About Me

Chintan Shah

Chintan Shah
Chintan Shah is a security research lead with McAfee Labs, focused on several areas of advanced threat research, ...

Read More

Blogs

Feeds & Podcasts

Meet the Bloggers

Archive

Tags

"McAfee FOCUS 12", "McAfee FOCUS 2012", #12scams, #changedmypassword, #ChatSTC, #DigitalDivide, #eCommChat, #McAfeeFOCUS, #MerryMcAfee, #MFETrivia, #MobileMyths, #SecChat, #SecurityLegos, #SecWebinar, #SextRegret, $1 million guarantee, .pre, 0 day vulnerability, 0day vulnerability, 1-day, 3DS, 3G, 3Rs, 12 Scams of Christmas, 49ers, 99 things, 419 scam, 2011 Threats Predictions, 2012, 2012 Gartner Magic Quadrant, 2012 London Olympics, 2012 Security Predictions, 2012 Virtual Sales Kickoff, 2013, 2013 predictions, 2013 threat predictions, 2013 threats, Aaron Swartz, Abbreviation, ABC, ABC News, Abu Dhabi, Accelerated Deal Registration, access to live fraud resolution agents, Accountability, Account hacked, Account Takeover Scams, Accredited Channel Engineer, ACE, ACE certification partner, ACE Incentive Rebate, ACH, Acquisition, ActionScript, addiction, addiction to Facebook, Adobe, Adobe Flash, Adobe Reader, adult dating service, adult entertainment, adult online content, advance-fee fraud, Advanced Persistent Threat, advanced persistent threats, Advanced Threat Defense, adware, AET, affiliate marketing schemes, Aishwarya Rai videos, Aitkin Creek Primary School, Aitkin Creek Primary School Craigieburn, alephzain, Alex Merton-McCann, Alex Thurber, AllAccess, All Access, AllAcess, Amazon, American jobs, Amitabh Bachchan dies, AMTSO, Amy Chua, analysis, and Data Loss Prevention, Android, Android/BadNews, Android/BadPush, Android/Chuli, Android/Chuli.A, Android/DeaiFraud, Android/FakeToken, Android/FakeUpdates, Android/FkSite, Android/FkSite.A, Android/JobFraud, Android/NickiSpy, Android/OneClickFraud, Android/Smsilence, android antivirus, Android Bot analysis, Android Dropper, Android Exploit, Android Malware, Android Malware Analysis, Android Market, Android Mobile Malware, Android Rooting Exploit, Android security, android security app, Android slide, Android SMS broadcast, animation, anit-spam, Annual Channel Partner Satisfaction Survey, Annual Partner Survey, Anonymous, Anonymous Group, anti-malware, anti-phishing, anti-phishing phishing spam anti-spam anti-malware “identity theft” “computer security” scams firewall, anti-pshing, anti-spam, anti-spyware, anti-theft, anti-virus, anti-virus program pops up, Antievasion, antimalware, Antisec, antivirus, Antivirus software, AP, APIs, App Alert, AppContainer, Apple, Apple iOS, application blacklisting, application control, application developers, applications, application security, App Lock, AppLocker, app protection, apps, app safety, app security, app store, app stores, APSA13-02, APT, APTs, Aquisition, arrests, Arun Sabapathy, ASIC, Ask Toolbar, ASL, ASLR, ATM scams, ATM skimming, ATS, attack, attackers, attacks, augmented reality, Australia, Australian Government, authentication, AutoIt, automated clearing house, automated transaction server, automobile, automotive, Autorun, AutoRun malware, AV, AV-TEST.org, avatar, award, awards, AWE2013, AxizWorkgroup, Aylesbury, Backdoor, Backscript, Back To School, backup data, Backup Security, bad-reputation URLs, Bad Apps, BadNews Bug, balanced scorecard, bank accounts, bank fraud, banking, banking applications, banking fraud, banking trojan, banks, Barbara Coloroso, Barcelona, Barrett Brown, batchwiper, Battle Hymn of the Tiger Mother, bCyberwise, Bec Spink, behavior-based detection, behaviour, Belarus, Bernie Madoff, best practices, beyond the PC, Big Data, big security data, bill collectors call for nonpayment, Bill Rancic, binaries, binary, Bing, Bin Laden Scams, Biological Computer, biometric authentication, biometrics, Bios, Bioskit, birthday greetings, Bitcoin, bittorrent, BlackBerry, Blackhat, Black Hat, black hat hackers, Blackhole Exploit Kit, Bloomberg, blue screen, Blue Toad, Bluetooth, Bollywood, BOM, bombings, book, bootkit, Boston Marathon, bot, botnet, botnets, bots, box.com, box.net, boyfriend, boys, brain power, Brazil, BRB, breach, breakup, breakups, Brent Conran, Brent Sanders, Bring your own device, Britney Spears, broker, browser, bueno, buffer overflow, bullying, Burger King, business continuity, businesses, Business IT, byod, C&C command bot, C&C communication, C&C Server, C-SAVE program, CA, CallWindowProcA, Cameron Diaz, Canada, canada online scams, Canadian celebrities, Canalys, CanSecWest, captain of football team, car hacking, case study, Cayman Islands, CD9, CDC, celebrities, celebrity, celebrity phone hack, Celebrity video in Facebook, cell phone, cell phones, certificate authority, certification, CES, CES 2013, Chainfire, chain mails, Chameleon, Change Control, change your password day, Channel Demand Generation Kit, channel partner, Channel Partners, Channel Partner Town Hall, Channel Program, Channels Town Hall, Channelwise Awards, Charity Phishing Scams, chart, chat, chat rooms, check in, Checklist to keep teenagers safe online, child identity theft, child labour, children, children online safety, children safety online, child safety, Chile, China, Chinese, chris barton, Christian Morales, christmas, Christmas scams, christmas shopping, Christmas shopping concerns, Christmas shopping crimes, Chrome, chromebook, CIO Insomnia Project, Cisco, CISO, CISO Executive Summit, Citadel, Citrix, Civil War, class action lawsuit, classblogs, cleaning up, clickjacking, cloud, cloud-based, cloud-based collaboration, cloud application, cloud apps, cloud based application, Cloud city, Cloud computing, Cloud Expo, cloud security, Cloud Single Sign-On, Club Penguin, CMP, CNBC, CNN, code size, codes malveillants, Cofer Black, cold boot, collaboration, college students, Colombia, Command and Control, Commercial/SMB, Commercial and Enterprise Deal Registration, Communications and the Digital Economy, community service, Complete Endpoint Protection Enterprise, complex, Compliance, Comprehensive Malware Protection, Compromised Sites, computer, computer issues, computer loss, computers, computer security, computer setup, computer support, computer theft, computerworld, conference, Conficker, conférence utilisateur, Connected Home, consolidation, Consumer, consumerization, consumerization of IT, consumer mobile, consumers, Consumer Security, consumer threat alert, Consumer Threat Notices, consumer threats, Consumer Trends Report, consumer web safety, content, Content Protection, content security, Continuing Education, control, conversion rate optimization, cookies, Cool Exploit Kit, Cork, corporate data, corporate network, Corporate Responsibility, cost of losing your smartphone, counter identity theft, creating safe passwords, creating strong passwords, credit card fraud, credit card fraud and protection, credit card skimming, credit card thefts, credit fraud alerts, credit monitoring, credit monitoring and resolution, credit scores, crimeware, criminal hacking, critical infastucture, critical infrastructure, CRN, cross-device security, cross-site scripting, CSP, CTO, Culture, cupcake, currency, customer data, customer service, Cutwail, CVE-2010-3333, CVE-2012-0158, CVE-2013-0422, CVE-2013-0633, CVE-2013-0634, CVE-2013-0640, CVE-2013-0641, CVE-2013-1493, CVE 