<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>CounterMeasures -  A Security Blog » ZeuS</title>
	<atom:link href="http://countermeasures.trendmicro.eu/tag/zeus/feed/" rel="self" type="application/rss+xml" />
	<link>http://countermeasures.trendmicro.eu</link>
	<description>Trend Microâ€™s Rik Ferguson blogs about current security issues.</description>
	<lastBuildDate>Wed, 01 Feb 2012 14:48:59 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>History of the botnet &#8211; White Paper</title>
		<link>http://countermeasures.trendmicro.eu/history-of-the-botnet-white-paper/</link>
		<comments>http://countermeasures.trendmicro.eu/history-of-the-botnet-white-paper/#comments</comments>
		<pubDate>Fri, 12 Nov 2010 13:09:08 +0000</pubDate>
		<dc:creator>Rik Ferguson</dc:creator>
				<category><![CDATA[malware]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[downadup]]></category>
		<category><![CDATA[malicious code]]></category>
		<category><![CDATA[waledac]]></category>
		<category><![CDATA[worm_downad]]></category>
		<category><![CDATA[ZeuS]]></category>

		<guid isPermaLink="false">http://countermeasures.trendmicro.eu/?p=2463</guid>
		<description><![CDATA[Just a quick update, the three part series I have blogged here has been published today as a White Paper. If you&#8217;re interested it can be downloaded here as a 13 page PDF.<div class="addthis_toolbox addthis_default_style " addthis:url='http://countermeasures.trendmicro.eu/history-of-the-botnet-white-paper/' addthis:title='History of the botnet &#8211; White Paper '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_button_google_plusone" g:plusone:size="medium"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></description>
			<content:encoded><![CDATA[<p>Just a quick update, the three part series I have blogged here has been published today as a White Paper. If you&#8217;re interested it can be downloaded <a onclick="pageTracker._trackPageview('/go/CMblog/botnetwhitepaper/');" href="http://uk.trendmicro.com/imperia/md/content/uk/trendmicro_the_botnet_chronicles_en.pdf">here</a> as a 13 page PDF.</p>
<div class="addthis_toolbox addthis_default_style " addthis:url='http://countermeasures.trendmicro.eu/history-of-the-botnet-white-paper/' addthis:title='History of the botnet &#8211; White Paper '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_button_google_plusone" g:plusone:size="medium"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></content:encoded>
			<wfw:commentRss>http://countermeasures.trendmicro.eu/history-of-the-botnet-white-paper/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Bredolab, dead, dying or dormant?</title>
		<link>http://countermeasures.trendmicro.eu/bredolab-dead-dying-or-dormant/</link>
		<comments>http://countermeasures.trendmicro.eu/bredolab-dead-dying-or-dormant/#comments</comments>
		<pubDate>Tue, 26 Oct 2010 16:14:07 +0000</pubDate>
		<dc:creator>Rik Ferguson</dc:creator>
				<category><![CDATA[Bad guys always lose]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[Fake AV]]></category>
		<category><![CDATA[malicious code]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[ZeuS]]></category>

		<guid isPermaLink="false">http://countermeasures.trendmicro.eu/?p=2431</guid>
		<description><![CDATA[As I blogged earlier today, Dutch law enforcement took action to remove 143 servers from the internet which were acting as command &#38; control servers for the Bredolab botnet. &#160; In an update to that news, they have also announced the arrest of a 27 year old Armenian citizen suspected of being the brains behind [...]<div class="addthis_toolbox addthis_default_style " addthis:url='http://countermeasures.trendmicro.eu/bredolab-dead-dying-or-dormant/' addthis:title='Bredolab, dead, dying or dormant? '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_button_google_plusone" g:plusone:size="medium"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></description>
			<content:encoded><![CDATA[<p>As I <a href="http://countermeasures.trendmicro.eu/dutch-authorities-move-on-bredolab/">blogged </a>earlier today, Dutch law enforcement took action to remove 143 servers from the internet which were acting as command &amp; control servers for the Bredolab botnet.<br />
&nbsp;<br />
In an update to that news, they have also <a href="http://www.guardian.co.uk/technology/2010/oct/26/bredolab-worm-suspect-arrested-armenia">announced the arrest</a> of a 27 year old Armenian citizen suspected of being the brains behind the operation.<br />
&nbsp;<br />
So is Bredolab, dead, is it dying or is it simply dormant?<br />
&nbsp;<br />
The glib answer is that we don&#8217;t know, but let&#8217;s consider the current situation. Many if not most of the victim machines infected by Bredolab remain infected, the botnet has simply been decapitated. How effective has that decaptiation been? The graph below shows the marked decrease in the number of Bredolab samples collected from a pool of Bredolab C&amp;C servers, this shows clearly the effectiveness of the law enforcement action.<br />
