miércoles, 16 de enero de 2013

BOTNET PONY 1.9 Malware


For the past few months has been detected at Crimeware scene a new class of  Malware called PONY Bonet. The Pony Control panel is identified by the logo of a this animal that appears in the famous Facebook game "Farmville"

The login screen panel of this new botnet Pony is:


Once control panel is accessed, it displays a menu with all available options. It can see that has been developed to capture all types of passwords and login credentials of infected users when they access applications and Internet sites. This is a very powerful type of Spy - Keylogger Malware with very dangerous features.



Pony Trojan is configured to capture all kinds of confidential information and access passwords for the following applications:

Passwords for FTP and SSH servers. The Trojan is able to recognize almost all FTP & SSH applications both commercial and opensource and extract its credentials:

  System Info , FAR Manager , Total Commander , WS_FTP , CuteFTP , FlashFXP , FileZilla , FTP commander , BulletProof FTP , SmartFTP , TurboFTP , FFFTP , CoffeeCup FTP / Sitemapper , CoreFTP , FTP Explorer , Frigate3 FTP , SecureFX , UltraFXP , FTPRush , WebSitePublisher , BitKinex , ExpanDrive , ClassicFTP , Fling , SoftX , Directory Opus , FreeFTP / DirectFTP , LeapFTP , WinSCP , 32bit FTP , NetDrive , WebDrive , FTP Control , Opera , WiseFTP , FTP Voyager , Firefox , FireFTP , SeaMonkey , Flock , Mozilla , LeechFTP , Odin Secure FTP Expert , WinFTP , FTP Surfer , FTPGetter , ALFTP , Internet Explorer , Dreamweaver , DeluxeFTP , Google Chrome , Chromium / SRWare Iron , ChromePlus , Bromium (Yandex Chrome) , Nichrome , Comodo Dragon , RockMelt , K-Meleon , Epic , Staff-FTP , AceFTP , Global Downloader , FreshFTP , BlazeFTP , NETFile , GoFTP , 3D-FTP , Easy FTP , Xftp , FTP Now , Robo-FTP , LinasFTP , Cyberduck , Putty , Notepad++ , CoffeeCup Visual Site Designer , FTPShell , FTPInfo , NexusFile , FastStone Browser , CoolNovo , WinZip , Yandex.Internet , MyFTP , sherrod FTP , NovaFTP , Windows Mail , Windows Live Mail , Becky! , Pocomail , IncrediMail , The Bat! , Outlook , Thunderbird , FastTrack .

Screen from menu management of the FTP grabber :


Also captures all kind of e-mails and their passwords, stored certificates and  RDP passwords


Control panel allows capturing all types of passwords for loging web applications on HTTP and HTTPS. It has a very powerful filter to configure Captures, selecting or excluding Internet domains to start capturing data when infected users access in these pages, and selects by text strings, domains , countries , dates, etc.


The statistical panel shows confidential data captured from Web browsing of infected users.


compromised Users by the Trojan Pony are ordered by their IP, the information gathered can be selected for each user by selecting the desired IP profile:


It is very interesting to see in the statistical panel the variety of data types that can be captured by the Trojan from infected users



 All captured data is encrypted and stored in a MySQL database to prevent being stolen if someone gains access to this information:


Finally we present part of  file structure of the KIT PONY Troyan:



Also Have been found other malicious addresses containing Pony panels actives at:

hXXp://217.195.200.12:8080/ponyb/admin.php
hXXp://195.5.208.204:8080/ponyb/admin.php
hXXp://9jal33ts.com/ponysample/admin.php
hXXp://198.27.83.179/popo/
hXXp: http://hostohu.net/p0x/admin.php
hXXp://vpro.juplo.com/p/admin.php

domingo, 13 de enero de 2013

PONY 1.9 BOTNET

Desde hace unos pocos meses se ha detectado en el escenario del cibercrimen una nueva clase de Bonet Malware denominada PONY y que se identifica su panel por el logo de este animal que aparece en el famoso juego para Facebook “Farmville”

La pantalla de login al panel de este nuevo botnet Pony es la siguiente:


Una vez que se ha accedido a este Panel de Control aparece el menú con todas las opciones disponibles observándose que ha sido diseñado para capturar todo tipo de credenciales de acceso de las aplicaciones de los usuarios infectados así como de los sitios de Internet a los que accede. 

Se trata de un potente Malware del tipo Spy – Keylogger con funcionalidades muy peligrosas.


