+ All Categories
Home > Technology > nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

Date post: 06-May-2015
Category:
Upload: nu-the-open-security-community
View: 13,390 times
Download: 0 times
Share this document with a friend
Description:
No bullshit on underground crime: traces, trends, attribution, techniques and more by Fyodor Yarochkin
103
http://null.co.in/ http://nullcon.net/ NO BULLSHIT Underground crime: traces, trends, attribution, and more Fyodor Y., Grugq and a whole bunch of unnamed people :)
Transcript
Page 1: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

http://null.co.in/ http://nullcon.net/

NO BULLSHITUnderground crime: traces, trends, attribution,

and more

Fyodor Y., Grugq and a whole bunch of unnamed people :)

Page 2: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

http://null.co.in/ http://nullcon.net/

Agenda

• Overview• APT vs. Commercialized crime• Data sources• Analysis techniques• Attribution• APT, greed and more• Final words

Page 3: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

3http://null.co.in/ http://nullcon.net/

Still .. meet the “authors”.. :)Started as hobby project

We talked about thisAt c0c0n

Here you’ll see Some fresh stuff

Why?...Something we doWhen we need aGood laugh :)

Page 4: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

Чтобы заработь на Интернете не

нужноничего и даже

мозгов

“ 想要在網路賺錢 - 連腦袋也不需要用” - 網路的tutorial ;)

My favorite quote:

Page 5: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

But it is not only about money

Page 6: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

http://null.co.in/ http://nullcon.net/

Attack attribution

Page 7: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

7http://null.co.in/ http://nullcon.net/

General: $$ vs. APT

• $$ -> attacks en masse; social engineering is common; doesn’t relay on 0day; rapid outbreaks

• APT -> multi-staged; single targeted exploit; mostly “spear-phishing” or variants;

Page 8: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

8http://null.co.in/ http://nullcon.net/

A word on attribution

• Attribution is not just the malware analysis

Page 9: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

9http://null.co.in/ http://nullcon.net/

Points to note

• Binary analysis (reversing)• Exploit coding style and encoding• Infection vectors (iframing, malvert,

mass mailing etc)• Bits and pieces in binary and

deobfuscated code

Page 10: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

http://null.co.in/ http://nullcon.net/

Brief: Data sources and Tools (covered in

workshop)

Page 11: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

11

http://null.co.in/ http://nullcon.net/

Data analysis and sources• Dealing with large volume of data

(public forums, bbs, manual follow up)

• Mostly public data (reading, scrapping, post analysis etc)

• Often: post mortem analysis of compromised systems

Page 12: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

12

http://null.co.in/ http://nullcon.net/

Intelligence Gathering

• Automated and manual analysis of publicly available data

Page 13: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

13

http://null.co.in/ http://nullcon.net/

Automation: difficulties

• Language: complicated for automated processing (slang, misspellings, multiple spellings)

• Context evaluation for new items of trade requires manual analysis

Page 14: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

14

http://null.co.in/ http://nullcon.net/

Ex.: What does this say?

Page 15: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

15

http://null.co.in/ http://nullcon.net/

Good luck w/ automated translation

• After language adaption filter:

Page 16: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

16

http://null.co.in/ http://nullcon.net/

Slang sources• Fenya - Russian prison slang

• Anglonims - English loan words

• Rhyming slang - Sounds like the English word

• Direct translation

Team Cymru has a nice research on russian slang. Not repeated here

Page 17: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

17

http://null.co.in/ http://nullcon.net/

Tools of trade• Covered in workshop. So we’ll skip

that part

Page 18: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

http://null.co.in/ http://nullcon.net/

So, russian underground - mafia or geeks? :)

Page 19: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

19

http://null.co.in/ http://nullcon.net/

From russia with ...

