AVG Blogs

Sun
Featured
News & Threats:
Have you ever chatted with a Hacker within a virus?
Posted 337 days ago by Hynek Blinka
93
 


This is an impressive and first-time experience in my anti-virus career. I chatted with a hacker while debugging a virus. Yes, it’s true. It happened when the Threat team were researching key loggers for Diablo III while many game players playing this game found their accounts stolen.  A sample is found in battle .net in Taiwan.

The hacker posted a topic titled “How to farm Izual in Inferno” (Izual is a boss in Diablo III ACT 4), and provided a link in the content which, as he said, pointed to a video demonstrating the means.

 

Below is the ‘Video’. It’s a RAR archive actually containing two executable files. These two files are almost the same except the icon.

 

The malware will connect to a remote server via TCP port 80 and download a new file packed by Themida.

 

That’s very simple Downloader/Backdoor behavior and we are only interested in looking for key logging code for Diablo III so we didn’t pay much attention to it.

But an astonishing scene staged at this time. A chatting dialog popped up with a text message:

(Translated from the image below)

Hacker: What are you doing? Why are you researching my Trojan?

Hacker: What do you want from it?

 

The dialog is not from any software installed in our virtual machine. On the contrary, it’s an integrated function of the backdoor and the message is sent from the hacker who wrote the Trojan. Amazing, isn’t it? It seems that the hacker was online and he realized that we were debugging his baby.

 

We felt interested and continued to chat with him. He was really arrogant.

(Translated from the image below)

Chicken: I didn’t know you can see my screen.

Hacker: I would like to see your face, but what a pity you don’t have a camera.

 

He is telling the truth. This backdoor has powerful functions like monitoring victim’s screen, mouse controlling, viewing process and modules, and even camera controlling.

 

We then chatted with hacker for some time, pretending that we were green hands and would like to buy some Trojan from him. But this hacker was not so foolish to tell us all the truth. He then shut down our system remotely.

Regarding this malware, no Diablo III key logging code was captured. What it really wants to steal is dial up connection’s username and password.

 

It sounds like a movie story, but it’s real. We are familiar with malware and we are fighting with them every day. But chatting with malware writers in real time doesn’t happen so often. Next time, I will be on the alert.

The malware and its components are detected by the AVG as Trojan horse BackDoor.Generic variants.

Franklin Zhao & Jason Zhou

 



 
  • http://www.facebook.com/profile.php?id=100002611191654 To No

    CZEGO ? Lecę na ryj, przepraszam.

  • Anonymous

    Virus+chatting with the creator of the virus=
    A delirium caused by fever?

    Just kidding Z&Z nice read ;)

  • http://www.facebook.com/marcinx Marcin Olszowy

    Fun story but what’s wrong with your fact checks? “A sample is found in battle .net in Taiwan, China” Please open an atlas or Google for Taiwan and maybe you’ll realize that it’s an independent republic with about 20 million inhabitants who will all be pissed off when you say they’re in China.

  • Anonymous

    One point to be made here. Unless you want a bunch of people hate you, avoid political comments (namely “Taiwan, China”) part.

  • http://twitter.com/GODJonez Joonas Lehtolahti

    I once investigated a keylogger/backdoor app distributed through Xfire instant messenger. It was advertised being aimbot for the video game Halo, but in reality it installed itself to system to be launched automatically on boot with random name, and contacted to some foreign IRC server, sending keystrokes, mouse clicks, and so on live there, also giving the hacker possibility of giving back commands to launch or shut down programs, for example. And of course to spread around, it would send links to itself through the instant messenger program, so it would seem like a friend is recommending to try the program out.

    Having found the mechanism it used to connect with the hacker, I actually used a separate IRC client to log in to the server and tried to chat with him (presumably male), but he didn’t respond to me. In the end I contacted the abuse department of the ISP owning the IP address space where the IRC server was and provided detailed description and log files on network activity what is going on there. I never got any response from the ISP, but at least reports of this malware spreading stopped quite soon after.

  • http://www.wandernauta.nl Wander Nauta

    So you were running the trojan’s code, even if you weren’t yet sure what it would do? I’m not a security expert, and obviously you are, but that doesn’t seem like a good idea to me at all…

  • http://www.facebook.com/profile.php?id=100002084425052 Sergiu Wittenberger Badau

    It happened to me while I was testing a version of SubSeven, a window popped up and some guy started chatting with me :)

  • http://twitter.com/horsebones Leke

    I’d sell my soul to the devil for those skills (pun intended).

