Pages

Friday, 2 March 2012

Chinese Threat Actor Part 3


Sin Digoo Identified

Another email mentioned in Joe's blog was jeno_1980@hotmail.com which is linked to xxgchappy@vip.sina.com





Espionage Domains

Malware reported on umu1.echosky.biz


Malware reported on www.dellpc.us - December 2007



BlackHat Domains

Archive on socialup.net reveals ICQ info of Jeno aka Tawnya aka xxgchappy

http://web.archive.org/web/20100106025256/http://www.socialup.net/contacts.php

ICQ 567950703



The ICQ search leads to a blackhatworld profile with handle "xxgchappy" and a domain makewithmoney.com

Domain name: makewithmoney.com

Creation date: 18 Nov 2009 02:17:06

Expiration date: 18 Nov 2010 02:17:06

Registrant Contact:
personal
eric charles ()

Fax:
Santa Cruz 1156 High Street
california, california 95064
US

Administrative Contact:
personal
eric charles (jeno_1980@hotmail.com)
+1.831459019
Fax: +1.831459019
Santa Cruz 1156 High Street
california, california 95064
US



Twitter

https://twitter.com/leedoctor




http://www.blackhatworld.com/blackhat-seo/members/73099-xxgchappy.html



http://www.v7n.com/forums/social-networking/161752-wts-cheap-digg-service-0-1-per-digg.html


Jeno promoted his socialup.net in chinese forums





The profile mentions www.hnsj.org as his website





Whois record of hnsj.org

Domain ID:D155737903-LROR
Domain Name:HNSJ.ORG
Created On:27-Mar-2009 10:10:58 UTC
Last Updated On:04-Apr-2010 05:17:20 UTC
Expiration Date:27-Mar-2011 10:10:58 UTC
Sponsoring Registrar:eNom, Inc. (R39-LROR)
Status:OK
Registrant ID:f1f613654acc4737
Registrant Name:eric charles
Registrant Organization:personal
Registrant Street1:Santa Cruz 1156 High Street
Registrant Street2:
Registrant Street3:
Registrant City:california
Registrant State/Province:State
Registrant Postal Code:95064
Registrant Country:YE
Registrant Phone:+1.831459019
Registrant Phone Ext.:
Registrant FAX:+1.831459019
Registrant FAX Ext.:
Registrant Email:jeno_1980@hotmail.com


Personal Domains

Search on hnsj.org revealed some interesting information. The domain is related to mobile phone sales and the name of the company is Henan Mobile Network.




Archive

http://web.archive.org/web/20100109050932/http://www.hnsj.org/article.php?id=4




QQ number 55356626 is posted as contact on HNSJ.ORG



xxgchappy promoted hnsj.org on his baidu blog

http://hi.baidu.com/%BA%D3%C4%CF%CA%D6%BB%FA%CD%F8/home






His baidu profile mentions further details

http://passport.baidu.com/?business&aid=6&un=xxgchappy#0


Further search reveals other QQ and Phone contacts

http://bbs.shangdu.com/t/20080831/01004001126/126-1.htm

2008 post

慧慧数码旗舰店

http://shop36037986.taobao.com ( Shop doesn't exist now)

各种智能手机专卖
淘宝名店 钻石信誉 全国热卖
保原装 非原装赔偿精神损失50.全额退款。
百脑汇2楼2b16
QQ:55356626
旺旺:慧慧数码旗舰店
13949001667
我们的专业,值得信赖。

Phone number 13949001667 (mobile GSM card) is part of Zhengzhou City, Henan Province and name mentioned here is Zhang

http://www.hahait.com/h41328



Company Name:Henan phone network 
Tel:0371-66900779
Company Address:Longhai Road, No. 188 Central Plains Communications Digital City A420
Contact:Mr. Zhang
Fax:
E-mail:
Company QQ:Click to chat878,972,156   Click to chat390,363,752   Click to chat55,356,626  
Website:http://www.hahait.com/41328
Scope of business:Phone Samsung LG Nokia    

QQ 878972156

QQ 390363752

QQ 55356626


The QQ number is linked to a post on a car forum dated 2005

http://www.xcar.com.cn/bbs/viewthread.php?tid=6300657

http://www.xcar.com.cn/bbs/viewthread.php?tid=1576356

爱 卡 I D:Jeno
小狮子 1。6 xmt
车牌 豫ADB922
手机号 13513899779


Whois Record- XIUXING.INFO

Domain ID:D13719670-LRMS
Domain Name:XIUXING.INFO
Created On:09-Jun-2006 06:16:29 UTC

