFGQi_HG4/s1600-h/shark3_remote_memory_execution.jpg"></a></p><p align="left"></p><p align="left"></p><p align="left">Previous versions included features not so popular among RATs by default such as, built-in VirusTotal submission, process injection, and with the new version promoted to have a built-in rootkit capabilities, next to its Vista compatibility, let's ask the ultimate question - <a href="http://ddanchev.blogspot.com/2007/07/shark2-rat-or-malware.html">is it a RAT, or is it a malware?</a> That's the rhetorical question.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=aoWGyZC"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=aoWGyZC" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Jwm49yC"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Jwm49yC" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=WjfZd4c"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=WjfZd4c" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=nABV3Zc"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=nABV3Zc" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=hXhFcSC"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=hXhFcSC" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=QLTXPQC"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=QLTXPQC" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=sbgJAvc"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=sbgJAvc" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/197818830" height="1" width="1"/>]]></content:encoded>
      <pubDate>Sun, 09 Dec 2007 17:44:58 +0000</pubDate>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/version">version</category>
      <category domain="http://securityratty.com/tag/shark3 window">shark3 window</category>
      <category domain="http://securityratty.com/tag/shark3">shark3</category>
      <category domain="http://securityratty.com/tag/diy malware">diy malware</category>
      <category domain="http://securityratty.com/tag/rhetorical question">rhetorical question</category>
      <category domain="http://securityratty.com/tag/shark3 keylogger">shark3 keylogger</category>
      <category domain="http://securityratty.com/tag/built-in rootkit capabilities">built-in rootkit capabilities</category>
      <category domain="http://securityratty.com/tag/rat">rat</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/197818830/shark-malware-new-versions-coming.html">The Shark Malware - New Version's Coming</source>
    </item>
  </channel>
</rss>