&nbsp;<br />
<a href="http://countermeasures.trendmicro.eu/wp-content/uploads/2010/10/bredo_davido.jpg"><img class="size-full wp-image-2432" title="Bredolab binaries downloaded over time" alt="Bredolab binaries downloaded over time" src="http://countermeasures.trendmicro.eu/wp-content/uploads/2010/10/bredo_davido.jpg" alt="" width="510" height="262" border="0" /></a><br />Bredolab binaries downloaded over time<br />
&nbsp;<br />
Â </p>
<p>What we do know though, is that there is at least one Bredolab C&amp;C server still active and that it is not hosted in the Netherlands, where there is one, there is the potential for more.<br />
&nbsp;<br />
TrendLabs continue to monitor the situation, but it is clear from past experience with botnets such as Mega-D and Cutwail that criminal software displays remarkable tenacity and a disturbing ability to rise phoenix-like from the ashes of a concerted take-down attempt. Let&#8217;s hope that is not the case with Bredolab.</p>
<div class="addthis_toolbox addthis_default_style " addthis:url='http://countermeasures.trendmicro.eu/bredolab-dead-dying-or-dormant/' addthis:title='Bredolab, dead, dying or dormant? '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_button_google_plusone" g:plusone:size="medium"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></content:encoded>
			<wfw:commentRss>http://countermeasures.trendmicro.eu/bredolab-dead-dying-or-dormant/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Dutch Authorities move on Bredolab</title>
		<link>http://countermeasures.trendmicro.eu/dutch-authorities-move-on-bredolab/</link>
		<comments>http://countermeasures.trendmicro.eu/dutch-authorities-move-on-bredolab/#comments</comments>
		<pubDate>Tue, 26 Oct 2010 10:53:49 +0000</pubDate>
		<dc:creator>Rik Ferguson</dc:creator>
				<category><![CDATA[Bad guys always lose]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[Fake AV]]></category>
		<category><![CDATA[malicious code]]></category>
		<category><![CDATA[Rogue AV]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[ZeuS]]></category>

		<guid isPermaLink="false">http://countermeasures.trendmicro.eu/?p=2422</guid>
		<description><![CDATA[According to a press releaseÂ today from the High Tech Crime Team of the National Crime Squad in the Netherlands, action has been taken to isolate 143 servers from the Internet. &#160; The servers were actively involved in the BredolabÂ botnet, from the release they would appear to be command and control servers. The servers were hosted [...]<div class="addthis_toolbox addthis_default_style " addthis:url='http://countermeasures.trendmicro.eu/dutch-authorities-move-on-bredolab/' addthis:title='Dutch Authorities move on Bredolab '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_button_google_plusone" g:plusone:size="medium"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></description>
			<content:encoded><![CDATA[<p>According to a <a href="http://www.om.nl/actueel/nieuws-_en/@154338/dutch_national_crime/">press release</a>Â today from the High Tech Crime Team of the National Crime Squad in the Netherlands, action has been taken to isolate 143 servers from the Internet.<br />
&nbsp;<br />
The servers were actively involved in the <a href="http://us.trendmicro.com/imperia/md/content/us/trendwatch/researchandanalysis/bredolab_final.pdf">Bredolab</a>Â botnet, from the release they would appear to be command and control servers. The servers were hosted by a company called LeaseWeb, one of the largest hosting providers in the Netherlands, who fully cooperated in the coordinated takedown operation.<br />
&nbsp;<br />
<div id="attachment_2423" class="wp-caption alignleft" style="width: 550px"><img class="size-full wp-image-2423 " title="celebdeath1" src="http://countermeasures.trendmicro.eu/wp-content/uploads/2010/10/celebdeath1.jpg" alt="" width="510" height="281" /><p class="wp-caption-text">Bredolab infection mails</p></div><br />
&nbsp;<br />
Bredolab is primarily a downloading platform and has served to distribute fake AV and ZeuS to victim computers. The botnet, which originated in Russia, only rose to prominence in August 2009. Dutch Authorities estimate that it was capable of infecting 3 million computers per month at its peak. The primary initial trigger for infection with Bredolab was usually though mail, but infection vectors have been widely abused and also include drive-by download and even propagation through other forms of malware, for example, Cutwail has been seen to drop Bredolab as a payload, and Bredolab has been known to return the favour!<br />
Â &nbsp;<br />
It is unclear right now whether the botnet has been effectively decapitated or it this only represents a setback to the criminals behind it. The bots remain infected with the malware so if alternative command &amp; control servers exist, then reconfiguration and regrouping remains a possibility. TrendLabs are investigating current activity levels of the botnet and I will update this blog as soon as new information is available.</p>