Last Updated On:29-May-2007 01:13:12 UTC
Expiration Date:09-Jun-2009 06:16:29 UTC
Sponsoring Registrar:eNom, Inc. (R126-LRMS)
Status:OK
Registrant ID:49A2353365A0954B
Registrant Name:tawnya grilth
Registrant Organization:i-tobuy.com
Registrant Street1:po box 211
Registrant Street2:
Registrant Street3:
Registrant City:sin digoo
Registrant State/Province:ca
Registrant Postal Code:92101
Registrant Country:US
Registrant Phone:+1.818926523
Registrant Phone Ext.:
Registrant FAX:
Registrant FAX Ext.:
Registrant Email:jeno_1980@hotmail.com


xiuxing.info is a forum related to Buddhism.



Jeno mentions his buddhism website on his profile along the same QQ number used in HNSJ.org






Tawyna  Grilth aka Eric Charles aka xxgchappy aka Jeno aka undercurrent


Personal Details

QQ number 55356626 Profile




The personal email "xxgchappy@vip.sina.com" is also mentioned on a Shellcode article written by Jeno at Xfocus, a famous chinese hacking forum dated 2003.




转自:http://www.xfocus.net
创建时间:2003-08-31
文章属性:原创
文章提交:jeno (xxgchappy_at_vip.sina.com)

作者:jeno
Email: jeno@vip.371.net
Time: 2003-8-31

Xfocus Profile

https://www.xfocus.net/bbs/index.php?lang=cn&act=Profile&do=03&MID=35525


DOB 1980-10-1

The name Jeno and DOB 1980 makes the email Jeno_1980@hotmail.com which is used as registrant email.


Kaixin001 Chinese Social Network

xxgchappy@vip.sina.com is the registrant email of chinese social network Kaixin001.

http://www.kaixin001.com/home/17206761.html


Personal details mentioned on Kaixin profile.

Name - 张长河 Zhang Chang-he

Living in Zhengzhou, Henan Province, China.


QQ number 55356626 leads to a personal blog revealing his pic

http://55356626.qzone.qq.com



Conclusion

Jeno registered all the domains associated with espionage and considering his xfocus and rootkit.com profile we can zero on Jeno or he is some way associated with the group.

 
Update 16 Feb 2013

http://www.businessweek.com/articles/2013-02-14/a-chinese-hackers-identity-unmasked


Journals published by Zhang Chang-he (2005-2011)

http://www.cnki.net/KCMS/detail/search.aspx?dbcode=CJFQ&sfield=au&skey=%E5%BC%A0%E9%95%BF%E6%B2%B3&code=22840348;20139954;21141875;




Windows Rootkit

http://www.cnki.net/KCMS/detail/detail.aspx?QueryID=5&CurRec=2&recid=&filename=XXGC200702023&dbname=cjfd2007&dbcode=CJFQ&pr=&urlid=&yx=

http://www.docin.com/p-49869286.html 


Analysis of Windows Startup

http://www.cnki.net/kcms/detail/detail.aspx?filename=XXGC200903027&dbcode=CJFQ&dbname=CJFD2009

http://www.docin.com/p-253321277.html


Security Analysis of PCI device

http://www.docin.com/p-279253540.html


Capturing File Transferred or Printed Based on SMB in LAN

http://www.cnki.net/kcms/detail/detail.aspx?filename=WJSJ200606039&dbcode=CJFQ&dbname=cjfd2006


Wednesday, 29 February 2012

Chinese Threat Actor Part 2

Follow up on Joe Stewart Investigation

http://www.secureworks.com/research/threats/sindigoo/

Chinese Threat Actor Part 1

http://cyb3rsleuth.blogspot.com/2011/08/chinese-threat-actor-identified.html

king_public@hotmail.com also owns another email king_public@163.com

RootKit Database

(23025,'king-rose','e211f11c0b28434bf7f1c8fb510fa9ae','Club tom','king_public@hotmail.com',1,1106582903,'','','','','','',0,'','',1106837367,'61.51.59.63',0,0,0,1106583113,0,0,0,'BH','19800126','','','',0,'')

IP - 61.51.59.63

Location     CHINA, BEIJING, BEIJING
Connection through    CHINA UNICOM BEIJING PROVINCE NETWORK

IP - 123.120.127.153

20446,'king-z','e211f11c0b28434bf7f1c8fb510fa9ae','k,z,y','wzy_100@hotmail.com',1,1097652186,'','','','','','',0,'','',1284013010,'123.120.127.153',0,0,0,1284013010,0,0,0,'','','','','',0,'')

Location     CHINA, BEIJING, BEIJING
Connection through    CHINA UNICOM BEIJING PROVINCE NETWORK



The Kaixin profile linked to king_public@hotmail.com reveals the name Wang Liang Chen (王亮晨 ) and his other email king_public@163.com is also linked to a Kaixin profile.