2012-1535, CVE 2012-1723, CVE 2012-1889, CVE2013-0422, Cyber, cyber addiction, cyber attack, Cyberattack, cyber attacks, cyberattacks, cyberbullying, cyber bullying, Cyberbunker, cybercasing, Cybercrime, cybercrime, cybercriminal, cybercriminals, cyber criminals, Cybercrims, cybercrooks, Cyber Defence, Cyber Defence Center, Cyber Defense Symposium 2012, cyberdéfense, Cyber Ed, cybereducation, cyber education, cyberespionage, cyber ethics, cyber fraud, Cyber Insurance, Cyber Intelligence Sharing and Protection Act of 2011, cybermom, Cyber Monday, Cyber Monday shopping, cyber mum, cybermum, Cybermum India, Cyber risks, cybersafe, cybersafety, cyber safety for women, Cyber safety tips, cyber safety tips for women; International Women’s Day;security software;, Cyber savvy mom, cyber scams, cyberscams and identity theft, cyber schemers, cyber scrooges, cybersecurity, cyber security, cyber security awareness, cybersecurity concerns, Cyber Security Mom, cybersecurity mom, cyberspace, cybersquatter, cybersquatting, cyber stalking, cyberterrorists, cyber threat, cyberthreats, cyberwar, cyber warfare, cyberwarfare, cyercrooks, DAM, dangerous searches, Darkshell, DAT 6807/6808, data, Database, database activity monitoring, database security, data breach, data breaches, Datacenter, data center, data centers, data center security, Datacenter Security, Data Center Security Channel Kit, Data Center Security Channel Kit Guide, Data Classification, data governance, data loss, Data Loss Prevention, Data Protection, Data Protection Act, Data Protection Regulation, data theft, dating, dating scams, dating site, Dave DeWalt, Dave Marcus, David Small, DDoS, Deal Registration, decade of cybercrime, deceptive online promotions, decline, dedicated security appliances, Deep Command, DeepDefender, Deep Defender, Deepika Padukone, Deep parsing, DeepSAFE, DefCon, DefCon Kids, Defender 2013, Delete Virus, Delta Goodrem, democracy, denial of service, denied credit, Denmark, DEP, Department of Broadband, Department of Commerce, department of defense, depression, detection, development, device, Device Control, devices, dewalt, DEX, Dexter, digital age, digital assets, digital assets survey, digital assets worth, Digital Certificates, Digital Deception, digital device, digital devices, Digital divide, digital gadgets, digital life, digital life protection, digital music and movie report, digital natives, digital reputation, digital retail, digital security, distributed denial of service, distributor, DLP, Dmitri Alperovitch, dmp stealing, DNS, DNSChanger, DoCoMo 110 Dialer, DOD, dog breeders, dogs, Domain Generation Algorithm, Dorgbot Skype, Dorifel, DoS, DougaLeaker, download, downloader, downloaders, doxxing, drawing cyber lines, drive-by downloads, drivers licences, drivers license, drivers license identity theft, dropbox, Dubai, dumpster diving, Duqu, e-card scams, e-gold, e-mail id, earnings, easter, Easter scam, eBay, EBC, ecards, ecard spam, eCommerce, Ecuador, Edublogs, education, educational games, educators, Eelectric Vehicle, EFF, ELAM, elcomsoft, election, Electronic Medical Records, electronic voting, email, Email & Web Security, Email & Web Security, email accounts, email content security, Email Protection, emails, email scam, email scams, email security, email spoofing, email tracking service, embedded, embedded devices, Embedded Security, embedded security solutions, EMEA, Emerging Markets, Emerging Market Security, EMM, emma watson, emma watson pictures, empathy, employee policies, employment fraud, Employment Identity Theft Scams, encoding, encrypted text file, encryption, Encryption App, end-to-end security architecture, Enda Kenny, endpoint, Endpoint Protection, Endpoint Protection Advanced, Endpoint Security, Endpoint security suite upgrade, endpoint suites, energy, Enhanced Deal Registration, ENISA, enterprise, enterprise-grade DLP, enterprise firewall, enterprise mobility, enterprise resource planning, enterprise scurity, enterprise security, envy, Envy on Facebook:A Hidden Threat to Users’ Life Satisfaction?, epayment, ePHI, epo, ePO Deep Command, ePO DeepCommand, ePolicy Orchestrator, Epsilon, epsilon security breach, ERP, ESM, espionage, etiquette, EU, European teen research, EV, evasion, Evernote, evoting, Executive Briefing Center, Executive Briefing Centre, Exif, ex partners, exploit, Exploit-CVE2013-0422, Exploit-CVE2013-0422 Analysis, Exploit-Kits, Exploit Analysis, exploitation, Exploit for Android, exploiting real brand names, Exploit Kit, exploits, Exynos, Ezzidine Al-Qassam, facebook, Facebook clean up, Facebook friends, Facebook likes, Facebook photos, Facebook safety, Facebook Scam, Facebook Security, Facebook spam, Facebook Threat, Facial recongnition, factory reset, fake-av, fake ads, fake alert, fake ant, fake anti-virus software, Fake AntiVirus, fake anti virus, Fake Anti Virus Scams, FAKEAV, FakeBank, FakeBankDropper, fake emails, Fake Identity, fake installer, FakeRean, fake security software, fake software, fake system tool programs, faketoken, fake updates, fake websites, Fake YouTube plugin, false, false news, families online, family, family identity safety, family online safety, family online safety tips, family protection, Family Safety, Farmville, Fast Start SMB Training, FBI, FBI warning, FDA, FDCC, features, federal, Federal Cybersecurity, Federal ID, Festi, fictitious identity theft, FIFA, file scanning, file sharing, filtering products, financal, Finance, Financial Fraud, financial industry, financial institutions, Financial Market Security, financial organizations, financial records, financial scams, Financial Security, Financial Services, financial software, Firefox, Firesheep, firewall, FISMA, FitBit, Fixed Function Devices, Flame, Flamer, Flash, flashback, Flash Player, Focus, Focus11, FOCUS12, FOCUS 2011, forensic, forrester, forwards, foul language, Foundstone, Fourth Quarter 2012, France, France Law, Français, fraud, fraud resolution, fraud resolution agent assistance, fraudulent, fraudulent credit card or bank charges, free, freely downloadable morphing tool, free money scam, free money scams, free offers, free WiFi spots, french, French Law, Friday Security Highlights, friends, FTC, functions calls, fuzz, fuzzing, G-J Schenk, Galaxy SIII, gambling, game of thrones, games, gaming, gaming consoles, Garter, Gartner, Gartner Security and Risk Management Summit, Gauss, Gavin Struthers, geolocation, George Kurtz, George W Bush, geotag, geotagging, Gert-Jan Schenk, GFIRST, GhostShell, gift cards and iPad promotions online, gift online shopping, gifts, gift scams, girlfriend, Giveaway, global channel partner, Global Cybersecurity, global education program, Global Payments, Global Risk 2012 report, Global SecurityAlliance Partner Summit, Global Threat Intellgence, global threat intelligence, Global unprotected rates, gmail, gold software support, good parenting, google, Google booth, google code, Google Glass, Google Play, government, government networks, governments, Gozi, GPS, grads, graduation, graphs, gratis, Great Place to Work; Best Workplaces Ireland 2013, GSM, GTI, Guardian Analytics, hack, hacked mobile phones, Hacked Sites, hacker, Hackers, hackers steal credit card numbers and sensitive personal data, hacking, Hacking