Nytro Posted June 28, 2013 Report Posted June 28, 2013 [h=3]Infiltrating malware servers without doing anything[/h]Today i was searching more samples of BlackPOS because this malware use FTP protocol.And knowing this, i was interested to crawl more panels but then i realised something...Why did i look only for BlackPOS, instead of targeting everything ?So i downloaded a random malware pack found on internet and send everything to Cuckoo.After i've just parsed each of these generated pcaps to get some stuff (simple but effective)Everything automated of course, it's too enormous to do that manually, especially on malware pack. Cuckoo. pcap junkie.Here is a small part:ftp://u479622:y6yf2023@212.46.196.140 - Win32/Ustealftp://4bf3-cheats:hydsaww56785678@193.109.247.80 - Win32/Ustealftp://u445497390:090171qq@31.170.164.56 - Win32/Ustealftp://raprap8:9Y7cGxOW@89.108.68.81 - Win32/Ustealftp://u195253707:1997qwerty@31.170.165.230 - Win32/Ustealftp://pronzo_615:f4690x0nq8@91.223.216.18 - Win32/Ustealftp://lordben8:xCoMFM2c@89.108.68.89 - Win32/Ustealftp://u698037800:denisok1177@31.170.165.251 - Win32/Ustealftp://u268995895:vovamolkov123@31.170.165.187 - Win32/Ustealftp://b12_8082975:951753zx@209.190.85.253 - Win32/Ganelp.gen!Aftp://oiadoce:cremado33@187.17.122.141 - Win32/Delf.Pftp://cotuno:nokia400@198.23.57.29 - Win32/SecurityXploded.Aftp://fake01:13758@81.177.6.51 - WS.Reputation.1ftp://h51694:2222559@91.227.16.13 - Win32/Ustealftp://fintzet5@mail.ru:856cc58e698f@93.189.41.96 - Win32/Ustealftp://b12_8082975:951753zx@209.190.85.253 - Win32/Ustealftp://h51694:2222559@91.227.16.13 - Win32/Ganelp.Eftp://450857:6a5124c7@83.125.22.167 - Win32/Ganelp.gen!Aftp://b12_8082975:951753zx@209.190.85.253 - Win32/Ganelp.gen!Aftp://getmac:8F4ODYLQlvpjjQ==@222.35.250.56 - Win32/Ganelp.Gftp://u797638036:951753zx@31.170.165.29 - Virus.Downloader.Rozenaftp://b12_8082975:djdf3549384@10.0.2.15 - Win32/Ganelp.gen!Aftp://onthelinux:741852abc@209.202.252.54 - Win32/Ganelp.Eftp://b12_8082975:951753zx@209.190.85.253 - Win32/Ganelp.Eftp://450857:6a5124c7@83.125.22.167 - Win32/Ganelp.gen!Aftp://u206748555:as3515789@31.170.165.165 - Win32/Ustealftp://fintzet5@mail.ru:856cc58e698f@93.189.41.96 - Win32/Ustealftp://griptoloji:3INULAX@46.16.168.174 - Win32/Ustealftp://u459704296:ded7753191ded@31.170.164.244 - Win32/Ustealftp://dedmen2:reaper24chef@176.9.52.231 - Win32/Ustealftp://srv35913:JLN18Hp7@78.110.50.123 - F*ck this shitftp://ftp1970492:ziemniak123@213.202.225.201 - F*ck this shitftp://dron2258:NRm8CNfW@89.108.68.89 - F*ck this shitftp://u996543000:123456789a@31.170.165.235 - F*ck this shitftp://u500739002:jd7H2ni99s@31.170.165.199 - F*ck this shitftp://0dmaer:1780199d@193.109.247.83 - F*ck this shitftp://u404100999:vardan123@31.170.164.25 - F*ck this shitftp://a9951823:www.ry123456@31.170.161.56 - F*ck this shitftp://u194291799:80997171405@31.170.165.18 - F*ck this shitftp://u478149:qqgclnbi@212.46.196.140 - F*ck this shitftp://u114972719:1052483w@31.170.165.192 - F*ck this shitftp://a1954396:omeromer123@31.170.162.103 - F*ck this shitftp://googgle.ueuo.com:741852@5.9.82.27 - F*ck this shitftp://fr32920:Nw3hRUme@92.53.98.21 - F*ck this shitftp://u974422848.root:vertrigo@31.170.164.119 - F*ck this shitftp://u205783311:gomogej200897z@31.170.165.192 - F*ck this shitftp://u188483768:andrewbogdanov1@31.170.165.251 - F*ck this shitftp://coinmint@coinslut.com:c01nm1nt!