Top Banner
1 The Business of Cybercrime Luis Corrons PandaLabs Technical Director
69

The Business of Cybercrime Library/Security/The_Busin… · 41 different servers with Mpack running 366,717 web pages “iframed ...

Oct 09, 2020

Download

Documents

dariahiddleston
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: The Business of Cybercrime Library/Security/The_Busin… · 41 different servers with Mpack running 366,717 web pages “iframed ...

1

The Business of Cybercrime

Luis Corrons

PandaLabs Technical Director

Page 2: The Business of Cybercrime Library/Security/The_Busin… · 41 different servers with Mpack running 366,717 web pages “iframed ...

2

The Business of Cybercrime

AgendaAgenda

1.1. Malware figuresMalware figures

2.2. WhoWho isis behindbehind thisthis??

3.3. Web Web AttackAttack ToolkitsToolkits

4.4. A Real CaseA Real Case

5.5. UndergroundUnderground Shopping Shopping CartCart

6.6. WhereWhere toto buybuy??

Page 3: The Business of Cybercrime Library/Security/The_Busin… · 41 different servers with Mpack running 366,717 web pages “iframed ...

3

Malware figuresMalware figures

The Business of Cybercrime

Page 4: The Business of Cybercrime Library/Security/The_Busin… · 41 different servers with Mpack running 366,717 web pages “iframed ...

4

Malware Malware evolutionevolution

The Business of Cybercrime

Source: PandaLabs

Malware detected per year

Page 5: The Business of Cybercrime Library/Security/The_Busin… · 41 different servers with Mpack running 366,717 web pages “iframed ...

5

Malware Malware evolutionevolution by by typetype

The Business of Cybercrime

Source: PandaLabs

Page 6: The Business of Cybercrime Library/Security/The_Busin… · 41 different servers with Mpack running 366,717 web pages “iframed ...

6

Malware Malware evolutionevolution by by typetype

The Business of Cybercrime

Source: PandaLabs

Page 7: The Business of Cybercrime Library/Security/The_Busin… · 41 different servers with Mpack running 366,717 web pages “iframed ...

7

WhoWho isis behindbehind thisthis??

The Business of Cybercrime

Page 8: The Business of Cybercrime Library/Security/The_Busin… · 41 different servers with Mpack running 366,717 web pages “iframed ...

8

YesterdayYesterday’’ss BadBad GuysGuys

Blaster.B Nestky / Sasser CIH 29-A

Jeffrey Lee Parson Sven Jaschan Chen Ing-Hau Benny

The Business of Cybercrime

Page 9: The Business of Cybercrime Library/Security/The_Busin… · 41 different servers with Mpack running 366,717 web pages “iframed ...

9

TodayToday’’ss BadBad GuysGuys

Jeremy JaynesAndrew SchwarmkoffJames Ancheta

Phishing SpamSpam

The Business of Cybercrime

Page 10: The Business of Cybercrime Library/Security/The_Busin… · 41 different servers with Mpack running 366,717 web pages “iframed ...

10

Web Web AttackAttack ToolkitsToolkits

The Business of Cybercrime

Page 11: The Business of Cybercrime Library/Security/The_Busin… · 41 different servers with Mpack running 366,717 web pages “iframed ...

11

Web Attack Toolkits Malware server

Page 12: The Business of Cybercrime Library/Security/The_Busin… · 41 different servers with Mpack running 366,717 web pages “iframed ...

12

MPack

The Business of Cybercrime

Page 13: The Business of Cybercrime Library/Security/The_Busin… · 41 different servers with Mpack running 366,717 web pages “iframed ...

13

MPack

�� TrackingTracking MpackMpack forfor 2 2 monthsmonths ((AprilApril & May 2007):& May 2007):

�� 41 41 differentdifferent serversservers withwith MpackMpack runningrunning

�� 366,717 web 366,717 web pagespages ““iframediframed””

�� More More thanthan 1 1 millionmillion usersusers infected (1,217,741)infected (1,217,741)

The Business of Cybercrime

Page 14: The Business of Cybercrime Library/Security/The_Busin… · 41 different servers with Mpack running 366,717 web pages “iframed ...

