|
|
Malware authors have always been coming up with new and improved ways to control compromised machines. Remote-access Trojans have been in use for a long time. One of the most infamous is Back Orifice.
With the prevalence of DIYÂ kits, every kid on the block has the ability to invade other people’s computers at whim. But what has changed over the course of time is the ease of use of these kits along with the advancement in stealth technologies. SharK is one such remote-access Trojan kit that allows the attacker to customize the Trojan with loads of features available within the toolkit.

Fig 1: SharK2 Server configuration options.
In a nutshell, the server created using the kit can be typically configured to do the following:
One of the unique characteristics of this kit is its ability to identify sandboxes. Even though anti-sandboxing techniques were discussed widely, this kit would probably be one of the few to implement this feature. Clubbed with this are anti-debugging and VMware detection techniques that could make the process of analyzing this Trojan a little difficult.

Fig 2: Web Downloader Component
Once infected, the victim would connect back to the specified address and port.

Fig 3: Interactive process blacklist
The kit is also constantly updated to introduce new features. With the alleged leaked source code up for sale in various forums, more versions are likely to emerge. Having a look at our samples collection was enough to establish that malicious people have already started capitalizing on this toolkit.
We at McAfee Avert Labs are on the lookout for new threats as always and we detect the configurator as BackDoor-DKG.cfg and the server is detected as BackDoor-DKG with the current DATS.
|
|
“You are presenting us here like we are some kinds of terrorists.”
…nop,in a lot of ways,you’re way worse than them:
because “terrorists” are at least motivated by an ideology.
You just spread malware around the net,
in order to gain your personal 15 minutes of fame.
Get a life…the sooner the better:
before you earn yourselves a ticket to jail.
“You should also mention that the shark coders are 17 and 14 years old.”
The majority of users of this so-called “product” are around that age,
at least that’s what’s revealed from Chasenet’s script-kiddie forum.
Shark,Bifrost and all the rest of servers and crypters,
with supposedly “FUD” private versions for sale:
a disgusting form of underground commerce,
based on exploiting human stupidity of bored teenagers…
and by avoiding paying taxes
You are presenting us here like we are some kinds of terrorists.
Detecting a sandbox is pretty easy today, maybe this could be a little knock-knock to the coders of that kind of software.
“With the alleged leaked source code up for sale in various forums”
and that’s a fake.
greetz,
sharK coder.
PS: You should also mention that the shark coders are 17 and 14 years old.
Submit your own comments / message for this post