Top Banner
http://krebsonsecurity.com/2010/09/
23

Http://krebsonsecurity.com/2010/09/. Welcome to SpyEye Front-end interface called “CN 1” or “Main Access Panel.”

Dec 16, 2015

Download

Documents

Nigel Floyd
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Http://krebsonsecurity.com/2010/09/. Welcome to SpyEye Front-end interface called “CN 1” or “Main Access Panel.”

http://krebsonsecurity.com/2010/09/

Page 2: Http://krebsonsecurity.com/2010/09/. Welcome to SpyEye Front-end interface called “CN 1” or “Main Access Panel.”

Welcome to SpyEye

Front-end interface called “CN 1” or “Main Access Panel.”

Page 3: Http://krebsonsecurity.com/2010/09/. Welcome to SpyEye Front-end interface called “CN 1” or “Main Access Panel.”

Create task for billing a CCSpyEye Console

Page 4: Http://krebsonsecurity.com/2010/09/. Welcome to SpyEye Front-end interface called “CN 1” or “Main Access Panel.”

More billinghammer

Page 5: Http://krebsonsecurity.com/2010/09/. Welcome to SpyEye Front-end interface called “CN 1” or “Main Access Panel.”

Bot List

Page 6: Http://krebsonsecurity.com/2010/09/. Welcome to SpyEye Front-end interface called “CN 1” or “Main Access Panel.”

Bot Net Statistics

Page 7: Http://krebsonsecurity.com/2010/09/. Welcome to SpyEye Front-end interface called “CN 1” or “Main Access Panel.”
Page 8: Http://krebsonsecurity.com/2010/09/. Welcome to SpyEye Front-end interface called “CN 1” or “Main Access Panel.”

Upload a Task Fileinstruct the bot to go to a specific sit

(to generate clicks for possible ad revenue) or to possibly download more malware

Page 9: Http://krebsonsecurity.com/2010/09/. Welcome to SpyEye Front-end interface called “CN 1” or “Main Access Panel.”

Uploads configuration filesUpdates SpyEye binary files for the bots to download

Page 10: Http://krebsonsecurity.com/2010/09/. Welcome to SpyEye Front-end interface called “CN 1” or “Main Access Panel.”

Virtest is a website in Eastern Europe that allows logged-in users to scan binary files and exploit

packs to test if they are being detected by antivirus engines

Page 11: Http://krebsonsecurity.com/2010/09/. Welcome to SpyEye Front-end interface called “CN 1” or “Main Access Panel.”

Settings button

Socks 5 backconnetAllow the bot master to create reverse connections to the bot

Page 12: Http://krebsonsecurity.com/2010/09/. Welcome to SpyEye Front-end interface called “CN 1” or “Main Access Panel.”

SYN 1 or the Formgrabber Access Panel

Amount of data being collectedDate & Time

Page 13: Http://krebsonsecurity.com/2010/09/. Welcome to SpyEye Front-end interface called “CN 1” or “Main Access Panel.”

Search the database of stolen information

Page 14: Http://krebsonsecurity.com/2010/09/. Welcome to SpyEye Front-end interface called “CN 1” or “Main Access Panel.”

Search for a specific bankHhows the entire HTTP request

and all of the data the user sent to the bank

User namePassword

Page 15: Http://krebsonsecurity.com/2010/09/. Welcome to SpyEye Front-end interface called “CN 1” or “Main Access Panel.”

Overview of the sites that the infected computers

Page 16: Http://krebsonsecurity.com/2010/09/. Welcome to SpyEye Front-end interface called “CN 1” or “Main Access Panel.”

Bot master creates a .TXT file that will display FTP user names and passwords

Page 17: Http://krebsonsecurity.com/2010/09/. Welcome to SpyEye Front-end interface called “CN 1” or “Main Access Panel.”

Bot herder can specify an email address to receive a copy of the C&C server’s database

Page 18: Http://krebsonsecurity.com/2010/09/. Welcome to SpyEye Front-end interface called “CN 1” or “Main Access Panel.”

SpyEye can also capture screenshots from infected machines

Page 19: Http://krebsonsecurity.com/2010/09/. Welcome to SpyEye Front-end interface called “CN 1” or “Main Access Panel.”

For ExampleScreenshot of a user at home authenticating

with his/her bank login by using an onscreen keypad

Page 20: Http://krebsonsecurity.com/2010/09/. Welcome to SpyEye Front-end interface called “CN 1” or “Main Access Panel.”

Screenshot displaying all of the user’s account numbers and

how much money was in each account

Page 21: Http://krebsonsecurity.com/2010/09/. Welcome to SpyEye Front-end interface called “CN 1” or “Main Access Panel.”

Steals only Bank of America credential

Page 22: Http://krebsonsecurity.com/2010/09/. Welcome to SpyEye Front-end interface called “CN 1” or “Main Access Panel.”

Displays stolen credit card informationto use the user’s credit cards for the

Create task for Billing

Page 23: Http://krebsonsecurity.com/2010/09/. Welcome to SpyEye Front-end interface called “CN 1” or “Main Access Panel.”

Security certificates that SpyEye has stolen