  • http://twitter.com/PolBias Political Bias

    “Taiwan”, not “Taiwan, China”

    And the hacker was obviously from mainland China.

  • Rob Ayers

    Any chance you would share that infected code?

  • Anonymous

    lulz, he was using a modified version of flame…

  • http://twitter.com/TerrorBite TerrorBite

    Can’t say I’ve ever chatted to a hacker within a virus, but I have chatted to someone who hacked me.

    I was hanging out on IRC, as I usually do. One user, who we’ll call Fred, was pasting Python code into the chat, the purpose of which was apparently to remove a trojan from a Linux system. I less-than-politely (as was the style for that channel) asked them to paste it elsewhere, as it was spamming the channel.

    [14:10:54] Fred: pastebin that s***, gee
    [14:11:08] TerrorBite suck it

    They went silent for ten minutes, and I thought nothing of it. Then…

    [14:22:24] hey TerrorBite
    [14:23:04] hey Fred
    [14:23:13] Linux [redacted].pubip.serverbeach.com 2.6.32-22-server #36-Ubuntu SMP Thu Jun 3 20:38:33 UTC 2010 x86_64 GNU/Linux
    [14:23:14] shut up.
    [14:27:51] Wat
    [14:28:10] did you seriously just
    [14:28:34] yes.
    [14:28:35] well f***.

    He’d just hacked my server right in front of me, and that line of text was the proof. However, Fred turned out to be a grey-hat, and what followed was a quite interesting discussion during which I learned exactly how I’d been exploited and how to fix it.

    Needless to say I’m a little more paranoid now, and my server now runs OSSec, csf, custom AppArmor profiles amongst other security enhancements.

  • http://twitter.com/CosmicParrot Cosmic Parrot

    Nothing new since Sub7 …

  • http://www.facebook.com/people/Kaye-Scrue/100001966302049 Kaye Scrue

    That’s a trojan, not a virus. The difference in required skill to produce makes the distinction very important. You were talking to a 12 year old with a copy of visual basic, not a skilled bit twiddler.

  • Anonymous

    Very interesting article, thank you :)

  • http://www.facebook.com/profile.php?id=100001647322939 Alex Connolly

    This is all too common and really isn’t a new thing. I know a few hackers around the age of 15 who have their own dedicated, self-programmed software for performing tasks like this. Microphone streaming is another biggy too.

  • http://twitter.com/thomhastings Thom Hastings

    Is it possible to disclose a translation of the full conversation transcript?

  • http://twitter.com/thomhastings Thom Hastings

    Is it possible to disclose a translation of the full conversation? Just curious.

  • http://twitter.com/Trollaroid Trollaroid

    Maybe this is a good technique to bring over to the light side; have apps with built-in chat with the developers for real-time customer service.

  • Anonymous

    Now THAT, is some next level shit.

  • http://twitter.com/kieranjscott Kieran James Scott

    Wow.

    Just wow.
    This kind of stuff blows my mind, even as a web developer.

  • Anonymous

    No reason to be politically dishonest here. Taiwan is an independent country, and you shouldn’t label it as if it were a place in China (Taiwan, China). A memetic trojan embedded in a security blog post? ;-) You should be ashamed.

  • http://tonytonyjan.github.com/ Jian, Wei-Hang

    這根本在拍電影XD

  • http://twitter.com/Darestium Jordan Hodgson

    Wow :) T’is very interesting

  • Joe Mudaka

    Really interesting.

  • Ray Wang

    Taiwan is not part of China.
    This person is came from China instead of Taiwan.

  • http://blogs.avg.com Charlie Sanchez

    Thanks for all your feedback! I’ve corrected the Taiwan reference, no offence intended to anyone.

  • http://www.liquidmatrix.org/blog/2012/06/20/researcher-chats-with-hacker-within-a-virus/ Researcher Chats With Hacker Within A Virus | Liquidmatrix Security Digest

    [...] Source: Article Link [...]

  • http://arstechnica.com/security/2012/06/hacker-uses-malware-built-in-chat-to-toy-with-researchers/ Hacker uses malware built-in chat to toy with researchers | Ars Technica

    [...] III got a surprise when the hacker started chatting with them—through a feature in the malware. Franklin Zhao & Jason Zhou of antivirus company AVG were looking for keylogging code in the malware with a debugger after downloading it to a virtual [...]

