[00:02.400 --> 00:06.340] And the purpose of this talk is it's going to be mostly introductory. [00:06.680 --> 00:21.040] We're going to go over the common tools that are used, where they can be gotten, their availability, their functionalities, and then after that, how they're used, how the stolen data is converted into cash, and then how to obtain that cash. [00:22.200 --> 00:28.820] The tools of the trade that we're going to be going over, we have four common commercial exploit kits. [00:28.940 --> 00:31.480] We have the Eleanor Exploit Kit and Fragus. [00:31.700 --> 00:35.060] Those are very common drive-by download software. [00:35.680 --> 00:40.000] For actual payloads, we'll be going over the Zeus Trojan and SpyEye. [00:40.360 --> 00:48.540] Zeus has been pretty much the standard of digital crime since about 2007, and SpyEye has recently emerged as a competitor. [00:48.540 --> 00:59.980] And then, as for the monetization of stolen data, we're going over resale, carding, wire transfers, fake merchant accounts, and then the actual cashing out and laundering of it. [01:02.720 --> 01:08.580] For common methods of infection, the way... I'm sure many of you have experienced it or seen it. [01:08.780 --> 01:13.420] You go to a website, it has a malicious iframe in it with some malicious JavaScript. [01:13.420 --> 01:17.220] It attempts to exploit your browser, often successfully. [01:17.860 --> 01:22.580] It could use anything from a Java exploit, to a Flash exploit, to a PDF exploit, Internet Explorer. [01:22.960 --> 01:30.220] Basically, anything it can do to crash the browser, get a malicious executable pulled from anywhere on the web, infect the machine, and then own it. [01:31.480 --> 01:43.580] Without drive-by downloads, there's also ways to spread infections, you know, typical spamming through email, back-dooring torrents from dirty sites, or just with straight-up USB drive switchblades. [01:44.760 --> 01:48.100] This is a screenshot of the Eleanor exploit pack. [01:50.520 --> 01:54.120] On this screenshot, it shows a list of the operating systems. [01:54.440 --> 02:01.520] There are about 8,250 hits on Windows XP, 3,680 on Windows Vista. [02:01.520 --> 02:19.880] The exploits that this uses is the MS-09002, which is an Internet Explorer 6 exploit, MDAC, Java exploit, and this PDF 2012, this was the old PDF 0 day that was made a big deal about a few months ago. [02:20.420 --> 02:25.380] It's since been patched, but this exploit kit was hitting it before it was patched. [02:26.160 --> 02:29.880] And this is the statistics page of the exploit pack. [02:30.040 --> 02:34.560] They're very organized, they're very sophisticated content management systems. [02:34.920 --> 02:41.440] This is keeping track of every browser that touches the exploit kit, how many hit it, and how many successful exploitations it had. [02:42.020 --> 02:48.080] The most successful one on here was, the most commonly used, was Internet Explorer 8. [02:48.260 --> 02:55.240] And it had, from 5,000 hits, they had about 425 successful infections, which is about an 8.13 success rate. [02:55.820 --> 02:59.220] And on Internet Explorer 6, they had a 12% infection rate. [02:59.420 --> 03:05.280] They hit about 209 of 1,716 infected machines. [03:05.440 --> 03:08.760] And those are, those are successfully deployed payloads. [03:08.900 --> 03:12.700] So that's, they're building up quite a nice little botnet with this package. [03:13.860 --> 03:19.480] This is a, this is a screenshot of the installer page of the unique exploit pack. [03:19.860 --> 03:21.280] A competitor to Eleanor. [03:21.620 --> 03:23.080] Very similar functionalities. [03:23.480 --> 03:29.140] All these exploit kits operate in a standard PHP MySQL content management system. [03:29.340 --> 03:30.940] They've got the MySQL database. [03:31.380 --> 03:33.900] The exploits are kept in PHP files. [03:34.380 --> 03:39.600] And then they're called upon once they're, once they're hit from the, from the malicious iframe. [03:41.620 --> 03:43.720] This is the Phoenix exploit kit. [03:44.140 --> 03:46.640] Another competitor to the other two. [03:47.160 --> 03:49.740] They all pretty much serve the same purpose. [03:50.060 --> 03:53.600] They generate iframes on the fly with known exploits. [03:54.020 --> 03:55.240] And sometimes zero days. [03:55.380 --> 04:00.920] These kits usually go for a few hundred dollars to a few thousand dollars on carding forums or any other malware forum. [04:01.440 --> 04:05.200] You can usually buy them directly from the author or through resellers. [04:05.200 --> 04:10.620] A lot of times resellers will backdoor them so that they can, so that they can also get access to the compromised machines. [04:12.200 --> 04:13.880] This is one of the nicer ones. [04:13.980 --> 04:15.420] This is the Fragas exploit kit. [04:15.580 --> 04:17.520] It's got a real spiffy Ajax interface. [04:18.060 --> 04:20.820] It's got, you, you don't have to know anything about coding. [04:20.960 --> 04:22.660] You don't need to know how to write HTML. [04:22.740 --> 04:23.760] You don't need to know an iframe. [04:23.900 --> 04:27.340] You can pretty much pay someone to install this on a, on a host for you. [04:27.340 --> 04:32.060] And you can just start generating the code you need to start sticking places and infecting people. [04:32.760 --> 04:37.140] It's, it's even, as you can see in the bottom, it's got a, you know, check boxes of which exploits you want to hit. [04:37.720 --> 04:41.460] The MDAC exploit, more Internet Explorers, PDF ones. [04:42.000 --> 04:45.180] It'll, you can just have it select all of them and hit all of them. [04:45.240 --> 04:48.760] Or you can just target specific exploits if you know the traffic that's going to be hitting the page. [04:49.840 --> 04:52.720] Normally, the, a browser will hit the page once. [04:53.100 --> 04:54.540] It'll attempt to exploit. [04:55.080 --> 04:57.980] And then when you, and then it'll redirect you to something innocent like Google. [04:58.120 --> 05:01.680] So you don't really know what happened until you start to see your machine behaving strangely. [05:04.000 --> 05:09.940] And what is the payload that is most commonly deployed with the, with exploit kits? [05:10.220 --> 05:12.040] The most common one is the Zeus Trojan. [05:12.400 --> 05:17.440] It's used by pretty much all the miscreants of the, of the, of the web. [05:17.440 --> 05:21.380] You've got spammers, script kitties, organized crime, fishers, um, carters. [05:21.640 --> 05:27.780] They, they, um, this is kind of a, a one size fits all Trojan that will, that does all sorts of nastiness. [05:28.040 --> 05:31.000] Um, it can be propagated through any of the methods we just discussed before. [05:31.320 --> 05:35.220] Spam, phishing, peer to peer, um, and iframes on malicious websites. [05:35.720 --> 05:42.160] And the way it works is it will, it'll hook into a lot of malware will just create a separate service. [05:42.280 --> 05:44.820] You, when you press control, alt, delete, you'll see some weird thing in your task manager. [05:44.820 --> 05:47.200] Maybe check your msconfig, you'll see some weird things running. [05:47.800 --> 05:48.800] Zeus will not do any of