@108.170.30.2 - F*ck this shitftp://agooga:nokiamarco@198.23.57.29 - F*ck this shitftp://nicusn:n0305441@198.23.57.29 - F*ck this shitftp://u355595964:xmNmK4CfvX@31.170.165.193 - F*ck this shitftp://fmstu421:oxjQG1i7@46.4.94.180 - F*ck this shitftp://u651787226:123698745s@31.170.164.98 - F*ck this shitftp://u492312765:530021354@31.170.165.250 - F*ck this shitftp://mandaryn:m0jak0chanaania@213.180.150.18 - F*ck this shitftp://spechos8:onxGoTDG@89.108.68.85 - F*ck this shitftp://6fidaini:vardan123@193.109.247.80 - F*ck this shitftp://8steamsell:frozenn1@195.216.243.45 - F*ck this shitftp://u478644:57zw1q56@212.46.196.138 - F*ck this shitftp://u478230:lytlz3ub@212.46.196.133 - F*ck this shitftp://u730739228:warhammer3@31.170.165.238 - F*ck this shitftp://sme8:y6kByIZA@89.108.68.85 - F*ck this shitftp://koctbijib1@mail.ru:83670bb9072b@93.189.41.100 - F*ck this shitftp://u457127536:741852963q@31.170.165.245 - F*ck this shitftp://u450728967:987456987@31.170.165.187 - F*ck this shitftp://u730739228:warhammer3@31.170.165.238 - F*ck this shitftp://0lineage2-world:plokijuh@195.216.243.7 - F*ck this shitftp://expox@1:0628262733Y@188.40.138.148 - F*ck this shitftp://admin@enhanceviews.elementfx.com:123456@198.91.81.3 - F*ck this shitftp://ih_3676461:123456@209.190.85.253 - F*ck this shitftp://0alfa-go-cs:killer2612@195.216.243.45 - F*ck this shitftp://5nudapac:nudapac@195.216.243.82 - F*ck this shitftp://450857:6a5124c7@83.125.22.167 - F*ck this shitI've added signature manually by browsing VirusTotal report but i got too many results so i've just leaved 'F*ck this shit' to all of them.Crawling VirusTotal with the API can be also an idea to retrieve results but i'm lazy. Looking at random pcap i've found some was fun:Malware using free hosting service is a bad idea: Malware builded with wrong datas (epic failure) Malware badly coded: Infecting yourself with Ardamax and enabling all features on it is a bad idea: Another configuration failure: FTP's full of sh*t: You can learn about actors, eg from dedmen2@176.9.52.231, emo boy (i've included him on the ftp list): Protip: don't buy a Nikon Coolpix L14v1.0, low quality picture.I got also some false positive, this one is fun because it's a server against malware infection: I have no idea why UsbFix was on a malware pack, anyway the use of FTP protocol for legit tools is also a bad idea, and this is not the only 'anti-malware' server i've found, got some weird stuff for viral update and many others, this technic is a double edged sword but most of result lead on malware servers. Posted by Steven K at 00:18 Sursa: XyliBox: Infiltrating malware servers without doing anything Quote
Nytro Posted June 28, 2013 Author Report Posted June 28, 2013 cURL-ul pulii...Pentru cei care mai fac request-uri cu cacatul de cURL, la URL aveti grija sa dati replace la spatii cu "+":curl_setopt ($ch, CURLOPT_URL, str_replace(' ', '+', $_GET['url'])); Quote