14

MPack

The Business of Cybercrime

Page 15: The Business of Cybercrime Library/Security/The_Busin… · 41 different servers with Mpack running 366,717 web pages “iframed ...

15

IcePack

Login

The Business of Cybercrime

Page 16: The Business of Cybercrime Library/Security/The_Busin… · 41 different servers with Mpack running 366,717 web pages “iframed ...

16

IcePack

The Business of Cybercrime

Page 17: The Business of Cybercrime Library/Security/The_Busin… · 41 different servers with Mpack running 366,717 web pages “iframed ...

17

IcePack

Operating System

The Business of Cybercrime

Page 18: The Business of Cybercrime Library/Security/The_Busin… · 41 different servers with Mpack running 366,717 web pages “iframed ...

18

IcePack

Browser

The Business of Cybercrime

Page 19: The Business of Cybercrime Library/Security/The_Busin… · 41 different servers with Mpack running 366,717 web pages “iframed ...

19

IcePack

The Business of Cybercrime

Page 20: The Business of Cybercrime Library/Security/The_Busin… · 41 different servers with Mpack running 366,717 web pages “iframed ...

20

IcePack

Referrers

FTP import

FTP checker

The Business of Cybercrime

Page 21: The Business of Cybercrime Library/Security/The_Busin… · 41 different servers with Mpack running 366,717 web pages “iframed ...

21

IcePack

iFramer

Country blocking

The Business of Cybercrime

Page 22: The Business of Cybercrime Library/Security/The_Busin… · 41 different servers with Mpack running 366,717 web pages “iframed ...

22

FirePack

The Business of Cybercrime

Page 23: The Business of Cybercrime Library/Security/The_Busin… · 41 different servers with Mpack running 366,717 web pages “iframed ...

23

Traffic Pro

The Business of Cybercrime

Page 24: The Business of Cybercrime Library/Security/The_Busin… · 41 different servers with Mpack running 366,717 web pages “iframed ...

24

Neosploit

The Business of Cybercrime

Page 25: The Business of Cybercrime Library/Security/The_Busin… · 41 different servers with Mpack running 366,717 web pages “iframed ...

25

And many more…

- E-corepack

- Nuclear traffic

- Multi exploits pack

- Nuclear Malware Kit

- Prime Exploit System

- Web-Attacker

- SmartPack

The Business of Cybercrime

Page 26: The Business of Cybercrime Library/Security/The_Busin… · 41 different servers with Mpack running 366,717 web pages “iframed ...

26

A Real CaseA Real Case

The Business of Cybercrime

Page 27: The Business of Cybercrime Library/Security/The_Busin… · 41 different servers with Mpack running 366,717 web pages “iframed ...

27

The Business of Cybercrime

Page 28: The Business of Cybercrime Library/Security/The_Busin… · 41 different servers with Mpack running 366,717 web pages “iframed ...

28

InfectedInfected TeamTeam

–– ProxyProxy

•• 5 5 -- $2.5$2.5

•• 1,000 1,000 -- $300$300

–– DDoSDDoS

•• 1 1 hourhour -- $20$20

•• 24 24 hourshours -- $100$100

•• MajorMajor projectsprojects startingstarting at $200at $200

•• 10 minutes 10 minutes forfor free!free!

The Business of Cybercrime

Page 29: The Business of Cybercrime Library/Security/The_Busin… · 41 different servers with Mpack running 366,717 web pages “iframed ...

29

InfectedInfected TeamTeam

–– Spam: Spam: < 192,000,000 e< 192,000,000 e--mail mail addressesaddresses

•• USA (USA (homehome usersusers) ) –– 117,000,000117,000,000–– US$150 / US$150 / millionmillion messagesmessages

•• USA (USA (enterprisesenterprises) ) –– 4,000,0004,000,000–– US$150 / US$150 / millionmillion messagesmessages

•• Western Western EuropeEurope ((homehome usersusers) ) –– 45,000,00045,000,000–– US$130 / US$130 / millionmillion messagesmessages

•• Western Western EuropeEurope ((enterprisesenterprises) ) –– 902,256902,256–– US$130 / US$130 / millionmillion messagesmessages

•• RussiaRussia ((homehome usersusers) ) –– 20,700,00020,700,000–– US$100 / US$100 / millionmillion messagesmessages

•• RussiaRussia ((enterprisesenterprises) ) –– 5,000,0005,000,000–– US$120 / US$120 / millionmillion messagesmessages

The Business of Cybercrime

Page 30: The Business of Cybercrime Library/Security/The_Busin… · 41 different servers with Mpack running 366,717 web pages “iframed ...