Wang Zhong Yun (王仲俊)

http://www.kaixin001.com/home/22655901.html

http://www.kaixin001.com/photo/logolist.php?uid=22655901



Gender: Male
Current residence: Beijing
Zodiac Sign: Pisces

The spacewalk picture is used as profile picture for king_public@hotmail.com kaixin. 

His social network got many friends and the profile appears genuine.











Further analysis reveals that king_public@163.com is linked to many tech and hacker forums with handles "W100", "King-W" and "King-Z"

Tianya Board


Male, Beijing, Pisces





http://topic.csdn.net/t/20031223/17/2594994.html



http://topic.csdn.net/t/20050926/19/4295450.html



51CTO Blog



8dragon










Known emails and handles of the actor

king_public@hotmail.com

wzy_100@hotmail.com

king_public@163.com

king_w100@163.com

Handles - King-Z, King-W, W100, King-rose


Chinese Threat Actor Part 3

Monday, 13 February 2012

Gigabid Affiliate

Gigabid - Clickbot and Fake AV Affiliate

INCOME UP TO 400 $ - 1K US

US, GB, CA, AU, AT, BE, BG, DE, GR, DK
IE, ES, IT, CY, LU, MT, NL, PT, FI, FR, SE

STANDARD US CA GB AU

up to 90%

NEW METHOD FOR THE ENVELOPE!
Earn up to $ 830 A DAY
UP TO 20% Referral
COMPATIBLE with other software



















Friday, 10 February 2012

Evade Antivirus Detection

Bad Guys way


- Scan malware at multiple Anti Virus Checker that do not send samples to AV companies.
- Crypt malware with Polymorphic crypters to avoid detection.


MyAV Scan - Private AV Scanners and Crypters


About




 Services



Multiple Scanners & Crypters






Desktop Version


Wednesday, 1 February 2012

Andromeda Bot


English translation by @Sherb1n

Coder - Waahoo - Adv on Private Forum

Description:

This versatile modular bot can be used as the foundation for a botnet with an endless variety of possibilities. The bot’s functionality can be expanded through a system of plugins, any number of which can be added at any time.

Supports unlimited number of reserve domains.

Data exchange protocol between the bot and the admin server is RC4-encrypted.

 You can reconfigure your botnet to your needs at any time, by yourself.

Doesn’t overload the system, doesn’t require admin rights to install, doesn’t trigger a UAC pop-up.

The bot protects itself, so an unskilled user will not be able to remove it from the system.

Bypasses firewalls, doesn’t appear in the list of processes, injects into a trusted process.

Doesn’t produce any DLLs, doesn’t contain TLS, easy to encrypt.

Regardless of how successful the installation is, the original executable is deleted.

Works on WinXP through Win7, including x64 systems.

Very lightweight, written entirely in Assembler.

There are two versions of this bot:

01.* public inject-based, uses QueueUserAPC
02.* bypass-based; this version, unlike the one above, can get through proactive defense.

Written in PHP, bundled with MySQL.
Detects bots behind the NAT.
Keeps botnet stats: # of bots online/offline/dead, breakdown by country, breakdown by platform.
Keeps track of the number of finished/unfinished tasks.
Can set a limit on the number of times the task will be executed.
Can assign tasks to individual bots.
Assign tasks based on the bots’ countries.
Clear all stats/delete all dead bots from the DB.

Admin panel screenshots:










Price list:

01.* - $200
02.* - not for sale at the moment.
Rebuild for a new URL (main URL) - $10
For each additional reserve URL - $10

We accept:

Liberty Reserve (preferred)
Webmoney.

Tuesday, 31 January 2012

StyxCrypt

About

World's first fully automated online obfuscation service is a service to provide a full range of obfuscation services of binary data and source code by nine input data formats.