<div class="addthis_toolbox addthis_default_style " addthis:url='http://countermeasures.trendmicro.eu/dutch-authorities-move-on-bredolab/' addthis:title='Dutch Authorities move on Bredolab '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_button_google_plusone" g:plusone:size="medium"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></content:encoded>
			<wfw:commentRss>http://countermeasures.trendmicro.eu/dutch-authorities-move-on-bredolab/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>TechCrunch Europe hacked</title>
		<link>http://countermeasures.trendmicro.eu/techcrunch-europe-hacked/</link>
		<comments>http://countermeasures.trendmicro.eu/techcrunch-europe-hacked/#comments</comments>
		<pubDate>Mon, 06 Sep 2010 16:03:22 +0000</pubDate>
		<dc:creator>Rik Ferguson</dc:creator>
				<category><![CDATA[Hacking]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Site Compromise]]></category>
		<category><![CDATA[compromise]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[hacked]]></category>
		<category><![CDATA[malicious code]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[web]]></category>
		<category><![CDATA[ZeuS]]></category>

		<guid isPermaLink="false">http://countermeasures.trendmicro.eu/?p=2303</guid>
		<description><![CDATA[The eagle-eyed harmony guy spotted about an hour ago that some malicious code had been added to the WordPress installation over at TechCrunch Europe. Â  &#160; &#160; Â  The code redirects to a host which is serving up malicious PDF files. The PDFs are designed to exploit a vulnerability which leads to the download of [...]<div class="addthis_toolbox addthis_default_style " addthis:url='http://countermeasures.trendmicro.eu/techcrunch-europe-hacked/' addthis:title='TechCrunch Europe hacked '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_button_google_plusone" g:plusone:size="medium"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></description>
			<content:encoded><![CDATA[<p>The eagle-eyed <a href="http://twitter.com/theharmonyguy/status/23151442700" target="_blank">harmony guy spotted</a> about an hour ago that some malicious code had been added to the WordPress installation over at TechCrunch Europe.<br />
Â <br />
&nbsp;<br />
<div id="attachment_2304" class="wp-caption alignleft" style="width: 447px"><img class="size-full wp-image-2304" title="techcruch europe infection" src="http://countermeasures.trendmicro.eu/wp-content/uploads/2010/09/techcruch.png" alt="" width="437" height="334" /><p class="wp-caption-text">Web reputation breaks the infection chain</p></div><br />
&nbsp;<br />
Â <br />
The code redirects to a host which is serving up malicious PDF files. The PDFs are designed to exploit a vulnerability which leads to the download of that Poison Ivy of the criminal underworld, ZeuS.<br />
Â &nbsp;<br />
The malicious server is hosted by Netdirect over in Frankfurt Germany, a provider with a relatively <a title="Diagnostic page for AS28753 (NETDIRECT)" href="http://www.google.com/safebrowsing/diagnostic?site=AS:28753" target="_blank">colourful history</a> of their own.<br />
Â &nbsp;<br />
The file itself has <a href="http://www.virustotal.com/file-scan/report.html?id=d756a1bd936e30739fe23cbe2896e1b301825f347aae72ff8a7f428831e1819b-1283786063" target="_blank">very low detection rates </a>at present and only serves to underline the need for a security solution that considers the threat as a whole instead of focusing on one aspect of the threat.<br />
Â &nbsp;<br />
If you&#8217;re using our stuff, you&#8217;re safe, the redirection to the bad host never happens and you never see the malicious file.<br />
Â &nbsp;<br />
The folks at TechCrunch have been made aware and we hope they clean up their WordPress installation soon.<br />
&nbsp;</p>
<div class="addthis_toolbox addthis_default_style " addthis:url='http://countermeasures.trendmicro.eu/techcrunch-europe-hacked/' addthis:title='TechCrunch Europe hacked '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_button_google_plusone" g:plusone:size="medium"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></content:encoded>
			<wfw:commentRss>http://countermeasures.trendmicro.eu/techcrunch-europe-hacked/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Identity Crisis?</title>
		<link>http://countermeasures.trendmicro.eu/identity-crisis/</link>
		<comments>http://countermeasures.trendmicro.eu/identity-crisis/#comments</comments>
		<pubDate>Wed, 31 Mar 2010 20:06:45 +0000</pubDate>
		<dc:creator>Rik Ferguson</dc:creator>
				<category><![CDATA[Opinion]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[data loss]]></category>
		<category><![CDATA[identity]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[snooping]]></category>
		<category><![CDATA[ZeuS]]></category>

		<guid isPermaLink="false">http://countermeasures.trendmicro.eu/?p=1956</guid>
		<description><![CDATA[What if confidence in a personâ€™s identity were eroded to such a degree that it became impossible to prove who you are anymore? &#160; &#160; Cybercrime is already laser focused on information theft in its many forms; banking details, information to assist in the theft of identity such as driving licence numbers, passport numbers, motherâ€™s [...]<div class="addthis_toolbox addthis_default_style " addthis:url='http://countermeasures.trendmicro.eu/identity-crisis/' addthis:title='Identity Crisis? '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_button_google_plusone" g:plusone:size="medium"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></description>
			<content:encoded><![CDATA[<p><strong>What if confidence in a personâ€™s identity were eroded to such a degree that it became impossible to prove who you are anymore?</strong><br />
&nbsp;<br />
<div id="attachment_1960" class="wp-caption alignleft" style="width: 590px"><a href="http://countermeasures.trendmicro.eu/wp-content/uploads/2010/03/beer.jpg"><img class="size-full wp-image-1960" title="beer" src="http://countermeasures.trendmicro.eu/wp-content/uploads/2010/03/beer.jpg" alt="" width="510" height="398" /></a><p class="wp-caption-text">Yes sir, that ID appears to be in order.</p></div><br />
&nbsp;<br />
Cybercrime is already laser focused on information theft in its many forms; banking details, information to assist in the theft of identity such as driving licence numbers, passport numbers, motherâ€™s maiden name, date of birth, place of birth, the list goes on. Underground forums already exist where this information is traded as a commodity, whole identities for the purposes of financial fraud (loans, credit cards etc.) can be bought for as little as $10 USD.<br />
&nbsp;<br />
Much of this theft is accomplished through the use of malware, malicious software infecting people&#8217;s computers. This type of criminal malware used to be the preserve of organised crime, as the cost of purchase was prohibitive to hobbyists. Now however, ZeuS for example which used to be a top-end product is available to download free of charge. ZeuS and malware like it has advanced information and remote control capabilities that allow an attacker to snoop on, or modify or steal any information stored in your PC, entered into your browser or any key you press on the keyboard. Crimeware of this sort has become so widespread and so cheap that criminals are now resorting to selling it with add-on services such as hosting or management in order to attract customers.<br />
&nbsp;<br />
In an age where utilities companies, credit card companies, banks and other financial institutions are moving their customers ever more toward online services, e-billing and e-statements arenâ€™t we only making it more simple to steal an identity and at the same time more ethereal to assert one? Stolen documents and templates for document creation are available online if you know where to look, so thatâ€™s your driving licence taken care of and your passport for that matter. When it comes to proving your address; well don&#8217;t you normally need something like your most recent utility bill, for a mortgage your last three months bank statements&#8230;<br />
&nbsp;<br />
The standard advice has always been, and continues to be â€śBuy a shredder, shred all personal correspondence, deter identity thievesâ€ť. The truth is though, much identity theft is perpetrated electronically and if the criminal can use their software to steal your login details for your utility companies, bank and mortgage provider they have no need to go rummaging through your bin bags at three in the morning.<br />
&nbsp;<br />
What do I have, what do any of us have, that really incontrovertibly proves that we are who we say we are? Remember biometric identification is only as good as the initial ID itself, so if I can be you, I can be you enough to apply for a biometric document and present my *own* fingerprints, iris or facial geometry. What then? Do I become you? Who then are you? If we gradually change the parts of a car until nothing is left of the original and yet all the parts make the whole, is it the same car?<br />
&nbsp;<br />
If trust were eroded to such an extent that no one had the confidence necessary to trust a &#8220;proof&#8221; of identity, what would be the outcome? Would the local and even global financial system collapse as the risk of lending became too great? Would the world of online consumer commerce carry on regardless, asserting that â€ś<em>reception of funds is sufficient proof to ship</em>â€ť thus furthering the crisis of confidence as everyoneâ€™s bank accounts became a public and shared utility?<br />
&nbsp;<br />