30

InfectedInfected TeamTeam

–– Personal Personal cryptorcryptor ($15, ($15, updatesupdates $5)$5)

–– ABLoaderABLoader ($60, ($60, builderbuilder $500)$500)

–– RooTRooT iFrameiFrame ($25 ($25 RussianRussian, $50 , $50 EnglishEnglish))

–– SpamPHPSpamPHP Script ($2)Script ($2)

–– FTPCheckIframeFTPCheckIframe ($25)($25)

The Business of Cybercrime

Page 31: The Business of Cybercrime Library/Security/The_Busin… · 41 different servers with Mpack running 366,717 web pages “iframed ...

31

MPackMPack

DreamDream DownloaderDownloader

LimboLimbo

Total Total InvestmentInvestment: :

1,500$1,500$

InfectedInfected TeamTeam

The Business of Cybercrime

Page 32: The Business of Cybercrime Library/Security/The_Busin… · 41 different servers with Mpack running 366,717 web pages “iframed ...

32

InfectedInfected TeamTeam

The Business of Cybercrime

Page 33: The Business of Cybercrime Library/Security/The_Busin… · 41 different servers with Mpack running 366,717 web pages “iframed ...

33

InfectedInfected TeamTeam

The Business of Cybercrime

Page 34: The Business of Cybercrime Library/Security/The_Busin… · 41 different servers with Mpack running 366,717 web pages “iframed ...

34

InfectedInfected TeamTeam

The Business of Cybercrime

Page 35: The Business of Cybercrime Library/Security/The_Busin… · 41 different servers with Mpack running 366,717 web pages “iframed ...

35

InfectedInfected TeamTeam

Win32.exe = Trojan downloaderWin32.exe = Trojan downloader

InstalledInstalled::

Spammer Spammer TrojanTrojan

RogueRogue AntiSpywareAntiSpyware

The Business of Cybercrime

Page 36: The Business of Cybercrime Library/Security/The_Busin… · 41 different servers with Mpack running 366,717 web pages “iframed ...

36

InfectedInfected TeamTeam

RogueRogue AntiSpywareAntiSpyware

CommissionsCommissions paidpaid perper installationinstallation::

$0.40 USA, Canada$0.40 USA, Canada

$0.20 UK, France, Germany, Italy, Spain, Belgium, Luxembourg, Mo$0.20 UK, France, Germany, Italy, Spain, Belgium, Luxembourg, Monaconaco

$0.05 Austria, Denmark, Finland, Sweden, Norway, The Netherlands$0.05 Austria, Denmark, Finland, Sweden, Norway, The Netherlands

$0.01 China, Korea, Japan$0.01 China, Korea, Japan

The Business of Cybercrime

Page 37: The Business of Cybercrime Library/Security/The_Busin… · 41 different servers with Mpack running 366,717 web pages “iframed ...

37

InfectedInfected TeamTeam

LetLet’’s do some mathss do some maths

China, Korea, Japan:China, Korea, Japan: $0.01 * 70,300 = $703$0.01 * 70,300 = $703

Finland, NorwayFinland, Norway……:: $0.05 * 70,300 = $3,515$0.05 * 70,300 = $3,515

UK, FranceUK, France……:: $0.20 * 70,300 = $14,060$0.20 * 70,300 = $14,060

USA, Canada:USA, Canada: $0.40 * 70,300 = $28,120$0.40 * 70,300 = $28,120

And the same numbers in 30 daysAnd the same numbers in 30 days……

China, Korea, Japan:China, Korea, Japan: $0.01 * 70,300 * 30 = $21,090$0.01 * 70,300 * 30 = $21,090

Finland, NorwayFinland, Norway……:: $0.05 * 70,300 * 30 = $105,450$0.05 * 70,300 * 30 = $105,450

UK, FranceUK, France……:: $0.20 * 70,300 * 30 = $421,800$0.20 * 70,300 * 30 = $421,800

USA, Canada:USA, Canada: $0.40 * 70,300 * 30 = $843,600$0.40 * 70,300 * 30 = $843,600

The Business of Cybercrime

Page 38: The Business of Cybercrime Library/Security/The_Busin… · 41 different servers with Mpack running 366,717 web pages “iframed ...