Currently we support the most demanded spectrum of morphing formats which are demanded by thousands of webmasters:

JavaScript;
HTML;
EXE;
DLL;
PDF;
SWF;
IFrame;
PHP;
ASP;

Multi Obfuscator has it's own polymorphic engine which enables a possibility to morph a vide range of inupt data. This means every time you morph something you will get absolutely different binary and source code.
System provides an external API and gives a possibility to automate software and services for all customers.
You will be fully satisfied by morphing quality and speed of updates.







FAQ

Q: What's this service about?
A: Our service is first world-class fully automated multicrypt service. At the moment we have the maximum quantity of morphing input data types, fully automated system based on polymorphic engine and API suported.


Q: What types of crypting do you support?
A: We support nine morphing data tyes:

HTML: source code with or without JavaScript;


JavaScript: inside HTML or standalone (which is helpful for clickunders, popunders and morphing any type of context advertising);
EXE and DLL as Windows Coff PE executables;
PDF: content morphing;
SWF: morping source AS3-scripts;
PHP / ASP source scripts;


Q: Who are your customers?
A: Our customers are partners program, online casino, traffic stocks, banner networks, adult, pharma and so on.


Q: What are your benefits compare to private services?
Firstly no one of private services can't morph such quantity of data types as we can. We have a polymorphic kernel that guarantees that all output code will be fully different and enthropy will be almost 100%. As we have a polymorphic stub every crypted fule will be unique and can live before reversing and disassembly long time. We have rapid updates and you will not wait and waste your time. Also we have API to automate your services. Hope reasons above will help you to make right decision to work with us.


Q: Can you guarantee 100% FUD on Coff/PE? Do you provide money back in this case?
A: No, we cannot guarantee 100% FUD. Also we don't have money back system (but in any case support can add an amount to your balance by it's own opinion in case of detects). If you can use it — welcome. If you noticed a detect please contact support and tell them details and check URL; it can help to make FUD in a short time. For the projects with huge loads we have private cryptor. Please contact support for it.


Q: How can I crypt the file?
A: To encrypt a file or URL simlpy register in the system, charge your balance, select your tariff and upload a file to crypt in the user menu «Obfuscation».
Innovation is an automated service verification, which checks the file after obfuscation, provides a link to check the results of which you can agree (and get a file) or disagree (money back to your balance).
Therefore, if the job is "stuck" on the status of "Pending", you simply open the task, click on the link and make sure that you are satisfied.

Q: Do you have automation and possibility to work with API?
A: Yes, we provide API for development needs and also we have sample PHP library

Q: What's the maximum file size?
A: EXE / DLL is 160 kilobytes and other crypting services are 1 megabyte.

Q: What are your demands to Coff/PE files?
A: Files must be provided as is without packing by any Coff/PE packer like UPX, PECompact and so on.

Q: Can I obfuscate files with greater size?
A: Yes, you can. Knock support, it will answer all your questions.

Q: How scheduler works?
A: Scheduler morphs your source every time to let you get always new and fresh version. Morphing interval can be selected by customer by adding a new task to morph.


Q: What payment methods do you support?
A: Currently we support WebMoney in authomatic mode and Leberty Reserve in manual mode.


Q: I crypted the file, but not satisfied by result. What should I do?
A: You should fill the form in contacts where describe task number and your complain. We will answer in as soon as it will be possible.


Q: Did you pass the tests?
A: Yes, we did. You can ask public and private links by contacting our support.


Q: Is the service anonymous?
A: Yes, it's totally anonymous. All files are fully deleted in 30 days.


Q: What does it mean - Styx?
A: Just read wiki: http://en.wikipedia.org/wiki/Styx
The Styx (Greek: Στύξ, also meaning "hate" and "detestation") (adjectival form: Stygian, /ˈstɪdʒi.ən/) is a river in Greek mythology that formed the boundary between Earth and the Underworld (often called Hades which is also the name of this domain's ruler). It circles the Underworld nine times.

Sunday, 29 January 2012

Ann Loader

English Translation by @Sherb1n

Ann Loader Seller – Noncenz - Adv on Forums

You know our team from projects like RedZone password recovery system, MKL professional keylogger, Destination Darkness DDoS bot (aka Optima), PassView password viewer, and others. AnnLoader is a worthy addition to this collection!

