Pages

Wednesday, 29 February 2012

Chinese Threat Actor Part 2

Follow up on Joe Stewart Investigation

http://www.secureworks.com/research/threats/sindigoo/

Chinese Threat Actor Part 1

http://cyb3rsleuth.blogspot.com/2011/08/chinese-threat-actor-identified.html

king_public@hotmail.com also owns another email king_public@163.com

RootKit Database

(23025,'king-rose','e211f11c0b28434bf7f1c8fb510fa9ae','Club tom','king_public@hotmail.com',1,1106582903,'','','','','','',0,'','',1106837367,'61.51.59.63',0,0,0,1106583113,0,0,0,'BH','19800126','','','',0,'')

IP - 61.51.59.63

Location     CHINA, BEIJING, BEIJING
Connection through    CHINA UNICOM BEIJING PROVINCE NETWORK

IP - 123.120.127.153

20446,'king-z','e211f11c0b28434bf7f1c8fb510fa9ae','k,z,y','wzy_100@hotmail.com',1,1097652186,'','','','','','',0,'','',1284013010,'123.120.127.153',0,0,0,1284013010,0,0,0,'','','','','',0,'')

Location     CHINA, BEIJING, BEIJING
Connection through    CHINA UNICOM BEIJING PROVINCE NETWORK



The Kaixin profile linked to king_public@hotmail.com reveals the name Wang Liang Chen (王亮晨 ) and his other email king_public@163.com is also linked to a Kaixin profile.

Wang Zhong Yun (王仲俊)

http://www.kaixin001.com/home/22655901.html

http://www.kaixin001.com/photo/logolist.php?uid=22655901



Gender: Male
Current residence: Beijing
Zodiac Sign: Pisces

The spacewalk picture is used as profile picture for king_public@hotmail.com kaixin. 

His social network got many friends and the profile appears genuine.











Further analysis reveals that king_public@163.com is linked to many tech and hacker forums with handles "W100", "King-W" and "King-Z"

Tianya Board


Male, Beijing, Pisces





http://topic.csdn.net/t/20031223/17/2594994.html



http://topic.csdn.net/t/20050926/19/4295450.html



51CTO Blog



8dragon










Known emails and handles of the actor

king_public@hotmail.com

wzy_100@hotmail.com

king_public@163.com

king_w100@163.com

Handles - King-Z, King-W, W100, King-rose


Chinese Threat Actor Part 3

Monday, 13 February 2012

Gigabid Affiliate

Gigabid - Clickbot and Fake AV Affiliate

INCOME UP TO 400 $ - 1K US

US, GB, CA, AU, AT, BE, BG, DE, GR, DK
IE, ES, IT, CY, LU, MT, NL, PT, FI, FR, SE

STANDARD US CA GB AU

up to 90%

NEW METHOD FOR THE ENVELOPE!
Earn up to $ 830 A DAY
UP TO 20% Referral
COMPATIBLE with other software



















Friday, 10 February 2012

Evade Antivirus Detection

Bad Guys way


- Scan malware at multiple Anti Virus Checker that do not send samples to AV companies.
- Crypt malware with Polymorphic crypters to avoid detection.


MyAV Scan - Private AV Scanners and Crypters


About




 Services



Multiple Scanners & Crypters






Desktop Version


Wednesday, 1 February 2012

Andromeda Bot


English translation by @Sherb1n

Coder - Waahoo - Adv on Private Forum

Description:

This versatile modular bot can be used as the foundation for a botnet with an endless variety of possibilities. The bot’s functionality can be expanded through a system of plugins, any number of which can be added at any time.

Supports unlimited number of reserve domains.

Data exchange protocol between the bot and the admin server is RC4-encrypted.

 You can reconfigure your botnet to your needs at any time, by yourself.

Doesn’t overload the system, doesn’t require admin rights to install, doesn’t trigger a UAC pop-up.

The bot protects itself, so an unskilled user will not be able to remove it from the system.

Bypasses firewalls, doesn’t appear in the list of processes, injects into a trusted process.

Doesn’t produce any DLLs, doesn’t contain TLS, easy to encrypt.

Regardless of how successful the installation is, the original executable is deleted.

Works on WinXP through Win7, including x64 systems.

Very lightweight, written entirely in Assembler.

There are two versions of this bot:

01.* public inject-based, uses QueueUserAPC
02.* bypass-based; this version, unlike the one above, can get through proactive defense.

Written in PHP, bundled with MySQL.
Detects bots behind the NAT.
Keeps botnet stats: # of bots online/offline/dead, breakdown by country, breakdown by platform.
Keeps track of the number of finished/unfinished tasks.
Can set a limit on the number of times the task will be executed.
Can assign tasks to individual bots.
Assign tasks based on the bots’ countries.
Clear all stats/delete all dead bots from the DB.

Admin panel screenshots:










Price list:

01.* - $200
02.* - not for sale at the moment.
Rebuild for a new URL (main URL) - $10
For each additional reserve URL - $10

We accept:

Liberty Reserve (preferred)
Webmoney.