Exposed, Hackitivism, Hacktivism, hacktivists, Hacktivity, halloween, Happy Families, harassment, Harbowl, hard token, Hashtag, HASHTAG as a name, HB1140, head in the sand, Healthcare, Healthcare Security, Healthy Harold, Heat Map, heidi klum, Heuristics, Hi5, highroller, HIMSS12, HIPAA, hips, Hispanic, HITECH, hoax, hoax - slayer, holiday, holiday gifts, holiday malware, Holidays, holiday scams, holiday screensavers, holiday shopping, holiday shopping fraud, holiday shopping scams, holiday snaps, holiday websites, home network issues, homework, host intrusion prevention, Host IPS, household devices, How Secure Is My Password?, how to check computer, how to keep teens safe online, how to protect, how to protect devices, how to search online, how to secure wireless connection, how to set up wi fi, how to talk to kids, how to talk to teens, HTML5, HTPPS, https, HV, Hybrid Vehicle, IaaS, IBISWorld, iCloud, ICS, IDA, IDC, idenitty theft, identify potential cyber-threats, identify spam, Identity, identity as a service, Identity CoE, identity exposure, identity fraud, identity fraud scams, Identity Management, identity protection, identity protection $1 million guarantee, identity protection alerts, identity protection fraud, identity protection surveillance, identity surveillance, identity theft, identity theft. app privacy, identity theft celebrities, identity theft expert, identity theft fraud, identity theft McAfee, identity theft protection, identity theft protection identity protection fraud, identity theft protection product, identity theft resolution, identity theft ring, identity theft risk, identity theft scams, identity theft tax scams, Identity thieves and cybercriminals, identity threat protection, IDF, IDF 2011, IDF 2012, IDK, IDS, ID theft, IE 10, iframe, IIM Bengaluru suicide case, illegal immigrants, image.exe, Image stealing, image stealing trojan, images uploaded to FTP, image theft, impersonation, in.cgi, Incident Response, Incumbency Advantage Program, indentity, India, India cybermum, Indian Celebrity video, Indian kids, Indonesia, industrial control systems, infected mobile apps, infographic, information, information collected by advertisers or social media marketing, information growth, Information leak, Information Protection, Information Security, Information Warfare, Infosec, Infrastructure, Initiative to Fight Cybercrime, in love, in lurve, innovation, innovative, insiders, Insider Threats, Instagram, integration, Integrity, Integrity Control, intel, Intel Cloud SSO, Intel Developer Forum, intellectual property, Intelligent Systems Framework, internet, Internet access, internet addiction, internet connected devices, internet enable devices, Internet evolution, Internet Explorer, Internet Explorer 10, Internet filtering, internet identity trading surveillance, Internet monitoring, Internet of Everything, Internet of Things, Internet Phishing Scams, internet privacy, Internet Safety, internet safety list for 2013, Internet Safety News, internet safety software, internet safety solution, Internet Safety Solutions, internet safety tips, internet safety tips. internet safety news, Internet scams, internet security, internet security news, internet security tips, Internet slang, internet time limits, Internet voting, Interop, in the cloud, introduction to social networking, IntruShield, intrusion detection, intrusion prevention, Intrusion prevention systems, intuitive, In vehicle Infotainment, investment scams, IoE, iOS, iOS 6.1, IoT, IP, iPad, iPad scams, iphone, Iphone 5, iphone security, IPS, IPv6, IQ, Iran, IRC bot, IRCBOT for android, IRCE 2012, Ireland, Irish Examiner, Irish Prime Minister, IronPort, IRS, IRS scams, I Series, ISF, ISP, Israel, Israeli Defense Force, IT, IT as a Service, IT market, itouch, IT Security, IT Security market, iTunes, iWatch, Japan, japan earthquake safe donation, japan earthquake scams, japan tsunami scams, jar, java, Java exploit, Java Runtime Environment, JavaScript, Java update, Java virus, Java Vulnerability, jelly bean, jihad, job applications, Joe Sexton, John Bernard Campbell, JPEG, JPEG Commands, jpg, Julia Gillard, julian Assange, July 9, Justin Coulson, KakaoTalk, kama sutra koobface, KaoSpy, Kathleen Morris, Katrina Kaif, keep family PC safe, keeping kids safe online, keep mobile smartphone safe, Kelihos, Ken Kartsen, kernel, Kernel 0day vulnerability, kernel mode, keycatchers, keyless, keyloggers, key logging, kids, kids on internet, kids on iPhone, kids online, kids online behavior, Kids online behaviour, kids online safety, kids on twitter, kids safety, king county, knowledge assets, KnowledgeBase, koobface, Korea, Kraken, kurtz, labs, language translation, laptops, Larry Ponemon, LART, Last Resort, Late Payment Scam, law, law enforcement, LCEN, leaked passwords, leaked personal information, legal, legal identifier, legal risk, Legos, Leopold Primary School, Lethic, Life Education, LilyJade, linkedin, links, Linux, Linux/Exploit:Looter Analysis, Linux and Windows, Lisa Matherly, Little Red Box, live-tweeting, live access to fraud resolution agents, Living Social, lizamoon, Lloyds, loader, location data, Location services, locked-, Lockheed Martin, locks, logging out of accounts, loggins, login details, LOIC, LOL, London, loneliness, Looter Analysis, Lori Drew, loss of gadgets, lost, lost computer, lost or stolen driver’s license credit cards debit card store cards, lost or stolen Social Security card or Social Security number, lost or stolen wallet, lost PC, lost wallet protection, lottery, love, Love Relationships and Technology, luckysploit, LulzSec, M&A, M2M, Maazben, mac, mac/OSX, Mac antivirus, mac malware, Mac OSX, Mac OS X, Mac passwords, Mac security, mac threat, Magento, Magic Quadrant, mailbox raiding, Mail fraud, mail order bride spam, make passwords secure\, Malaysia, maleware, Mali, Malicious Android Application, malicious apps, malicious code, malicious files, malicious program, Malicious QR Code, malicious sites, malicious software, malicious website, malicious websites, malware, malware analysis, Malware Experience, malware forums, malware protection, Malware research, malware samples, malware spread through chat link, malware statistics, malware stealing credentials, malware threats, malware using skype as spreading vector, malweb, managed security services, Managed Service Provider, Managed Services, Management, managing personal affairs online, Mandatory Security Hotfix, map, mapping the mal web, maps, Marc Olesen, Mariposa, Maryland, mass mailing worm, mass sql injection, master boot record, mastercard, Maturity Model, MBeanInstantiator vulnerability, MBR, mcaf.ee, McAfee, Mcafee's Who Broke the Internet, McAfee-Synovate study, McAfee Advice Center, mcafee all access, McAfee and Verizon keeping customers safe, McAfee AntiSpyware, McAfee Antivirus Plus, McAfee Application Control, McAfee Asset Manager, McAfee Channel, McAfee Channel, McAfeeChannelChief, mcafee channel chief, McAfee Channel Partner, McAfee Cloud Security Platform, McAfee Compete Endpint Protection suites, McAfee Consumer Threat Alert, McAfee Data Loss Prevention, McAfee Deep Command, McAfee Deep Defender, McAfee Digital Divide study, Mcafee DLP, McAfee Email Gateway, McAfee Email Gateway 7.0, McAfee Email Protection Suite, McAfee Email Security, McAfee EMM, McAfee Employees, McAfee Endpoint Encryption, McAfee Endpoint Suites, McAfee Enterprise Mobility Management, McAfee Enterprise Mobility Manager, McAfee Enterprise Security Manager, McAfee ePO, McAfee ePolicy Orchestrator, McAfee Exploring Digital Divide Study, McAfee Facebook page, McAfee Family Protection, McAfee Family Protection for Android, McAfee Firewall Enterprise, McAfee FOCUS, McAfee FOCUS 2011, McAfee free tool, McAfee Global Unprotected Rates Study, McAfee Identity Protection, mcafee identity theft protection, McAfee Initiative to Fight Cybercrime, McAfee Internet Security, McAfee Internet Security for Mac, mcafee internet security for mac; mcafee family protection for mac, McAfee Labs, McAfee Labs Q3 Threat Report, McAfee Labs Threats Report, McAfee LiveSafe, McAfee managed Service Provider Program, mcafee mobile, McAfee MobileSecurity, McAfee Mobile Security, McAfee MOVE, McAfee MOVE AV, McAfee Network Intrusion Prevention Systems, McAfee Network Security, Mcafee Network Security Manager, McAfee Network Security Platform, McAfee NSP, McAfee One Time Password, McAfee Partner, McAfee Partner Connected, McAfee Partner Learning Center, McAfee Partner Locator, McAfee Partner of the Year Award, McAfee Partner Portal, McAfee Partner Program, McAfee Partner Summit, McAfee Partner Summit 2012, McAfee Policy Auditor, McAfee Profitability Stack, McAfee Q1 Threat Report, McAfee Q1 Threat Report 2013, McAfee Q2 Threat report, McAfee Q3 Threat Report, McAfee Q4 2011 Threat report, McAfee Rebates, McAfee research, McAfee Rewards, McAfee Risk Advisor, McAfee Safe Eyes, McAfee Safe Eyes Mobile, McAfee SafeKey, McAfee SafeKey Password Manager, McAfeeSECURE, McAfee SECURE, mcafee secure shopping, McAfee Security, McAfee SecurityAlliance, McAfee Security Journal, McAfee Security Management, McAfee security products, McAfee Security Scanner, McAfee security software offer, McAfee Security Webinars, McAfee Site advisor, McAfee SiteAdvisor, McAfee Social Protection, McAfee Software, mcafee spamcapella, McAfee Stack Challenge, McAfee survey, McAfee TechMaster services, McAfee Technology Centre, McAfee Threat Predictions, mcafee threat report, McAfee Threats Report, McAfee Total Access for Endpoint, McAfee Total Access for Servers, mcafee total protection, McAfee Vulnerability Manager, McAfee Vulnerability Manager for Databases, mcafee wavesecure, McAfee Web Gateway, McAfee® Internet Security Suite, McCain, mCommerce, MDM, media, medical device security, medical identify theft, Medical identity theft, medical records, Medicare, memory, Menaces, Metro, Mexico, michael jackson, Microsoft, Microsoft Security Bulletin, Microsoft SQL Server database, Microsoft XML Core Services, Mid-Market, Middle East, Mike Decesare, Mike Fey, Millennium@EDU, mining, MMORPG, MMS, MMS 3.0, Mobile, mobile antivirus, mobile app, mobile applications, mobile apps, mobile banking, mobile carriers, Mobile Commerce, mobile computing, mobile cybercrime, mobile data communications, Mobile Data Protection, mobile data protocols, mobile device, Mobile Device Management, mobile devices, mobile devices and security threats, mobile device security, mobile devices issues, mobile exploit, mobile identity security, mobile malware, mobile myths, mobile passwords, mobile payments, mobile phones, mobile phone spyware, mobile PIN, mobile platform, mobile privacy, mobile protection, mobile safety, mobile safety tips, mobile security, mobile security app, Mobile Security Premium Protection, mobile security software, mobile shopping, mobile shopping threats, mobile smartphone security, mobile software platforms, mobile spam, mobiles security, mobile threats, mobile trends, mobile Wi-Fi, mobile wireless internet security concerns, Mobile World Congress, mobility, moghava.a, Moira, Moira Cronin, mom, money laundering, money orders, monitor a child’s identity, monitor credit and personal information, monitoring, Monkif, Mornings, Morphing, Moshi Monsters, most dangerous celebrities, most risky, Mother's day, mothering, mothering advice, mothering boys, mothering Internet safety, mother of boys, Mother’s day spam, movies, MS12-020, M Series, msn spaces, MSP, msvcr71.dll, multifactor authentication, multilayer security system, Multiplatform FakeAV, multiple devices, multiple social security numbers, MultiRogue, multitenancy, mum, Mummy blogger, MWC, mwc13, myAut2Exe, Mybios, my child is a bully, myspace, MySQL, mystery shoppers, mythbusters, NACACS, Narilam, national cybersecurity awareness month, National Cyber Security Awareness Week, national identification card, national institute of science and technology, National Press Club, National Security Agency, National Small Business Week, NATO, NBC News, NCCDC, NCCoE, NCSA, ndr, near field communication, negative online experiences, Netbook, netbooks, netiquette, Netmum, nettraveler, network, Network Access, Network Behavior Analysis, Network Evasions, Network IPS, Network Perimeter Security, Network Security, Network Security; Email & Web Security; Security-as-a-Service, Network Security Manager, Network Security Platform, network security server security, network threat behavior analysis, New age names, New online safety survey, news, News Feed, New teen survey, New Year, new year resolution, new year resolutions, New Year’s resolutions, New York Times, next-gen IPS, Next Generation, next generation data center, Next Generation IPS, NFC, NGFW, NGIPS, ngrbot, NickiSpy, Nigerian 419 Scam, nigerian scam, Night Dragon, NIST, Nitol, Nitro Security, NitroSecurity, NitroView, Niwa, NMU, Nobel Prize, north america, Northern Beacher Christian School, North Korea, NotCompatible, NSA, NSP, NSP 7.5, NSS Labs, NTBA, Nuclear Exploit-Kit, Nuquel, NY Times, Oak Ridge National Laboratory, Obad, obama, Obfuscation, Occupy Wall Street, OCTO, OHR, Oil & Gas, OLE, olympics, Olympic scams, OMB, one-click fraud, one-time password, OnePoll, online, Online Ads, Online Backup, online banking, online banking safely, Online Behavior, online behaviour, online bettings, online book shopping, online bookstore, online child safety, online coupon scams, online credit fraud, online danger, online dangers, online dating, online e-tailers, online ethics, online fraud, online game, online games, online game spam, online gaming, online gangs, online grocery ordering, online harassment, online holiday shopping, online marketing sites, online marketplace, online payment, online personal data protection, online predators, online reputation, online retail, online safety, online safety for kids, online safety of kids, Online safety of teens, online safety resolutions, online safety tips, Online scammers, online scams, online search, online security, online security education, online shopping, online shopping risks, online shopping scams, online shopping threats, online stores, online surfing, online threat, online threats, onlinethreats, online video, online voter registration, Open Source, operational risk, Operation Aurora, Operation High Roller, Operation Last Resort, Operation Shady RAT, OpLastResort, optimization, optimization testing, Optimized, optimize PC, Orange, organized crime, organized criminals, OS, OS/X, oscars, OTP, outages, outlook, over-achieving