[Functionality]

• You can set up tasks: X installs in country A, and so on.
• Set task priority
• Edit and re-arrange the tasks
• The build is only 14KB
• The program is written in API
• You can adjust the bot load and set up a white zone
• AnnLoad has a stable, fast, easy-to-use and safe admin panel.
• The control panel does not store your password in the config file, only in cache!
• AnnLoad algorithm does not contain anything that can mess with the encryption process (service mode, tls, etc…)

[Admin panel screenshots]












[Additional modules]

1) ThiefX. Version: 1.3. Password grabber. This module can grab passwords from 14 programs (more can be added upon request):
• Fxp (ftp)
• Total commander (ftp)
• Filezilla (ftp)
• Wsftp (ftp)
• Mozilla Firefox (включая 7-ю версию) (web, forms)
• Opera (включая последние версии) (web, forms, ftp)
• CuteFTP (ftp)
• Qip2005 (icq)
• Qip2010 (icq, eml)
• QipInfium (icq, eml)
• The bat (eml)
• RDP (rdp)
• Google Chrome (web)
• Safari (web)

2) Substitution. Version: 1.0. The module allows you to edit/substitute the hosts file on your bots.

3) We can create a module that will be modifying the Webmoney purse id in the clipboard. Contact us on ICQ if interested.

4) MKL Keylogger. Version: 1.1. Dependable keylogger, supports Cyrillic, can send logs to HTML/FTP.

[License agreement]

By accepting the license terms for this software, you acknowledge that you will use AnnLoad exclusively for testing your own systems. Any other use of this software is in violation of this agreement and of the laws of the Russian Federation. If you do not agree to one or more clauses of this agreement, do not use the software in any way or manner.
The DD team shall not be liable for any damage to you or third parties arising from the use of this software.
The product is delivered “as is”.
You may lose your license for violating the terms of this agreement or if such decision is made by the DD team.

[Payment]

•WebMoney (WMR/WMZ/WMU/WME).
•Liberty Reserve. (+ 5% of the price)
•Perfect Money.(+ 5% of the price)
•LiqPay. (+6% of the price)
•AlertPay (+6% of the price)
•YouMax (+ 7% of the price)
•Ukash (+5% of the price)
•We can work with an escrow. Escrow fees are paid by the client.
•We do not work with protection.

[Why you should buy from me]

• Fairness, friendliness, politeness.
• Honesty (I am ready to work through an escrow, but on your dime).
• I’m often online (daily, with rare exceptions).
• Personal WM passport (BL >120).
• I have been selling software for over 10 months.
• I will always try to answer all your questions, like ‘where to go for hosting’, ‘where to buy installs’, ‘who to order a script from’, etc.

[Referral program]

• Very straightforward: bring in a client, get anywhere from $45 to $100. The more clients you bring, the more $$$ you get!

[Price list]

• Minimal: Loader, no free updates - $330
• Standard: Loader, +1 month of free updates - $380
• Bronze: Loader, +3 months of free updates, plus 1 fee re-build - $480
• Silver: Loader, +6 months of free updates, plus 2 free re-builds - $530
• Gold: Loader, + free updates forever, + 5% discount on our other products, + 5 free re-builds, + module of your choice for free - $630.
• Platinum: Loader, + free updates, + 25% discount on our other products, + free re-builds, + 2 modules of your choice for free - $725.
• Diamond: Loader, + free unlimited updates, + free unlimited re-builds, + 30% discount on our other products, + all modules for free = $825.
• Updates - $35-$85 (depending on the importance of the update).
• Re-build (change of URL) - $35.
• Source code – contact us.
• New functionality – contact us.

[Modules]

• ThiefX. Password grabber - $50
• Subsitution. Hosts file substitution - $35
• MKL Keylogger - $55. This module can be purchased as a stand-alone product for $85.
• New modules request – contact us.

Saturday, 28 January 2012

Citadel Zeus bot

English Translation by @Sherb1n

- New clone of Zeus after ICE IX

Coder- Aquabox - Adv on Underground Forums

Citadel 1.1 - FF/IE/Chrome Grabber + Video Recording & Anti Tracker Protection

We’re offering a great solution for creating and updating your botnet.
We’re not trying to re-invent the wheel or come up with a revolutionary product. We have simply perfected the good old Zeus, making significant functionality improvements, adapting it to the survival conditions of today’s security landscape, and giving it a new name. Originally, we developed it for our own needs; during the development process, we also decided to create a “social circle” of support community, which is described later in this article.

Changes have been made both to the bot itself and to the web components.
We don’t sell “eye candy”. What you are paying for is the new functionality and coders’ motivation to support the product.