that. [05:48.940 --> 05:50.780] Zeus will hook services.exe. [05:50.900 --> 05:55.060] It'll act like a legit, it'll act like a legitimate Windows process and run silently. [05:55.600 --> 06:00.740] Um, every 25 minutes, it'll beacon out to the command and control server with an encrypted post request. [06:00.880 --> 06:02.580] It's encrypted with RC4 encryption. [06:03.100 --> 06:06.620] And, um, Zeus is also very similar to the exploit kits. [06:06.740 --> 06:15.160] It's just a PHP MySQL, um, uh, interface with, um, with an executable that's, that's built with, uh, with a builder that comes with the package. [06:15.660 --> 06:20.120] And every half hour, an infected machine will beacon out to the, to the command and control server. [06:20.120 --> 06:23.780] And it'll have a log of all the post requests that's been sent. [06:23.900 --> 06:27.300] All the, all the bank logins, all the view states, all the, uh, all the cookies. [06:27.940 --> 06:30.540] Um, every, um, uh, every credit card number. [06:30.640 --> 06:33.340] Every form field that's been entered and sent in a post request. [06:33.620 --> 06:37.840] It will log it, encrypt it with RC4, and then beacon it out to the command and control server. [06:38.020 --> 06:38.740] On port 80. [06:38.740 --> 06:44.480] So, you, you, you, if you're looking for traffic on weird ports and weird traffic, you're not going to find it. [06:44.600 --> 06:47.360] Because it's just, it's just using, uh, it's behaving as it should. [06:47.520 --> 06:55.220] You know, you, the only, you, the only thing that can be really done is just look for RC4 traffic coming out over port 80 to some weird website that you've never heard of. [06:56.200 --> 07:01.480] Um, this is, uh, this is a screenshot of the Zeus command and control interface. [07:01.740 --> 07:03.300] This, uh, this is an, an older version. [07:03.420 --> 07:05.320] The newest version is, uh, 2.0. [07:05.460 --> 07:06.880] It still looks pretty much the same. [07:06.880 --> 07:15.260] Um, this is, uh, this, these, the software retails for about 200 to, 200 bucks to five, to five grand. [07:15.520 --> 07:17.500] Um, there's a few leaked versions that are out for free. [07:17.940 --> 07:19.820] Um, of course, those are, those are backdoored. [07:20.000 --> 07:22.160] If you, if you use those, someone will quickly take over. [07:22.940 --> 07:35.700] And, um, this, this, uh, particular one that we got access to the command and control center of, it had, uh, 5,000, uh, 5,000, uh, 675 infected machines and 4,900,000 reports in the database. [07:35.700 --> 07:42.300] So this, it was a very, it was an old botnet that had been sitting around for a while just collecting data from these 6,000 infected machines. [07:42.520 --> 07:45.280] And it eventually built up to 4.9 million reports. [07:45.500 --> 07:49.900] And that's, that adds up to a lot of passwords, credit card numbers, and session cookies. [07:51.120 --> 07:53.600] Um, here's, uh, an example of the report header. [07:53.920 --> 07:56.600] Um, I've blacked out, you know, relevant information. [07:57.060 --> 07:59.000] It's, uh, here's, it gives the bot ID. [07:59.200 --> 08:03.020] Each infected machine will have an, uh, a unique identifier for that machine. [08:03.640 --> 08:07.480] Um, it'll tell you the version of the, of the payload that infected the machine. [08:07.720 --> 08:11.060] What, it'll fingerprint the entire operating system, give you the IP address. [08:11.320 --> 08:17.280] And at the bottom where it says source, um, this is a log from when it jacked some PayPal, some PayPal credentials. [08:18.520 --> 08:21.420] On this next page, we see the report of that. [08:21.800 --> 08:23.800] Um, and it's, it's grabbed everything. [08:24.060 --> 08:29.880] Uh, the login email, login password, first name, last name, credit card number, last three digits, billing address. [08:30.500 --> 08:33.820] Um, the, uh, an additional email address, city, state, zip. [08:34.220 --> 08:39.920] Everything you need to, to pretty much do any type of fraud that, um, that you would like. [08:40.520 --> 08:44.060] Um, now, Zeus also has many plugins available. [08:44.060 --> 08:50.220] Third-party plugins that are targeted, uh, that are targeted directly for financial institutions. [08:50.360 --> 08:52.020] Primarily, Zeus is a banking Trojan. [08:52.160 --> 08:55.140] It targets financial institutions so that money can be stolen. [08:55.800 --> 09:01.640] Um, there are plugins that are written and using a function called web, uh, the web injects of, of Zeus. [09:01.860 --> 09:09.940] Where it will rewrite the HTTP response, um, for, for your, um, when you log into your bank and you get the HTTP response for the screen. [09:10.300 --> 09:13.560] It will give, it'll inject additional form parameters. [09:13.560 --> 09:18.340] And those form parameters will be what's required to initiate a wire transfer. [09:18.560 --> 09:21.660] But you'll just think it's your bank asking for additional security questions. [09:21.660 --> 09:24.880] Oh, they're, they're increasing their security, so you fill out the form. [09:25.400 --> 09:30.360] Um, as soon as you fill those out, it goes back to this, it checks in with this mule software. [09:30.600 --> 09:37.000] And on this specific one, um, it tells it to automatically transfer between $5,000 to $7,000 the moment that it comes through. [09:37.600 --> 09:45.260] And so, the moment that the form is filled out, it does a cross-site request forgery to the, to the bank and transfers the money out to a mule account. [09:45.460 --> 09:47.520] And this is a mule CMS, um, program. [09:47.820 --> 09:53.240] And every day, uh, it's, it's scheduled as soon as someone logs in, it'll initiate this transfer. [09:53.240 --> 09:59.500] So, they'll be pulling, even if they're just pulling one person a day, that's still $5,000 to $7,000 a day that they're doing. [09:59.660 --> 10:04.420] And they're definitely doing it to more than one person if they have several, uh, several thousand machines on their botnet. [10:04.980 --> 10:13.600] And, um, it's, the, one of the, one of the real, um, real nice mule software, uh, is called, um, URL Zone. [10:13.840 --> 10:26.540] Where it'll do the, it'll, it'll do that, but in addition to injecting the forms and initiating a wire transfer in the back end, it will rewrite your statement on the HTTP response so you don't see a balance change. [10:26.740 --> 10:30.060] It looks like nothing has taken place until you actually go to the ATM. [10:31.920 --> 10:36.640] And, um, Zeus is also, uh, notoriously difficult to detect. [10:36.980 --> 10:43.920] Um, I took a payload from the Zeus tracker, which is, uh, a, a tracker that monitors a known Zeus command and control servers. [10:44.160 --> 10:46.400] I, I just took a payload directly from the tracker. [10:46.560 --> 10:47.420] It had been around for months. [10:47.500 --> 10:48.660] It was well known. [10:48.820 --> 10:49.500] It was flagged. [10:49.600 --> 10:51.260] And I uploaded it to VirusTotal. [10:51.560 --> 10:53.100] Less than half detected it. [10:53.320 --> 10:56.540] After, I'd say about, at the time it had been about six months. [10:56.540 --> 11:00.680] Uh, less than