El troyano Pony está configurado para capturar toda clase de información confidencial y datos de acceso para las siguientes aplicaciones:
Contraseñas de acceso para servidores FTP y SSH. El troyano es capaz de reconocer casi todas las aplicaciones FTP, SSH existentes en el mercado y extraer sus credenciales:

System Info , FAR Manager , Total Commander , WS_FTP , CuteFTP , FlashFXP , FileZilla , FTP commander , BulletProof FTP , SmartFTP , TurboFTP , FFFTP , CoffeeCup FTP / Sitemapper , CoreFTP , FTP Explorer , Frigate3 FTP , SecureFX , UltraFXP , FTPRush , WebSitePublisher , BitKinex , ExpanDrive , ClassicFTP , Fling , SoftX , Directory Opus , FreeFTP / DirectFTP , LeapFTP , WinSCP , 32bit FTP , NetDrive , WebDrive , FTP Control , Opera , WiseFTP , FTP Voyager , Firefox , FireFTP , SeaMonkey , Flock , Mozilla , LeechFTP , Odin Secure FTP Expert , WinFTP , FTP Surfer , FTPGetter , ALFTP , Internet Explorer , Dreamweaver , DeluxeFTP , Google Chrome , Chromium / SRWare Iron , ChromePlus , Bromium (Yandex Chrome) , Nichrome , Comodo Dragon , RockMelt , K-Meleon , Epic , Staff-FTP , AceFTP , Global Downloader , FreshFTP , BlazeFTP , NETFile , GoFTP , 3D-FTP , Easy FTP , Xftp , FTP Now , Robo-FTP , LinasFTP , Cyberduck , Putty , Notepad++ , CoffeeCup Visual Site Designer , FTPShell , FTPInfo , NexusFile , FastStone Browser , CoolNovo , WinZip , Yandex.Internet , MyFTP , sherrod FTP , NovaFTP , Windows Mail , Windows Live Mail , Becky! , Pocomail , IncrediMail , The Bat! , Outlook , Thunderbird , FastTrack .

La pantalla del menú de gestión del capturador FTP:





También captura cualquier tipo de direcciones de e-mails , así como sus contraseñas de acceso , certificados que tenga almacenados el usuario , además de contraseñas de acceso RDP


El panel permite la captura de todo tipo de contraseñas de acceso a aplicaciones web bajo HTTP y HTTPS. Dispone de un filtro muy potente para configurar las capturas , seleccionando o excluyendo los dominios de Internet a los que el usuario infectado acceda para empezar a capturar datos cuando se encuentre en dichas páginas , así como cadenas de texto de captura , países de los dominios víctimas , fechas , etc.


El panel de seguimiento de los datos confidenciales capturados de la navegación Web de los usuarios infectados.


Los usuarios comprometidos por el troyano Pony están ordenados por su IP , pudiéndose seleccionar la información recopilada para cada usuario seleccionando el perfil de la IP deseada:



Es muy interesante observar en el panel estadístico la cantidad de información que puede capturar de los usuarios infectados por el troyano:




Todos los datos capturados son cifrados y almacenados en una base de datos en MySQL para evitar que sean robados si alguien logra acceder acceder a dicha información:


Finalmente se presenta parte de la estructura de ficheros del KIT PONY:



Se han localizado otras direcciones maliciosas conteniendo paneles Pony activos en:
hXXp://217.195.200.12:8080/ponyb/admin.php
hXXp://195.5.208.204:8080/ponyb/admin.php
hXXp://9jal33ts.com/ponysample/admin.php
hxxp://198.27.83.179/popo/

lunes, 7 de enero de 2013

Trojan Multi Locker Version 3 - "Trojan police"




In last times it has been detected an increase number of infections caused by the Trojan Ransomware, also called Ransomlock or Multi-Locker or more famously known as "Trojan police" because it simulates the user computer has been intervened and blocked by police until they pay a fee for legal penalty which is nothing more than a fraud or scam by criminals.

This time will be analyzed the Trojan Kit MULTI LOCKER Version 3

The user's computer is compromised by visiting the infection vector:

hxxp://62.76.45.94/exe.php

It downloads the malicious binary:

hXXp://62.76.45.94/colt.exe

Size: 7680
MD5:baa5de00714b02660bfc092b53c449f7

The IP 62.76.45.94 is hosted at the ISP Clodo-Cloud in Russia.

