Darkleech – malicious Apache mod anti-forensics – client-side.

2013.03.18

I wrote about Darkleech last year, and one of questions remain  - among anti-forensics features of it, that seller declared, were:

- frame delivered to unique users only, no frame on repeat. 

So – How it looks like for victim and how implemented?

Since than Linux/Chapro.A was posted in SecLists and  analysed by Kaspersky and ESET.

Afterwards Eric Romang provided some details, that it appear to be version of Darkleech module.

And here it appear again: UnixFreaxJP blog report about massive attack on Japanese segment of Internet.

Well, It’s time to see, is it DarkLeech and how anti-forensics implemented there from client PoV :)

Ok. Let’s see on any of servers that in list:

Read more…

Do You live in ‘bad_country’? :D [updated1]

2012.09.28

If You looking for info about Exploit Kits – move on, there is nothing about them here

Here – unknown for me TDS (traffic distribution system), that used in recent huge attack on hacked websites customers.

This is how it looks like:

Juicy, You say? iframe, looks like lead to MDS that will finally 302 us to weaponized page of ExploitKit:)

Read more…

DarkLeech – malware mod for Apache.

2012.09.16

It was expected, actually…

But – from the beginning.

Few last weeks I read about some strange malicious activity on Apache servers (WebmasterworldUnmaskParasites.com):

Iframe with malicious code was injected in multiple pages of Apache server dynamically.

Standard cleanup was not helpful at all, multiple co-located hosts were infected the same way.

Any website, moved to new server, became clean << When I saw this, it became obvious, that compromise is part of web-server itself, not per site.

So – I made a little research, and found  new product on black market, that You may be interested in :)

Read more…

“Security Shield” Fake Antivirus

2012.09.14

Since all the IT world busy with new release of BHEK, here some not BHEK stuff Ж)

Start point was sent by the friend with remark – “…maybe BHEK2″?

Let’s see :)

Read more…

BlackHole Exploit Kit 2.0 – anti-forensics features announced

2012.09.12

So, major news in malware world today – release of BlackHole Exploit Kit ver 2.0, announced by Paunch at the morning.

Full text of Advertisement You may read in Russian and translated english at Kafeine’s blog

Since my part of the interest is anti-forensics features, let’s see, what exactly Paunch ad disclose:

Read more…

SimpleTDS as part of RedKit Exploit Kit

2012.09.04

Another Malware Distribution System, SimpleTDS (named after URLQuery), appeared at horizon today morning.

As I found at the end – it was part (integrated or attached in this case) of known RedKit EK – thx to @kafeine blog post “CVE-2012-4681 – Redkit Exploit Kit – I want Porche Turbo”

Disclamer: All links provided lead to lists of malicious or potentially malicious resources. Do not click there on any link, or don’t run any file, without proper knowledge, env prepared and skills trained.

Well, it was a morning… :)

Read more…

Malware delivery system – few recent tricks

2012.09.03

Malware Delivery Systems, or Loaders, responsibly to deliver malicious exe\dll to victim.

Each day,  malware creators implement new tricks to harden analysis and detection of malware hosts by automated systems, and each day malware hunters follow them to the end step by step :)

here is some example of such walk :)

Read more…

Malware hunt – wildfowl to find

2012.09.02

More than twice for last 24 hours I was asked non-trivial question:

Where You find targets for malware hunt, if You not part of big team, malware researcher or not own a honeynet.

Actually, if You want to fight malware, IMHO it very useful to have honey-pot system, or at least be in security business somehow. It will provide You non-stop flow of malicious targets to review. But if not, and You still want to help?

Disclamer: All links provided lead to lists of malicious or potentially malicious resources. Do not click there on any link, or don’t run any file, without proper knowledge, env prepared and skills trained.

Well, here are few links, that aggregate latest known threats, that You can practice on:

1. Malware Domain List:

http://www.malwaredomainlist.com/update.php

2. URL Query

http://urlquery.net/

3. Malekal.com list of malware

http://www3.malekal.com/malwares/

4. VX Vault

http://vxvault.siri-urz.net/ViriList.php?

5. Site Inspector (by Comodo)

http://siteinspector.comodo.com/recent_detections

6. Scumware.org

http://www.scumware.org/index.scumware

7. Malc0de Database

http://malc0de.com/database/

8. Sucuri Malware Labs

http://labs.sucuri.net/?malware

9. Clean-MX Realtime database

http://support.clean-mx.de/clean-mx/viruses

10. Sourcefire Vulnerability Research Team Labs

http://labs.snort.org/iplists/

11. Zeus Tracker

https://zeustracker.abuse.ch/monitor.php?browse=binaries

12. NovCon Minotaur Analysis System

http://minotauranalysis.com/malwarelist-urls.aspx

p.s. Many thanks to DrM for almost tripling the list! :)

Note: threats usually detected by many participants, blocked and dead, as result (and this is good!), so if You looking for alive target- see recent updates, search for simulate domains, hosted on same IP etc.

Happy and lucky hunt. Share Your findings (You can do it also here http://twitter.com/MalwareMustDie ), and in case You know another good lists of malware urls and targets – comment and I will add it to list.

Happy and lucky hunt

Cheers

D.L.

What is “Dedic”?

2012.08.17

Well, if You speak Russian and in computer crimes world from any side, You know what  I am talking about. If not – here are brief look at what it is, what purposes and why named this way.

Read more…

Drive-by download malware within 643MB avi

2012.08.08

 

Did You know, that ASF (Advanced Systems Format) by design include feature that can be used as drive-by download? No? Then – this post for You.

Read more…