In a worst case scenario the financial system as we know it today ceases to exist, no further mortgages or loans are possible, bank accounts become untrusted by default rather than inviolate bastions of privacy. Criminal intelligence that relies on tracking identities, such as counter-terrorism, declines in capability until it represents a liability and serious inconvenience to the innocent as they are repeatedly accused of acts they did not commit. We cannot retreat back into the paper based society of the 1900s as advances in information technology have voided any pretence of reliability that may ever have offered. Neither can we rely on having chips implanted under our skin, that technology as it stands today has already been shown to be unreliable, and besides, if all it takes is ownership of a chip, then arenâ€™t offenses such as kidnap and murder viable options for identity theft?<br />
&nbsp;<br />
Perhaps society would return to the parochial notion of â€ś<em>If you werenâ€™t born in the village then I donâ€™t know you and I don&#8217;t trust you</em>â€ť; no change then for where I live!</p>
<div class="addthis_toolbox addthis_default_style " addthis:url='http://countermeasures.trendmicro.eu/identity-crisis/' addthis:title='Identity Crisis? '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_button_google_plusone" g:plusone:size="medium"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></content:encoded>
			<wfw:commentRss>http://countermeasures.trendmicro.eu/identity-crisis/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Kneber for sale or rent (rooms to let 50 cents)*</title>
		<link>http://countermeasures.trendmicro.eu/kneber-for-sale-or-rent-rooms-to-let-50-cents/</link>
		<comments>http://countermeasures.trendmicro.eu/kneber-for-sale-or-rent-rooms-to-let-50-cents/#comments</comments>
		<pubDate>Fri, 19 Feb 2010 13:15:58 +0000</pubDate>
		<dc:creator>Rik Ferguson</dc:creator>
				<category><![CDATA[malware]]></category>
		<category><![CDATA[Underground Economy]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[data loss]]></category>
		<category><![CDATA[kneber]]></category>
		<category><![CDATA[malicious code]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[ZeuS]]></category>

		<guid isPermaLink="false">http://countermeasures.trendmicro.eu/?p=1790</guid>
		<description><![CDATA[I realise I might be getting a reputation as the infosec curmudgeon, always ready with a bucket of cold water when the occasion demands, but once again I feel moved to write about hype. &#8220;Seemingly there is no reason for these extraordinary intergalactical upsets. Only Dr Hans Zarkov formerly at NASA has provided any explanation&#8221;* [...]<div class="addthis_toolbox addthis_default_style " addthis:url='http://countermeasures.trendmicro.eu/kneber-for-sale-or-rent-rooms-to-let-50-cents/' addthis:title='Kneber for sale or rent (rooms to let 50 cents)* '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_button_google_plusone" g:plusone:size="medium"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></description>
			<content:encoded><![CDATA[<p>I realise I might be getting a reputation as the infosec curmudgeon, always ready with a <a title="Google, China, Chicken Little and Cyber Armageddon"  href="http://countermeasures.trendmicro.eu/google-china-chicken-little-and-cyber-armageddon/" target="_blank">bucket of cold water</a> when the occasion demands, but once again I feel moved to write about hype.</p>
<blockquote><p>&#8220;Seemingly there is no reason for these extraordinary intergalactical upsets. Only Dr Hans Zarkov formerly at NASA has provided any explanation&#8221;*</p></blockquote>
<p>Stories in the press recently have been aghast at the scale of a &#8220;new&#8221; botnet called Kneber. According to a <a title="NetWitness blog" href="http://www.networkforensics.com/2010/02/18/move-over-china-here-comes-russia/" target="-blank">report from NetWitness</a> one particular botnet that uses the ZeuS crimeware has successfully infiltrated thousands of corporations and tens of thousands of computers. This is of course terrible news for the companies affected and certainly many corporate security lessons can be learned from experiences such as this.</p>
<p>&nbsp;</p>
<p>What is important to point out though is that there is nothing at all that is &#8220;new&#8221; or &#8220;unprecedented&#8221; about a botnet using ZeuS or a botnet of this size, <a href="http://threatinfo.trendmicro.com/vinfo/web_attacks/ZeuS_ZBOTandKneberConnection.html" target="_blank">ZeuS (or ZBot)</a> has been around since at least 2007. In the online underground ZeuS is the equivalent of commodity crimeware. It is openly traded in online forums both as a software product and as preinfected botnets. Increasingly providers are finding that they must bundle services with their criminal offering,Â or Crimeware as a Service.</p>
<p>&nbsp;</p>
<p><div id="attachment_1792" class="wp-caption alignleft" style="width: 621px"><a href="http://countermeasures.trendmicro.eu/wp-content/uploads/2010/02/saleorrent.gif"><img class="size-full wp-image-1792" title="Screen shot from underground forum" src="http://countermeasures.trendmicro.eu/wp-content/uploads/2010/02/saleorrent.gif" alt="Screen shot from underground forum" width="510" height="333" /></a><p class="wp-caption-text">Screen shot from underground forum</p></div><br />