half detected that the, this specific public Zeus payload. [11:01.000 --> 11:03.060] Um, it was for the 19 out of 40. [11:03.820 --> 11:12.240] Um, I decided to take that a little further and just run the executable through a very common free, uh, code obfuscation. [11:12.440 --> 11:16.080] Uh, this program is made for legitimate developers to protect their code. [11:16.200 --> 11:18.860] If they want to add licensing, they want to prevent people decompiling it. [11:18.860 --> 11:22.140] Uh, there's a, a, a million and one legitimate uses for this program. [11:22.300 --> 11:29.040] But if you also run malware through it, it rewrites the signature and makes it much more difficult to detect from antiviruses. [11:29.280 --> 11:34.240] So I took this known payload, ran it through the, ran it through the obfuscator and re-uploaded it to VirusTotal. [11:37.520 --> 11:42.860] And, and, and only five out of 41 detected it. [11:43.040 --> 11:46.340] The, it dropped from, uh, dropped down to 12%. [11:46.980 --> 11:50.400] Um, everything pretty much failed it. [11:50.480 --> 11:53.740] Even the ones that flagged it only flagged it as suspicious. [11:54.000 --> 11:55.160] They didn't flag it as malware. [11:55.300 --> 11:58.320] They didn't flag it as, um, the Zeus Trojan or Z-Bot. [11:58.320 --> 12:01.280] They just said, something's off about this. [12:01.360 --> 12:02.460] You might want to look into it. [12:02.880 --> 12:05.040] But everything else gave it, gave it the green light. [12:08.360 --> 12:11.080] And competing with Zeus is SpyEye. [12:11.620 --> 12:14.000] Um, it's, uh, very similar. [12:14.340 --> 12:15.660] Um, it's got a much nicer interface. [12:15.660 --> 12:16.960] They make use of Ajax. [12:17.240 --> 12:22.400] Uh, sells for about 500 bucks and it will clean your Zeus infection when you get hit with it. [12:22.400 --> 12:24.600] The, the, the reason it does this. [12:26.240 --> 12:30.540] The, the, the reason it does this is it wants to be the only banking malware on the machine. [12:30.760 --> 12:35.120] It, it, it, you know, the, the, the author said in an interview with, uh, the malware intelligence blog. [12:35.360 --> 12:43.100] He was saying that, uh, we're going to start seeing trends where malware authors will implement better antivirus solutions than the antivirus vendors. [12:43.300 --> 12:44.500] Not because they care. [12:44.580 --> 12:45.660] They just don't want the competition. [12:45.860 --> 12:49.700] They don't want weird conflicts preventing data from going to where it's supposed to go. [12:49.700 --> 12:54.820] So, so, SpyEye will clean Zeus infections, but leave you with SpyEye. [12:56.580 --> 12:59.480] And here's another screenshot of the, of the statistics panel. [12:59.640 --> 13:03.180] I blanked out the, the IP addresses, um, you know, for obvious reasons. [13:03.340 --> 13:05.720] And, uh, it's, it's a much nicer interface. [13:05.880 --> 13:10.120] It has, um, it's, uh, it's, uh, it's all, all Ajax based. [13:10.120 --> 13:13.120] And, um, it's, it's, it's very nice. [13:13.300 --> 13:21.880] And the, the payload is also more difficult to detect than Zeus because it is, uh, it is used by far less people. [13:21.880 --> 13:34.880] And, um, we, we, uh, actually found, um, uh, found, uh, a website where someone had uploaded a copy of the SpyEye Trojan and 50 out of 50 failed the antivirus test. [13:35.060 --> 13:38.200] It, it was, it completely sailed through 100% clear. [13:38.740 --> 13:41.600] And, um, the, and that, I, that's not uncommon. [13:41.780 --> 13:44.880] That's the majority of these types of malware. [13:44.880 --> 13:48.040] The only ones that are getting caught are real big sloppy campaigns. [13:48.560 --> 13:54.680] If someone wants to, if someone really wants to set it up, you know, antivirus isn't going to fix it. [13:54.760 --> 13:56.020] You're, you're, you're still going to get hit. [13:56.720 --> 14:03.440] And you're not, and you won't even know it because on most times you get hit with malware, you start getting pop-ups, your machine gets slow. [14:03.720 --> 14:06.460] There's a whole bunch of indicators that something's wrong. [14:06.860 --> 14:08.160] These run silently. [14:08.560 --> 14:12.400] They're, they're, they're designed so that you, you think everything is okay. [14:12.540 --> 14:13.800] Your computer's running as normal. [14:13.800 --> 14:19.860] It's just, it's keeping a little log and then beaconing out an encrypted post every half hour to the command and control center. [14:20.640 --> 14:26.840] And, um, it's, it's, uh, it's been very effective over the last several years and it's calling, it's causing a lot of problems. [14:28.000 --> 14:34.220] Now, once you have all this data, you know, say there's the, the people with the five million reports, what do they do with it? [14:34.500 --> 14:41.720] Well, they can either sell it to other fraudsters, which is a very common, um, there's Internet forums all over the place where they're selling Zeus data and credit card data. [14:41.720 --> 14:50.200] They can either sell it by the gigabyte if they don't want to sort it, or they can break it up and go through it and analyze and sell it, uh, sell it individually if they want to invest the time. [14:51.220 --> 14:59.600] Um, they, they could use that data for carding where, you know, just typically ordering stuff, having it sent to a drop or, you know, just typically, you know, old known carding. [14:59.600 --> 15:10.240] And, um, one of the, one of the interesting things is, uh, a lot of them are, there's been a case where the FTC just discovered, um, about $10 million of fraud through a hundred different merchant accounts. [15:10.240 --> 15:15.840] And basically what some people had done is they had set up several hundred merchant accounts in different states. [15:16.380 --> 15:20.640] And it, it, in order to create a corporation in most states, there's really no verification for it. [15:20.700 --> 15:21.680] You can just do it online. [15:21.680 --> 15:25.140] As long as you have a valid credit card, you can become, uh, you can incorporate. [15:25.400 --> 15:26.780] And that's not a problem for these guys. [15:27.420 --> 15:31.120] And they're, um, so they'll create a few hundred corporations in different states. [15:31.120 --> 15:41.940] Uh, then using fake IDs to establish those and fake IDs to establish merchant accounts, they will start charging each card from a, from a big breach or from a big botnet, just a few cents each. [15:42.180 --> 15:45.580] And they will, they will make, uh, ridiculous sums of money from this. [15:45.820 --> 15:53.480] And since it's just a few cents, the majority of the people aren't gonna call for a chargeback to question some 50 cent charge or even a $1.50 charge. [15:53.480 --> 16:01.200] And, um, this, this kind of developed after, uh, after a while, uh, carters were using charities as checking services to check the validity of their cards. [16:01.340 --> 16:04.900] They charged 25 cents, 50 cents, um, you know, through a, through a charity. [16:05.040 --> 16:06.380] If the card works, it's valid. [16:06.760 --> 16:15.220] They decided, let's not, you know, let's, what, why give money to charity when