Once the computer is infected, Ransomware Malware modifies the whole system configuration and registry so that each time the user restarts the computer, trojan automatically takes over control blocking full system. Besides virus presents a false screen display of police asking user to pay the fine for allegedly viewed child pornography or illegal contents against intellectual property

This fake police screen is downloaded from the fraudulent server at address:

hXXP://62.76.45.94/lending/tds.php

This script checks the language version at user's browser to display the fake police screen in the local country language of the user with relevant legal notices with warnings from the police of that country.

The code script of "tds.php" is show as follows:




In the case of Spanish users would display the following fraudulent screen hosted at:

hXXP://62.76.45.94/lending/ES.php


In this example, the screen is very poorly designed unlike other kits detected most detailed enough to trick the user making the veracity of it.

Criminals can modify these fake warning pages to achieve the appearance of legality accessing the mini editor that exists in the kit Ramsomware, also called by some antivirus companies as Ransomlock.

The panel is called MULTI LOCKER LENDING  EDITOR and is accessed via the URL:

Hxxp://62.76.45.94/lending/
  

And file structure of the LENDING KIT is:
 

If user pays the fee through the online payment systems UKASH, MoneyPack, etc .his Machine will be free once entered the code returned by these payment systems



Ransomware statistical panel is accessed through the main login page:


Once logged in can see the main menu screen of KIT MULTI LOCKER Version 3



Panel with statistical tracking of infected users



menu of users who have paid for unlocking their computers



The KIT file structure is as follows:

Panel Kit Installation

Troyano policía Multi Locker Version 3



En los últimos tiempos se ha detectado un incremento de las infecciones producidas por el troyano Ramsomware , también llamado  Ramsomlock o Multi Locker o más comúnmente por el “Troyano de la policía” debido a que simula que el equipo ha sido intervenido y bloqueado por la policía hasta que no se pague una cuota por penalización legal que no es más que un fraude o estafa por parte de los criminales.

En esta ocasión se va a analizar el kit del Troyano MULTI LOCKER Versión ·

El equipo del usuario es comprometido al visitar el vector de infección:  

hxxp://62.76.45.94/exe.php

Que descarga el binario malicioso:

hXXp://62.76.45.94/colt.exe

Tamaño: 7680
MD5:baa5de00714b02660bfc092b53c449f7

La IP  62.76.45.94 esta alojada en el ISP Clodo-Cloud de Rusia

 Una vez que el equipo esta infectado el Malware modifica toda la configuración del sistema y del registro para que cada vez que el usuario reinicie el equipo automáticamente el troyano toma el control del mismo bloqueando todo el sistema,  además de presentar la pantalla falsa de la policía solicitando que pague la multa por supuestamente haber visitado contenidos ilegales de pornografía infantil o contra la propiedad intelectual

Esta pantalla falsa se descarga desde la dirección del servidor fraudulento:

hXXP://62.76.45.94/lending/tds.php

Que lo que hace es chequear la versión del idioma del navegador del usuario para mostrar la pantalla falsa en el idioma del usuario y con los correspondientes avisos legales o de los cuerpos policiales de dicho país.

 El código del script TDS.php es el siguiente:

 
Para el caso de los usuarios españoles mostraría la siguiente pantalla fraudulenta alojada en la dirección:

hXXP://62.76.45.94/lending/ES.php


En este caso la pantalla esta bastante mal diseñada no como en otros kits detectados bastantes mas detallados logrando engañar al usuario con la veracidad de la misma.
 
Los criminales pueden modificar las paginas de advertencia para lograr la apariencia de legalidad accediendo al mini editor que existe en el kit del Ramsomware también llamado por algunas casas antivirus como Ransomlock.

El panel se denomina MULTI LOCKER LENDING EDITOR y se accede mediante la URL:

Hxxp://62.76.45.94/lending/

 
Y la estructura de ficheros del KIT:



Si el usuario paga la cuota a través de los medios de pago por Internet UKASH, MoneyPack, etc el equipo será liberado una vez introducido el código del recibo que ofrecen estos medios de pago



Al panel estadístico del Ramsomware se accede mediante la página de acceso principal:



Una vez que se accede aparece la pantalla del menú principal del  KIT MULTI LOCKER Version 3
 
 
Con su menú estadístico de usuarios infectados
 


Y el menú de seguimiento de los usuarios que han pagado por desbloquear su equipo
 

  
La estructura de archivos del KIT es la siguiente:

Su panel de instalación: