ie8 fix
madison

Zero Day

Ryan Naraine, Emil Protalinski and Dancho Danchev

DIY botnet kit spotted in the wild

By | September 22, 2011, 6:51am PDT

Summary: Security researchers from GData, have spotted a DIY (do it yourself) botnet kit, available for sale at selected underground communities.

Security researchers from GData, have spotted a DIY (do it yourself) botnet kit, available for sale at selected underground communities.

The DIY kit goes for sale at €10, and allows easy creation of botnets.

Some of its features include:

  • Possibility to carry out DDoS attacks
  • SOCKS; bot owner can use victim’s pc as proxy
  • Firefox password stealer; stealing passwords saved in Firefox database
  • Remote execution of any file
  • Pidgin password stealer; stealing passwords from the instant messenger Pidgin
  • jDownloader password stealer; stealing passwords from a downloader of one-click hoster

The bot builder doesn’t have any propagation modules, making it a relatively low profile underground release, as it cannot spread.

Over the past few years, we’ve been witnessing the migration from DIY tools to web malware exploitation kits as a means for infection and propagating. DIY botnet creation kits with no spreading modules, aren’t the real danger, the real danger comes from DIY botnet kits in a combination with web malware exploitation kits, since they cover both the infection and the dissemination vectors.

Kick off your day with ZDNet's daily e-mail newsletter. It's the freshest tech news and opinion, served hot. Get it.

Topics

Dancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, malware and cybercrime incident response.

Disclosure

Dancho Danchev

More details on Dancho Danchev's current and past professional affiliations, can be found in his LinkedIn profile.

Biography

Dancho Danchev

Dancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, and cybercrime incident response. He's been an active security blogger since 2007, and maintains a popular security blog sharing real-time threats intelligence data with the rest of the community on a daily basis. More details on Dancho Danchev's current and past professional affiliations, can be found in his LinkedIn profile. You can also follow him on Twitter

Related Discussions on TechRepublic

Did you know you can take part in these discussions with your ZDNet membership?
7
Comments

Join the conversation!

Just In

RE: DIY botnet kit spotted in the wild
cybr2th@... 24th Sep
So, basically I will have plenty of job security removing this crap. YESSSSS! I MEAN, ummmm...thats terrible.
0 Votes
+ -
Dancho, Dancho, pricing PLEASE! (kidding)
Dietrich T. Schmitz * Your Linux Advocate 22nd Sep
Find 'em and hang 'em high.
Creeps.
0 Votes
+ -
@Dietrich T. Schmitz * Your Linux Advocate Get six pack Abs

I???m busy and can???t spend 60 minutes a day with exercises.
Truth About Six Pack Abs does not require this.
30-45 minutes workouts 2-3 times a week should do the trick

go here : goo . gl /YR85Z
0 Votes
+ -
These tool kits have been around forever, maybe the actual name of the BOT should have been removed as I found the download on two fairly low level "security sites" with relative ease because I knew the name.
@Parassassin
... self propagating variety even the name would have been blanked out.
This one looks like it is more trouble to use than what it is worth.
0 Votes
+ -
I agree with Schmitz above. Find 'em and hang 'em. Hang 'em high. I mean that in the nicest way.
0 Votes
+ -
Live And Let DIY
ldo17 22nd Sep
What does it matter to ya

You got a job to do, you got to do it well

You got to give the other fella heeeeeeeeeeeeeelllllllllll ...
0 Votes
+ -
So, basically I will have plenty of job security removing this crap. YESSSSS! I MEAN, ummmm...thats terrible.

Join the conversation!

Formatting +
BB Codes - Note: HTML is not supported in forums
  • [b] Bold [/b]
  • [i] Italic [/i]
  • [u] Underline [/u]
  • [s] Strikethrough [/s]
  • [q] "Quote" [/q]
  • [ol][*] 1. Ordered List [/ol]
  • [ul][*] · Unordered List [/ul]
  • [pre] Preformat [/pre]
  • [quote] "Blockquote" [/quote]
ie8 fix
Click Here
ie8 fix

The best of ZDNet, delivered

ZDNet Newsletters

Get the best of ZDNet delivered straight to your inbox

Facebook Activity

White Papers, Webcasts, & Resources
ie8 fix
ie8 fix