children, oversharing, OWASP, P2P, packed, packers, packing, PACT, PARC, parental advice, Parental control, parental controls, parental permission, parenting, parenting digital natives, parents, partner, Partner Acceleration Resource Center, Partner Care, Partner Connected, Partner Learning Connection, Partner Portal, partners, Partner Summit, PartnerTalk newsletter, passport, passports, passware, password, password complexity check, Password Day, password management, password manager, password protection, passwords, password security, password stealer, Pastebin, pat calhoun, patch, PatchGuard, Patch Tuesday, Patmos, Paul Otellini, PAW, pay-as-you-go, pay-per-install malware, paycash, Payload, payment, paypal, pay securely, PC, PC Addiction, PCI, PCI Compliance, PCI DSS, PC passwords, pc protection, PCRat, PCs, pc security, PC setup, PDF, pedro bueno, peer-to-peer file sharing networks, peer pressure, peer to peer, Peer to Peer file sharing, Pemberton, People, perception, personal data, personal identity fraud, personal identity theft, personal identity theft fraud, personal information, personal information loss, personal information over mobile phones, personal information protection, Personal information security, personal privacy, personal protection, personal tablet, Peru, peter king, pets, pet scams, pet shops, Phantom websites, PHI, phishing, phishing kits, phishing scams, phishing shareware, photo privacy, photo protection, photos, Photo sharing, Phyllis Schneck, pic.exe, pickpockets, pic sharing, piers morgan, PII, PIN, pins, Pinterest, pinterest scam, piracy, PixSteal Trojan, Playstation, Podcast, Poetry Group, Poland, Police, policies, Ponemon Institute, Ponzi scam, pooled mining, POP, Pop Tropica, pop ups, pornography, POS, POS systems, Postcode Lottery, posting inappropriate content, posting videos online, posts, PostScript, potential employers, Potentially unwanted program, POTS, power grid, power loss, Pre-detection, Pre-Installed Malware, pre-teens on FB, predictions, Premium SMS Trojan, presidential election, president obama, Primary School students, Prinimalka, Printers, privacy, Privacy Awareness Week, privacy law, privacy setting, privacy settings, Privacy settings on Google +, private data, Proactive Corporation, proactive identity protection, proactive identity surveillance, proactive security, Products, Profitability Calculator, Profitability Stack, profits, Project Blitzkrieg, promotion, protect, Protect all devices, protect devices, protect digital assets, protecting kids online, protecting photos, protecting teens, protection, protect kids online, protect teens, provide live access to fraud resolution agents, Public-Private partnerships, public policy, Public Sector, puget sound, Pune Police, pup, puppy love, puppy scams, Pushbot, push notification, PWN2OWN, pws, Q1 Threats Report, Q2 Threats Report, Q3 Threats Report, Q4, qr code, QRCode, QR codes, Quarterly Global Channels Webcast, quarterly threat report, Quervar, R&D, raj samani, Ramnit, Ransom-AAY.gen.b, ransomeware, Ransomware, rançonnage, raonsomware, Rapport, RAR, RAT, Ravens, RC4 algorithm, RC4 encryption, rdp, Real-Time for ePO, realtec, Real Time ePO, Realtime ePO, Rebecca Black, Recent Facebook Scam, Recent Facebook threat, Records phone conversations, recover files, recurring revenue, Red Exploit-Kit, redirect, Red Kit, Red October, Red Team, reference architecture, regulation, regulations, reinfect mbr, relationships, remote evoting, Renee James, replacing your smartphone, reporting, reputational risk, Rep Weiner, research, reseller, resolutions, responsibility, responsible mail, Responsible netizens, restorative justice, restore credit and personal identity, retail, retail security, return-oriented programming, reverse engineering, RFID, riches, ring tones, risk, Risk Advisor, risk and, Risk and Compliance, risk intelligence, Risk Management, risk of personal information loss, risks of online shopping, risky, risky app, risky celebrity searches, risky celebrity to search, risqué photos, Riverbed, Robert Siciliano, roberts siciliano, ROFL, rogue anti-virus software, rogue antivirus, rogue applications, Rogue Certificates, rogue security software, ROI, role playing games for kids, romance scams, Rookits, root exploit, Rooting Exploit, rootkit, RootkitRemover, Rootkits, ROP, RPM Italian, RSA, RSA 2012, RSAC, RTF, ruins, rules/guidelines for kids' cyber safety, Russia, s, SaaS, SaaS Monthly Specialization, SaaS security solutions, safe, safe email tips, Safe Eyes, safeguard, SafeKey, safe online shopping, safe password tips, Safe search, safe searching, safe search tips, safe shopping, safe shopping tips, Safe surf, safe surfing, safe transactions, safety, safety tips, SAIC, sales conversions, Salesforce.com, Samsung, Samsung Galaxy SIII, sandbox, San Jose, Santa, Saudi Arabia, Saviynt Access Manager, SCADA, scam, scammers, scams, Scam Video, SCAMwatch, SCAP, scareware, scarface, SchmooCon, school captain, school holidays, schools, SC Magazine, Scream and Shout, screensavers, sear, search, Search engine optimization, Search engine poisoning, SEC Guidance, secrecy, Secret Life of Teens, Secret Life of Teens research, Secret Lives of Teens, SecTor, Secure Boot, secure cloud computing, Secure Computing, secure container, secure data, secure devices, Secure Electronic Registration and Voting Experiment, Secure Email Gateway, secure mobile devices, secure new devices, secure passwords, secure smartphone, secure wi fi, Securing new devices, security, Security-as-a-Service, Security 101, Security and Defense Agenda, security attacks, SecurityAwareness, security awareness, Security best practice, security branding, security breach, security breaches, security conferences, Security Connected, Security Connected Reference Architecture, Security Education, security fence, Security Influence, security information and event management, Security Innovation Alliance, security landscape, security management, security metrics, security optimization, security partner, security policy, security policy enforcement, security protocols, Security Seals, security software, Security Summit, security threats, security trends, self-defence, selfie, selling like, sensitive data, sensitive documents, sensitive information, Sentrigo acquisition, SEO, seo abuse, SEPA, SERVE, server, services, settings, sexting, Shady RAT, SharePoint, sharing photos, sharing pictures, shellcode, Shop.org, shopping scams, shortened URLs, short url, shoulder surfing, SIA, SIA Partners, SIEM, signature-based detection, signed drivers, Silent Circle, Silent Text, simple safety tips, site advisor, SiteAdvisor, siteadvisor research, Sitting On Top Of The World, Situational Awareness, Skype, skype.exe, Skype malware, SkyWiper, Skywyper, SlowLoris, Small busines, Small Business, Smart Grid, Smart Perimeter, smartphone, smart phone, smartphones, smartphone safety, smartphone secuity, smartphone security, smart phone threats, SmartScreen, SMB, SMB Advisor Tool, SMB Deal Registration, SMB Extravaganza, SMBs, SMB security, SMB Specialization, smishing, sms, SMS Lingo, sniffing tools, SNS Addiction, social business, social comparison, social connections, social engineering, Social Engineering tricks by malware, social media, social