• What is the biggest russian export besides oil, gas and nuclear scientists?? :)

Page 20: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

20

http://null.co.in/ http://nullcon.net/

-malware -Stuff that lives in your PCAgainst your will :)

Page 21: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

21

http://null.co.in/ http://nullcon.net/

Typical export sample:

• Targets MS platforms• Often - multi-component (loader,

payload functions in form of DLL etc)• Sensitive information collection (data,

keystrokes and credential information)• Turns computer into web proxy, smtp

proxy, socks etc (useful for rent, spamming etc)

• May extort money from end user

Page 22: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

22

http://null.co.in/ http://nullcon.net/

Looks familiar?

Page 23: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

23

http://null.co.in/ http://nullcon.net/

Моscow arest (31/08/2010)

Annual income: over 500,000 rubles (100,000USD)

One unlock charged at300 rubles (10USD) Via SMS

Page 24: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

24

http://null.co.in/ http://nullcon.net/

Scale: big

Page 25: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

25

http://null.co.in/ http://nullcon.net/

“export” through legitimate sites

Page 26: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

26

http://null.co.in/ http://nullcon.net/

Which end up in Google blacklist

Page 27: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

27

http://null.co.in/ http://nullcon.net/

Why such spike?

• Fun?• Profit!

Page 28: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

28

http://null.co.in/ http://nullcon.net/

But there’s much more..

malware

OTHERCOOLSTUFF:-)

Page 29: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

29

http://null.co.in/ http://nullcon.net/

That’s not a russian hax0r

Page 30: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

30

http://null.co.in/ http://nullcon.net/

This is closer..

Page 31: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

http://null.co.in/ http://nullcon.net/

Insight on underground market

:-)

Page 32: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

http://null.co.in/ http://nullcon.net/

We don’t sell or advertize any service

We simply look at the trades :-)

Disclaimer:

Page 33: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

33

http://null.co.in/ http://nullcon.net/

“We are after the money!” ;-)

• Banking credentials• Credit cards• Shops and goods• Online goods and services• Online currencies• Monetization via Carrier

providers and more

Page 34: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

34

http://null.co.in/ http://nullcon.net/

“Ликбез”

• WMZ - web money - one wmz = one USD

• Drop - money mule• CC - creditcards• Abuse resistant - Safe to host any

kind of fraudulent service • Partnerka - partnership program

Page 35: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

35

http://null.co.in/ http://nullcon.net/

Online currencies

• Web Money (WMZ)• Yandex Money• LR (liberty reserve• Epassporte (dead!)

Page 36: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

36

http://null.co.in/ http://nullcon.net/

More payment systems

Page 37: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

37

http://null.co.in/ http://nullcon.net/

Exchange points

Page 38: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

38

http://null.co.in/ http://nullcon.net/

Trading rules

Guarantee service

Page 39: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

39

http://null.co.in/ http://nullcon.net/

Service verification

Page 40: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

40

http://null.co.in/ http://nullcon.net/

blacklists

Page 41: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

41

http://null.co.in/ http://nullcon.net/

White lists

Page 42: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

42

http://null.co.in/ http://nullcon.net/

Credit cards

Very accessible

Page 43: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

43

http://null.co.in/ http://nullcon.net/

CC deals made easy

Page 44: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

44

http://null.co.in/ http://nullcon.net/

Cards, burners

Page 45: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

45

http://null.co.in/ http://nullcon.net/

And more

Page 46: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

46

http://null.co.in/ http://nullcon.net/

Bad $$ => good $$ :P

Page 47: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

47

http://null.co.in/ http://nullcon.net/

Other Online goods

Page 48: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

48

http://null.co.in/ http://nullcon.net/

Professional massinfection

<--Pricing (per 1000 installs)

<--Pricing (per 1000 installs)

Page 49: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

49

http://null.co.in/ http://nullcon.net/

ICQ - elite nums :p

Page 50: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

50

http://null.co.in/ http://nullcon.net/

Mail cracking -:)

~65USD

Price in rubles

Page 51: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

51

http://null.co.in/ http://nullcon.net/

Looks familiar?