38

InfectedInfected TeamTeam

WhoWho’’s paying these Rogue s paying these Rogue AntiSpywareAntiSpyware installations?installations?

The Business of Cybercrime

Page 39: The Business of Cybercrime Library/Security/The_Busin… · 41 different servers with Mpack running 366,717 web pages “iframed ...

39

The Business of Cybercrime

Page 40: The Business of Cybercrime Library/Security/The_Busin… · 41 different servers with Mpack running 366,717 web pages “iframed ...

40

The Business of Cybercrime

Page 41: The Business of Cybercrime Library/Security/The_Busin… · 41 different servers with Mpack running 366,717 web pages “iframed ...

41

The Business of Cybercrime

Page 42: The Business of Cybercrime Library/Security/The_Busin… · 41 different servers with Mpack running 366,717 web pages “iframed ...

42

The Business of Cybercrime

Page 43: The Business of Cybercrime Library/Security/The_Busin… · 41 different servers with Mpack running 366,717 web pages “iframed ...

43

The Business of Cybercrime

Page 44: The Business of Cybercrime Library/Security/The_Busin… · 41 different servers with Mpack running 366,717 web pages “iframed ...

44

The Business of Cybercrime

Page 45: The Business of Cybercrime Library/Security/The_Busin… · 41 different servers with Mpack running 366,717 web pages “iframed ...

45

The Business of Cybercrime

Page 46: The Business of Cybercrime Library/Security/The_Busin… · 41 different servers with Mpack running 366,717 web pages “iframed ...

46

The Business of Cybercrime

Page 47: The Business of Cybercrime Library/Security/The_Busin… · 41 different servers with Mpack running 366,717 web pages “iframed ...

47

The Business of Cybercrime

Page 48: The Business of Cybercrime Library/Security/The_Busin… · 41 different servers with Mpack running 366,717 web pages “iframed ...

48

The Business of Cybercrime

Page 49: The Business of Cybercrime Library/Security/The_Busin… · 41 different servers with Mpack running 366,717 web pages “iframed ...

49

The Business of Cybercrime

Page 50: The Business of Cybercrime Library/Security/The_Busin… · 41 different servers with Mpack running 366,717 web pages “iframed ...

50

The Business of Cybercrime

Page 51: The Business of Cybercrime Library/Security/The_Busin… · 41 different servers with Mpack running 366,717 web pages “iframed ...

51

The Business of Cybercrime

Page 52: The Business of Cybercrime Library/Security/The_Busin… · 41 different servers with Mpack running 366,717 web pages “iframed ...

52

UndergroundUnderground Shopping Shopping CartCart

The Business of Cybercrime

Page 53: The Business of Cybercrime Library/Security/The_Busin… · 41 different servers with Mpack running 366,717 web pages “iframed ...

53

UndergroundUnderground Shopping Shopping CartCart

–– Web Web AttackAttack ToolkitsToolkits

•• MPackMPack–– US$700US$700

–– DreamDownloaderDreamDownloader + US$300+ US$300

–– AddingAdding newnew exploitexploit + US$50+ US$50--150150

–– AvoidAvoid AV AV detectiondetection + US$20+ US$20--3030

•• IcePackIcePack–– Lite:Lite: US$30US$30

–– Platinum:Platinum: US$400US$400

•• FirePackFirePack–– US$3US$3,000,000

•• TrafficTraffic ProPro–– US$40US$40

•• EcoreEcore–– BundleBundle US$590 (US$590 (forfor a a domaindomain / / ipip withwith ecoreecore installedinstalled).).

