SlideShare una empresa de Scribd logo
1 de 42
Descargar para leer sin conexión
RISE OF THE BANKING TROJANS 
Subtitle Redacted
Z... Whatever 
Alternative Talk Title
ZEUS IS NOT DEAD YET 
Actual Talk Title 
m/-.-m/ 
http://www.sodahead.com/
Marion Marschalek 
@pinkflawd 
marion@cyphort.com 
http://hqwallbase.com/28103-lego-stormtroopers-wallpaper-2560x1600
What is ZEUS? 
Old. 
Banking Trojan. 
Data Stealer. 
Open Source :)
2007 
2010 
2011
Source: http://securityblog.s21sec.com
ZEUSold but gold 
Zeus 
Citadel 
SpyEye 
ZitMo 
ZeusVM/KINS 
Zberp 
http://forum.fr.grepolis.com/
ZEUSmode of operation 
1.Drop executable in users %APP% folder 
2.Create and execute a batch file to delete dropper 
3.Maintain registry key for persistence 
4.Inject payload to system processes 
5.Download customized configuration
Registry Key 
Infector 
Decrypt & load DLL 
Inject DLL 
ZEUSmode of operation
Hell is infected with some dark bastard of zeus hail satan!!
E(DDIE)VASIONTECHNIQUES
E(DDIE)VASIONtechniques 
Weapons of matchdestruction!
E(DDIE)VASIONtechniques 
Weapons of MATCHdestruction!
ZEUSE(DDIE) VASION 
%APP%Uwirpa 
10.12.2013 
23:50 
%APP%Woyxhi 
10.12.2013 
23:50 
%APP%Hibyo 
19.12.2013 
00:10 
%APP%Nezah 
19.12.2013 
00:10 
%APP%Afqag 
19.12.2013 
23:29 
%APP%Zasi 
19.12.2013 
23:29 
%APP%Eqzauf 
20.12.2013 
22:23 
%APP%Ubapo 
20.12.2013 
22:23 
%APP%Ydgowa 
20.12.2013 
22:23 
%APP%Olosu 
20.12.2013 
23:03 
%APP%Taal 
20.12.2013 
23:03 
%APP%Taosep 
20.12.2013 
23:03 
%APP%Wokyco 
16.01.2014 
13:22 
%APP%Semi 
17.01.2014 
16:34 
%APP%Uheh 
17.01.2014 
16:34
E(DDIE)VASIONon the system level 
OpenProcess 
Check AccessToken 
WriteProcessMemory 
CreateRemoteThread 
Boom.
Domain 
Generation 
Algorithms 
http://blog.malwaremustdie.org/ 
E(DDIE)VASIONon the perimeter
E(DDIE)VASION 
on the binary level
E(DDIE)VASION 
on the binary level
Eddie In The Browser 
USER 
BANK.COM 
BROWSER 
inject 
web 
content 
grab 
user 
input 
+
•UpdateURL & ConfigBackup URL 
•UploadURL 
•InjectionInformation 
•URL Masks: 
•For identifying websites to log 
•For identifying websites to screenshot 
•URL Mappingsfor Redirection 
•IP/URL Mappings to insert to host file to override DNS lookups 
CONFIGURATION
SUMMING IT UP 
DROPPERkilf.exe 
C&C SERVER 
control communication and updates 
DELETE SCRIPT 
KUQ9491.bat 
ZBOT 
vogiap.exe 
CONFIGURATIONehri.ofu 
drop Zbotfiles 
delete dropper 
PROCESS 
explorer.exe 
inject code
ZitMoZeus in the Mobile 
Zeus Infection 
Installation of ZitMo 
Social Engineering 
Spying of Online-Banking credentials 
Capture mTAN 
Do Transaction
ZeusVM/ KINS 
Born December 2011 
Sold as a kit since 2013 
Heavily based on Zeus source code 
http://blog.fox-it.com/2013/07/25/analysis-of-the-kins-malware/
Zeus VIRTUAL MACHINE 
1. Grab next opcode 
2. Call opcode handler
INVISIBLE PERSISTENCE 
thread for managing autorun key 
...
CONFIGURATIONhiding in plain sight
CONFIGURATIONhiding in plain sight
http://blog.malwarebytes.org 
https://blog.malwarebytes.org 
CONFIGURATIONhiding in plain sight
Carberp 
There is no honour among thieves: 
“Leaking the source code was not like the leaking of a weapon, but more like the leaking of a tank factory” 
1.9GB Sources 
http://krebsonsecurity.com/
ZBERP 
+ 
= 
2
ZBERP?
ZBERP?
ZBERP?
ZBERP ..? 
Infection Routine 
Anti-Disassembly 
Invisible Persistence 
Graphical Configuration 
Virtual Machine Execution 
Encrypted C&C communication 
Suspend-Thread Code Injection 
Hooking Technique 
ZEUS 
KINS 
CARBERP
BRAVE NEW WORLD 
NOW WHAT ABOUT DETECTIONS?
HUNTING ZEUS 
1.Drive-by infections 
2.Anomalies in network traffic 
3.Threat intelligence feeds to follow C&Cs 
4.File system & registry key changes 
5.Watch your data
malware Killchain 
Awareness | Behavior | Correlation | Intelligence | Encryption 
LURE 
EXPLOIT 
INFECT 
CALL 
HOME 
STEAL 
DATA
RESOURCES 
•Eddie Sources: 
•http://www.guitarworld.com/photo-gallery-many-faces-iron-maidens-eddie 
•http://maiden-world.com/articles/history-of-eddie.html 
•http://ultimateclassicrock.com/iron-maiden-eddie-album-covers-retrospective/ 
•http://www.cyactive.com/zberp-baby-super-trojan/ 
•https://blog.malwarebytes.org/security-threat/2014/02/hiding-in-plain- sight-a-story-about-a-sneaky-banking-trojan/ 
•http://www.fortiguard.com/legacy/analysis/zeusanalysis.html 
•http://www.symantec.com/connect/blogs/brief-look-zeuszbot-20 
•http://www.reuters.com/article/2007/07/17/us-internet-attack- idUSN1638118020070717
https://sunchaser.info/fun/ed-force-one.html 
Thank you 
marion@cyphort.com 
@pinkflawd