Page 52: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

52

http://null.co.in/ http://nullcon.net/

Passport scans

4-5USD/scan avg.eu, .ru, .us, asianOne-hand salesAlso offered - scan “redraw”Special prices for bulk

52

Page 53: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

53

http://null.co.in/ http://nullcon.net/

Full package is also available

Page 54: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

54

http://null.co.in/ http://nullcon.net/

“Business package” PaIncludes..

Под средства любой загрязненности! For money of any state of dirtinessВ комплект входит: Pack includes1.Банковский акк(online доступ) Online bank account access2.АТМ картa(Дневной лимит на снятие средств 1000$/6000$ В МЕСЯЦ-Возможно увеличение лимита +30$-) ATM card (1000/6000USD per month withdrawal limit)3.Карта кодов (для online доступа) online access passwords4.Копия паспорта дропа Passport copy of “poor john”5.Sim-ka SIM card

Also can be pre-ordered on custom passport scan (25USD)

Page 55: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

55

http://null.co.in/ http://nullcon.net/

Drop:

Another way to turn dirty cash into profit

Page 56: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

56

http://null.co.in/ http://nullcon.net/

Saw the news? :)

Page 57: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

57

http://null.co.in/ http://nullcon.net/

Zeus witchunt :)

Not sure if this would change things :)

Page 58: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

58

http://null.co.in/ http://nullcon.net/

New bots - custom made

http://www.nomina.ru/search/alternatives_by_value.php?paid_till=2010-09-06&domain=rundll32.ru

Page 59: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

59

http://null.co.in/ http://nullcon.net/

Or pre-built

Why “zeus” when you can buy this?! :p

Page 60: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

60

http://null.co.in/ http://nullcon.net/

Comes with handyAdmin panel

Page 61: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

61

http://null.co.in/ http://nullcon.net/

Traf + loader = $$$$

Page 62: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

62

http://null.co.in/ http://nullcon.net/

Costs

• AU - 300-550$

• UK - 220-300$

• IT - 200-350$

• NZ - 200-250$

• ES,DE,FR - 170-250$

• US - 100-150$

• RU, UA, KZ, KG .. 10-40$

Per 1000 Unique visitors

Page 63: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

63

http://null.co.in/ http://nullcon.net/

Mass domaintheft

Page 64: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

64

http://null.co.in/ http://nullcon.net/

DDOSVery affordable

We remove sites of your concurrents with DDOS attack. Fast and effective. Supported:

Prices (in WMZ ~= USD)

Discounts for bulk

Page 65: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

65

http://null.co.in/ http://nullcon.net/

Abuse resistant hosting

Page 66: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

66

http://null.co.in/ http://nullcon.net/

Malware A/V QA

Page 67: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

67

http://null.co.in/ http://nullcon.net/

Hash crackingIn cloud

Page 68: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

68

http://null.co.in/ http://nullcon.net/

CaptchaIn cloud

Page 69: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

69

http://null.co.in/ http://nullcon.net/

Exploit packs

Page 70: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

70

http://null.co.in/ http://nullcon.net/

With nice stats

Page 71: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

71

http://null.co.in/ http://nullcon.net/

Stats per countryClicks, loads (pwned ;), percentage)

Page 72: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

72

http://null.co.in/ http://nullcon.net/

Need to build Botnet?

Page 73: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

73

http://null.co.in/ http://nullcon.net/

WelcomeTDS system

Page 74: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

74

http://null.co.in/ http://nullcon.net/

Seller

Page 75: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

75

http://null.co.in/ http://nullcon.net/

Buyer

Page 76: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

76

http://null.co.in/ http://nullcon.net/

Owner

Page 77: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

77

http://null.co.in/ http://nullcon.net/

“Game” rules :)Iframe traff. 4USD/1000 clicks No bot traf (ruclicks)