we could just create merchant accounts and, and start getting the money. [16:15.300 --> 16:20.220] And they, they made about 10 million bucks on this one instance that the FTC was able to pop. [16:20.340 --> 16:22.140] And this is just one that they were able to find. [16:22.800 --> 16:25.940] And then there's also affiliate program fraud, which is also very popular. [16:26.440 --> 16:31.280] Set up affiliate accounts, pay-per-click, you know, resale, commission-based, pay-per-lead, any of those. [16:31.860 --> 16:36.600] Um, set it up with fake, fake ID info, um, or, or, or real ones if they don't care. [16:37.000 --> 16:40.480] And, um, then just start using stolen cards to purchase stuff. [16:40.660 --> 16:50.900] And if it's a digital product, like an e-book or something, or from, there's a case where people, a group of people in California uploaded their own song to iTunes and then used a whole bunch of stolen credit cards to download it over and over again. [16:50.900 --> 16:53.920] But they, they got caught because it was, they put the real info. [16:54.040 --> 16:54.380] They're stupid. [16:55.040 --> 17:01.180] And, um, and, um, and then you can also, um, it's also used for, for pay-per-click fraud. [17:01.320 --> 17:07.440] Uh, where you can take all the infected, um, and that's, that's, uh, another thing about these, about the Zeus botnet and the SpyEye botnet. [17:07.440 --> 17:10.760] Every infected machine becomes a SOCKS5 proxy. [17:11.420 --> 17:15.320] And they get a list of SOCKS, of all the infected machines that are currently online. [17:15.840 --> 17:18.820] So, each one of those, you can bounce through to do whatever you want. [17:18.920 --> 17:19.820] And it'll be by region. [17:20.000 --> 17:23.140] So, if you want to commit, uh, if you want to rip off a U.S. [17:23.240 --> 17:24.740] merchant, you use a U.S. [17:24.860 --> 17:26.740] proxy and do what you need to do. [17:26.740 --> 17:29.680] And there are, and you get lists of thousands. [17:29.960 --> 17:35.440] And, uh, you can chain those up and they'll use it for pay-per-click fraud, denial of service, uh, anything like that. [17:35.920 --> 17:42.660] And then the, the most popular one, and, uh, as we saw with the Mule software, is fraudulent wire transfers. [17:43.640 --> 17:48.560] And, um, with the, they'll use any, it doesn't just have to be a bank. [17:48.640 --> 17:52.360] It could be any, uh, any account that you can fund. [17:52.500 --> 17:58.440] It could be a gambling account, bank account, affiliate account, uh, pretty much anything that you send money and it funds it. [17:58.520 --> 18:01.220] If they get the credentials, they will attempt to withdraw it. [18:02.760 --> 18:03.900] And how is this done? [18:03.900 --> 18:09.920] Um, they are, they, through the use of Mule accounts is, uh, is a popular one. [18:10.240 --> 18:16.010] Um, there's, I'm sure, uh, a lot of you have seen spam, you know, work from home, become a payroll consultant. [18:16.720 --> 18:18.300] You know, human resources from your house. [18:18.640 --> 18:23.520] And, uh, basically it'll be someone with a, a, a bunch of stolen banking creds. [18:23.640 --> 18:27.460] And they need, they need someone to go and open up checking accounts that they could wire the money into it. [18:27.580 --> 18:29.560] And they could keep some of it and then forward it on. [18:29.940 --> 18:33.880] And a lot of them are, are just people who are getting scammed from, you know, they, they're really thinking about it. [18:33.880 --> 18:34.780] They're working from home. [18:34.940 --> 18:36.220] They answered a Craigslist ad or something. [18:36.800 --> 18:39.620] And then there's other people who are, they, they're in on it. [18:39.780 --> 18:46.420] And they know it's up and they'll use fake IDs or they'll just, they'll just say, they'll use the real info and be like, Oh, I, I responded to an ad on Craigslist. [18:46.480 --> 18:47.580] I, I had no idea. [18:48.240 --> 18:53.720] And, um, the, I'm sure a lot of times mule, mule arrangements will be either like a 50, 50 or a 60, 40. [18:54.000 --> 19:08.320] So they'll, they'll wire in $10,000 of stolen money from a method is, uh, once, once the money's been bounced around, um, there, it usually ends up, uh, either directly cashed out or in a digital, it'll, it'll languish in a digital currency account. [19:08.320 --> 19:12.340] And, uh, before, back in the early 2000s, it was e-gold. [19:12.540 --> 19:14.820] Uh, they were based in, in Palm Beach County in Florida. [19:15.360 --> 19:19.860] Uh, Secret Service raided them because they were being used for laundering by the people who did the TJX breach. [19:20.620 --> 19:25.080] And then, uh, after that, everyone kind of moved to web money, which is basically like a Russian PayPal. [19:25.440 --> 19:28.140] And it has, uh, very, very little controls. [19:28.160 --> 19:33.860] And you can, you used to be able to move, uh, huge sums of money, uh, instantly for very little fees. [19:34.380 --> 19:37.980] Uh, Russia has implemented a lot of financial controls now. [19:37.980 --> 19:41.500] Um, you know, they have their own similar Patriot Act legislation over there. [19:41.600 --> 19:46.380] And it's caused a lot of, um, and it's caused a lot of fraudsters to move from web money to Liberty Reserve. [19:46.740 --> 19:50.520] And Liberty Reserve is a Costa Rican digital currency, uh, account. [19:50.920 --> 19:57.220] Um, you can, it's as easy to set up an account with Liberty Reserve as, you know, with a free email, a Hotmail, a Yahoo, or something like that. [19:57.440 --> 19:59.340] They'll give you, they'll just give you an account number. [19:59.620 --> 20:05.480] And so if you're, if, you know, if you're on an underground forum, you need someone to just quickly send you money, you just give them a Liberty Reserve number. [20:05.480 --> 20:13.120] They can just instantly transfer the money from their account, send a money order, or just send a wire transfer directly into the Liberty Reserve account. [20:13.560 --> 20:16.860] And it's used because it's anonymous. [20:17.640 --> 20:19.660] They pride themselves on their anonymity. [20:19.840 --> 20:25.220] It's used legitimately for a lot of Forex trading and some online gambling. [20:26.180 --> 20:30.420] But it's very popular in the fraud market because of how easy it is to use. [20:30.420 --> 20:40.340] And usually, one of the final stages of the cash-out is the transfer from the Mule account or the digital currency account into a prepaid debit card. [20:40.700 --> 20:44.800] And there's different levels of risk involved into how this is done. [20:46.140 --> 20:50.440] A lot of people who get caught will do it the quickest way, though. [20:50.740 --> 20:52.380] They'll have banking creds. [20:52.480 --> 20:55.760] They'll have access to an account with money. [20:55.760 --> 21:01.220] And they'll just quickly, as fast as they can, transfer everything they can to a series of prepaid debit cards. [21:01.340 --> 21:02.900] And then they'll start pulling the money out. [21:04.260 --> 21:06.420] But, you know, cameras are at ATMs. [21:06.560 --> 21:07.820] You know, you have to walk into a place. [21:07.840 --> 21:08.320] You walk