Volutions - ID | News | Gadget | Tutorial | Freeware | Template | Etc.: Botnet
Showing posts with label Botnet. Show all posts
Showing posts with label Botnet. Show all posts

Botnets: Measurement, Detection, Disinfection and Defence


“Botnets: Measurement, Detection, Disinfection and Defence” is a comprehensive report on how to assess botnet threats and how to neutralise them. It is survey and analysis of methods for measuring botnet size and how best to assess the threat posed by botnets to different stakeholders. It includes a comprehensive set of 25 different types of best-practices to measure, detect and defend against botnets from all angles. The countermeasures are divided into 3 main areas: neutralising existing botnets, preventing new infections and minimising the profitability of cybercrime using botnets. The recommendations cover legal, policy and technical aspects of the fight against botnets and give targeted recommendations for different groups.

Download: PDF

Botnets: Measurement, Detection, Disinfection and Defence


“Botnets: Measurement, Detection, Disinfection and Defence” is a comprehensive report on how to assess botnet threats and how to neutralise them. It is survey and analysis of methods for measuring botnet size and how best to assess the threat posed by botnets to different stakeholders. It includes a comprehensive set of 25 different types of best-practices to measure, detect and defend against botnets from all angles. The countermeasures are divided into 3 main areas: neutralising existing botnets, preventing new infections and minimising the profitability of cybercrime using botnets. The recommendations cover legal, policy and technical aspects of the fight against botnets and give targeted recommendations for different groups.

Download: PDF

Symantec Report on Attack Kits and Malicious Websites

Attack toolkits are bundles of malicious code tools used to facilitate the launch of concerted and widespread attacks on networked computers. Also known as crimeware, these kits are usually composed of prewritten malicious code for exploiting vulnerabilities along with various tools to customize, deploy, and automate widespread attacks, such as command-and-control (C&C) server administration tools.

As with a majority of malicious code in the threat landscape, attack kits are typically used to enable the theft of sensitive information or to convert compromised computers into a network of zombie bots (botnet) in order to mount additional attacks. These kits are advertised and sold in the online underground economy—a black market of servers and forums used to advertise and trade stolen information and services.
Symantec has found that attack kits are significantly advancing the evolution of cybercrime into a self-sustaining, profitable, and increasingly organized economic model worth millions of dollars.


Download: PDF

Attack Toolkits and Malicious Websites SlideShare

Symantec Attack Kit Evolution Timeline

Symantec Report on Attack Kits and Malicious Websites

Attack toolkits are bundles of malicious code tools used to facilitate the launch of concerted and widespread attacks on networked computers. Also known as crimeware, these kits are usually composed of prewritten malicious code for exploiting vulnerabilities along with various tools to customize, deploy, and automate widespread attacks, such as command-and-control (C&C) server administration tools.

As with a majority of malicious code in the threat landscape, attack kits are typically used to enable the theft of sensitive information or to convert compromised computers into a network of zombie bots (botnet) in order to mount additional attacks. These kits are advertised and sold in the online underground economy—a black market of servers and forums used to advertise and trade stolen information and services.
Symantec has found that attack kits are significantly advancing the evolution of cybercrime into a self-sustaining, profitable, and increasingly organized economic model worth millions of dollars.


Download: PDF

Attack Toolkits and Malicious Websites SlideShare

Symantec Attack Kit Evolution Timeline

Smartphone Botnets over SMS Demo

Here is the proof of concept code for smartphone botnet C&C over SMS from Shmoocon 2011. This is for the Android platform. If you are looking to work with iPhone contact me directly. I don’t have access to an iPhone at this time to properly test the PoC code for iPhone. So I’m not releasing such code publicly at this time. However, the same concept of proxying the modem and application layer to make smartphone bots is known to work for iPhone.