Payday - every monday

Page 78: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

78

http://null.co.in/ http://nullcon.net/

Making money together

Fake AV affiliation program

Page 79: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

79

http://null.co.in/ http://nullcon.net/

Fake AV payouts

BalanceLogin

Page 80: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

http://null.co.in/ http://nullcon.net/

Crimeware: trendsAnd research

Page 81: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

81

http://null.co.in/ http://nullcon.net/

Moving mobile• Steal a dollar from million - still a

million dollars• Trojaned handsets on sale• WAP sites spreading trojaned games

are very popular• Android trojan samples from china:

– http://www.antiy.com/cn/news/android_adrd.htm

– Geinimi

Page 82: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

82

http://null.co.in/ http://nullcon.net/

Brief on antiy rep

Page 83: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

83

http://null.co.in/ http://nullcon.net/

Spreading vector

Page 84: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

84

http://null.co.in/ http://nullcon.net/

Mobile Malware

Page 85: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

85

http://null.co.in/ http://nullcon.net/

A case study

• Available from a WAP site• X-rated version of python game• With a secret inside :)

Page 86: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

86

http://null.co.in/ http://nullcon.net/

Taking a glance

Page 87: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

87

http://null.co.in/ http://nullcon.net/

The trick!

Press the button “stop” as soon as possible!

Page 88: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

88

http://null.co.in/ http://nullcon.net/

SEO spam

<*bad* word (rus)

Page 89: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

89

http://null.co.in/ http://nullcon.net/

Now - delivered professionally :)

Page 90: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

90

http://null.co.in/ http://nullcon.net/

malwertising

Page 91: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

91

http://null.co.in/ http://nullcon.net/

Malware infectionHidden behind login screens

• Frequent in banking or other online credential targeted attacks

• Effectively prevents services like google blacklist, HA and other from identifying infections

Page 92: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

92

http://null.co.in/ http://nullcon.net/

Anti-DDOS el russo

Page 93: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

93

http://null.co.in/ http://nullcon.net/

Research

• Monetization schemes• Taking over the existing ifrastructures

for forensics analysis and statistics• Hunt the hunters

Page 94: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

Hunt the hunter• Pwnkit - automated exploitkit pwner

• Automated exploit kit fingerprinting

• Password bruteforce

• Exploiting bugs and common misconfigurations

• Generates statistics on exploit pack usage :in the wild:

Page 95: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

http://null.co.in/ http://nullcon.net/

Botnet cost estimation :)

Page 96: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

96

http://null.co.in/ http://nullcon.net/

DIY botnet ;)

• aim: build a 1000000 node networks

• No skills required• Buy these (available on sale):

– Traffic– Abuse-resistant service– Exploitpack– Botnet gear

Page 97: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

97

http://null.co.in/ http://nullcon.net/

How much it costs

• Traffic - 10-15KUSD (mixed) infection ratio around 10-20% (depending on exploit pack)

• Abuse resistant server 300USD/month• Exploitpack 200-2000USD• Botnet gear 500- 10,000USD • = 15-20,000USD total + 1-2 months

of work

Page 98: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

http://null.co.in/ http://nullcon.net/

So what’s up with russian authorities?! :)

Page 99: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

99

http://null.co.in/ http://nullcon.net/

No words ;-)

Page 100: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

100

http://null.co.in/ http://nullcon.net/

What’s next?

Page 101: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

101

http://null.co.in/ http://nullcon.net/

Get some edukation :-)

Page 102: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

102

http://null.co.in/ http://nullcon.net/

finale• Computer users ultimately trust their PC

and follow its instructions (please download XX to disinfect YY :p)

• You can be victim, even if you paid for Kaspersky and apply patches regularly :)

• While malware is what you mostly see, cybercrime is not about malware, it is about money

• Global economy - global fraud - global fun? :p

• 0day is not important. Volume is important• (Mostly) not organized crime but ecosystem

Page 103: nullcon 2011 - No bullshit on underground crime: traces, trends, attribution, techniques and more

103

http://null.co.in/ http://nullcon.net/

Thanks!Throw your questions!

[email protected] http://www.o0o.nu


Recommended