out. [21:08.440 --> 21:09.060] There's time stamps. [21:09.280 --> 21:16.640] There's a lot of ways to get caught doing that, especially when they see the destination of, you know, it's like, okay, this came from a known compromised account. [21:16.640 --> 21:22.440] And it's going to a prepaid debit card of a, you know, unknown routing number that handles prepaid debit. [21:22.960 --> 21:26.520] So a lot of them will get frozen, or they'll just straight get arrested. [21:28.160 --> 21:31.820] And then... or you can also bounce it through the mules. [21:32.400 --> 21:37.480] You have a mule, and then you have them sent to a mule account, and then you have them send it to the prepaid debit account. [21:38.380 --> 21:40.380] And that's, you know, it's less risk. [21:41.160 --> 21:46.860] It's less chance the funds are going to get frozen, and the person who's going to get an angry knock at the door will be the mule first. [21:47.660 --> 21:56.380] And then there's... you can also bounce it through a series of mules and digital currencies and just build up the layers and make the trail much more difficult to follow. [21:56.600 --> 21:58.720] But in the end, there always is a money trail. [21:59.400 --> 22:01.520] In the United States, they will follow that money trail. [22:01.780 --> 22:05.060] They will follow it to the, you know, to your door if you're in the United States. [22:05.580 --> 22:14.720] But if you're in the Ukraine, or you're in Eastern Europe somewhere, if there's no real agreements between the U.S. [22:15.100 --> 22:20.180] government and that government, it can be very, very difficult to enforce laws that prevent this. [22:21.140 --> 22:26.420] And also, because you could... from prepaid debit cards, you don't even need to pull it out of an ATM. [22:26.560 --> 22:31.180] You can also initiate transfers out of that prepaid debit account, so you can just have it wired to you at a Western Union. [22:31.180 --> 22:35.500] And so there's plenty of methods to actually get that done. [22:35.980 --> 22:40.020] And again, some typical methods of money laundering and cash out. [22:40.480 --> 22:44.140] Take it directly from the stolen account, drop it to a prepaid card to cash it out of an ATM. [22:44.720 --> 22:50.820] Take it from an account, drop it to a mule, and have them pull the money out and physically send you half. [22:50.980 --> 22:54.760] And that's what a lot of people in Eastern Europe and Russia will do. [22:54.900 --> 22:58.840] They won't deal with any of the digital stuff. [22:58.840 --> 23:07.660] They might pay their mules in pre-loaded, prepaid debit cards, but they'll just want cash sent to their drop because it's the easiest and safest way. [23:08.980 --> 23:18.000] And then, again, you have, again, proxying it through several mules, several digital currency accounts, and then cashing it out with a prepaid card. [23:19.480 --> 23:22.620] And, again, don't try any of this. [23:22.940 --> 23:24.340] You will go to jail. [23:24.640 --> 23:27.240] They take it very seriously in the United States. [23:28.060 --> 23:30.780] They're very heavy-handed with their sentencing here. [23:31.720 --> 23:37.120] And more and more, there are more international task forces being formed to combat this type of stuff. [23:37.120 --> 23:43.880] Just an example of the heavy-handed tactics, Soup Nazi, the guy who did the TJX breach, 20 years in a U.S. [23:44.000 --> 23:44.540] federal prison. [23:44.960 --> 23:51.240] One of the people he worked with got 30 years in a Turkish prison for doing transfers out of bank accounts in Turkey. [23:51.440 --> 23:52.660] He didn't even live in Turkey. [23:52.900 --> 23:54.480] He was passing through. [23:54.600 --> 23:58.160] He was flying to vacation somewhere, and there was a stop in Turkey. [23:58.320 --> 24:03.060] And since he was known to them, they picked him up, and they're not going to let him go for the next 30 years. [24:04.800 --> 24:06.620] Yeah, and it's a Turkish prison. [24:09.020 --> 24:10.060] And mitigation. [24:12.260 --> 24:14.480] These techniques, they're going to continue. [24:16.500 --> 24:18.680] It's very difficult to stop them. [24:18.780 --> 24:22.060] The only thing you can really do is make yourself a less attractive target. [24:22.560 --> 24:23.740] Antiviruses aren't going to work. [24:23.940 --> 24:30.620] Your bank's fraud controls aren't going to work because they'll transfer the stuff out in increments and patterns that evade the fraud detection. [24:31.100 --> 24:34.720] The only thing you can really do, you know, lock your browsers down. [24:34.880 --> 24:36.260] Try to prevent iframe injection. [24:36.720 --> 24:39.000] Don't stick strange USB drives into your machines. [24:40.040 --> 24:42.520] Use NoScript on web... [24:42.520 --> 24:46.220] You know, when you're browsing around, watching TV shows or downloading wares, use NoScript. [24:46.420 --> 24:48.940] But, you know, sometimes you need websites that need... [24:48.940 --> 24:51.720] That you need to have JavaScript so you could whitelist them. [24:51.800 --> 24:54.360] But for the most part, just keep NoScript always running. [24:54.900 --> 24:55.920] Use Adblocker. [24:55.920 --> 25:04.580] A real common thing to do is if you have a malicious iframe from a program, just buy up some advertisements and here's my ad. [25:04.780 --> 25:08.920] And you just give them the malicious code and it can be embedded into an image or something. [25:09.100 --> 25:11.060] And then it'll just be served up on legitimate websites. [25:11.280 --> 25:16.020] So you can visit MySpace.com and they have a deal with an ad network that pushes an ad through. [25:16.180 --> 25:18.200] And no one has any idea that there's malicious code. [25:18.280 --> 25:20.900] And meanwhile, then you're just hitting people on MySpace. [25:20.900 --> 25:21.760] And that happened. [25:22.020 --> 25:26.000] And MySpace was delivering up malicious iframes through their advertisements a few years ago. [25:26.180 --> 25:27.520] And it continues on. [25:28.400 --> 25:30.640] Also, PDF files. [25:31.660 --> 25:32.280] There's a... [25:32.280 --> 25:33.580] Adobe calls it a feature. [25:34.260 --> 25:36.140] But you're able to... [25:36.140 --> 25:40.780] They support JavaScript and embedded executables in a PDF file. [25:41.540 --> 25:45.540] And you're able to change the text on... [25:45.540 --> 25:49.900] When you embed an executable in a PDF file and you open it up, it'll tell you... [25:50.760 --> 25:53.160] It'll tell you, warning, there's an executable in here. [25:53.240 --> 25:54.200] Are you sure you want to run it? [25:54.600 --> 26:00.000] You can pretty much hex the PDF and change that to say, this is a copyrighted PDF file. [26:00.140 --> 26:00.660] Are you sure you... [26:00.660 --> 26:03.300] You must accept the agreement in order to read the... [26:03.300 --> 26:04.520] In order to read this document. [26:04.700 --> 26:06.200] And then all of a sudden, you've gotten hit. [26:06.200 --> 26:10.880] And that's just one way, I guess, it's kind of social engineering with a PDF. [26:11.360 --> 26:14.880] But then all the time, there's always new exploits coming out for PDF. [26:15.020 --> 26:19.880] So just by