Download the Shmoocon slides here: http://www.grmn00bs.com
Download the code here. http://www.grmn00bs.com

To use:
compile with arm-gcc with the -static flag set
Copy to anywhere on the underlying OS that is writable (/data is good).
Rename /dev/smd0 to /dev/smd0real
Start the bot application
Kill the radio application (ps | grep rild)
The radio will automatically respawn and now the bot proxy will be working.

This proof of concept code has payloads removed, so the functionality you see in the demos will need to be added manually. Add your own stuff. Have fun and please share it with me if you do something interesting. Usual disclaimers apply. The proof of concept swallows botnet related messages based on a key that you can change, but it does not perform potentially malicious payloads as seen in the demos.

Video Demonstration:

Shmoocon 2011 Smartphone Botnets over SMS Demo


Credit: Georgia Weidman

Smartphone Botnets over SMS Demo

Here is the proof of concept code for smartphone botnet C&C over SMS from Shmoocon 2011. This is for the Android platform. If you are looking to work with iPhone contact me directly. I don’t have access to an iPhone at this time to properly test the PoC code for iPhone. So I’m not releasing such code publicly at this time. However, the same concept of proxying the modem and application layer to make smartphone bots is known to work for iPhone.

Download the Shmoocon slides here: http://www.grmn00bs.com
Download the code here. http://www.grmn00bs.com

To use:
compile with arm-gcc with the -static flag set
Copy to anywhere on the underlying OS that is writable (/data is good).
Rename /dev/smd0 to /dev/smd0real
Start the bot application
Kill the radio application (ps | grep rild)
The radio will automatically respawn and now the bot proxy will be working.

This proof of concept code has payloads removed, so the functionality you see in the demos will need to be added manually. Add your own stuff. Have fun and please share it with me if you do something interesting. Usual disclaimers apply. The proof of concept swallows botnet related messages based on a key that you can change, but it does not perform potentially malicious payloads as seen in the demos.

Video Demonstration:

Shmoocon 2011 Smartphone Botnets over SMS Demo


Credit: Georgia Weidman

Researcher will release Smartphone Botnet PoC code at Shmoocon

A researcher at ShmooCon DC this weekend will demonstrate a smartphone botnet spewing spam and unleash proof-of-concept code that builds a botnet out of Android and iPhone smartphones.

Georgia Weidman, an independent researcher, says her botnet attack evolved out of work she did on making an Android application send SMS text messages transparently such that the user didn't even know it was happening from his or her smartphone. "As I did more research, I [realized] if I did this in the base operating system instead of in 'userspace' where most apps are, it would be a better way to do it," she says. "If I can remotely control someone's phone, it can be part of a botnet."

More info: http://www.darkreading.com

Researcher will release Smartphone Botnet PoC code at Shmoocon

A researcher at ShmooCon DC this weekend will demonstrate a smartphone botnet spewing spam and unleash proof-of-concept code that builds a botnet out of Android and iPhone smartphones.

Georgia Weidman, an independent researcher, says her botnet attack evolved out of work she did on making an Android application send SMS text messages transparently such that the user didn't even know it was happening from his or her smartphone. "As I did more research, I [realized] if I did this in the base operating system instead of in 'userspace' where most apps are, it would be a better way to do it," she says. "If I can remotely control someone's phone, it can be part of a botnet."

More info: http://www.darkreading.com

Koobface: Inside a Crimeware Network

Introduction
There are numerous computer systems around the world that are under the control of malicious actors.These compromised computers,often known as zombies,form a botnet that receives and executes commands from botnet operators who harvest passwords,credit card numbers,and sensitive information from the zombies.Botnet operators also put the “zombies” to work by forcing them to send spam messages,create fraudulent accounts,and host malicious files.Rather than relying on sophisticated technical exploits,some botnet operators simply trick users into compromising themselves.Through fake Web sites,users are encouraged to download malicious software masquerading as benign.Sometimes,these fake,malicious Web sites are sent to users by their contacts on social networking sites.The rise of social networking tools has given attackers a platform to exploit the trust that individuals have in one another.People are much more likely to execute a malicious file if it has been sent to them by someone they know and trust.The information that individuals post online and the interests contained within their profile information can also be used to lure individuals into executing malicious software.Koobface is a botnet that leverages social networking platforms to propagate.