&nbsp;</p>
<p>Older versions of the software are downloadable free of charge, though these are often backdoored by other criminals. There is no honour among thieves. In fact botnets are in such plentiful supply that the price of preinfected machines is surprisingly low.<br />
&nbsp;</p>
<div id="attachment_1793" class="wp-caption alignleft" style="width: 248px"><a href="http://countermeasures.trendmicro.eu/wp-content/uploads/2010/02/botsale.gif"><img class="size-full wp-image-1793 " title="Screen shot from underground forum" src="http://countermeasures.trendmicro.eu/wp-content/uploads/2010/02/botsale.gif" alt="Screen shot from underground forum" width="238" height="199" /></a><p class="wp-caption-text">175 thousand bots for sale... globally.</p></div>
<p>&nbsp;</p>
<p>Of course if you don&#8217;t have the means or the desire to run your own botnet, you can always simply buy the output&#8230;</p>
<p>&nbsp;</p>
<div id="attachment_1795" class="wp-caption alignleft" style="width: 502px"><a href="http://countermeasures.trendmicro.eu/wp-content/uploads/2010/02/zeuslogs2.gif"><img class="size-full wp-image-1795" title="Screen shot from underground forum" src="http://countermeasures.trendmicro.eu/wp-content/uploads/2010/02/zeuslogs2.gif" alt="https://zeustracker.abuse.ch/index.php" width="492" height="253" /></a><p class="wp-caption-text">I&#39;m a lumberjack and I&#39;m OK. Logs for sale.</p></div>
<p>&nbsp;</p>
<p>A quick look at <a title="abuse.ch ZeuS Tracker" href="https://zeustracker.abuse.ch/index.php" target="_blank">ZeuS Tracker </a>shows they are tracking almost 1300 command &amp; control servers for various ZeuS botnets of which about half are online right now. They show the average binary detection rate (how your antivirus products detects using pattern files or signatures) is as low as 49.62% which goes some way towards explaining the successful infection rate.<br />
&nbsp;<br />
It is widely known that malware writers and other criminals have already worked out how to overcome traditional anti-malware protection that relies on pattern or signature updates. They simply roll their code as often as possible, estimates say that we are currently seeing a unique malicious binary every 1.5 seconds.<br />
&nbsp;<br />
So here&#8217;s corporate security lesson number one from this recent publicity&#8230;<br />
&nbsp;<br />
Make sure your anti-malware solution is not relying simply on the infection layer &#8220;<em>what the file looks like</em>&#8220;; make sure that it is also investigating the exposure layer, &#8220;where <em>the file comes from and who the file reports back to</em>&#8220;. If ZeuS Tracker knows where the bad guy servers are, so should every one of your endpoints. At that point, what the actual binary looks like becomes a secondary issue.</p>
<p>&nbsp;<br />
By the way <a href="http://free.antivirus.com/rubotted/">here </a>is a free tool to check if you are a part of a bot network.<br />
&nbsp;<br />
* With apologies to Roger Miller and Queen</p>
<div class="addthis_toolbox addthis_default_style " addthis:url='http://countermeasures.trendmicro.eu/kneber-for-sale-or-rent-rooms-to-let-50-cents/' addthis:title='Kneber for sale or rent (rooms to let 50 cents)* '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_button_google_plusone" g:plusone:size="medium"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></content:encoded>
			<wfw:commentRss>http://countermeasures.trendmicro.eu/kneber-for-sale-or-rent-rooms-to-let-50-cents/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Your guilty conscience could get you pwned</title>
		<link>http://countermeasures.trendmicro.eu/your-guilty-conscience-could-get-you-pwned/</link>
		<comments>http://countermeasures.trendmicro.eu/your-guilty-conscience-could-get-you-pwned/#comments</comments>
		<pubDate>Wed, 03 Feb 2010 15:28:59 +0000</pubDate>
		<dc:creator>Rik Ferguson</dc:creator>
				<category><![CDATA[malware]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[Underground Economy]]></category>
		<category><![CDATA[banking]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[malicious code]]></category>
		<category><![CDATA[ZeuS]]></category>

		<guid isPermaLink="false">http://countermeasures.trendmicro.eu/?p=1746</guid>
		<description><![CDATA[I just received an email from some guy called Willie Hickey. Aside form having an extremely amusing name, Mr. Hickey was offering me some very urgent advice: &#160; &#160; Â The message reads &#8220;Hey, some jerk has posted your pictures (u understand what kind of pictures are there) and sent a link of them to all [...]<div class="addthis_toolbox addthis_default_style " addthis:url='http://countermeasures.trendmicro.eu/your-guilty-conscience-could-get-you-pwned/' addthis:title='Your guilty conscience could get you pwned '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_button_google_plusone" g:plusone:size="medium"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></description>