  • http://covac-software.com/ Christian Sciberras

    While integrated chat is something pretty interesting, I’ve left messages to the hackers on systems they got hold of (and which I fixed after I was commissioned to).

  • http://visualrobots.wordpress.com/2012/06/20/hacker-uses-malware-built-in-chat-to-toy-with-researchers/ Hacker uses malware built-in chat to toy with researchers | vis a vis | visual mind

    [...] III got a surprise when the hacker started chatting with them—through a feature in the malware. Franklin Zhao & Jason Zhou of antivirus company AVG were looking for keylogging code in the malware with a debugger after downloading it to a virtual [...]

  • Anonymous

    Why did you execute and infect yourself with the trojan before you knew what it did?

  • Juan Fernando M

    Dial up connection’s username and password?? Really??

  • Anonymous

    I experienced something similar once, my boss who was a quadriplegic with cerebral palsy and that typed with his hat had a web design and hosting startup and I was his only employee. A hacker got on the Linux and was trying to gain control of the system, my boss saw it and tried to stop him and the hacker started chatting with him and told him to go away and leave him alone. so my boss frantically typed with his hat one key at a time and managed to outmaneuver him, he shut down the system and it worked.

  • Anonymous

    Just to provide a little background on Ray’s reasoning.

    It appears the aforementioned forum does come from Taiwan’s battle.net, administered by Blizzard Entertainment, and serves as the only official Chinese language Diablo III forum. There is currently no Diablo III forum on China’s regionalized battle.net, and I suspect many Chinese (also possibly Singaporean or Malaysian) users visit the Taiwanese site for discussion (evident by the Simplified Chinese conversation captured in the first screenshot).

    Given that Hacker posted and named its executable file in Simplified Chinese, it is more likely that Hacker is from China (or elsewhere Simplified Chinese is natively used) rather than from Taiwan, where the forum is based in.

  • http://www.yehuoji.com/archives/39731.html 中国黑客通过木马内置聊天功能和AVG研究人员聊天_互联网资讯最新报道_野火集

    [...] AVG安全研究人员与一位中国黑客通过木马内置聊天功能展开了“友好”的交流。这位黑客通过《暗黑III》游戏论坛散播恶意程序,他声称提供一个与BOSS对战的视频文件,但实际上是按键记录工具,能窃取受害者的 battle.net帐号。 [...]

  • http://xjspace.org/1451.html 黑客通过内置聊天功能和木马研究人员聊天 – Official blog for xjspace

    [...] AVG安全研究人员与一位中国黑客通过木马内置聊天功能展开了“友好”的交流。这位黑客通过《暗黑III》游戏论坛散播恶意程序,他声称提供一个与BOSS对战的视频文件,但实际上是按键记录工具,能窃取受害者的battle.net帐号。安全研究人员在研究恶意程序的关键日志代码时发生了一件不可思议的事情:一个聊天窗口突然弹出,黑客输入了中文询问“你研究我的木马干什么”,“想研究出什么来”。聊天功能整合在木马中,他接着说,“我都不知道还能看到屏幕”,“你没有摄像头,有摄像头我就能看看你长什么样了”。研究人员继续与他聊天,表示要从他手中购买木马,但黑客并不蠢,他随后远程关闭了系统。 [...]

  • http://intranet.securemymind.com/%e4%b8%ad%e5%9b%bd%e9%bb%91%e5%ae%a2%e9%80%9a%e8%bf%87%e6%9c%a8%e9%a9%ac%e5%86%85%e7%bd%ae%e8%81%8a%e5%a4%a9%e5%8a%9f%e8%83%bd%e5%92%8cavg%e7%a0%94%e7%a9%b6%e4%ba%ba%e 中国黑客通过木马内置聊天功能和AVG研究人员聊天 | 安全业界观察

    [...] AVG安全研究人员与一位中国黑客通过木马内置聊天功能展开了“友好”的交流。这位黑客通过《暗黑III》游戏论坛散播恶意程序,他声称提供一个与BOSS对战的视频文件,但实际上是按键记录工具,能窃取受害者的 battle.net帐号。 [...]