The operators of the botnet(known as Ali Baba and 40 LLC)have developed a system that uses social networking platforms,such as Bebo,Facebook,Friendster,Fubar,Hi5,MySpace,Netlog,Tagged,Twitter,and Yearbook,to send messages containing malicious links.These links are often concealed using the URL shortening service bit.ly and sometimes redirects to Blogspot blogs that redirect users to false YouTube pages hosted on compromised Web servers. These pages encourage users to download malicious software masquerading as a video codec or a software upgrade.Koobface also uses search engine optimization (SEO) techniques that allow these malicious sites to be listed highly in search engine results for popular search terms.


Download: PDF

Koobface: Inside a Crimeware Network

Introduction
There are numerous computer systems around the world that are under the control of malicious actors.These compromised computers,often known as zombies,form a botnet that receives and executes commands from botnet operators who harvest passwords,credit card numbers,and sensitive information from the zombies.Botnet operators also put the “zombies” to work by forcing them to send spam messages,create fraudulent accounts,and host malicious files.Rather than relying on sophisticated technical exploits,some botnet operators simply trick users into compromising themselves.Through fake Web sites,users are encouraged to download malicious software masquerading as benign.Sometimes,these fake,malicious Web sites are sent to users by their contacts on social networking sites.The rise of social networking tools has given attackers a platform to exploit the trust that individuals have in one another.People are much more likely to execute a malicious file if it has been sent to them by someone they know and trust.The information that individuals post online and the interests contained within their profile information can also be used to lure individuals into executing malicious software.Koobface is a botnet that leverages social networking platforms to propagate.

The operators of the botnet(known as Ali Baba and 40 LLC)have developed a system that uses social networking platforms,such as Bebo,Facebook,Friendster,Fubar,Hi5,MySpace,Netlog,Tagged,Twitter,and Yearbook,to send messages containing malicious links.These links are often concealed using the URL shortening service bit.ly and sometimes redirects to Blogspot blogs that redirect users to false YouTube pages hosted on compromised Web servers. These pages encourage users to download malicious software masquerading as a video codec or a software upgrade.Koobface also uses search engine optimization (SEO) techniques that allow these malicious sites to be listed highly in search engine results for popular search terms.


Download: PDF

The Botnet Chronicles

A Journey to Infamy

Botnets are considered one of the most prevalent and dangerous threats lurking on the Web today.The damage they cause can range from information theft and malware infection to fraud and other crimes.A botnet refers to a network of bots or zombie computers widely used for malicious criminal activities like spamming, distributed denial-ofservice (DDoS) attacks,and/or spreading FAKEAV malware variants.A botnet connects to command-and-control (C&C) servers,enabling a bot master or controller to make updates and to add new components to it.This white paper examines where the first botnets came from and how they have evolved over the past 10 years to become some of the biggest cybercrime perpetrators on the Web at present.

Download PDF

The Botnet Chronicles

A Journey to Infamy

Botnets are considered one of the most prevalent and dangerous threats lurking on the Web today.The damage they cause can range from information theft and malware infection to fraud and other crimes.A botnet refers to a network of bots or zombie computers widely used for malicious criminal activities like spamming, distributed denial-ofservice (DDoS) attacks,and/or spreading FAKEAV malware variants.A botnet connects to command-and-control (C&C) servers,enabling a bot master or controller to make updates and to add new components to it.This white paper examines where the first botnets came from and how they have evolved over the past 10 years to become some of the biggest cybercrime perpetrators on the Web at present.