–– DomainDomain / / additionaladditional ipip US$490US$490

–– HelpHelp forfor thethe installationinstallation US$15US$15

The Business of Cybercrime

Page 54: The Business of Cybercrime Library/Security/The_Busin… · 41 different servers with Mpack running 366,717 web pages “iframed ...

54

UndergroundUnderground Shopping Shopping CartCart

–– MalwareMalware

•• KeyloggerKeylogger TellerTeller 2.0 2.0 –– TypicalTypical keyloggerkeylogger; ; itit uses uses stealthstealth techniquestechniques andand isis quite complete: US$40quite complete: US$40

•• WebmoneyWebmoney TrojanTrojan–– ItIt captures captures WebmoneyWebmoney accountsaccounts: US$500 (: US$500 (thethe firstfirst 100 100 willwill obtainobtain itit forfor US$400!)US$400!)

•• WMTWMT--spyspy: : –– AnotherAnother TrojanTrojan toto obtainobtain WebMoneyWebMoney accountsaccounts, , butbut cheapercheaper thanthan thethe previousprevious oneone

–– TrojanTrojan US$5US$5

–– UpdatesUpdates US$5US$5

–– BuilderBuilder US$10US$10

•• SNATCH TROJAN: SNATCH TROJAN: –– ItIt stealssteals passwordspasswords andand has has rootkitrootkit functionalitiesfunctionalities: : US$600 US$600

•• Limbo: Limbo: –– BankingBanking TrojanTrojan, , keyloggerkeylogger, etc. , etc. US$1,000US$1,000

•• PinchPinch: : –– VeryVery complete complete TrojanTrojan. . US$30US$30

–– UpdateUpdate: : US$5US$5

The Business of Cybercrime

Page 55: The Business of Cybercrime Library/Security/The_Busin… · 41 different servers with Mpack running 366,717 web pages “iframed ...

55

UndergroundUnderground Shopping Shopping CartCart

–– JoinerJoiner andand encryptionencryption

•• PolarisPolaris–– PolymorphicPolymorphic encryptionencryption forfor youryour executablesexecutables US$20US$20

•• FreejoinerFreejoiner–– HidesHides youryour executablesexecutables joiningjoining themthem withwith otherother files US$30 + US$5 files US$30 + US$5 perper updateupdate

•• My My joinerjoiner–– OtherOther joinerjoiner belongingbelonging toto thethe creatorcreator ofof PinchPinch US$10US$10

•• PityPity JoinerJoiner–– JustJust anotheranother joinerjoiner US$7US$7

The Business of Cybercrime

Page 56: The Business of Cybercrime Library/Security/The_Busin… · 41 different servers with Mpack running 366,717 web pages “iframed ...

56

UndergroundUnderground Shopping Shopping CartCart

–– OtherOther ToolsTools

•• FTP FTP checkerchecker–– ProgramProgram toto validatevalidate stolenstolen FTP FTP accountsaccounts. . US$15US$15

•• DreamDream BotBot BuilderBuilder–– FloodsFloods serversservers US$500 + US$25 US$500 + US$25 perper updateupdate

The Business of Cybercrime

Page 57: The Business of Cybercrime Library/Security/The_Busin… · 41 different servers with Mpack running 366,717 web pages “iframed ...

57

UndergroundUnderground Shopping Shopping CartCart

–– SpamSpam

•• Spam Spam HostingHosting:: US$200US$200

•• DedicatedDedicated spam spam serverserver US$500US$500

•• +10,000,000 Mails +10,000,000 Mails perper dayday US$600 US$600

•• SMS spam (SMS spam (perper messagemessage)) US$0.2US$0.2

•• ICQ (1,000,000)ICQ (1,000,000) US$150 US$150

Mailing Mailing listslists forfor spam:spam: (US$)(US$)

ACCOUNTSACCOUNTS USAUSA GERMANYGERMANY RUSSIARUSSIA UKRANIAUKRANIA

1,000,000 1,000,000 100100 100100 100100 100100

3,000,0003,000,000 200200 200200 200200 200200

5,000,0005,000,000 300300 300300 300300 --

8,000,0008,000,000 500500 500500 500500 --

16,000,00016,000,000 900900 -- -- --

32,000,00032,000,000 15001500 -- -- --

The Business of Cybercrime

Page 58: The Business of Cybercrime Library/Security/The_Busin… · 41 different servers with Mpack running 366,717 web pages “iframed ...