media cleanup, social media in the classroom, social media online scams, social media passwords, social media scams, social media threats, social network, social networking, social networking best practices, social networking scams, social networking sites, social networking sites security, social networks, social responsibility, Social Security, Social Security Card, social security number, Social Security number fraud, social security number theft, Social Security number thefts, social skills, Sofia Vergara, soft token, software, Software-as-a-Service, software installation, solid state drive, SoLoMo, Solution, Sony, Sophos, South Africa, South Korea, spam, Spamhaus, spam mail, Spams, spear, Spearphishing, Spellstar, spoof, sport, SpyEye, Spyware, sql attacks, SQL Injection, SSN fraud, Ssucl, st. patricks day, Stack Challenge, stack pivoting, stamper.a, State of Security, stay safe from phishing, stay safe online, stay safe tips, Stealth, stealth attack, stealth crimeware, stealth detection, stealthy attack, steganography, Stephen Conroy, Steve Jobs, Stinger, stolen cards, stolen computer, stolen email addresses, stolen mail, stolen medical card, stolen passwords, stolen PC, stolen Social Security number thefts, Stonesoft, Stonesoft Aquisition, Stop.Think.Connect, storage, stored, Stratum, strong password, student loan applications, Stuxnet, subscription, substation, Suites, summer activities, summer games, Summer holidays, Summer Olympics, summer vacation, Superbowl, Support, Support Notification Service, support services, surfing, survey, survive reboot, suspicious, suspicious messages, suspicious URLs, Swartz, swine flu, Symbian, symbols, Sype, System Progressive Protection, sécurité informatique, T-Mobile, tablet computers, tablets, tablet security, tag, TAGITM, Tags: Cybermum, targeted attack, targeted attacks, taxes, tax filing tips, taxpayer warning, Tax Preparer Scams, tax returns, tax scams, tax season reminder, TCO, teacher abuse over the internet, Teaming Plan, Tech Data, tech gifts, technical support, technology, technology development, technology trends, Tech Savvy Teenagers, tech services, tech support, TED, teenage, teen behavior, teen cyclones, teen hate video, teen love, Teen Online Research, teens, teens and porn, teens online, teens online dating, teens online safety, Teens on social networking sites, teens posting video, Telecommunications, terrorism, Testing, Tetris, Texas fertilizer plant explosion, text message, text messaging, Thailand, The Age of Cyber Warfare, The Bullied and The Bystander, The Bully, The Economist, the European Network and Information Security Agency, The Profitability Stack, The Secret Life of Teens, The Stack, The Tallinn Manual on the International Law Applicable to Cyber Warfare, The Use of the Internet for Terrorist Purposes, The VARGuy, threat, threat intelligence, threat predictions, threat reduction, threat report, Threats, threats on women's day, Threats Predictictions, thumb drive, thurber, Tiered Pricing, Tiger mother, time limits, Tips, tips and tricks, Tips for a secured password, Tips for Consumers, tips to mobile security, tips to stay safe online, TITUS, TJX, TMI, Todd Gebhart, tools, toothbrushes, Top 25 Companies to Partner With, Total Access, Total Access for Business, Total Access for Business Promotion, total disconnection, Total Protection for Enterprise, Total Protrection 2012, TPM, tracking usage, traffic manager, transfer data, translator, travel, travel related online scams, travel risk, travel scams, travel security, Travnet, trending topics, trends, Trevi, trojan, trojan banker, trojans, troubleshoot PC, Trust and Safety, Trusted Computing Module, trustedsource, trusted websites and web merchants, Trusteer, trustmark, Trustmark Security, TSA, TSB and STP, Tulane, Tumblr, Turkey, tweens, Tweens Teens and Technology, tweet, Tweets, twitter, Twitter celebrities, Twitter chat, Twitter online security, Twitter Spam, twitter spam; phishing; twitter scam, two-factor authentication, type in website address incorrectly, types of phishing, typing in incorrect URLs, typos, typosquatting, U.S. Cyber Challenge Camps, U.S. Economy, UAE, ukash, Ultrabook, Ultrabooks, Ultrabook security, unauthorized credit card transactions, uncategorized, Underground Economies, uninitialized local variable, unique password, United Arab Emirates, United Nations High Commissioner for Refugees, Unix, unlimited technical support, unpacking, unprotected PCs, unsecured unprotected wireless, unsecured unprotected wireless security risks, unsecured wireless, Unsecure websites, unsubscribe, untag, update computer, UPS scam, UPS scams, UPX, urchin.js, URL hijacking, URL shortening services, USB drives, US Department of Defense, use after free, use of cookies advertising personal security, use of Social Security number (SSN) as national ID, user identification, user mode, US passport, USSC, USSD, UTF-8, UTM, vacations, Valentine's Day, valentine scams, valentines day scams; romance scams; email spam, valentines day scams; romance scams; valentine threats, ValidEdge, ValidEdge sandboxing, value-add, Vanity Fair, VB6, vbs, Vericept DLP, verify website's legitimacy, Verizon DBIR, Verizon Mobile Security with Total Equipment Protection, ViaForensics, video game, Video of Nayanthara and Simbu, video shot of infosys girl, vinoo thomas, violent video games, virtual arguments, Virtualization, VIrtual Machines, Virtual Sales Kickoff 2012, Virtual Sales Kickoff 2013, virus, Viruses, Virus protection, virusscan, VirusScan Enterprise with ePO 8.8, VirusTotal, visa, vista, Vista Defender 2013, Visual Basic 6, VMworld 2011, Vontu DLP, VorVzakone, voter registration, voting, vPro, vSkimmer, vulnerabilities, vulnerability, vulnerability management, Vulnerability Manager, vulnerability manager for databases, W32/XDocCrypt.a, waledac, Wall Street Journal, Walmart, WAN, Washington D.C., water facility, water pumps hacked, water treatment facilities hacked, wave secure, wearables, wearable technology, web, Web 2.0, Webcast, web filtering, web gateway, Webinar, web mobs, web protection, web searches, web security, Websense DSS, Web services, web sites, website security, web threats, welfare fraud, wells fargo, Westfield, Westinghouse, what to do if your child is a bully, what to do when your wallet is lost missing or stolen, white hat hackers, whitelist, Whitelisting, Wi-Fi, Wi-Fi WEP WAP protection breach, wifi, Wii, wikileaks, will.I.am, Win7 Defender 2013, Win 8, window, windows, Windows 7, Windows 8, Windows 8 Metro, Windows Credential, Windows Defender, windows malware, Windows Mobile, Windows Runtime, Windows Server 2012, Windows Store, Wind River, WinRT, winsh, wiring money, Women’s Day, word cloud, work with victim restore identity, World Cup, world of warcraft, worm, Worm/Autorun, worm:Win32/Nuquel, Worms, wrong transaction scam emails, www.counteridentitytheft.com, Xbox, XDA-Developers, XDocCrypt, Xerox, XFA, xirtem, xmas, XPDefender 2013, xss, XtremeRAT, Yahoo!, Yahoo password hacked, yousendit, youth, youtube, You Tube, You Tube Channel, Youtube Scam, you tube videos, Zbot, Zero-Day, Zero-Day Attack, ZeroAccess, zero padding, zeus, ZIP, zombie, zombie computers, zombies, • Facebook etiquette, • Most dangerous celebrity, • Parental control