Download PDF

The Zeus malware R&D program

Trusteer captured and analyzed a new version (2.1) of the Zeus financial malware and found that it has added sophisticated new mechanisms to commit online fraud and remain the Trojan of choice for criminals.

Zeus has not only improved its business logic but also its ability to avoid detection and automatic analysis by antivirus vendors. Zeus is under the spotlight of security vendors, banks, and law enforcement, which forces its developers to continually improve it to avoid losing business to competing malware like Bugat, Clampi, and SpyEye.Just like commercial application developers, the creators of Zeus run an R&D program to ensure it can avoid detection and side-step the growing number of IT security mechanisms designed to detect, block and eliminate it.

More about Zeus v2.1: http://www.net-security.org

The Zeus malware R&D program

Trusteer captured and analyzed a new version (2.1) of the Zeus financial malware and found that it has added sophisticated new mechanisms to commit online fraud and remain the Trojan of choice for criminals.

Zeus has not only improved its business logic but also its ability to avoid detection and automatic analysis by antivirus vendors. Zeus is under the spotlight of security vendors, banks, and law enforcement, which forces its developers to continually improve it to avoid losing business to competing malware like Bugat, Clampi, and SpyEye.Just like commercial application developers, the creators of Zeus run an R&D program to ensure it can avoid detection and side-step the growing number of IT security mechanisms designed to detect, block and eliminate it.

More about Zeus v2.1: http://www.net-security.org

Security firm warns of commercial, on-demand DDoS botnet

IMDDOS, which is mainly based in China, has grown to become one of the largest active botnets, Damballa says

Computerworld - The security firm Damballa is warning of a large and fast growing botnet created specifically to deliver distributed denial of service (DDoS) attacks on demand for anyone willing to pay for the service.

The IMDDOS botnet is operated out of China and has been growing at the rate of about 10,000 infected machines every day for the past several months, to become one the largest active botnets currently, Damballa says.
Gunter Ollman, vice president of research at Damballa, said that what makes IMDDOS significant is its openly commercial nature. The botnet's operators have set up a public Web site potential attackers can use to subscribe for the DDoS service, and to launch attacks against targets.

The site offers various subscription plans and attack options, and provides tips on how the service can be used to launch effective DDoS attacks. It even provides customers with contact information for support and customer service.
Anyone with knowledge of Chinese can essentially subscribe to the service and use it to initiate DDoS attacks against targets of their choice, anywhere around the globe and with next to no effort, Ollman said.

More info

See also Global botnet offering DDoS services

Security firm warns of commercial, on-demand DDoS botnet

IMDDOS, which is mainly based in China, has grown to become one of the largest active botnets, Damballa says

Computerworld - The security firm Damballa is warning of a large and fast growing botnet created specifically to deliver distributed denial of service (DDoS) attacks on demand for anyone willing to pay for the service.

The IMDDOS botnet is operated out of China and has been growing at the rate of about 10,000 infected machines every day for the past several months, to become one the largest active botnets currently, Damballa says.
Gunter Ollman, vice president of research at Damballa, said that what makes IMDDOS significant is its openly commercial nature. The botnet's operators have set up a public Web site potential attackers can use to subscribe for the DDoS service, and to launch attacks against targets.

The site offers various subscription plans and attack options, and provides tips on how the service can be used to launch effective DDoS attacks. It even provides customers with contact information for support and customer service.
Anyone with knowledge of Chinese can essentially subscribe to the service and use it to initiate DDoS attacks against targets of their choice, anywhere around the globe and with next to no effort, Ollman said.

More info

See also Global botnet offering DDoS services

Mumba Botnet Disclosed

The Mumba botnet, so called because of some funky attributes our researchers found on the server, was created by one of the most sophisticated group of cybercriminals on the internet known as the Avalanche Group.