			<content:encoded><![CDATA[<p class="mceTemp">I just received an email from some guy called Willie Hickey. Aside form having an extremely amusing name, Mr. Hickey was offering me some very urgent advice:</p>
<p>&nbsp;</p>
<p><div id="attachment_1747" class="wp-caption alignleft" style="width: 638px"><a href="http://countermeasures.trendmicro.eu/wp-content/uploads/2010/02/williehickey.png"><img class="size-full wp-image-1747" title="Mail from Willie Hickey" src="http://countermeasures.trendmicro.eu/wp-content/uploads/2010/02/williehickey.png" alt="Mail from Willie Hickey" width="510" height="198" /></a><p class="wp-caption-text">Mail from Willie Hickey</p></div><br />
&nbsp;<br />
Â The message reads</p>
<blockquote><p>&#8220;Hey, some jerk has posted your pictures (u understand what kind of pictures are there) and sent a link of them to all ur friends. I have already replied back. Said, that he is an idiot. See the link:&#8221;.</p></blockquote>
<p>&nbsp;<br />
This little piece of social engineering is obviously designed to arouse fear and doubt in the recipient; &#8220;<em>Oh no, not those photos, the zookeeper promised he would destroy the negatives.</em>&#8221;<br />
&nbsp;</p>
<div class="mceTemp">Don&#8217;t be tempted though to click the link. There are no photos, there is no Willie Hickey.</div>
<p>&nbsp;</p>
<div class="mceTemp">The link leads to a malicious JavaScript which redirects the browser to a Russian IP address where multiple PDF exploits and an ActiveX exploit are used to push out a variant of the <a href="http://countermeasures.trendmicro.eu/nospace-for-another-banking-trojan/">ZeuS crimeware</a>. The sample itself has very low detection rates with only <a title="VirusTotal" href="http://www.virustotal.com/analisis/a05cc494a906a791f9b395b16bcc82c9e8f1dd1a4c212aab33386dfb47e53c5e-1265209172" target="_blank">9 out of 40 detections on VirusTotal</a></div>
<p>&nbsp;</p>
<div class="mceTemp">If you&#8217;re already a Trend Micro user you would be protected from this as the malicious website is already blocked by the Smart Protection Network and the malware detected. If you have received a similar mail and clicked the link and are worried you may be affected, run a free clean up with <a title="Trend Micro HouseCall" href="http://housecall.trendmicro.com/uk/" target="_blank">HouseCall</a>.</div>
<div class="addthis_toolbox addthis_default_style " addthis:url='http://countermeasures.trendmicro.eu/your-guilty-conscience-could-get-you-pwned/' addthis:title='Your guilty conscience could get you pwned '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_button_google_plusone" g:plusone:size="medium"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></content:encoded>
			<wfw:commentRss>http://countermeasures.trendmicro.eu/your-guilty-conscience-could-get-you-pwned/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>NoSpace for another banking Trojan</title>
		<link>http://countermeasures.trendmicro.eu/nospace-for-another-banking-trojan/</link>
		<comments>http://countermeasures.trendmicro.eu/nospace-for-another-banking-trojan/#comments</comments>
		<pubDate>Mon, 09 Nov 2009 16:29:16 +0000</pubDate>
		<dc:creator>Rik Ferguson</dc:creator>
				<category><![CDATA[malware]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Underground Economy]]></category>
		<category><![CDATA[banking]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[data loss]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[malicious code]]></category>
		<category><![CDATA[MySpace]]></category>
		<category><![CDATA[web]]></category>
		<category><![CDATA[Zbot]]></category>
		<category><![CDATA[ZeuS]]></category>

		<guid isPermaLink="false">http://countermeasures.trendmicro.eu/?p=1514</guid>
		<description><![CDATA[Today saw the beginning of a new spam run from the ZeuS or Zbot family of malware. Victims will receive an email similar to the one below prompting them to &#8220;update&#8221; their MySpace account, very similar to the Facebook spam run from last week. Spam email from Zeus bot Â  Â  Â  The link in [...]<div class="addthis_toolbox addthis_default_style " addthis:url='http://countermeasures.trendmicro.eu/nospace-for-another-banking-trojan/' addthis:title='NoSpace for another banking Trojan '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_button_google_plusone" g:plusone:size="medium"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></description>
			<content:encoded><![CDATA[<div class="mceTemp">Today saw the beginning of a new spam run from the ZeuS or Zbot family of malware. Victims will receive an email similar to the one below prompting them to &#8220;update&#8221; their MySpace account, very similar to the Facebook spam run from last week.