  • http://exploitarchive.com/boot-up-nokia-and-windows-8-hackers-in-the-virus-why-dont/ Boot up: Nokia and Windows 8, hackers in the virus, why don’t … | Exploit Archive

    [...] Have you ever chatted with a Hacker within a virus? AVG Hacker: What are you doing? Why are you researching my Trojan? [...]

  • http://cn.cybersharq.com/131697.html 中国黑客通过木马内置聊天功能和AVG研究人员… | 博鲨科技 跨界畅游|中国领先的网站制作、电子商务、在线交易方案提供商

    [...] AVG安全研究人员与一位中国黑客通过木马内置聊天功能展开了“友好”的交流。这位黑客通过《暗黑III》游戏论坛散播恶意程序,他声称提供一个与BOSS对战的视频文件,但实际上是按键记录工具,能窃取受害者的 battle.net帐号。 [...]

  • http://www.freebuf.com/news/4503.html 中国黑客通过木马内置聊天功能和AVG研究人员聊天- FreebuF.COM

    [...] AVG安全研究人员与一位中国黑客通过木马内置聊天功能展开了“友好”的交流这位黑客通过《暗黑III》游戏论坛散播恶意程序,他声称提供一个与BOSS对战的视频文件,但实际上是按键记录工具,能窃取受害者的 battle.net帐号。 安全研究人员在研究恶意程序的关键日志代码时发生了一件不可思议的事情:一个聊天窗口突然弹出,黑客输入了中文询问“你研究我 的木马干什么”,“想研究出什么来”。聊天功能整合在木马中,他接着说,“我都不知道还能看到屏幕”,“你没有摄像头,有摄像头我就能看看你长什么样 了”。研究人员继续与他聊天,表示要从他手中购买木马,但黑客并不蠢,他随后远程关闭了系统。 [...]

  • http://vansrealm.com/boot-up-nokia-windows-8-hackers-virus-dont-android-tablets-sell/ VAN'S REALM – TAKE CAUTION! YOU HAVE NOW ENTERED MY ZONE.

    [...] Have you ever chatted with a Hacker within a virus? >> AVG Hacker: What are you doing? Why are you researching my Trojan? [...]

  • http://www.gyvernetworks.com/TechBlog/2012/06/have-you-ever-chatted-with-a-hacker-within-a-virus/ Gyver Networks | Desktop, laptop, netbook, PC workstation hardware & software replacement & support

    [...] Source:  avg.com [...]

  • http://xlinesoft.com/ Sergey Kornilov

    Dial up connection passwords? Somebody’s playing with time machine.

  • http://diablo3.ingame.de/525933/diablo-3-hacker-verbreitet-trojaner-uber-battle-net-forum/ Diablo 3: Hacker verbreitet Trojaner über Battle.net-Forum | Diablo 3 – inDiablo.de

    [...] AVG-Blog VN:F [1.9.17_1161]Rating: 0.0/5 (0 votes cast) [...]

  • Chris DeJoseph

    so they could figure out what it does

  • Justin White

    Were you guys logging network traffic of this program? I’m assuming the second party was using some anonymizing proxies, but there had to be something outgoing to alert him the program was running on your system. Did you try to trace it at all? He was likely bouncing off zombie machines all over the place, but at least starting a trace and reporting any zombies you saw to the appropriate authorities (zombies’ ISPs for example) would’ve been nice.

  • http://twitter.com/kodemage Benjamin F. Klahn

    So they could see what it did… Duh.

  • http://nerdinaboxonline.com/2012/06/21/malware-author-taunts-security-researchers-with-built-in-chat/ Malware author taunts security researchers with built-in chat » Nerd In A Box Online

    [...] Have you ever chatted with a Hacker within a virus? (via JWZ) [...]

  • http://profile.yahoo.com/REDGCN6NVNFTCIKQV56OKOWZ64 julia

    this is not from Taiwan, they don’t use simplified Chinese.

  • http://justinkent.me/ Justin Kent

    lol, generic

  • http://twitter.com/chrishacken Chris Hacken

    Because you can’t figure out what it does until you run it. Drr

  • http://rcstar.net/2012/596/obratnaya-svyaz-c-xakerom.jsp Обратная связь c хакером « Исчадие Ада

    [...] «Звучит, как сюжет фильма, но это правда. Мы знакомы с вредоносным софтом и боремся с ним ежедневно. Однако чат с хакером в реальном времени случается не так уж часто. В следующий раз будем настороже», — написали программисты в блоге компании. [...]