Más contenido relacionado

Similar a Zeus' Not Dead Yet

Dominique Karg - Advanced Attack Detection using OpenSource tools
Dominique Karg - Advanced Attack Detection using OpenSource toolsDominique Karg - Advanced Attack Detection using OpenSource tools
Dominique Karg - Advanced Attack Detection using OpenSource tools
Security B-Sides
 
Devoxx France 2013 Cloud Best Practices
Devoxx France 2013 Cloud Best PracticesDevoxx France 2013 Cloud Best Practices
Devoxx France 2013 Cloud Best Practices
Eric Bottard
 
Kernel Mode Threats and Practical Defenses
Kernel Mode Threats and Practical DefensesKernel Mode Threats and Practical Defenses
Kernel Mode Threats and Practical Defenses
Priyanka Aash
 
Sophos what-is-zeus-tp
Sophos what-is-zeus-tpSophos what-is-zeus-tp
Sophos what-is-zeus-tp
Onet Paradis
 

Similar a Zeus' Not Dead Yet (20)

Dissecting ZeuS malware
Dissecting ZeuS malwareDissecting ZeuS malware
Dissecting ZeuS malware
 
Zeus
ZeusZeus
Zeus
 
Dominique Karg - Advanced Attack Detection using OpenSource tools
Dominique Karg - Advanced Attack Detection using OpenSource toolsDominique Karg - Advanced Attack Detection using OpenSource tools
Dominique Karg - Advanced Attack Detection using OpenSource tools
 
Breaking the cyber kill chain!
Breaking the cyber kill chain!Breaking the cyber kill chain!
Breaking the cyber kill chain!
 
Virtually Pwned
Virtually PwnedVirtually Pwned
Virtually Pwned
 
CEHv10 M0 Introduction.pptx
CEHv10 M0 Introduction.pptxCEHv10 M0 Introduction.pptx
CEHv10 M0 Introduction.pptx
 
Devoxx France 2013 Cloud Best Practices
Devoxx France 2013 Cloud Best PracticesDevoxx France 2013 Cloud Best Practices
Devoxx France 2013 Cloud Best Practices
 
Understand study
Understand studyUnderstand study
Understand study
 
Dissecting Zeus by Nick Bilogorskiy
Dissecting Zeus by Nick BilogorskiyDissecting Zeus by Nick Bilogorskiy
Dissecting Zeus by Nick Bilogorskiy
 
Malware's most wanted-zberp-the_financial_trojan
Malware's most wanted-zberp-the_financial_trojanMalware's most wanted-zberp-the_financial_trojan
Malware's most wanted-zberp-the_financial_trojan
 
(De)serial Killers - BSides Las Vegas & AppSec IL 2018
(De)serial Killers - BSides Las Vegas & AppSec IL 2018(De)serial Killers - BSides Las Vegas & AppSec IL 2018
(De)serial Killers - BSides Las Vegas & AppSec IL 2018
 
