About Me

Rahul Mohandas

Rahul Mohandas

Read More

Feeds & Podcasts

Blogs

Meet the Bloggers

Archive

Tags

#SecChat $1 million guarantee 12 Scams of Christmas access to live fraud resolution agents Acquisition Alex Thurber Android antivirus Apple botnet Channel Partners cloud security Compliance Consumer counter identity theft credit card fraud and protection credit fraud alerts credit monitoring credit monitoring and resolution critical infrastructure Cyber Security Mom cyberbullying Cybercrime cybermom data breach data center data center security Data Protection Dave DeWalt DLP Email & Web Security embedded encryption Endpoint Protection enterprise facebook fake anti-virus software Family Safety Friday Security Highlights global threat intelligence google government Hacktivism how to talk to kids how to talk to teens identity fraud identity fraud scams identity protection identity protection $1 million guarantee identity protection fraud identity protection surveillance identity surveillance identity theft identity theft expert identity theft fraud identity theft protection identity theft protection product Identity thieves and cybercriminals intel iphone kids online behavior lost wallet protection malware McAfee McAfee Channel McAfee Family Protection McAfee Identity Protection McAfee Initiative to Fight Cybercrime McAfee Labs McAfee security products Mid-Market Mobile mobile malware mobile security monitor credit and personal information Network Security online personal data protection online safety Operation Aurora PCI personal identity theft fraud personal information loss personal information protection phishing privacy proactive identity protection proactive identity surveillance Public Sector restore credit and personal identity Risk and Compliance scam scams scareware security smartphones social media social networking social networks spam Stuxnet twitter vulnerability Web 2.0 work with victim restore identity

SharK2: Trojan Creation Made Easy!

Tuesday, August 21, 2007 at 10:00am by Rahul Mohandas
Rahul Mohandas

Malware authors have always been coming up with new and improved ways to control compromised machines. Remote-access Trojans have been in use for a long time. One of the most infamous is Back Orifice.

With the prevalence of DIY kits, every kid on the block has the ability to invade other people’s computers at whim. But what has changed over the course of time is the ease of use of these kits along with the advancement in stealth technologies. SharK is one such remote-access Trojan kit that allows the attacker to customize the Trojan with loads of features available within the toolkit.

Server

Fig 1: SharK2 Server configuration options.

In a nutshell, the server created using the kit can be typically configured to do the following:

  • Load the Trojan at every startup using ActiveX keys specified in the registry.
  • Social-engineer the victim to believe he has opened a genuine executable, like notepad.
  • Ability to bind with other genuine files.
  • Capable of acting like a retrovirus disabling antivirus softwares. The kit also gives users the option to blacklist and cripple various security and analysis tools on the victim machine.
  • Also have stealth options like melting the server on execution, modifying file attributes, modifying file creation time of the server, or opening the ports only when there is an Internet connection.
  • Encrypts the header and uses its own stub.

One of the unique characteristics of this kit is its ability to identify sandboxes. Even though anti-sandboxing techniques were discussed widely, this kit would probably be one of the few to implement this feature. Clubbed with this are anti-debugging and VMware detection techniques that could make the process of analyzing this Trojan a little difficult.

Client

Fig 2: Web Downloader Component

Once infected, the victim would connect back to the specified address and port.

  • Like many Trojans, SharK uses the RC4 cipher to encrypt the traffic.
  • Keylogger works with WH_KEYBOARD_LL hooks.
  • Interactive DOS-Shell
  • Manipulate running processes, windows, and services from the remote console.
  • Interactive Process blacklisting, which alerts the attacker if the blacklisted process is found on the victim machine and prompts the attacker to take action (see Fig 3).
  • Code injection into a hidden Internet Explorer window in an attempt to bypass firewalls.
  • Uses Web Downloader to download and execute files on the victim machine (see Fig 2).
  • Attacker could redirect victims to various phishing Web sites.

blacklist

Fig 3: Interactive process blacklist

The kit is also constantly updated to introduce new features. With the alleged leaked source code up for sale in various forums, more versions are likely to emerge. Having a look at our samples collection was enough to establish that malicious people have already started capitalizing on this toolkit.

We at McAfee Avert Labs are on the lookout for new threats as always and we detect the configurator as BackDoor-DKG.cfg and the server is detected as BackDoor-DKG with the current DATS.

Bookmark and Share

Submit your own comments / message for this post

Your email is never published nor shared. Required fields are marked *

 

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

Comments (2)

  • xrt-27 August 27, 2007 11:44AM

    “You are presenting us here like we are some kinds of terrorists.”

    …nop,in a lot of ways,you’re way worse than them:
    because “terrorists” are at least motivated by an ideology.
    You just spread malware around the net,
    in order to gain your personal 15 minutes of fame.
    Get a life…the sooner the better:
    before you earn yourselves a ticket to jail.

    “You should also mention that the shark coders are 17 and 14 years old.”
    The majority of users of this so-called “product” are around that age,
    at least that’s what’s revealed from Chasenet’s script-kiddie forum.
    Shark,Bifrost and all the rest of servers and crypters,
    with supposedly “FUD” private versions for sale:
    a disgusting form of underground commerce,
    based on exploiting human stupidity of bored teenagers…
    and by avoiding paying taxes ;-)

  • sNiper209 August 24, 2007 11:13AM

    You are presenting us here like we are some kinds of terrorists.

    Detecting a sandbox is pretty easy today, maybe this could be a little knock-knock to the coders of that kind of software.

    “With the alleged leaked source code up for sale in various forums”

    and that’s a fake.

    greetz,

    sharK coder.

    PS: You should also mention that the shark coders are 17 and 14 years old.