  • http://arscity.ru/2012/06/22/programmisty-avg-poobshhalis-s-xakerom-po-vstroennomu-v-troyan-chatu.htm Программисты AVG пообщались с хакером по встроенному в троян чату | Виртуальный город ArsCity

    [...] не так уж часто. В следующий раз будем настороже», — написали программисты в блоге компании. Поделиться [...]

  • Thomas …

    He did it *in a virtual machine*.
    So that there’s no risk of his *physical machine* getting infected.

  • http://qualsec.ulb.ac.be/2012/06/22/have-you-ever-chatted-with-a-hacker-within-a-virus/ Have you ever chatted with a Hacker within a virus? » Quality and security of information systems

    [...] Have you ever chatted with a Hacker within a virus?. [...]

  • 子 场

    哇。牛逼~~~

  • http://technabob.com/blog/2012/06/22/chat-with-a-hacker/ Want to Chat with a Hacker? Debug His Malware

    [...] – he ended their hackroulette session by shutting down the researchers’ system. Head to the AVG blog to read the full [...]

  • http://rivaldesign.wordpress.com/2012/06/22/want-to-chat-with-a-hacker-debug-his-malware/ Want to Chat with a Hacker? Debug His Malware « Rival Design

    [...] – he ended their hackroulette session by shutting down the researchers’ system. Head to the AVG blog to read the full [...]

  • http://twitter.com/exittoshell Tim M.

    How else do you expect to learn what it is capable of without running it on a computer that is intended to get infected like a typical (dumb) user?

  • http://twitter.com/saiberfun SAI Gaming

    You guys are serious? Thats one of the most simple trojans I’ve ever seen. It’s been used on me already and I already had access to it >_>

  • Anonymous

    How else is he going to find out what it does?

  • http://neutek.net/blog/hacker-uses-malware-built-in-chat-to-toy-with-researchers/ : neutek : Hacker uses malware built-in chat to toy with researchers

    [...] III got a surprise when the hacker started chatting with them—through a feature in the malware. Franklin Zhao & Jason Zhou of antivirus company AVG were looking for keylogging code in the malware with a debugger after downloading it to a virtual [...]

  • http://taylanisikdemir.wordpress.com/2012/06/24/have-you-ever-chatted-with-a-hacker-within-a-virus/ Have you ever chatted with a Hacker within a virus? « Development Notes

    [...] http://blogs.avg.com/news-threats/chatted-hacker-virus/ Share this:ShareEmailFacebookTwitterLinkedInStumbleUponLike this:LikeBe the first to like this. Categories: Reading Links Comments (0) Trackbacks (0) Leave a comment Trackback [...]

  • http://www.blacknewbieteam.org/2012/06/25/hacker-interrupts-avgs-malware-analysis/ Hacker interrupts AVG’s malware analysis | BLACK NEWBIE TEAM

    [...] during the analysis, the Chinese hacker opened a chat window within the trojan, demanding to know what the researchers [...]

  • http://speartipllc.wordpress.com/2012/06/25/diablo-hacker-springs-reverse-engineers/ Diablo hacker springs reverse engineers « speartipllc

    [...] But during the analysis the Chinese hacker opened a chat window within the trojan, demanding to know what the researchers were doing.  Read more from SCMagazine. Share this:TwitterFacebookLike this:LikeBe the first to like this. This entry was posted on Monday, June 25th, 2012 at 9:09 pm and posted in News. You can follow any responses to this entry through the RSS 2.0 feed. Canadians Build Cyber Perimeter » [...]

  • 崇河 舒

    Can you speak Chinese?

  • http://blog.jobbole.com/22417/ 你通过病毒和黑客聊过天么? – 博客 – 伯乐在线

    [...] [本文英文原文链接:Have you ever chatted with a Hacker within a virus? ] 分享到: (function(){ var _w = 55 , _h = 16; var param = { url:location.href, type:'3', count:'1', appkey:'2606191112', title:'', pic:'', ralateUid:'1670481425', language:'zh_cn', rnd:new Date().valueOf() } var temp = []; for( var p in param ){ temp.push(p + '=' + encodeURIComponent( param[p] || '' ) ) } document.write('') })() 伯乐在线博客传播最新的职业资讯和最有价值的职业分享,欢迎订阅哦。如果您也愿意 分享一份自己的原创/译文,可以 从这里开始~ [...]