(De)serial Killers - BSides Las Vegas & AppSec IL 2018
(De)serial Killers - BSides Las Vegas & AppSec IL 2018(De)serial Killers - BSides Las Vegas & AppSec IL 2018
(De)serial Killers - BSides Las Vegas & AppSec IL 2018
 
Kernel Mode Threats and Practical Defenses
Kernel Mode Threats and Practical DefensesKernel Mode Threats and Practical Defenses
Kernel Mode Threats and Practical Defenses
 
Sophos what-is-zeus-tp
Sophos what-is-zeus-tpSophos what-is-zeus-tp
Sophos what-is-zeus-tp
 
Attacks and Defences
Attacks and DefencesAttacks and Defences
Attacks and Defences
 
SSL/TLS for Mortals (JavaOne 2017)
SSL/TLS for Mortals (JavaOne 2017)SSL/TLS for Mortals (JavaOne 2017)
SSL/TLS for Mortals (JavaOne 2017)
 
Basic Malware Analysis
Basic Malware AnalysisBasic Malware Analysis
Basic Malware Analysis
 
Netpluz - Managed Firewall & Endpoint Protection
Netpluz - Managed Firewall & Endpoint Protection Netpluz - Managed Firewall & Endpoint Protection
Netpluz - Managed Firewall & Endpoint Protection
 
Duck Hunter - The return of autorun
Duck Hunter - The return of autorunDuck Hunter - The return of autorun
Duck Hunter - The return of autorun
 
Nimrod duck hunter copy
Nimrod duck hunter   copyNimrod duck hunter   copy
Nimrod duck hunter copy
 

Más de pinkflawd (11)

The Magic Superpowers of a well-established "Us"
The Magic Superpowers of a well-established "Us"The Magic Superpowers of a well-established "Us"
The Magic Superpowers of a well-established "Us"
 
La Quadrature Du Cercle - The APTs That Weren't
La Quadrature Du Cercle - The APTs That Weren'tLa Quadrature Du Cercle - The APTs That Weren't
La Quadrature Du Cercle - The APTs That Weren't
 
Big Game Hunting - Peculiarities In Nation State Malware Research
Big Game Hunting - Peculiarities In Nation State Malware ResearchBig Game Hunting - Peculiarities In Nation State Malware Research
Big Game Hunting - Peculiarities In Nation State Malware Research
 
Shooting
ShootingShooting
Shooting
 
The A and the P of the T
The A and the P of the TThe A and the P of the T
The A and the P of the T
 
TS/NOFORN
TS/NOFORNTS/NOFORN
TS/NOFORN
 
How would you find what you can't see?
How would you find what you can't see?How would you find what you can't see?
How would you find what you can't see?
 
Catch Me If You Can
Catch Me If You CanCatch Me If You Can
Catch Me If You Can
 
Curing A 15 Year Old Desease
Curing A 15 Year Old DeseaseCuring A 15 Year Old Desease
Curing A 15 Year Old Desease
 
Troopers Diffray v1.1
Troopers Diffray v1.1Troopers Diffray v1.1
Troopers Diffray v1.1
 
brightfuture
brightfuturebrightfuture
brightfuture
 

Último

Hospital management system project report.pdf
Hospital management system project report.pdfHospital management system project report.pdf
Hospital management system project report.pdf
Kamal Acharya
 
Kuwait City MTP kit ((+919101817206)) Buy Abortion Pills Kuwait
Kuwait City MTP kit ((+919101817206)) Buy Abortion Pills KuwaitKuwait City MTP kit ((+919101817206)) Buy Abortion Pills Kuwait
Kuwait City MTP kit ((+919101817206)) Buy Abortion Pills Kuwait
jaanualu31
 
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
ssuser89054b
 
DeepFakes presentation : brief idea of DeepFakes
DeepFakes presentation : brief idea of DeepFakesDeepFakes presentation : brief idea of DeepFakes
DeepFakes presentation : brief idea of DeepFakes
MayuraD1
 

Último (20)

Hospital management system project report.pdf
Hospital management system project report.pdfHospital management system project report.pdf
Hospital management system project report.pdf
 
Introduction to Serverless with AWS Lambda
Introduction to Serverless with AWS LambdaIntroduction to Serverless with AWS Lambda
Introduction to Serverless with AWS Lambda
 
S1S2 B.Arch MGU - HOA1&2 Module 3 -Temple Architecture of Kerala.pptx
S1S2 B.Arch MGU - HOA1&2 Module 3 -Temple Architecture of Kerala.pptxS1S2 B.Arch MGU - HOA1&2 Module 3 -Temple Architecture of Kerala.pptx
S1S2 B.Arch MGU - HOA1&2 Module 3 -Temple Architecture of Kerala.pptx
 