This group has perfected a mass-production system for deploying phishing sites and data stealing malware. Mumba uses the latest version of Zeus, currently one of the most common malwares and infected 55,000 computers worldwide.Of course, the longer cyber criminals can keep their botnets out in the open the more money they make, so they invest a great deal of time and resources in protecting their systems and hiding their servers from detection by security researchers and law enforcement officials.

This was certainly the case with the Mumba botnet, which was extremely effective at harvesting web users data. The full report, which can be downloaded from this blog, shows that the Mumba botnet was responsible for stealing more than 60 gigabytes of personal data from people, including their details from social networking websites, bank account details, credit card numbers and emails.
The United States had the highest share of PCs infected by the Mumba botnet (33 percent), followed by Germany (17 percent), Spain (7 percent), United Kingdom (6 percent), Mexico and Canada (both 5 percent).

Download Revised Mumba Botnet Whitepaper

Mumba Botnet Disclosed

The Mumba botnet, so called because of some funky attributes our researchers found on the server, was created by one of the most sophisticated group of cybercriminals on the internet known as the Avalanche Group.

This group has perfected a mass-production system for deploying phishing sites and data stealing malware. Mumba uses the latest version of Zeus, currently one of the most common malwares and infected 55,000 computers worldwide.Of course, the longer cyber criminals can keep their botnets out in the open the more money they make, so they invest a great deal of time and resources in protecting their systems and hiding their servers from detection by security researchers and law enforcement officials.

This was certainly the case with the Mumba botnet, which was extremely effective at harvesting web users data. The full report, which can be downloaded from this blog, shows that the Mumba botnet was responsible for stealing more than 60 gigabytes of personal data from people, including their details from social networking websites, bank account details, credit card numbers and emails.
The United States had the highest share of PCs infected by the Mumba botnet (33 percent), followed by Germany (17 percent), Spain (7 percent), United Kingdom (6 percent), Mexico and Canada (both 5 percent).

Download Revised Mumba Botnet Whitepaper

Botnet Exploits PDF Flaw

The Zeus botnet is now using an unpatched flaw in Adobe's PDF document format to infect users with malicious code, security researchers said.
The attacks come less than a week after other experts predicted that hackers would soon exploit the "/Launch" design flaw in PDF documents to install malware on unsuspecting users' computers.

The just-spotted Zeus variant uses a malicious PDF file that embeds the attack code in the document, said Dan
Hubbard, CTO of San Diego, California-based security company Websense. When users open the rogue PDF, they're asked to save a PDF file called "Royal_Mail_Delivery_Notice.pdf." That file, however, is actually a Windows executable that when it runs, hijacks the PC.

Zeus is the first major botnet to exploit a PDF's /Launch feature, which is, strictly speaking, not a security vulnerability but actually a by-design function of Adobe's specification. Earlier this month, Belgium researcher Didier Stevens demonstrated how a multistage attack using /Launch could successfully exploit a fully-patched copy of Adobe Reader or Acrobat.

Read more: http://www.pcworld.com

Botnet Exploits PDF Flaw

The Zeus botnet is now using an unpatched flaw in Adobe's PDF document format to infect users with malicious code, security researchers said.
The attacks come less than a week after other experts predicted that hackers would soon exploit the "/Launch" design flaw in PDF documents to install malware on unsuspecting users' computers.

The just-spotted Zeus variant uses a malicious PDF file that embeds the attack code in the document, said Dan
Hubbard, CTO of San Diego, California-based security company Websense. When users open the rogue PDF, they're asked to save a PDF file called "Royal_Mail_Delivery_Notice.pdf." That file, however, is actually a Windows executable that when it runs, hijacks the PC.

Zeus is the first major botnet to exploit a PDF's /Launch feature, which is, strictly speaking, not a security vulnerability but actually a by-design function of Adobe's specification. Earlier this month, Belgium researcher Didier Stevens demonstrated how a multistage attack using /Launch could successfully exploit a fully-patched copy of Adobe Reader or Acrobat.

Read more: http://www.pcworld.com
 
Support By Blogger