Evolving DDoS Botnets: 1. BlackEnergy

Monday, February 28, 2011 at 5:55am by
Chintan Shah

BlackEnergy was a very popular DDoS bot a couple of years back. This bot has been under development and has evolved quite a bit over toward its more current successor, the Darkness bot. This Bot has evolved with new features continuously added to extend its malicious capabilities. Researchers have been keeping an eye on it and current analysis of the Command and Control(C&C) traffic its bot existing in the wild have revealed that this bot could be the product of the Russian cybercrime market. Traces indicating the same production have been found within the bot executables as well.

This bot comes with a variety of DoSing capabilities and has been observed targeting Russian websites. Recently, during our investigation, we managed to get access to the BlackEnergy builder toolkit, which unlike previous available builder versions, comes with the option of building polymorphic binaries to bypass AV detections and also includes anti-debugging features. The toolkit comes with web functionality which includes PHP scripts for controlling the Bot and other details such as MySQL database schemas.

The first post in this series provides a detailed analysis of the BlackEnergy bot builder toolkit. We will also examine the server side PHP scripts to understand the bot command and control channel. Additionally we will also analyze the DDoS traffic generated by the bot. Next part of this series will shed some light over the recently emerging Darkness bot which is believed to be related to BlackEnergy and has overshadowed BlackEnergy in terms of its DoSing capabilities.

BlackEnergy DDoS Bot builder :

builder

The above screenshot is of the builder toolkit used to build the bot client which is then usually distributed through drive-by downloads or through Spam emails.

Below are all the default parameters used to build the bot client and as such most of the parameters are self explanatory.

Host: C&C Server communicating with the bot client.

Request Rate: Specifies the time interval after which new command should be fetched from the C&C server.

Build ID: Unique Build ID for each bot. This will change every time the builder tool kit  is invoked.

Default Command: Command to execute if bot client cannot connect to the C&C server.

Execute after: Time after which command should be executed.

Outfile : Final bot client executable name.

Default DDoS parameters:

ICMP Freq: No. of ICMP packets to send in the attack.

ICMP Size: Size of the ICMP packets in the attack.

Syn Freq: No. of SYN packets to send in SYN flood attack.

HTTP Freq: No. of HTTP Request to send in the HTTP flood attack.

HTTP Threads: No. of HTTP threads to create during the attack.

TCP /UDP Freq: No. of TCP/UDP packets to send during TCP/UDP flood attack.

TCP Size: Size of the TCP payload.

UDP Size: Size of the UDP payload.

Spoof IP’s: Boolean value to enable or disable IP Spoofing during the flooding.

Use Crypt traffic: May be used for encrypting the bot client communication.