  • http://www.lanfeng.net/archives/46685.html 反病毒工作经历:中国的黑客究竟有多张狂? – 蓝枫博客

    [...] 原文:Have you ever chatted with a Hacker within a virus? 本文标签: 安全,病毒,黑客 本文链接: [...]

  • Anonymous

    Do you own really understand, right?Do you think that these very interesting?

  • Anonymous

    Do you own really understand, right?Do you think that these very interesting?

  • http://niebezpiecznik.pl/post/rozmowa-z-tworca-trojana/ » * Rozmowa z twórcą trojana — Niebezpiecznik.pl –

    [...] analizowanego przez AVG trojana przemówił, kiedy Ci podpięli jego binarkę na debugger – ciekawa historia [...]

  • http://www.blugadgets.com/2012/06/26/hacker-chattet-mit-anti-virus-experten/ Hacker chattet mit Anti-Virus Experten | BluGadgets

    [...] beiden Experten. Verrückte Geschichte, nicht wahr? Mehr Informationen zu dem Vorfall findet ihr auf dem Blog des Unternehmens. [via [...]

  • http://www.ritholtz.com/blog/2012/06/tuesday-pm-reads-11/ 10 Tuesday PM Reads | The Big Picture

    [...] (Almost) All of Us Cheat and Steal (Time) • Have you ever chatted with a Hacker within a virus? (AVG) • Go Ahead, Think It Over  [...]

  • http://profile.yahoo.com/UI4EEYVRRLSEPHRVIUYGKV3HS4 BrianR

    He uses a virtual machine infected with the trojan to investigate it.

  • http://www.facebook.com/profile.php?id=727428732 Per Edman

    Sandbox machine. It’s a necessary tool.

  • 云峰 张

    they found it in Taiwan!

  • http://www.facebook.com/lishu.li.7 Lishu Li

    actually it’s not so fantastic .all of those functions can be carried out using Windows API,we also have talked about this on a forum http://topic.csdn.net/u/20120627/09/3130cd63-d34f-4721-94b0-67d460579137.html

  • http://www.facebook.com/lishu.li.7 Lishu Li

    嗯嗯

  • b g

    能给个md5吗,谢谢了。

  • http://techarena.xtreemhost.com/?p=246 Have you ever chatted with a Hacker within a virus? | Tech Arena

    [...] http://blogs.avg.com/news-threats/chatted-hacker-virus/ This entry was posted in Tech, Uncategorized and tagged Hackers by techarena.357159.admin. Bookmark the permalink. [...]

  • http://blog.lucrativesolution.com/boot-up-nokia-and-windows-8-hackers-in-the-virus-why-dont-android-tablets-sell-and-more/ Boot up: Nokia and Windows 8, hackers in the virus, why don’t Android tablets sell?, and more – Lucrative blog

    [...] Have you ever chatted with a Hacker within a virus? >> AVG [...]

  • Anonymous

    Did you use Google Translate? Or one of you “happened” to know Chinese?

  • http://www.facebook.com/777Magnum777 Paul Helm

    I hope I never get my hands on a black hat because I will hurt whatever is below that hat!

  • http://www.facebook.com/777Magnum777 Paul Helm

    I once had a real pest program called ‘exit fuel’ I remember thinking do the advertisers on this know they are on this? Because there was no way I would have ever done bussiness with anyone even remotely connected with it! I am shocked that the isp providers cannot detect and prosecute hackers or their servers. How stupid a system it seems to me to have end-users battling with these vandals! To me it is like pumping dirty water to everyone and having them filter it themselves at the faucets! The jaded part of me thinks that the anti-virus industry might well be the hackers and are just undoing their own crafty tangles!

  • http://www.facebook.com/777Magnum777 Paul Helm

    why does my pc download avg virus updates so often and many times ‘lost connection’ This sure is annoying!

  • http://www.facebook.com/sdphoto35 Steven Davis

    I chatted with a hacker in a virus in a dream with in a log at the bottom of the sea

  • http://www.facebook.com/kyle.pippig Kyle Pippig

    Any RAT can do this, especially stock RAT creation programs allow you full control of the victim’s computer, that’s the point of Remote Administration.

  • Anonymous

    what debugger are you using? As IT support at a universtity i see some really… cool viruses, that I would like to try and understand.