Generative AI or GenAI technology based PPT
Generative AI or GenAI technology based PPTGenerative AI or GenAI technology based PPT
Generative AI or GenAI technology based PPT
 
HOA1&2 - Module 3 - PREHISTORCI ARCHITECTURE OF KERALA.pptx
HOA1&2 - Module 3 - PREHISTORCI ARCHITECTURE OF KERALA.pptxHOA1&2 - Module 3 - PREHISTORCI ARCHITECTURE OF KERALA.pptx
HOA1&2 - Module 3 - PREHISTORCI ARCHITECTURE OF KERALA.pptx
 
A Study of Urban Area Plan for Pabna Municipality
A Study of Urban Area Plan for Pabna MunicipalityA Study of Urban Area Plan for Pabna Municipality
A Study of Urban Area Plan for Pabna Municipality
 
Kuwait City MTP kit ((+919101817206)) Buy Abortion Pills Kuwait
Kuwait City MTP kit ((+919101817206)) Buy Abortion Pills KuwaitKuwait City MTP kit ((+919101817206)) Buy Abortion Pills Kuwait
Kuwait City MTP kit ((+919101817206)) Buy Abortion Pills Kuwait
 
Engineering Drawing focus on projection of planes
Engineering Drawing focus on projection of planesEngineering Drawing focus on projection of planes
Engineering Drawing focus on projection of planes
 
Orlando’s Arnold Palmer Hospital Layout Strategy-1.pptx
Orlando’s Arnold Palmer Hospital Layout Strategy-1.pptxOrlando’s Arnold Palmer Hospital Layout Strategy-1.pptx
Orlando’s Arnold Palmer Hospital Layout Strategy-1.pptx
 
Double Revolving field theory-how the rotor develops torque
Double Revolving field theory-how the rotor develops torqueDouble Revolving field theory-how the rotor develops torque
Double Revolving field theory-how the rotor develops torque
 
GEAR TRAIN- BASIC CONCEPTS AND WORKING PRINCIPLE
GEAR TRAIN- BASIC CONCEPTS AND WORKING PRINCIPLEGEAR TRAIN- BASIC CONCEPTS AND WORKING PRINCIPLE
GEAR TRAIN- BASIC CONCEPTS AND WORKING PRINCIPLE
 
Computer Lecture 01.pptxIntroduction to Computers
Computer Lecture 01.pptxIntroduction to ComputersComputer Lecture 01.pptxIntroduction to Computers
Computer Lecture 01.pptxIntroduction to Computers
 
Tamil Call Girls Bhayandar WhatsApp +91-9930687706, Best Service
Tamil Call Girls Bhayandar WhatsApp +91-9930687706, Best ServiceTamil Call Girls Bhayandar WhatsApp +91-9930687706, Best Service
Tamil Call Girls Bhayandar WhatsApp +91-9930687706, Best Service
 
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
 
Work-Permit-Receiver-in-Saudi-Aramco.pptx
Work-Permit-Receiver-in-Saudi-Aramco.pptxWork-Permit-Receiver-in-Saudi-Aramco.pptx
Work-Permit-Receiver-in-Saudi-Aramco.pptx
 
data_management_and _data_science_cheat_sheet.pdf
data_management_and _data_science_cheat_sheet.pdfdata_management_and _data_science_cheat_sheet.pdf
data_management_and _data_science_cheat_sheet.pdf
 
NO1 Top No1 Amil Baba In Azad Kashmir, Kashmir Black Magic Specialist Expert ...
NO1 Top No1 Amil Baba In Azad Kashmir, Kashmir Black Magic Specialist Expert ...NO1 Top No1 Amil Baba In Azad Kashmir, Kashmir Black Magic Specialist Expert ...
NO1 Top No1 Amil Baba In Azad Kashmir, Kashmir Black Magic Specialist Expert ...
 
DeepFakes presentation : brief idea of DeepFakes
DeepFakes presentation : brief idea of DeepFakesDeepFakes presentation : brief idea of DeepFakes
DeepFakes presentation : brief idea of DeepFakes
 
Thermal Engineering -unit - III & IV.ppt
Thermal Engineering -unit - III & IV.pptThermal Engineering -unit - III & IV.ppt
Thermal Engineering -unit - III & IV.ppt
 
Employee leave management system project.
Employee leave management system project.Employee leave management system project.
Employee leave management system project.
 

Zeus' Not Dead Yet