having it load within your browser, it'll execute at the permission of your browser. [26:19.880 --> 26:21.180] And then you get hit. [26:22.020 --> 26:23.120] And Java applets. [26:23.500 --> 26:24.880] That's kind of like a fail... [26:24.880 --> 26:29.380] Like when an exploit kit can't hit you... [26:29.380 --> 26:30.700] Let's say you have a patched browser. [26:30.880 --> 26:33.560] You have everything you need to do. [26:33.860 --> 26:35.560] It'll launch the Java exploit. [26:35.560 --> 26:36.740] And it'll give you a pop-up window. [26:36.940 --> 26:39.220] And it'll sign it with whatever looks legitimate. [26:39.440 --> 26:41.760] It'll say, this is a Java app from Google. [26:42.800 --> 26:45.600] Because, you know, Google serves up Java apps when you hit their page. [26:46.060 --> 26:49.800] But it'll infect you. [26:50.100 --> 26:51.280] And don't accept them. [26:51.360 --> 26:54.500] Unless you're specifically expecting them. [26:54.580 --> 26:55.580] If you're logging in to work. [26:55.700 --> 26:58.820] If your bank needs you to use a Java applet. [26:59.000 --> 27:00.440] That's the only time you should be using them. [27:00.940 --> 27:03.180] Otherwise, just don't accept them because they pop up. [27:03.260 --> 27:04.660] You will get infected. [27:04.660 --> 27:08.080] And preventing an antivirus from... [27:08.080 --> 27:11.440] Regarding Trojans, you're going to get hit. [27:11.740 --> 27:13.520] The antiviruses aren't going to fix it. [27:14.080 --> 27:18.120] Just if you're downloading torrents, use a private tracker. [27:18.620 --> 27:21.660] That way, you know, people serving up malware will get kicked. [27:22.640 --> 27:26.120] And regarding the bank account theft. [27:26.120 --> 27:30.080] Don't use your debit card at gas station pumps or stores. [27:30.340 --> 27:34.180] Unless you don't mind everything being pulled out of it. [27:35.680 --> 27:41.000] It's a good thing to do is to have multiple checking accounts. [27:41.180 --> 27:45.140] One hooked into your debit card that only has a couple hundred dollars at any given time. [27:45.580 --> 27:50.140] When you need to fund the debit card, you just transfer it from another account. [27:50.360 --> 27:53.680] That will prevent if your dump gets stolen from a skimmer or something. [27:53.680 --> 27:57.720] They're not going to hit you for any more than that's on the debit card. [27:58.140 --> 27:59.280] That's not going to do anything. [27:59.440 --> 28:04.860] If your bank law gets stolen, they can have access and transfer anything every which way. [28:05.020 --> 28:06.080] But it helps. [28:06.600 --> 28:08.620] And again, you've got to be diligent. [28:08.800 --> 28:09.600] Check your bank statements. [28:09.700 --> 28:10.520] Watch your credit cards. [28:10.700 --> 28:11.320] It's a pain. [28:11.720 --> 28:14.240] But you've got to do it because they're doing it. [28:14.340 --> 28:16.060] They're checking your statements. [28:16.100 --> 28:18.400] They want to know how much money you have because they're going to take it. [28:19.280 --> 28:24.300] And bank fraud protection, they just want to charge you ten bucks a month to offer it. [28:24.380 --> 28:25.600] They're not going to do anything. [28:25.920 --> 28:28.840] At most, they'll turn it off if you make an expensive purchase. [28:28.940 --> 28:31.140] And most of the time, it's you trying to make a purchase. [28:31.140 --> 28:33.460] And you have to call and have them turn your card back on. [28:33.800 --> 28:35.380] Just monitor your own statement. [28:35.600 --> 28:41.520] You've got to take responsibility for your own statements and just be vigilant. [28:42.860 --> 28:44.740] Another warning, individual accounts. [28:45.800 --> 28:48.040] Automatically insured by FDIC for up to $100,000. [28:48.040 --> 28:54.140] And if you're hit with fraud or hit with anything like that, usually the bank or the FDIC will be able to cover you. [28:54.340 --> 28:55.900] Not the case with business accounts. [28:56.020 --> 29:01.700] And those are very ripe targets for Zeus because they'll have considerably more money than a personal account. [29:01.820 --> 29:05.820] One person might make $800 a month and that's all they'll have. [29:05.880 --> 29:10.280] But the business that's paying them will have $100,000 just sitting in their bank account. [29:10.460 --> 29:13.840] They can wire that on out and business accounts aren't insured. [29:13.840 --> 29:15.120] So they're screwed. [29:15.120 --> 29:16.220] They just eat the loss. [29:16.480 --> 29:20.260] And you shouldn't click yes on that pop-up. [29:22.060 --> 29:28.540] And if you have a business or you're just doing from home, have a dedicated machine for your online banking. [29:28.740 --> 29:30.600] Don't use Windows to log into your bank account. [29:30.700 --> 29:34.040] Just have a laptop somewhere, a cheap little netbook. [29:34.340 --> 29:36.500] Use a live CD or a live USB. [29:36.500 --> 29:42.060] And just something that's always going to be fresh when you log into your bank account. [29:42.180 --> 29:47.140] Just something that's definitely not Windows and not logging everything. [29:47.840 --> 29:52.600] Not able to be infected by one of these viruses that log everything and send it out. [29:53.520 --> 29:57.620] And some great resources are the malware intelligence blog. [29:57.800 --> 29:59.160] This is an Argentinian group. [29:59.300 --> 30:01.360] They do some very, very good work. [30:01.520 --> 30:03.040] They archive phishing pages. [30:03.560 --> 30:07.920] They have all sorts of white papers on different malware tools. [30:11.820 --> 30:18.980] That's malwareint.com, M-A-L-W-A-R-E-I-N-T.com. [30:19.420 --> 30:22.800] They have an interview with the author of SpyEye on there. [30:22.920 --> 30:24.940] And they say it's a very interesting interview. [30:25.220 --> 30:32.380] And then there's also the malware domain list, which lists URLs of known exploits, known exploit kits. [30:32.380 --> 30:36.440] And known Trojan command and control centers. [30:37.060 --> 30:43.480] And the Zeus tracker, which does the same thing as a malware domain list, but it has it specifically for Zeus. [30:43.840 --> 30:51.740] And each of these websites, the MDL and the Zeus tracker, they'll have lists, the CSV files that you can just export and add to your firewall rules. [30:51.860 --> 31:00.740] So any website that's listed on these websites, you can set it up so that no computer on your network will be able to connect to them. [31:00.740 --> 31:06.960] So that helps, but it's not going to prevent any new ones, unless you keep yourself regularly updated with their updates. [31:08.660 --> 31:10.580] And that is all. [31:10.700 --> 31:12.080] I guess I will take questions. [31:12.680 --> 31:13.400] Thank you. [31:20.930 --> 31:21.410] Yeah. [31:24.250 --> 31:30.130] Zeus and the malware sites, the command and controls that you took over, how did you find them, and how did you take them? [31:30.670 --> 31:35.170] They were listed in the Zeus tracker and on the malware domain list. [31:35.170 --> 31:38.950] And a lot of the times, the guys putting these together, they're not very skilled. [31:39.150 --> 31:41.250] They don't follow proper configuration