Microsoft Windows Vista Community Forums - Vistaheads
Driver Scanner 2009 - Free Scan Now



Welcome to the Microsoft Windows Vista Community Forums - Vistaheads, YOUR Largest Resource for Windows Vista related information.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so , join our community today!

If you have any problems with the registration process or your account login, please contact us.

Registry Mechanic - Free Scan Now

Advanced tools to handle stolen information

Security News



Click On Your Flag for Translation
Simplified Chinese French Spanish Italian Portugeuse Japanese German Dutch
Reply
  #1 (permalink)  
Old 05-11-2007
Paul's Avatar
Paul Paul is offline
Moderator
 

Join Date: Feb 2007
Location: wicklow mts
Posts: 9,473
Paul is on a distinguished road
Thanks: 0
Thanked 0 Times in 0 Posts
Advanced tools to handle stolen information
When analyzing one of the latest variants of LDPinch, an information stealing trojan, we found the drop-site used by the trojan to upload the stolen information. As you can see from the screenshot below, the files are named in the format of hour_minute-day.month.year_ipaddress_computername.


So whenever a user gets hit by this trojan, it will collect lots of information, and upload it to this site.
At the time of writing, there are 1591 files there, and new ones are arriving every few minutes. We are still in process of taking down the site. The files on the drop-site are encrypted using a proprietary encryption algorithm. To decrypt it, the authors behind LDPinch have created a reporting tool. Thanks to Adam at Sunbelt Software, we got access to this tool.
The reporting tool has a very nice UI. As you can see from the screenshot, everything is structured very nicely, you can see generic information about the computer itself such as hardware information (CPU, RAM, Disk, et cetera). You can also see which version of Windows is being used together with the license key. At the bottom of the screen you can see all of the stolen information such as ICQ credentials, usernames and passwords taken from stored e-mail accounts in Outlook and Thunderbird, and also information stored in the password managers of Internet Explorer, Firefox, and Opera. To protect the identity of the infected user we've blurred some of the information.



The tool also comes with some simple statistics and you can also export the information into different types of files, such as exporting all e-mail addresses to a TXT file, or the report as an HTML, et cetera. There are also facilities to filter the data or search for strings, such as all stolen credentials for yahoo.com for example.



The guys behind the trojan are from Russia and the tool is available in both English and Russian languages. This clearly indicates that the bad guys are working in a professional manner, creating easy-to-use tools to quickly get to the information instead of having just TXT files with loads and loads of text to filter through.

Right now the latest variant is LdPinch.BYJ, detection was added yesterday evening. On 10/05/07 At 04:18 AM


More...
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Sponsored Links
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
Advanced tools to handle stolen information Paul Security News 0 05-10-2007 12:18
Off the wire: Advanced tools to handle stolen information Steve Security News 0 05-10-2007 12:18
Advanced tools to handle stolen information Paul Security News 0 05-10-2007 08:18
Multiple Identies how handle? LenM microsoft.public.windows.vista.mail 4 02-24-2007 00:49
How to handle faxes Simone Chemelli microsoft.public.windows.vista.print fax scan 5 02-21-2007 22:09


All times are GMT +1. The time now is 14:20.


Registry Mechanic - Free Scan Now
Driver Scanner 2009 - Free Scan Now




Design by Vjacheslav Trushkin for phpBBStyles.com.
Powered by vBulletin® Version 3.6.7
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.0.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119