• New Labs report

    Read more how the Zeus trojan has been updated to undermine tracking and detection
  • FFIEC guidance

    How TrustDefender helps
  • TD Pro for Mac

    TrustDefender launches TrustDefender Pro for Mac to protect MacOS X users from a growing list of online threats.
  • Safety of online business

    TrustDefender helps to secure the future of e-commerce.
  • New Security Management

    Increasing company's preparedness for online fraudulent activity
  • TrustDefender enters next phase of growth

    Find out more.
  • Myth vs Reality

    Apple's approach to defeating malware attacks. Myths vs reality
  • TrustDefender Predictions

    The year of malware attacks.
  • HTML and JavaScript injection

    In-depth analysis into how the malware infiltrates websites and the details of its operation.
  • eCrime Summit Abu Dhabi

    TrustDefender continues its drive into the Middle East market exhibiting at eCrime Summit Abu Dhabi.
  • Matt Sheehan

    TrustDefender appoints Matthew Sheehan to drive aggressive sales growth strategy in Australia and New Zealand
  • InfoSight Partnership

    TrustDefender partners with InfoSight, Inc., to address need for effective online transaction security in the US
  • GBM Partnership

    TrustDefender and Gulf Business Machines (GBM) have announced their joint partnership.
  • Gozi Trojan

    TrustDefender Labs report has alarmingly discovered another variant of the Gozi Trojan with a 0% detection rate.
  • Tim Thompson

    TrustDefender appoints security and technology industry expert, Tim Thompson to lead Sales and Operations.
  • Urgent Announcement

    TrustDefender not associated with rogue AV software that is being distributed under the same name.
  • The New Zeus

    TrustDefender reveals true threat of new Trojan Carberp– the new Zeus!
  • GITEX Technology Week

    Showcasing their unique risk-based online transaction security solution at GITEX Technology Week in Dubai.
  • 25th Anniversary

    Leading security expert Andreas Baumhof to speak at 25th Anniversary of Security 2010 Conference.
  • Las Vegas Credit Union Conference

    Showcasing the world’s first real-time customer endpoint risk assessment and protection for online transactions in Las Vegas.
  • New Vice President

    Alex Shipp appointed Vice President of Advanced Threat Research at TrustDefender
  • Secure Online Identities

    TrustDefender comments on the US Government’s draft plan to secure online identities.
  • National Cyber Security Week 2010

    TrustDefender supports National Cyber Security Week 2010 and encourages Australians to take responsibility for online security.
  • Trust Defender raises $16m

    TrustDefender bringing it's ‘revolutionary real-time risk based online transaction security solutions’ to a market...
  • Growing Operations

    TrustDefender announces North American operations led by Joseph McGrath
Text text size decrease text size increase

Analysis of stolen data through Torpig (deployed through Mebroot / MBR / Sinowal)

Attention: open in a new window. Print

We have posted some technical analysis to the mebroot/MBR/Sinowal trojan lately and while we at TrustDefender Labs focus quite heavily on the analysis of the trojans and infection vectors itsself on the client side, Researchers at the University of California looked at the data they received on the server side. This compliments our research quite nicely as it provides hard facts how successful those attacks are and how much data the bad guys actually receive.

 

The research was done by Researchers at the Security Group, Department of Computer Science at University of California, Santa Barbara released a very interesting paper “Your botnet is my Botnet: Analysis of a Botnet Takeover”. (see http://www.cs.ucsb.edu/~seclab/projects/torpig/index.html)

In this paper the security researchers “infiltrated” the Torpig C&C control network for a period of 10 days and their results are nothing less but astonishing.

In the 10 days, the sinkholed C&C Server collected almost 70GB of data. This data included stolen credentials from 52,540 different infected machines and they sent some 297,962 unique credentials (username/password), credentials of 8,310 bank accounts at 410 different financial institutions. Furthermore the data included more than 11 million HTTP(S) Form Data, 1,258,862 email accounts, 1,235,122 windows password, …

stolen_data_type

Key quotes by the original text are:

  • The top targeted institutions were PayPal (1,770 accounts), Poste Italiane (765), Capital One (314), E*Trade (304), and Chase (217).
  • The most common cards include Visa (1,056), Master-Card (447), American Express (81), Maestro (36), and Discover (24).
  • While 86% of the victims contributed only a single card number, others offered a few more. Of particular interest is the case of a single victim from whom 30 credit card numbers were extracted.  Upon manual examination, we discovered that the victim was an agent for an at-home, distributed call center. It seems that the card numbers were those of customers of the company that the agent was working for, and they were being entered into the call center’s central database for order processing.

And very interestingly they also looked at the financial implications of this:

  • Quantifying the value of the financial information stolen by Torpig is an uncertain process because of the characteristics of the underground markets where it may end up being traded. A report by Symantec [37] indicated (loose) ranges of prices for common goods and, in particular, priced credit cards between $0.10–$25 and bank accounts from $10–$1,000.
  • If these figures are accurate, in ten days of activity, the Torpig controllers may have profited anywhere between $83k and $8.3M.
  • Also, a Torpig server was seized in 2008, resulting in the recovery of 250,000 stolen credit and debit cards and 300,000 online bank account login credentials [31].

For more on the botnet hijack, check out UC Santa Barbara’s Torpig project page.  Also features on Slashdot.

Comments

Name *
Email
Code   
Submit Comment

 

relatedarticles

TrustDefender Labs Report 1 (you will be directed to a contact form and we will send one out to you)

TrustDefender Labs Report 2 (you will be directed to a contact form and we will send one out to you)