New features for the bot:

[+] Fixed VNC bug on Vista/Win7. Internet Explorer is now fully supported (there used to be a rendering problem in IE)

[+] Added support for Mozilla Firefox 7.0 (recent versions have had problems sending the reports; the problem is now fixed)

[+] Crypto-protection (the body is decrypted in memory)

[+] DNS-redirects (not through hosts). Any URL can now be blocked/redirected, undetectable by heuristics. For example, block AV servers or redirect bank pages to a different host.
!BONUS! The list of popular AV server URLs to clock is included.

[+] Software version is included in the report. The report will contain detailed information on the holder’s browser version. This can be used to imitate the holder’s settings.

[+] Extra layer of protection from trackers – Login Key.

[+] Authentication mechanism for config updates (no direct URLs). Adequate protection against established trackers.

[+] Grabber support for Google Chrome. (tested on latest versions 15.x/16.x)

[+] Inject support for Google Chrome. (tested on latest versions 15.x/16.x)

[+] Added function search caching, for faster hook setting in Chrome.

[+] Added feature: bot can run system CMD commands at startup (the CMDList section) and upload the report to server. For example, you can specify that upon installation your bot should upload the output of “ipconfig /all” or the list of all shared drives. This is a good feature to have when analyzing a company’s internal structure. (For example, you can often see bots with names like ACCOUNTANT_PC, POS_SERV, DATABASE…)

[+] Added mechanism to check the integrity of hooks in some Windows.

[+] Environment heuristic analyzer can use a stop-list to terminate undesirable software (significantly improves stealth), all popular AV products are included in the list.

[+] Small bugs have been fixed.

[+] Video grabber gives you a unique opportunity to see how your injects work “through the eyes of the holder”. Just specify the list of URLs and the recording time in seconds in the config file, and the bot will start recording video (in MKV format) as soon as the holder visits one of the URLs. Make sure your server can receive files of 10-60MB.

[+] Removed the “cookie clearing” feature, because it was messing up the machine’s fingerprint.

[+] Added support for HTTP 1.0 and extended headers (for example, the response doesn’t always look like “HTTP/1.1 200 OK”, sometimes it can be “HTTP/1.1 200 follow document”, where code 200 is followed by a couple of words), this is applicable to Firefox & Chrome

[+] Added gate generator (in case you want to place files on an intermediary host for redirect)

[+] All of Zeus’s basic functionality is included. I don’t think it needs to be listed here.

[+] Fully revamped, more user-friendly web-admin interface.


Figure 1. Builder, main screen



Figure 2. Web-panel, main screen



We’re not going to talk about the bot’s uptime, you’ll see it for yourself. Gratitude is accepted in the form of LR tokens.

This is the basic package. Price: $2,399.00

Important:

Our software does not work on Russian-language systems. If a Russian or Ukrainian layout is detected, the bot terminates.

This is done to prevent installs on CIS systems. You may disagree, but that’s taboo for us.

If you want to test the bot or develop your own injects – install an English-language system. We will provide URLs to download the OS image and VMWare to save you some time.

ADDITIONAL MODULES:

List of new features for web-admin panel (individual modules):

[+] Full-featured VNC control panel.
Now you can:
- Collect data on specific companies and accounts of interest into a separate DB and a separate script. It has a nice layout, you can see the list of online bots and details of the collected accounts.
- Create a VNC connection to any bot in 2 mouse clicks.
- View stats on active/dead accounts (or bots).
- Add/edit memos to the collected accounts.
- Receive automated Jabber alerts whenever a new account is added or a bot comes online. For convenience, the alert contains the IP:PORT for VNC connection.
- Sort the bots depending on their online/used/unused status.
- Specify a BotID, and have a VNC connection automatically created whenever the bot comes online.
Price: $495.00

Figure 3. VNC control panel



[+] High-quality SOCKS checker module.
You can specify several DBs of different botnets. The module uses web surfing to check the SOCKS, for a 99.9% accuracy.
Price: $49.00

[+] Executable files auto-encryption module.
Tired of manually encrypting your files or waiting for that encrypter to come back online? Automate the encryption task with this awesome auto-crypt module that will automatically refresh your botnets’ exe files. The script operates through Death’s jabber service called cbot. $15 per encryption.
We are not responsible for the encryption quality. Script is triggered through cron and can encrypt the file as many times as you need.
Price: $395.00

[+] Log parser module.
Many of you have had this problem: lots of bots generate tons of logs, and today’s DB search technologies take up way too much time. We have developed a script that can look across several DBs simultaneously and extract all http/https URLs and related data.
Additional features: caching and memos, for your convenience.
Price: $295.00

Modules can be purchased only if you also buy the basic package; they cannot be sold separately. When buying a module, you get the right to receive updates and support for this module.

