Wednesday, 29 May 2013

Infiltrating malware servers without doing anything

Today i was searching more samples of BlackPOS because this malware use FTP protocol.
And knowing this, i was interested to crawl more panels but then i realised something...
Why did i look only for BlackPOS, instead of targeting everything ?
So i downloaded a random malware pack found on internet and send everything to Cuckoo.
After i've just parsed each of these generated pcaps to get some stuff (simple but effective)
Everything automated of course, it's too enormous to do that manually, especially on malware pack.

pcap junkie.

Here is a small part:
ftp://u479622:y6yf2023@ - Win32/Usteal
ftp://4bf3-cheats:hydsaww56785678@ - Win32/Usteal
ftp://u445497390:090171qq@ - Win32/Usteal
ftp://raprap8:9Y7cGxOW@ - Win32/Usteal
ftp://u195253707:1997qwerty@ - Win32/Usteal
ftp://pronzo_615:f4690x0nq8@ - Win32/Usteal
ftp://lordben8:xCoMFM2c@ - Win32/Usteal
ftp://u698037800:denisok1177@ - Win32/Usteal
ftp://u268995895:vovamolkov123@ - Win32/Usteal
ftp://b12_8082975:951753zx@ - Win32/Ganelp.gen!A
ftp://oiadoce:cremado33@ - Win32/Delf.P
ftp://cotuno:nokia400@ - Win32/SecurityXploded.A
ftp://fake01:13758@ - WS.Reputation.1
ftp://h51694:2222559@ - Win32/Usteal - Win32/Usteal
ftp://b12_8082975:951753zx@ - Win32/Usteal
ftp://h51694:2222559@ - Win32/Ganelp.E
ftp://450857:6a5124c7@ - Win32/Ganelp.gen!A
ftp://b12_8082975:951753zx@ - Win32/Ganelp.gen!A
ftp://getmac:8F4ODYLQlvpjjQ==@ - Win32/Ganelp.G
ftp://u797638036:951753zx@ - Virus.Downloader.Rozena
ftp://b12_8082975:djdf3549384@ - Win32/Ganelp.gen!A
ftp://onthelinux:741852abc@ - Win32/Ganelp.E
ftp://b12_8082975:951753zx@ - Win32/Ganelp.E
ftp://450857:6a5124c7@ - Win32/Ganelp.gen!A
ftp://u206748555:as3515789@ - Win32/Usteal - Win32/Usteal
ftp://griptoloji:3INULAX@ - Win32/Usteal
ftp://u459704296:ded7753191ded@ - Win32/Usteal
ftp://dedmen2:reaper24chef@ - Win32/Usteal
ftp://srv35913:JLN18Hp7@ - F*ck this shit
ftp://ftp1970492:ziemniak123@ - F*ck this shit
ftp://dron2258:NRm8CNfW@ - F*ck this shit
ftp://u996543000:123456789a@ - F*ck this shit
ftp://u500739002:jd7H2ni99s@ - F*ck this shit
ftp://0dmaer:1780199d@ - F*ck this shit
ftp://u404100999:vardan123@ - F*ck this shit
ftp://a9951823:www.ry123456@ - F*ck this shit
ftp://u194291799:80997171405@ - F*ck this shit
ftp://u478149:qqgclnbi@ - F*ck this shit
ftp://u114972719:1052483w@ - F*ck this shit
ftp://a1954396:omeromer123@ - F*ck this shit - F*ck this shit
ftp://fr32920:Nw3hRUme@ - F*ck this shit
ftp://u974422848.root:vertrigo@ - F*ck this shit
ftp://u205783311:gomogej200897z@ - F*ck this shit
ftp://u188483768:andrewbogdanov1@ - F*ck this shit!@ - F*ck this shit
ftp://agooga:nokiamarco@ - F*ck this shit
ftp://nicusn:n0305441@ - F*ck this shit
ftp://u355595964:xmNmK4CfvX@ - F*ck this shit
ftp://fmstu421:oxjQG1i7@ - F*ck this shit
ftp://u651787226:123698745s@ - F*ck this shit
ftp://u492312765:530021354@ - F*ck this shit
ftp://mandaryn:m0jak0chanaania@ - F*ck this shit
ftp://spechos8:onxGoTDG@ - F*ck this shit
ftp://6fidaini:vardan123@ - F*ck this shit
ftp://8steamsell:frozenn1@ - F*ck this shit
ftp://u478644:57zw1q56@ - F*ck this shit
ftp://u478230:lytlz3ub@ - F*ck this shit
ftp://u730739228:warhammer3@ - F*ck this shit
ftp://sme8:y6kByIZA@ - F*ck this shit - F*ck this shit
ftp://u457127536:741852963q@ - F*ck this shit
ftp://u450728967:987456987@ - F*ck this shit
ftp://u730739228:warhammer3@ - F*ck this shit
ftp://0lineage2-world:plokijuh@ - F*ck this shit
ftp://expox@1:0628262733Y@ - F*ck this shit - F*ck this shit
ftp://ih_3676461:123456@ - F*ck this shit
ftp://0alfa-go-cs:killer2612@ - F*ck this shit
ftp://5nudapac:nudapac@ - F*ck this shit
ftp://450857:6a5124c7@ - F*ck this shit
I've added signature manually by browsing VirusTotal report but i got too many results so i've just leaved 'F*ck this shit' to all of them.
Crawling VirusTotal with the API can be also an idea to retrieve results but i'm lazy.

Looking at random pcap i've found some was fun:
Malware using free hosting service is a bad idea:

Malware builded with wrong datas (epic failure)

Malware badly coded:

Infecting yourself with Ardamax and enabling all features on it is a bad idea:

Another configuration failure:

FTP's  full of sh*t:

You can learn about actors, eg from dedmen2@, emo boy (i've included him on the ftp list):
Protip: don't buy a Nikon Coolpix L14v1.0, low quality picture.

I got also some false positive, this one is fun because it's a server against malware infection:
I have no idea why UsbFix was on a malware pack, anyway the use of FTP protocol for legit tools is also a bad idea, and this is not the only 'anti-malware' server i've found, got some weird stuff for viral update and many others, this technic is a double edged sword but most of result lead on malware servers.


  1. Have you found any citadel and zeus game over in the wild?

  2. they include the fixes to block out other malware...

  3. software that record your videos? name

  4. j don't get it. All of this Ftp are allmost clear or have a few dumps of data (.bin probalby from Usteal). Most of them are random rubish or websites. Some doesn't have any malware data so why the hell did you publish some private fps with login and passwords?And why they are called malware servers?

  5. It's all a free FTP server's ore hacked ftp servres.
    All malware report must be encrypted. In some timout botmaster take and delete new report from server.
    Botmaster don't need buy a server for report! It's dont a bug it's a feature ^)

  6. Ahahahaha owned!!!

  7. Heh. Somebody is trying to frame Glavmed in the ftp credentials