Use polimorph exe: Inserts different encryption routines to bypass AV detection.

and antidebug

After specifying all the configuration options, clicking the “Build” button will output the bot client which is then distributed through various means.

Server Side Botnet Command and Control System :

The toolkit comes with the C&C server side PHP scripts which interacts with the MYSQL database at the backend to track the bot infections. We’ve observed the following files in the toolkit.

Auth.php                   MySQL.php

Config.php                Stat.php

Index.php                 db.sql

MySQL.php               Readme.txt

The C&C system comes with the basic HTTP password authentication scheme. Auth.php presents the Login/Password screen from where the Botnet can be further controlled by the Bot Master.

Auth

Admin and MySQL Login details are saved in the config.php file as below.

<?

// íàñòðîéêè áàçû

$opt['mysql_host'] = “localhost”;

$opt['mysql_user'] = “b0t2″;

$opt['mysql_pass'] = “2413038″;

$opt['mysql_base'] = “b0t2″;

// ëîãèí è ïàññ ê àäìèíêå

$opt['admin_pass']  = “admin”;

$opt['admin_login'] = “132″;

?>

Bot C&C system has a pretty simple database schema with the SQL queries in the db.sql file. Following is an excerpt  from that file.

– Table structure for table `opt`

CREATE TABLE `opt` (

`name` varchar(255) NOT NULL,

`value` varchar(255) NOT NULL,

PRIMARY KEY  (`name`)

);

Following are its default values which are displayed on the UI when index.php is accessed.

– Dumping data for table `opt`

INSERT INTO `opt` (`name`, `value`) VALUES (‘attack_mode’, ’0′),

(‘cmd’, ‘wait’),

(‘http_freq’, ’100′),

(‘http_threads’, ’3′),

(‘icmp_freq’, ’10′),

(‘icmp_size’, ’2000′),

(‘max_sessions’, ’30′),

(‘spoof_ip’, ’0′),

(‘syn_freq’, ’10′),

(‘tcpudp_freq’, ’20′),

(‘tcp_size’, ’2000′),

(‘udp_size’, ’1000′),

(‘ufreq’, ’1′);

db.sql also has an important table structure, “stat,” used for tracking the size of the botnet. All the data that is POSTed by the bot client is logged in this table along with the Build ID which is sent back by the bot client to the C&C system.

– Table structure for table `stat`

CREATE TABLE `stat` (

`id` varchar(50) NOT NULL,

`addr` varchar(16) NOT NULL,

`time` int(11) NOT NULL,

`build` varchar(255) NOT NULL,

PRIMARY KEY  (`id`)

);

Index.php is the script that connects to the SQL database and fetches the statistics which are displayed on the GUI. Here are a few of the SQL queries we found in this file:

Architecture of the Botnet:

We studied the Command and Control system of this bot and figured out how the scripts interact internally. Below is how the server side system interact with other modules that keep track of the infections.

displaystats

Botnet Commands

We have reverse-engineered C&C code on the bot client and have identified that it comes with three major type of commands. Arguments to these commands are also documented in the Readme.txt and cmdhelp.html files accompanying this package in the Russian language. During our analysis of the bot client binary we’ve also found the 4th command which is not documented in the help files. Let’s understand each of the commands.

A )  flood:-

The “Flood” command instructs the bot client to initiate several different types of flooding attacks. Arguments to this command instructs the bot about the type of flood attack to generate along with the other parameters as shown earlier Figure 1. Arguments to the type of flooding attacks can be following:

-      ICMP

-      UDP

-      SYN

-      HTTP

-      Data

The Flood command along with the arguments and other parameters are sent by the server to the bot client in Base-64 encoded format. Below is an example of the decoded command indicating how the bot client is instructed to carry out a TCP SYN flood on port 80:

4500;2000;100;1;0;30;500;500;200;1000;2000#flood syn mail.ru 80 #10#xEN-XPSP1_80D1F15C

B )  stop:-

Stop command instructs the bot client to temporarily stop DDoS floods.

command1

C )  die:-

Die command instructs the bot client to delete itself from the infected system. It calls the ExitProcess API to terminate the process and stop all DDoS activities

D ) open:-

This is the undocumented command. The binary analysis bot client shows that this command may be used to download other executable files or possibly to update the bot executable itself.

E )  wait:-

This command instructs the bot client to remain silent without performing any activity and contact the C&C server for new commands after the specified interval. Format of this command is as shown below:

4500;2000;100;1;0;30;500;500;200;1000;2000#wait#10#xEN-XPSP1_80D1F15C

This instructs the bot client to wait for 10 minutes before checking for new commands . This is exactly what can be figured out from the screenshot below.

wait

Network Communications:

The BlackEnergy Bot client uses HTTP protocol to communicate with the C&Cserver. It uses HTTP POST request to stat.php page. POST request data is then logged into the “stat” table in the database primarily used for tracking the bots. The information sent by the bot-client in the HTTP POST request message includes the ID and the build ID.

The ID parameter is a combination of the SMB hostname and the C:\ volume information of the infected machine. The code section below shows how the ID parameter is built.

build_code

Build_ID is the parameter which is randomly generated by the bot builder and is used to track the botnet infections.  In response, the C&C server replies with the Base-64 encoded command as shown below:

traffic

The decoded command shows the following:

4500;2000;100;1;0;30;500;500;200;1000;2000#wait#10#xEN-XPSP1_80D1F15C.

This shows the extent up to which the DDoS parameters are configurable in this bot. All the parameters are present even in the #wait# command. Likewise, a variety of different DoS commands can be given by C&C sever, a few of which are listed below:

# flood syn www.abc.com 25#10#

# flood http www.xyz.com#20#

# flood udp;dns;syn;1.1.1.1#10#

# flood icmp 1.1.1.1#5#

A very significant finding of our analysis has shown that the toolkit that is used to build the bot client executable is actually backdoored. On execution of the toolkit, it opens a random port on the builder’s system in listening mode. Also, it has been found to be sending significant system information to remote servers. Below is the snapshot of Base-64 encoded traffic that we captured when the toolkit was launched for the building of a bot.

backdoored

Decoding the above traffic shows the info that was being sent by this toolkit to the author of the toolkit.

b64_decoded

The toolkit is also found to send the following system information. Clearly there is no honor among thieves!

sysinfo

McAfee IPS coverage for BlackEnergy

McAfee Intrusion Prevention (formerly IntruShield) has released coverage for the BlackEnergy bot under the attack ID 0x48804c00 BOT: BlackEnergy Bot Traffic Detected. McAfee customers with up-to-date installations are protected against this malware.

In the next part of this series, we will take a closer look at the recent DDoS attack power of the Darkness bot.

Tags: , , , , , , , ,

Submit your own comments / message for this post

Your email is never published nor shared. Required fields are marked *

 

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

Comments (0)