CURRENTLY IN DEVELOPMENT:

[*] Advanced file search and upload. Search masks are specified in the config file. For example, “passwords*.txt”

[*] Ability to load the video-grabbing module from a remote host, to reduce the size of the build.


SERVICE & SUPPORT COMMUNITY (SOCIAL CIRCLE)

It’s hardly a secret that any product in this niche is a pile of junk on somebody’s hard drive unless it’s supported by a group of developers. As time goes on, a product must continue to satisfy the needs of the clients, but usually that’s where the problem occurs: there are lots of clients, but only one developer, and your IMs are often ignored. Time is money, that’s why we have created a social network-like platform for our clients.

Citadel CRM Store lets you influence the development of the product, namely:

- Report bugs and errors you discover in our software. All tickets are reviewed by tech support. You will receive a response in a timely manner and will not have to try to catch the developer in ICQ/Jabber.

- Every client has the right to create an unlimited number of requests and suggestions for new module/functionality. These requests can be public or private (visible to you only).

- Every client has the right to vote for ideas submitted by other members and to contribute money towards developing the module/functionality. Based on the voting results, the developers decide which module should be built.

- Every client has the right to comment on requests and talk to other members. Now you can find partners and like-minded people and take an active part in product development discussions.

- You can see all the stages of the development work if the new module is approved by the community. We provide timely updates on the status and completion date.

- If the module is approved, you can start making the initial deposits (50%). As soon as the deposits are made, developers start working on the project: the money is paid directly to the coders, and there will be no delays or procrastination. The process is transparent, every stage of the development work is displayed.

- Convenient notifications via Jabber about new comments or requests.

You will really appreciate this new approach!

When buying the basic package, you agree to make monthly maintenance payments of $125 (payments can be made for several months in advance). What’s included in this cost:

- We’re interested in working with our clients. There are lots of people who promise to “support the product, blah-blah”, but then either their updates come out once every 3 months, or the author just disappears. The problem is, authors need to be motivated. In our case – you support us, and we support you. As simple as that.

- Every month (around the 20th of the month) you get a builder update, including updated AV protection (bot body encryption, heuristic analysis prior to process injection).

- You get access to the CRM: a great opportunity to suggest new features and improvements, vote for others’ projects, and communicate with other members of the Citadel CRM Store.

- You get our support: we answer your questions (via ticketing system), provide installation assistance and usage recommendations. You are prohibited from transferring your personal CRM account to anyone else.

- In the near future, our CRM will start working with web programmers who will be focused exclusively on injects (including auto-transfers). The CRM allows our clients to create tasks, declare completion dates and prices, so that our coders can work on the approved projects. If you can write high-quality injects, let’s talk.

Figure 4. Citadel CRM Store



Demo access upon request (allow up to 24 hours).

Builder is tied to your PC; you can create unlimited number of domains.

We accept LR only. For WM-LR conversions, go to forums like mmgp.ru. We do not accept Webmoney.

To avoid wasting our time (and yours), don’t send us messages like “You there?”, etc. Just give us your request in this format: “Need to buy basic package, plus VNC, Auto-crypt, and SOCKS modules. What’s the total price with the discount?”

Citadel Zeus Bot Version 1.3


http://cyb3rsleuth.blogspot.co.uk/2012/03/citadel-13.html

Saturday, 21 January 2012

Game Hacker Shop






Online Game Account Project:

We only need large quantity online game account usa server and europe server.
First of all you need find some good game site, type key word “mmorpg” search on google,then try hack them and put trojan on site to collect player account information.

The account information we need :

For example :

Game Name : World Of Warcraft
Server : USA
Account Name : xxxxxxxxx
Account Password : xxxxxxxxx

PS: “World of Warcraft” Online account is hot now.We are buying World Of Warcraft Accounts always, unlimited quantity,If you have 10 000 accounts, we will buy 10 000 accounts.

usually we pay 100 accounts each time, and we will check if the accounts works, we will pay money in 1 hours.as more accounts you selling to us as higher price we will pay.

For each account,the price is not stable, it is around 1-2 usd for each accounts. if you got a good site, usualy you can get 1000 -10 000 accounts information.

