RSSAmplifier

Blog

XyliBox

If you want to make enemies, try to change something.

xylibox.comRSS feed ↗25 posts

Latest posts

BestAV (Fake Antispyware affiliate) exposed

Hello everyone, it's been a while. One of the first affiliate systems I ever infiltrated was BestAV, back in 2011, the same year I started XyliBox. Over the years i infiltrated most of the major FakeAV affiliate programs and BestAV was the biggest player in this scene. It was also the one i kept coming back to, a bit like me vs darkode :) It became something of a coup de cœur for me, even if that…

Citadel 0.0.1.1 (Atmos)

Guys of JPCERT, 有難う御座います! Released an update to their Citadel decrypter to make it compatible with 0.0.1.1 sample. Citadel 0.0.1.1 don't have a lot of documentation, so time as come to talk about it. Personally i know this malware under the name 'Atmos' (be ready for name war in 3,2,1...) The first sample i was aware is the one spotted by tilldenis here in jully 2015. I re-observed this campaign…

Betabot retrospective

Some of you know Betabot.. if you don't: http://www.ic3.gov/media/2013/130918.aspx 1.0.2.5 panel: Dashboard: extended information: Search options: Tasks: Remove bot: Terminate bot till next reboot: Botkill: Socks4: Set browser homepage: Visit URL option: Update bot option: Download file option: DDoS cmd option: Formgrabber logs: logins: users: Settings: IP blacklist: List of dns recod to modify:…

Alina 'sparks' source code review

I got on my hands recently the source code of Alina "sparks", the main 'improvement' that everyone is talking about and make the price of this malware rise is the rootkit feature. Josh Grunzweig did already an interesting coverage of a sample, but what worth this new version ? InjectedDLL.c from the source is a Chinese copy-paste of http://www.cnblogs.com/lzjsky/archive/2010/12/01/1892702.html and…

Tiberium/Consuella USPS money laundering service

Consuella was a 'USPS drop service' run by one of the Lampeduza administrator. This type of service is used to help credit card thieves to "cash out" by sending carded labels service overseas (or not) via USPS. They was also constantly recruiting mules in United states to keep addresses in rotation. Here is what look like the service from an admin point of view: Add a payement: Users: Supports:…

Cryptorbit locker

When Cryptorbit ransomware was targeting people i've visited them SQL database: Bad guy wallets: 1H6jc6Mz535zTts6DWdeJf3HdH4owGjsXo 15JTKDkU4U6Tn5MBc9Pt52mMzXDmvmaanR 18yP3oKzeqChWCYG2ZGPcBhMQBiXFeR2GF 17FSkXDULjtK6R9G3cpwmLMYbWRZJ9c8vZ 1KZvxpPzvkSCqm3VTffWBWcLumWK1KJfkK Pseudo decryptor ~ 4a8e11468649e045976574691cf53732

Captain Barbarossa

Captain Barbarossa, is used for Paypal phishing and sold as phishing kit, the kit include an admin panel. User is tricked with a fake Paypal login asking for details, here in German: Once infos are transmitted the datas are sent to the panel. Login: Main: Log manager:

Phase (Win32/PhaseBot-A)

Small write-up about 'Phase' a malware who appeared and vanished very rapidly. I had a look on it with MalwareTech who wrote several stories , it was shown that Phase is in reality a 'new' version of Solar bot, at least not so new, the code is so copy/pasted that even Antivirus such as Avast do false positives and now detect Napolar (Solar) as PhaseBot. Advert: Phase support website: The coder is…

Neutrino bot

Neutrino bot is a malware who appeared and vanished quickly like Phase . not worth the look anyway. Advert: Login: Task: Statistics: Clients: Files: Logs: Settings:

iBanking

iBanking is an android malware made to intercept voice and text informations. The panel is poorly coded. Login: Projects: Phone list: SMS List: All SMS (Incomming) All SMS (Outgoing): Call list (Incomming): Call list (Outgoing): Call list (Missed): Sounds: Contact list: Url report:

i/o

Wow, it's been a awhile since i haven't written anything new here... So to answer many questions.. no i'm not dead, and will try to get active again a bit next year. I'm not writing this due to explanation requests or people worried (even if i got solicited many time to write something) but more because i'm motivated again to write. As i've said many times to the recurrent e-mails i receive and…

Install service for Malware affiliates and individuals

This install service was running since a long time but the server recently died. People targeted are from Russia, Ukraine, Belarus, Kazakhstan, and Uzbekistan. Login: Statistics by days: (Date, Unique visits, General visits) Statistics by countries: (Countries, Unique visits, Percentage, General visits) Statistics by version: (Version, Unique visits, Percentage, General visits) Statistics by time:…

ATSEngine

ATSEngine injects can be found oftenly inside Zeus configs, it makes the webinjects more dynamic because most of the content is located remotely and can be updated much easily instead of sending new config to all the bots. It's the main difference with this, and a standard web inject inside Zeus. One just allows you to do a static change in the page while the other gives you much more options, for…

Android.Trojan.Rubobi.A (SmsPiratBot)

