madison

Zero Day

Ryan Naraine and Dancho Danchev

SpyEye gets new DDoS functionality

By | March 10, 2011, 8:34am PST

Summary: Researchers from RSA’s FraudAction Research Lab are reporting on a recently discovered new module within the popular crimeware SpyEye.

Researchers from RSA’s FraudAction Research Lab are reporting on a recently discovered new DDoS module within the popular crimeware SpyEye. Based on various conversations within the cybercrime ecosystem — I also get a mention there — the primary application of the plugin would be to attack legitimate sites such as Abuse.ch’s ZeusTracker, and the SpyEye tracker, a community-driven services aiming to track crimeware campaigns.

The DDoS plugin currently offers SYN Flood; UDP Flood and Slowloris Flood, modes of operation.

Next to the new module, the researchers have also observed a new trend aiming to generate additional noise and poison the results offered by the two services. By including legitimate sites next to the malicious one, cybercriminals aim to make it harder for the service to distinguish between legitimate and purely malicious ones:

This means that all the credentials collected by the Trojan from SpyEye bots, including screenshots, username and password combinations, and stolen certificates and cookies, will be sent to port 443 of the legitimate websites, like the ones mentioned above. When abuse.ch’s Trackers analyze SpyEye variants like the ones we traced, legitimate website domains will be classified as those variants’ communication points. These, in turn, will show up in the SpyEye Tracker blocklist, and serve to diminish its credibility.

This isn’t (See: Crimeware tracking service hit by a DDoS attack) the first coordinated attempt to disrupt the operation of the service, and definitely not the last, clearly speaking for its usefulness.

Kick off your day with ZDNet's daily e-mail newsletter. It's the freshest tech news and opinion, served hot. Get it.

Topics

Dancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, malware and cybercrime incident response.

Disclosure

Dancho Danchev

More details on Dancho Danchev's current and past professional affiliations, can be found in his LinkedIn profile.

Biography

Dancho Danchev

Dancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, and cybercrime incident response. He's been an active security blogger since 2007, and maintains a popular security blog sharing real-time threats intelligence data with the rest of the community on a daily basis. More details on Dancho Danchev's current and past professional affiliations, can be found in his LinkedIn profile. You can also follow him on Twitter

Talkback Most Recent of 13 Talkback(s)

  • RE: SpyEye gets new DDoS functionality
    We need to start dropping bodies of the people behind this crap!
    ZDNet Gravatar
    wkulecz
    10th Mar
  • RE: SpyEye gets new DDoS functionality
    Thanks!Good luck to you as well. grin replica watches
    ZDNet Gravatar
    lovedong
    13th Sep
  • RE: SpyEye gets new DDoS functionality
    We need to look at our surfing habits and modify them. Let's not JUST blame the authors of these programs. It's been over 20 years since I have been fighting against malware and since that time, everytime I get infected, it is caused directly by my own stupidity. Stop using P2P networks, stop clicking on links (posisoned) in emails, and for goodness sakes, avoid porn sites. There are other ways of course, that you can get infected. But they malware can't get in if you keep the front door closed and locked, keep your antivirus software up to date and just use common sense. BTW, for those that will scream bloody murder and say that antivirus programs don't work, reminder: check your surfing habits
    ZDNet Gravatar
    cboquin
    11th Mar
  • ZDNet Gravatar
    myclub
    1st Jul
  • RE: SpyEye gets new DDoS functionality
    Well done! Thank you very much for professional templates and community edition
    sesli chat sesli sohbet
    ZDNet Gravatar
    talih
    12th Aug
  • RE: SpyEye gets new DDoS functionality
    I also desire to signal in your RSS feeds. Thank you as soon as once again and maintain up the great operate! nccma cooler
    ZDNet Gravatar
    MACKENZI
    10th Sep
  • RE: SpyEye gets new DDoS functionality
    I used to be more than happy to seek out this internet-site.I wanted to thanks in your time for this glorious read!! I positively enjoying each little bit of it and I have you bookmarked to check out new stuff you weblog post. this thread is amazing i like your work and i appreciate you that you have share a useful stuff thanks for sharing the i shop abatwa
    ZDNet Gravatar
    MARAGARET
    11th Sep
  • RE: SpyEye gets new DDoS functionality
    I used to be more than happy to seek out this internet-site.I wanted to thanks in your time for this glorious read!! I positively enjoying each little bit of it and I have you bookmarked to check out new stuff you weblog post.Bookmarking now thanks please consider a follow up post. power sa shop
    ZDNet Gravatar
    RHIANNONA
    13th Sep
  • RE: SpyEye gets new DDoS functionality
    I think the representation of this article is actually superb one. This is my first visit to your site. Thanks a lot and keep sharing the information. Keep updating the information for all of us. Thanks ZDNet Government was launched as the brand's first industry vertical, with a mission to cater to IT professionals in the public secto I agree with your post. However, do you have any sources I can cite for my paper wheel car com bury
    ZDNet Gravatar
    SATURNINA
    13th Sep
  • RE: SpyEye gets new DDoS functionality
    Well welcome, hopefully you can become a vital member of the community and really help to push far ahead of google. Which Im sure the development team would love. This will of course earn you alot points too and get you on the leaders board. z d n e t t h a n k Im not sure i come to an agreement with you on every level, howevor it absolutely was a good posting, many thanks for taking the time to put up your ideas.
    ZDNet Gravatar
    TOCCAR
    25th Sep
  • RE: SpyEye gets new DDoS functionality
    This is my first visit to z d n e t site. Thanks a lot and keep sharing the information. Keep updating the information for all of us.how can i clean up, because i don???t know why it seems my skeen has to fat i get the glasses dirty every day.i search y a h o o Very good quality indeed. I surely recommend it. The template used in their site is also great.
    ZDNet Gravatar
    CLAUDET
    26th Sep
  • RE: SpyEye gets new DDoS functionality
    Fantastic news about the new release.I positively enjoying each little bit of it and I have you b o o k m a r k e d to check out new stuff you weblog post.Im not sure i come to an agreement with you on every level, howevor it absolutely was a good posting, many thanks for taking the time to put up your ideas
    ZDNet Gravatar
    MEJIAHA
    29th Sep
  • RE: SpyEye gets new DDoS functionality
    Good day to confirm this comment I would appreciate T h e b e s t o f Z D N e t d e l i v e r e d your website very nice to everyone Yes, Oracle is the only one with shared-disk architecture, but that is there advantage. It means you can add or remove nodes and the database lives on. In a shared nothing architecture, if you lose a node, you lose the system. I'm sure Oracle appreciates EMC highlighting their advantage.I also desire to signal in your RSS feeds. Thank you as soon as once again and maintain up the great operate Awesome post! Thank you very much || thanks for nice content this is really benefit to me.
    ZDNet Gravatar
    FAULKNE
    13th Oct

Talkback - Tell Us What You Think

Formatting +
BB Codes - Note: HTML is not supported in forums
  • [b] Bold [/b]
  • [i] Italic [/i]
  • [u] Underline [/u]
  • [s] Strikethrough [/s]
  • [q] "Quote" [/q]
  • [ol][*] 1. Ordered List [/ol]
  • [ul][*] · Unordered List [/ul]
  • [pre] Preformat [/pre]
  • [quote] "Blockquote" [/quote]
Click Here

The best of ZDNet, delivered

ZDNet Newsletters

Get the best of ZDNet delivered straight to your inbox

Facebook Activity

White Papers, Webcasts, & Resources