Showing posts with label banker. Show all posts
Showing posts with label banker. Show all posts

Thursday, 27 June 2013

Carberp C&C

And here we go, first Carberp panel i break from the leak, surely a test one, gateway was badly configured like domains.

Login:
To view the login page sometime you need a special key like:
/login/?x=11111111111111111111111111111111

It was not required on this server but if you want an example let's try on another Carberp C&C.
Without:
 With:

Dashboard, License Information:

Statistics:

Bots:

Diagram:

Search:

P2P:

Host:

Tasks:

Add a task:

Links:

Logs:

Filters:

Cab-files:

iBank:

Keylogger:

Add program:

Recycle bin:

AutoSystem:

Add domains:

Builds:

Add builds:

Settings:

Users:

User settings:

User permissions:

Edit user:

User information:

About my previous post, fun fact: in 2011 i've already found traces of logs in a C&C, and mystic compressor was used on the sample.
(14:44:15) Павел: надо в админку добавить
1. смотреть все логи по одному боту!
(14:44:27) Павел: показать всех ботовс RU онлайн чисто! логи по ним
(14:44:30) Павел: чтоб глядеть есть ли баги и тд
(14:45:40) aksoft@188.72.206.204/work: оказать всех ботовс RU онлайн чисто! логи по ним - это уточни
(14:45:57) Павел: ну вот чтобы вывод фильтровало
(14:46:14) Павел: нашло всех ботов у которых такая строка в логах есть:
isOfflineVersion = false isOnlineVersion = true
(14:46:18) Павел: language = RUS
(14:46:30) Павел: и после этого логи по ним всем чисто показала! лог вывела
http://www.kernelmode.info/forum/viewtopic.php?f=16&t=747

Friday, 15 July 2011

Trojan.Banker who target Caixa Penedès users



MD5: 47f21ce56d728992d6453823e5989b0e

Another phishing application, when run:

No Close button but can be closed with ALT+F4, fake login page:

Last page to complete:

Data submitted to bad guys:

Update successfully blah blah blah:

Related ~
Santander: Beware of fake banking applications (30 Apr 2k11)

Saturday, 30 April 2011

beware of fake banking applications



Well, this is not a new threat but they update it frequently and since months now...
I've started to have a look with SpamLoco, it's alway a very realistic phishing application.


You can't close this application (use ALT+F4) and the window is alway on top.

Here it simulate an activity with the bank (in reality your entered data are sent to a pirate)

Another one (we see it much)
Window is alway on top and.. oh there is a close button !

But you can't close it, until you have sent your datas (use taskmgr for kill the process)

So, let's complete what he want with some junks

This really look legit..

The last page to complete:

A variant:

And finaly...what a surprise:

The monitored network activity after pushing the 'complete button':

"ok.html" is an error page.. alright....


They even forget to add a correct title to the page.

------

You can view these sites for more details:
Phishing bancario con aplicaciones falsas para Windows
Rastreando a un phisher
New Brazilian Banking Trojans Alert