Collect information and send to us, we will help you exchange account information to cash, as soon as possible.

In the future we will keep find some new projects which no law risk and high profit.and post them on my site.

We think if you have ability ,sure you will get rich !

Welcome be partner with us !

(All online game account we buying must be Europe Server and American Server,online Game Account from korea,china mainland ,taiwan is very cheap, only 0.3-0.5 usd around each one.
Japanese online account higher price, but not easy to sell. So USA and Europe Account will be the best.)

List of Game We buying:

USA server and Europe Server:

World of Warcraft
Star Wars: The Old Republic
RuneScape
Final Fantasy XI
RIFT: Planes of Telara
EverQuest
EverQuest 2
Eve Online
Dark Age of Camelot
Rappelz Online
Lineage 2
Aion
Dungeons & Dragons Online
Tibia
City of Heroes
Guild Wars

Other MMORPG game, if you have large quantity of accounts, please contact us, we will try to buy them all.

----------------

This project are no risk on law, Most of countries in the world they do not have a law to protect virtual wealth in game. and especially If we do this business in another country. for example, you are in russia or usa, but you take account information from Europe.There are no police will start a case for 100-1000 accounts.

So the law risk for online game account business currently is zero.

--------------------
We can help you convert online game account to cash in 1-3 days, depending on the quantity of accounts.

We are also expecting good hackers to join us for new projects.We will pay money directly to you by West Union, or WEBMONEY E-gold、Liberty Reserve.

If you are good hacker,We will be glad to work with you for longtime partnership.and we will pay higher price for longtime partners.

Fast , Safe, that is always our target for online business.

Email onlineAbusiness@gmail.com
ICQ 607157280
Gtalk onlineabusiness

Wednesday, 21 December 2011

Malware Guard

English Translation by @Sherb1n

Malware Guard - Cyber Criminals now track their enemies

Malware Guard is a netfilter/iptables module for class-based filtering of incoming/outgoing packets.

 Purpose of the product - building a database of IP addresses belonging to leading anti-cybercrime organizations. Low update prices make Malware Guard an affordable system for protecting your admin servers, kits, and domains.

Specifications for version 0.1.7

- 7,881,166 IPv4 addresses. That's 0.18% of the entire IPv4 space.
- Database compression through subnet grouping.
- Extremely fast packet checks thanks to Linux kernel patch.

Data collection methods:

- RIPE scans.
- Fake collectors for SpyEYE, IRC networks, etc.
- Info on fresh FBI honeypots from an Insider.
...other more effective methods that we will not name here.

- All buyers will be verified through PM here on the forum, people with shady reputation will be turned down.
- Reselling is forbidden.
- We do not guarantee that your domain will not be black-listed. It's very easy to get burned (content analyzers in your browsers, abuse complaints, etc.)
- We do not answer questions that are not related to Malware Guard

By purchasing a license, you agree to abide by these terms.

Price list

1 server license: $250 (while in beta)
DB update: $10

----------------------------------------------------------------------------------

Original

Malware Guard — модуль для netfilter/iptables, позволяющий фильтровать входящие/исходящие пакеты по их классификации.
Цель продукта — регулярный сбор базы данных IP адресов, организации ведущих активную борьбу с кибер-преступностью.
Демократичные цены на обновление баз данных, делают «Malware Guard» доступной системой защиты Ваших админок, связок, доменов.

Технические характеристики версии 0.1.7

7 881 166 адресов IPv4. 0.18% от общего числа.
Компрессия базы данных за счет группировки в диапазоны(subnet)
Максимально быстрая проверка пакетов, за счет патча ядра Linux'a.


Методы сбора данных

Сканирование RIPE.
Фейковые коллекторы SpyEYE, IRC-сети, etc
Получение самых актуальных ФБР honeypot'ов от Инсайдера.
... более эффективные методы, которые останутся за кадром
— Все баеры верифицируются через ПМ на форуме, людям с смутной репутацией будет отказано в продаже.
— Перепродажа запрещена.
— Сервис НЕ гарантирует чистоту Ваших доменов. Спалится можно на чем угодно(анализаторы контента в Ваших же браузерах, абузы, etc)
— Сервис не отвечает на вопросы, не связанные с Malware Guard.

Покупая лицензию, Вы соглашаетесь с данными правилами.


Прайс-лист

Лицензия на 1 сервер: $250(в рамках beta-тестирования)
Обновление базы данных: $10