practices. [31:41.470 --> 31:43.070] They don't really know what they're doing. [31:43.210 --> 31:44.810] Oftentimes, they'll just pay someone to set it up. [31:45.210 --> 31:50.170] So just standard web application vulnerability analysis, you can get into a good portion of... [31:51.390 --> 31:51.830] Yes. [31:52.130 --> 31:53.570] A lot of them are like that. [31:54.010 --> 31:55.750] And additional vulnerabilities as well. [31:56.470 --> 31:57.210] Any other questions? [31:57.770 --> 31:58.210] Yes. [31:58.210 --> 32:06.330] For the exploit tax or the botnet taxes or whatever, they're sold in this forum. [32:06.710 --> 32:09.740] Do the authors do anything pirate? [32:09.940 --> 32:10.400] Yes. [32:12.080 --> 32:12.620] Yes. [32:13.040 --> 32:17.680] The builders for SpyEye and the new version of Zeus, they have licensing on it. [32:17.800 --> 32:21.340] They'll license the builder to your machine. [32:21.500 --> 32:24.380] And they'll set it up like, okay, here's yours. [32:24.400 --> 32:25.660] It's only going to work on your machine. [32:25.660 --> 32:31.580] And if they upload it to the server and someone rips it, we're hoping it gets cracked eventually. [32:31.760 --> 32:36.360] But you won't be able to use the builder unless it's particularly licensed to you. [32:36.920 --> 32:38.160] And I'll leave you a question. [32:46.960 --> 32:52.220] Yeah, the Zeus tracker, it has lists of countries where the servers are held. [32:52.360 --> 32:54.960] The majority of them are in Eastern Europe and China. [32:55.100 --> 32:59.540] But there's a lot of Zeus servers being hosted in the United States as well. [32:59.540 --> 33:05.300] And they'll get taken down when they're discovered, but they're popping up every single day. [33:06.980 --> 33:07.500] Both. [33:07.640 --> 33:07.860] Both. [33:08.000 --> 33:10.080] They'll compromise websites and turn them into Zeus hosts. [33:10.320 --> 33:16.340] And they'll also just buy some hosting and hope that it stays under the radar until it gets too big. [33:28.490 --> 33:29.370] Yes, yes. [33:29.590 --> 33:30.490] A lot of the... [33:31.010 --> 33:33.310] The spy author does speak English. [33:33.610 --> 33:34.450] And he... [33:34.950 --> 33:35.390] They... [33:35.390 --> 33:36.910] I'm not sure if there's a Russian version of spy. [33:36.930 --> 33:38.050] I think it might only be English. [33:38.210 --> 33:40.430] But on Zeus, it has two settings. [33:40.550 --> 33:43.050] You can either set it to display in Russian or display in English. [33:43.350 --> 33:48.670] There's a lot of actors in Europe who use the software and don't read Russian. [33:48.670 --> 33:58.230] But the majority of the people doing it, when we look at the log files on the compromised servers, they're coming from Eastern Europe and Russia. [33:58.370 --> 33:59.670] But they could be using proxies too. [33:59.790 --> 34:00.810] If they're smart, they are. [34:01.990 --> 34:02.310] Yes. [34:02.690 --> 34:07.750] Is the list of domain names in the malware domain list, does that tie into OpenDNS? [34:11.410 --> 34:22.110] If the list on malware domain list ties into OpenDNS, I'm not exactly sure of all the details that they have on the malware domain list. [34:22.310 --> 34:26.490] The primary functionality I know is that you can export the list and add it to your firewall rule set. [34:26.710 --> 34:29.090] I don't know the specifics on the OpenDNS, though. [34:30.930 --> 34:32.030] Oh, I'm sorry. [34:32.270 --> 34:32.390] Yeah. [34:38.640 --> 34:46.610] You know, most of the time, they don't know what to do, but they, you know, in the way you explain it, they're expensive. [34:46.830 --> 34:47.270] Yes. [34:47.510 --> 34:48.910] The writers, yeah. [34:49.210 --> 34:49.350] Yes. [34:49.790 --> 34:50.430] What's your... [34:50.430 --> 34:51.010] What's your... [34:51.010 --> 34:54.130] Oh, she was saying that the... [34:54.130 --> 34:59.550] She was asking about the people using it not being very sophisticated, but the Trojans themselves are very, very sophisticated. [34:59.990 --> 35:04.690] The authors of the Trojans and the kits, they're very skilled. [35:04.870 --> 35:06.750] They know exactly what they're doing. [35:06.750 --> 35:20.970] And, but they're, they're not really using it themselves because they can make much more money selling it at very high prices to people who, who, they don't have the skill to write it, but they can navigate a, you know, a point and click GUI interface. [35:21.210 --> 35:24.230] And that those, those are mainly the people who are using it. [35:24.570 --> 35:27.890] The authors are just kind of developing the code and then selling it. [35:28.050 --> 35:29.830] And those guys, those guys are very good. [35:29.990 --> 35:36.450] And for the Zeus, the Zeus group is a, is a Russian group, but they've been, Zeus has been decompiled and then rebuilt. [35:36.710 --> 35:41.690] So it's, there are many different variants and they're, but there's primarily Eastern Europe and Russia. [35:41.890 --> 35:43.430] And the authors are very, very skilled. [35:43.650 --> 35:43.990] Absolutely. [35:44.950 --> 35:45.330] Yes. [35:49.810 --> 36:06.870] It's, it, it, it, well, in the United States it is, but if the authors are, you know, a lot of times they're in like Russia or the Ukraine and it's in those places, it's not really illegal to, to develop the code, but it can be illegal to spread it, so there, [36:07.030 --> 36:14.370] or to sell it, but it's, they're, they're, they're, they're, the, the authors are tracked, but they haven't caught them at all. [36:14.630 --> 36:16.350] I'm sorry, you and then we'll go to you. [36:17.430 --> 36:25.890] So, things like Zeus, they put out posts on a defined interval, usually using RC4 encryption. [36:26.190 --> 36:31.290] Have you had any experience with using an IDS system, that's an IDS to track these in the end of up? [36:31.730 --> 36:45.990] That's, there, there are, there are people working on doing that, the, it's, it's just that since it comes out on, on port 80, it, it, it's, unless you're looking for just, you know, straight RC4 traffic, but it's, it's just gonna look like gibberish. [36:45.990 --> 36:47.870] So, how, how do you specify that? [36:48.230 --> 36:48.370] And... [36:56.850 --> 36:58.190] Not that I know of. [36:58.290 --> 36:58.530] Not yet. [36:58.650 --> 37:00.190] Not specifically for the Zeus Trojan. [37:08.340 --> 37:16.440] The Flash, he was asking if, the PDF files are, are vulnerable, if there are any other file formats that are vulnerable like that. [37:18.000 --> 37:20.680] Flash, pretty much Adobe products are, are very vulnerable. [37:21.940 --> 37:22.380] Yes. [37:22.720 --> 37:23.140] And then we'll go again. [37:23.680 --> 37:23.880] Yes. [37:24.100 --> 37:24.380] Yes. [37:31.000 --> 37:31.260] Yes. [37:31.360 --> 37:32.260] Is that a reliable feature? [37:35.930 --> 37:38.070] Maybe on the new one they've changed it, I'm not sure. [37:38.650 --> 37:43.030] On, but definitely on the old one, it's, it's standard, it's a standard beacon every 25 minutes. [37:43.610 --> 37:44.050] Yes. [37:45.430 --> 37:45.870] Yes. [37:45.870 --> 37:48.070] Oh yeah, yeah, you can, you can, you can configure it. [37:48.330 --> 37:51.790] But it'll, it'll, it'll stay, it'll stay consistent. [37:53.550 --> 37:53.970] Yes. [38:03.630 --> 38:04.790] It's mostly detection. [38:05.350 --> 38:08.470] The, the, the detection of the payload on, by antiviruses. [38:08.750 --> 38:10.650] The, the, the older versions for that are cheap. [38:10.890 --> 38:13.370] They're gonna have, they're gonna be detected by a lot more antiviruses. [38:13.370 --> 38:18.510] And the, the newer ones, they'll, you know, sometimes a hundred percent on detection rate. [38:18.970 --> 38:19.530] Yeah. [38:19.870 --> 38:21.530] You mentioned that Zeus will, [38:27.970 --> 38:31.750] does that mean it has browser specific hooks? [38:31.930 --> 38:32.470] Yes. [38:32.730 --> 38:33.990] It, it, it hooks in. [38:34.130 --> 38:35.430] It's definitely hooks in. [38:35.530 --> 38:39.510] For the majority, the, the older versions only hook Internet Explorer. [38:39.510 --> 38:42.750] But the newer ones have Firefox, will also hook Firefox as well. [38:45.130 --> 38:48.590] It's, it's probably, I'm, I'm sure someone's developed a plug-in for it by now. [38:48.750 --> 38:49.730] But I, I haven't seen it. [38:50.930 --> 38:51.490] Oh, oh, yes. [38:52.890 --> 38:57.250] Are these kids actively trying to avoid researchers getting their payload? [38:58.290 --> 38:58.690] Yes. [38:58.910 --> 39:03.290] They, they, they'll try to, you know, just try to secure their servers and stuff. [39:03.550 --> 39:03.930] But, um. [39:08.830 --> 39:09.770] Oh, oh, yes. [39:09.870 --> 39:10.250] Actually, yes. [39:10.250 --> 39:16.690] If, if you try to go to, if you try to hit an exploit kit with, uh, with Ubuntu or something like that, a lot of times they'll just directly redirect to Google. [39:17.190 --> 39:21.110] Or, um, or just show a blank page and won't attempt to do anything because it's the wrong user agent. [39:21.250 --> 39:22.450] It, it does detect user agent. [39:22.930 --> 39:23.230] Yes. [39:23.510 --> 39:29.710] Why don't I make, uh, a, a, a, a, a [39:35.260 --> 39:44.700] physical hardware device that he uses when he logs into his bank account? [39:45.160 --> 39:47.520] And, um, it, it, would that mitigate it? [39:47.640 --> 39:53.340] Uh, if, if the web application has poor session handling, then, then, yeah, it, it won't help. [39:53.440 --> 39:55.960] Because you can just, you can just grab the cookie and jump on the session. [39:56.100 --> 40:00.420] I have to, I think it requires you to input code just to make the transfer. [40:01.040 --> 40:09.320] Oh, oh, that, that, yeah, that, that would be, um, the, that would be what those additional fields that are being injected for to try to trick you to reveal that information. [40:09.660 --> 40:10.020] Yes. [40:24.750 --> 40:29.190] I would say most free porn, you'll, you'll probably get hit. [40:30.510 --> 40:31.870] Can you put it in my Mac? [40:34.790 --> 40:38.470] I just know you're so mad I can run the Mac kit uninstalled. [40:38.810 --> 40:39.370] All right. [40:39.570 --> 40:40.470] Any, any other questions? [40:41.870 --> 40:42.750] Yes, in the back. [40:43.470 --> 40:43.830] Um, [40:49.500 --> 40:59.500] it, it, it can, yeah, it, it, again, if it's, if it's being hit with an exploit, like an exploit kit, it's not really going to help much. [40:59.500 --> 41:05.260] But if for, you know, for just someone who's picking up a USB drive and sticking it in their machine, it, it might help. [41:05.740 --> 41:14.480] Um, but for, for the majority of drive by, drive by download exploits, the, the whole point is they want to get to a system permission or administrative permission before they even pull the executable. [41:14.580 --> 41:15.820] And that, that's what the exploit is for. [41:18.160 --> 41:19.460] And any other questions? [41:19.800 --> 41:20.160] Oh, yes. [41:23.260 --> 41:28.580] There's, there have, we have seen, uh, OSX exploits on exploit kits. [41:28.900 --> 41:32.640] Um, they, they weren't serving, they weren't serving up any payloads for it. [41:32.840 --> 41:38.620] Um, but there are no, there, there are, uh, Mac botnet, um, software just from several years ago. [41:38.800 --> 41:43.580] I'm not even sure if it's active anymore, but there's one just called Mac bot and, um, that, that, uh, that existed. [41:43.760 --> 41:50.840] And I'm, I'm, I haven't come across any, um, I have seen exploits for OSX from exploit kits, but I haven't seen any payloads for it. [41:52.220 --> 41:52.700] And... [41:52.700 --> 41:53.100] Okay. [41:53.460 --> 41:53.780] I... [41:54.680 --> 41:55.360] Any more? [41:55.540 --> 41:55.700] Okay. [41:55.900 --> 41:56.920] I guess, um, oh, yes. [41:57.300 --> 41:57.740] Is [42:02.270 --> 42:06.930] there another good defense or good detection method? [42:08.410 --> 42:08.890] Uh... [42:09.690 --> 42:10.170] Yeah. [42:10.350 --> 42:11.190] That's, that's about it. [42:11.310 --> 42:19.150] Just monitor, um, monitoring your, uh, well, if, for older versions, you can check your Windows system 32 directory. [42:19.430 --> 42:23.110] Um, there should, if there's a hidden directory called percent low sec. [42:23.190 --> 42:23.810] Percent. [42:24.390 --> 42:25.230] You're infected. [42:25.670 --> 42:31.130] And, but, but that's not, that's, that's only one variant of Zeus and the new ones will, will change around. [42:31.330 --> 42:38.170] And on the new Zeus 2.0, it will, um, each payload will have a new MD5 hash. [42:38.410 --> 42:45.410] So people trying to take the payloads and match which campaigns are from which, they can't do that with Zeus 2 because all the payload MD5 hashes are changing. [42:46.890 --> 42:47.250] Yes? [42:47.470 --> 42:48.050] Um, so [42:59.020 --> 42:59.560] many changes. [43:00.640 --> 43:03.500] Zeus, Zeus Tracker, um, tracks fast flux domains. [43:03.860 --> 43:05.400] They'll, they'll actually, um, they'll color code them. [43:05.520 --> 43:06.780] So you'll, you'll see like a blue one. [43:06.840 --> 43:07.600] Like this one's fast flux. [43:07.760 --> 43:08.360] It might not be here. [43:08.460 --> 43:10.120] And then when they find it again, they'll post it back up. [43:10.300 --> 43:12.140] So, so Zeus will track them. [43:12.320 --> 43:14.200] Um, I'm not sure about malware domain list though. [43:15.900 --> 43:16.860] Any, any questions? [43:17.280 --> 43:17.900] I can't see. [43:18.120 --> 43:18.320] Okay. [43:18.680 --> 43:20.580] Um, I guess, um, that's all. [43:20.800 --> 43:21.180] Um, thank you. [43:21.420 --> 43:21.880] I have... [43:24.980 --> 43:27.480] Oh, actually, one more thing. [43:27.700 --> 43:31.960] Um, we have a, we have a table downstairs in the mezzanine at the Hack Miami table. [43:32.120 --> 43:34.120] We have a server set up in the Knock Knock cage. [43:34.300 --> 43:37.120] And it has, um, it's gonna, it's hosting up, uh, these exploit kits. [43:37.220 --> 43:38.540] And it's got a Zeus CNC on it. [43:38.600 --> 43:39.780] It's got these malware things on it. [43:39.800 --> 43:42.840] So if you wanna, if you wanna come, you wanna come play with it, um, just come to our table. [43:42.840 --> 43:44.880] We'll have it set up and you can, you can have at it. [43:45.080 --> 43:45.480] Thank you. [43:50.640 --> 43:51.400] Thank you.