<dl id="attachment_1515" class="wp-caption alignleft" style="width: 503px;">
<dt class="wp-caption-dt"><a href="http://countermeasures.trendmicro.eu/wp-content/uploads/2009/11/zeusmail.png"><img class="size-full wp-image-1515" title="Spam email from Zeus bot" src="http://countermeasures.trendmicro.eu/wp-content/uploads/2009/11/zeusmail.png" alt="Spam email from Zeus bot" width="493" height="387" /></a></dt>
<dd class="wp-caption-dd">Spam email from Zeus bot</dd>
</dl>
</div>
<p>Â </p>
<p>Â </p>
<p>Â </p>
<p>The link in the mail leads to a standard fake MySpace login page, so of course your account details are stolen. Once you have &#8220;logged in&#8221; though, the supposed &#8220;MySpace Update Tool&#8221; is waiting to trick the unwary into installing their very own variant of the ZeuS agent. We detect this as <a title="TSPY_ZBOT.SMP" href="http://threatinfo.trendmicro.com/vinfo/grayware/ve_graywareDetails.asp?GNAME=TSPY_ZBOT.SMP" target="_blank">TSPY_ZBOT.SMP</a>, the Smart Protection Network also blocks the email spam and web addresses associated with this campaign.</p>
<div id="attachment_1516" class="wp-caption alignleft" style="width: 539px"><a href="http://countermeasures.trendmicro.eu/wp-content/uploads/2009/11/myspaceacctupdate.png"><img class="size-full wp-image-1516" title="Download page for the ZeuS agent" src="http://countermeasures.trendmicro.eu/wp-content/uploads/2009/11/myspaceacctupdate.png" alt="Download page for the ZeuS agent" width="510" height="336" /></a><p class="wp-caption-text">Download page for the ZeuS agent</p></div>
<div class="mceTemp">Â </div>
<div class="mceTemp">Â </div>
<div class="mceTemp">What&#8217;s the big deal with ZeuS? Well here&#8217;s an extract from the readme (apologies for the English, I think it&#8217;s written for an Eastern European audience&#8230;)</div>
<div class="mceTemp">Â </div>
<blockquote>
<div class="mceTemp">&#8220;<em>Does not create suspicion on the presence if you it do not want. Here is available in view of that like to do many authors spyware: an unloading firewalls, antiviruses, an interdiction for their updating, blocking Ctrl+Alt+Del etc.</em><em>Separate file of a configuration that allows to protect itself from loss botnet in cases of inaccessibility of the preferred server. Plus additional (reserve) files of a configuration to which the bot will address when the basic file of a configuration will not be accessible. This system guarantees a survival of yours botnet in 90 % cases.</em></div>
<p><em>Interception of POST-data + interception of the pressed keys (including inserted data from a clipboard).</em></p>
<p><em>Transparent URL-redirect (on fake-sites etc.) with the task of the elementary conditions of a redirect (for example: only at GET or POST inquiry, at presence or absence of certain data in POST-inquiry).</em></p>
<p><em>Transparent HTTP (S) contents substitution (the Web-inject which allows to substitute not only HTML pages, but also any other type of data). Substitution is set by means of instructions of masks of substitution.</em></p>
<p><em>Adjusted TAN-grabber for any countries.</em></p>
<p><em>The IDEAL DECISION FOR VIRTUAL KEYBOARDS: After calling on necessary URL, there is a reception of a screenshot in the field of the screen where the left button of the mouse has been pressed.</em></p>
<p><em>Reception of certificates from storehouse &#8220;MY&#8221; (certificates with a mark &#8220;not exported&#8221; are not exported correctly) and its clearing. After it any imported certificate will be saved on a server.</em></p>
<p><em>Interception of a login/password of reports POP3 and FTP in independence of port and its record to logs only at successful authorisation.</em></p>
<p><em>Change local DNS, removal/addition of file recording %system32 %\drivers\etc\hosts, i.e. comparison of the specified domain with specified IP for WinSocket.</em></p>
<p><em>Reception of a screenshot from the computer of a victim in real time, the computer should is out of NAT.</em></p>
<p><em>Reception of commands from a server part and report sending back about successful performance. (Now start of a local/removed file, immediate updating of a file of a configuration, OS destruction).</em></p>
<p><em>Socks4-server.</em></p>
<p><em>HTTP (S) a PROXY-server.</em>&#8220;</p></blockquote>
<p>My favourite part of this particular readme though has to be this:</p>
<blockquote><p>&#8220;<em>Record just visited pages at the first start on the computer. It is useful at installation through sploits if you buy loadings from suspicious service, it is possible to learn that is loaded more in parallel.</em>&#8220;</p></blockquote>
<p>Â </p>
<p>Basically as a budding cybercriminal it&#8217;s tough to find partners you can trust. So if the person you paid to load your bot up on their boobytrapped web page decides they will send their own little package to your victims as well, you&#8217;ll know about it.</p>
<p>Â </p>
<p>This particular vendor is offering a fully installed, configured <em>and supported </em>ZeuS installation; control panel, agent builder andÂ injection scriptsÂ Â for just $320 (USD).</p>
<div class="addthis_toolbox addthis_default_style " addthis:url='http://countermeasures.trendmicro.eu/nospace-for-another-banking-trojan/' addthis:title='NoSpace for another banking Trojan '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_button_google_plusone" g:plusone:size="medium"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></content:encoded>
			<wfw:commentRss>http://countermeasures.trendmicro.eu/nospace-for-another-banking-trojan/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>