58

UndergroundUnderground Shopping Shopping CartCart

–– AccountsAccounts

•• FTP FTP accountsaccounts: : –– US$1 US$1 perper accountaccount

•• IcqIcq numbersnumbers::–– FromFrom US$1 US$1 toto US$10 (US$10 (dependingdepending onon thethe ICQ ICQ numbernumber))

•• RapidShareRapidShare premiumpremium accountsaccounts::–– 1 1 monthmonth -- US$5US$5

–– 2 2 monthsmonths -- US$8US$8

–– 3 3 monthsmonths -- US$12US$12

–– 6 6 monthsmonths -- US$18US$18

–– 1 1 yearyear -- US$28US$28

•• Online Online ShopShop accountsaccounts–– ((megashop.rumegashop.ru, , bolero.rubolero.ru, , cup.rucup.ru, etc. ALL RUSSIAN): , etc. ALL RUSSIAN): -- US$50 US$50 eacheach

•• 50MB 50MB ofof Limbo Limbo TrojanTrojan logslogs–– US$30 (US$30 (containscontains email email accountsaccounts, , bankbank accountaccount numbersnumbers, , creditcredit cardcard numbersnumbers, etc. A , etc. A

percentagepercentage isis guaranteedguaranteed))

The Business of Cybercrime

Page 59: The Business of Cybercrime Library/Security/The_Busin… · 41 different servers with Mpack running 366,717 web pages “iframed ...

59

UndergroundUnderground Shopping Shopping CartCart

–– AlreadyAlready finishedfinished??

•• CreditCredit CardsCards–– VISA / MASTERCARDVISA / MASTERCARD

1 1 -- 1010 cardscards US$2 (US$2 (perper cardcard))

10 10 -- 100100 cardscards US$1.5 (US$1.5 (perper cardcard) )

–– AMEXAMEX

1 1 -- 1010 cardscards US$2.5 (US$2.5 (perper cardcard))

10 10 -- 100100 cardscards US$2 (US$2 (perper cardcard) )

•• PassportsPassports::–– Black Black andand whitewhite:: US$2US$2

–– Color:Color: US$5 US$5

The Business of Cybercrime

Page 60: The Business of Cybercrime Library/Security/The_Busin… · 41 different servers with Mpack running 366,717 web pages “iframed ...

60

WhereWhere toto buybuy??

The Business of Cybercrime

Page 61: The Business of Cybercrime Library/Security/The_Busin… · 41 different servers with Mpack running 366,717 web pages “iframed ...

61

The Business of Cybercrime

Page 62: The Business of Cybercrime Library/Security/The_Busin… · 41 different servers with Mpack running 366,717 web pages “iframed ...

62

The Business of Cybercrime

Page 63: The Business of Cybercrime Library/Security/The_Busin… · 41 different servers with Mpack running 366,717 web pages “iframed ...

63

The Business of Cybercrime

Page 64: The Business of Cybercrime Library/Security/The_Busin… · 41 different servers with Mpack running 366,717 web pages “iframed ...

64

The Business of Cybercrime

Page 65: The Business of Cybercrime Library/Security/The_Busin… · 41 different servers with Mpack running 366,717 web pages “iframed ...

65

The Business of Cybercrime

Page 66: The Business of Cybercrime Library/Security/The_Busin… · 41 different servers with Mpack running 366,717 web pages “iframed ...

66

The Business of Cybercrime

Page 67: The Business of Cybercrime Library/Security/The_Busin… · 41 different servers with Mpack running 366,717 web pages “iframed ...

67

The Business of Cybercrime

Page 68: The Business of Cybercrime Library/Security/The_Busin… · 41 different servers with Mpack running 366,717 web pages “iframed ...

68

The Business of Cybercrime

Page 69: The Business of Cybercrime Library/Security/The_Busin… · 41 different servers with Mpack running 366,717 web pages “iframed ...

69

ThanksThanks!!Luis Corrons

[email protected]

PandaLabs Blog:

http://www.pandalabs.com