Another Android botnet dumped recently. This malware can send and intercept sms from bots. Like most of android botnets, they are used mainly to target mobile banks like Sberbank (www.sberbank.ru - the biggest bank in Russia) In Russia, you can transfer money from one card to another card through mobile sms This botnet is sold 120$ Fake App: MD5: 2ea5e73653d1454c04ecd48202dcc391 Login: System…

Lame scareware

I've found a sample yesterday downloaded via this url: skyways.co/play.exe , console application, and ugly code + scareware and third party FakeAV call center. All the following was so lame that i need to talk about this. At first the malware will try to see if he's dropped into %SYSTEMROOT%/system/ If it's not the case then he will create a file: Then, you think he will write into the new file…

Android/FakeToken.A

OTP forwarder dumped months ago. Login: Statistics: Bots: Bot: Passwords: Send a command: Commands sent: Apps: Apps builder: MD5s: 2d4770137ae0b91446fc2f99d9fdb2b0 f629adcfbcdd4622ad75337ec0b1a0ff dd4ac55df6500352dd2cad340a36a40f b9f9614775a54aa42f94eedbc4796446 1fababfd02ea09ae924cd0a7dbfb708c bc8394bc9c6adbcfca3d450ee4ede44a 1cb87e1716c503bf499e529ee90e5b31 6db5cdd2648fcd445481cdfa2f2b065a…

ZeusVM and steganography

Months ago, researchers observed an evolution of ZeusVM, time to get back on this family. For informations, The first ZeusVM sample i've seen using steganography was the 21 November 2013. The IP of the C&C have Russian origin: 212.44.64.202 A Sutra TDS who redirect on Nuclear Exploit pack was pushing the payload, Roman of abuse.ch blacklisted 212.44.64.202 one month later on his Zeus tracker . The…

Zeus 1.1.3.4

RSA FirstWatch throw me recently a sample of a 'new' Zeus variant. I didn't really check all the changes that were made but seem it's nothing more than just a standard Zeus v2. But wait, it communicates over SSL and had a new kind of HTTP request pattern: Fiddler: Config download in python: import urllib2 request = urllib2 . Request ( 'https://secureinformat.com/?ajax' ) request. add_header (…

Plasma HTTP

Advert: Login: Online bot: offline bots: Commands: Statistics: Logs: Yeah take this lame article to second degree, i just talk about Plasma because i've promised to write something today on irc. I'm not dead but there nothing interesting to review for the moment, only crappy bots That also one of the reason i haven't talked of JackPos and all the rest. I have some interesting things but it's too…

Decoding Zeus 2.9.6.1 dynamic config

I got a look on the zeus builder who was released by the MMBB guy on exploit.in, finally i'm decided to write something about it, so let's talk about the change in the config encryption. MD5: 0a05783316e7f765e731aadf5098564f This version use AES instead of RC4 and can interact with the latest version of Firefox. Anyway it's nothing more than a basic Zeus v2. iBank parser on the panel, monitoring…

Troj/WowSpy-A

Recently a malware who target World of Warcraft got identified. This threat is known as Disker, Mal/DllHook-A or Trojan.Siggen5.64266 and can steal player accounts even if they use a Battle.net Authenticator. Yes, this is another post about password stealer mawlare... There is no option to retain password on the WoW client. The method used to spread this malware is by fake websites leading to…

Jolly Roger Stealer

Friend Kafeine have already do a post on it, although someone recently sent me a url on my cybercrime tracker.. i give a f%$k • dns: 1 ›› ip: 178.162.193.24 - adresse: LOADER.ISTMEIN.DE Bot statistic: CPU "Arhitecture" Task: Search module: HTTP: Mail: Create task: Task statistic: I haven't looked at a sample because i don't have it but sound very lame, like Plasma HTTP who grab everything without…

How the protection of Citadel got cracked

Recently on a forum someone requested cbcs.exe (Citadel Backconnect Server) If you want to read more about the Backconnect on Citadel, the link that g4m372 shared is cool: http://laboratoriomalware.blogspot.de/2012/12/troyan-citadel-backconnect-windows.html I've searched this file thought downloading a random mirror of the Citadel leaked package in hope to find it inside. Finally the file wasn't…

Win32/BruteForce.WP

DrWeb released a news about this malware in August, they know it as 'Trojan.WPCracker.1' And more recently ~ 1e8cd0f0f1702820c870302520bc0176 . This executable communicate with a C&C at dorblu99.net Let's have a closer look. Login: Main: Bot info: Broken wordpress: Statistics: Add domains: Add admin panels: Add logins: Add passwords: Add module for jm(zip): Add module for wp(zip): Add shell…

Win32/Atrax.A

Atrax is a TOR botnet, you can read about it on the excellent post of Aleksandr. Someone on kernelmode.info posted recently a fresh sample: MD5: 44a6a7d4a039f7cc2db6e85601f6d8c1 Fun things also, the coder leaved a message: "Nice blog post ESET 2013/07/24 Greetz to KernelMode.info" Atrax advertising: Programming language: C (No C++!) OS: Win XP - 8.1 (all x86/x64) Admin rights required: No Special:…