  • http://avtacha.wordpress.com/2012/08/19/%d7%94%d7%90%d7%9d-%d7%a1%d7%99%d7%9f-%d7%94%d7%99%d7%90-%d7%94%d7%9e%d7%95%d7%a8%d7%99%d7%90%d7%a8%d7%98%d7%99-%d7%a9%d7%9c-%d7%94%d7%9e%d7%90%d7%94-%d7%94-21/ האם סין היא המוריארטי של המאה ה-21 « אבטחה

    [...] זיהוי תוקף. בעבר, זיהוי צבא . תוקף היה יחסית קל. בשלב מסוים הגבול השתנה ובשלב מסויים במעט ונעלם כאשר דובר באנשי חמאס וג'יהד אשר משגרים פחיות לעברנו. הבעיה הייתה חתימה נמוכה. אי יכולת לזהות את הנשק בתמונות אויריות ומכ"מים עקב גודלו. היום אנו מתמודדים עם חתימות בלתי נראות. הכוונה היא שתוקף יכול להסתיר את עצמו בקלות. אין לנו כמעט כלים או יכולות להבין את מקורו של תוקף (אפילו לרמת יבשת) ואין לנו את היכולת להעיד האם מדובר בסיני בודד מול מחשב אשר עושה את זה להנאתו האישי, האם מדובר בצוות האקרים גרמנים, בקבוצת ממשל רוסית, או בהתקפה אשר מקורה בזומבים ( מחשבים אשר משמשים ככלי העברת מידע ללא ידיעת בעליהם).  במקרים מסויימים ההאקרים גם מדברים חזרה. כך לדוגמא, היה מקרה בו חוקר אבטחת מידע ניסה לנתח וירוס על מנת שחברתו תוכל לספק הגנה מתאימה בפני הוירוס. בשלב מסויים עלה כותב הוירוס מולו בצ'אט לאחר שהתלט לו על המחשב והזהיר אותו לא לנסות לחקור את הוירוס. [...]

  • http://www.tisf.co/avtacha/2012/08/19/%d7%94%d7%90%d7%9d-%d7%a1%d7%99%d7%9f-%d7%94%d7%99%d7%90-%d7%94%d7%9e%d7%95%d7%a8%d7%99%d7%90%d7%a8%d7%98%d7%99-%d7%a9%d7%9c-%d7%94%d7%9e%d7%90%d7%94-%d7%94-21/ האם סין היא המוריארטי של המאה ה-21 | אבטחה

    [...] זיהוי תוקף. בעבר, זיהוי צבא . תוקף היה יחסית קל. בשלב מסוים הגבול השתנה ובשלב מסויים במעט ונעלם כאשר דובר באנשי חמאס וג’יהד אשר משגרים פחיות לעברנו. הבעיה הייתה חתימה נמוכה. אי יכולת לזהות את הנשק בתמונות אויריות ומכ”מים עקב גודלו. היום אנו מתמודדים עם חתימות בלתי נראות. הכוונה היא שתוקף יכול להסתיר את עצמו בקלות. אין לנו כמעט כלים או יכולות להבין את מקורו של תוקף (אפילו לרמת יבשת) ואין לנו את היכולת להעיד האם מדובר בסיני בודד מול מחשב אשר עושה את זה להנאתו האישי, האם מדובר בצוות האקרים גרמנים, בקבוצת ממשל רוסית, או בהתקפה אשר מקורה בזומבים ( מחשבים אשר משמשים ככלי העברת מידע ללא ידיעת בעליהם).  במקרים מסויימים ההאקרים גם מדברים חזרה. כך לדוגמא, היה מקרה בו חוקר אבטחת מידע ניסה לנתח וירוס על מנת שחברתו תוכל לספק הגנה מתאימה בפני הוירוס. בשלב מסויים עלה כותב הוירוס מולו בצ’אט לאחר שהשתלט לו על המחשב והזהיר אותו לא לנסות לחקור את הוירוס. [...]

  • http://cryptoarm.ru/Ya-Rabinovich-ya-vas-otkluchayu Я – Рабинович! Я Вас отключаю! | КриптоАРМ

    [...] официальный блог AVG Tweet VK.init({apiId: 2780927, onlyWidgets: true}); VK.Widgets.Like('vk_like_3635', [...]

  • http://www.facebook.com/profile.php?id=1285147634 Pamala Ann Human-Smith

    i am just as jaded!