Pwning a Spammer's Keylogger
blog.spiderlabs.com
blog.spiderlabs.com
I'd say the older version that was analyzed before wasn't using unicode yet, whereas the later version was.
Very cool how you see the effects of character encodings all over the place - even where you don't expect them.
Also, if done right, the "encryption" should IMHO have been done after the file has been written in its native encoding using an input byte sequence. But seeing that the XOR key had that second 0 byte, I'd say that the encryption was done using a "string" key instead of plain bytes.
And don't get me started on the idea of using XOR as "encryption" - especially with repeated pattern like this, this can't even be reasonably called obfuscation IMHO.
But I was talking about the build of the software. The old was probably a build linking against the old ANSI API ("A" suffix), whereas the new one is using the wide version ("W" suffix), usually referred to as the Unicode variant of the API - hence my incorrect terminology.
Looking at the screenshots of that application, if I had to take a really wild guess, I would say that the application might have been built in delphi which moved to the Unicode API with Delphi 2010 IIRC.
That changed the byte-width of a the standard Delphi string (and the more basic PChar type) to 2 bytes and switched over to using the W-suffix API.
I guess all those years of doing Delphi work are rubbing off.
EDIT: I wonder why is the author using a version from 2004 though... I had to double check the date of the article. This tool is well worth the money!!!
To you, maybe. I have no use for it, so it's not, especially when it costs $200.
Also cygwin's midnight commander (when it fits the purpose).
I love console tools :)
It is fun to figure out how malware works.
I disassembled it but all I found was some basic initialization code and then a jmp to an address that didn't seem to exist. However when I ran it (in a VM) with a debugger it seemed to go through all kinds of Win32 Calls.
Very odd
If it is strong encryption I suppose the thing to do would be to capture the key in memory, but that would require more patience than I have.
"In common law, a hue and cry is a process by which bystanders are summoned to assist in the apprehension of a criminal who has been witnessed in the act of committing a crime."
Bear in mind that many of the servers used by these guys do not belong to them and are probably a neglected server somewhere that was setup by an innocent party for other purposes but was subsequently pwned by the malware people.
It would difficult to know what to do in these situations because your choices are going to be limited to doing nothing and letting them get away with it or going vigilante and possibly exposing yourself to legal risk.
You could inform law enforcement but they are likely to either do nothing or decide to arrest you instead (I knew someone who had the police come to his house and confiscate his computer for over a year because a fellow student saw him using DOS prompt on a school computer and decided to report him for "hacking").
He had a habit of rubbing people up the wrong way, bragging about being having 'leet' computer skills (he didn't) and doing idiotic things like mass net sends at school so I'm sure it was in many ways his fault. Does show how paranoid the police can be about "hackers" though.
>You're getting into dangerous legal territory there (technically you are by just connecting to the FTP I guess).
How would you be? The software which was unsolicitedly installed on your computer is already going to be making that connection whether you want it to or not.But seriously, it's nice to see this sort of post about breaking into the inbreakers' code.
I'm a little surprised that people are treating logging into the FTP server (if not deleting the keylogs) as a legal gray area. I understand the moral dilemma of vigilante justice, but in principle, just doing an FTP connect and LIST seems to be well within your right, given that they gave you software which logs in and makes a directory and sends your keylog. Is there a real concern that someone will take you to court for that?
I think the concern is more along drawing a bright line between black hat and white hat.
Researchers have to do stuff which is borderline illegal; at least it's sometimes tricky to know if they're breaking any laws. Thus, they'll create a set of clear and easy to understand rules and work to those, which means that they reduce their risk of legal action.
"Don't fight abuse with abuse" is (at least was) very common phrase. That's pretty good idea, when some people aren't capable of knowing who the bad person is. We don't want denial of service attacks against innocent people.
Having said that, it's annoying as hell that ISPs don't do more to stop this kind of thing.
Is this person suggesting that using a keylogger to spy on your employees/children without their knowledge is not 'badness'?!
I pointed this out to a few people who would use IM programs to 'flirt' with each other all day.
As for employees, if it's a work computer I pretty much say anything is fair game.
It was a lot of fun and felt a bit like being a detective of some kind.
If the password programs use the clipboard, then it is just another source for the keylogger to capture and trivial to add. (edit: a screenshot lower in the article of the 'Perfect Keylogger' options screen shows a clipboard option.)
Assuming that's how 1Password works, it should be safe. I think that's a fair assumption because using the clipboard or SendKeys to an input box is all kinds of trouble in practice, and the API is easy.
I'm going to agree with jiggy2011. Once you are compromised at that level then it's pretty much game over.
To nitrogen's point, there's definitely a corresponding GETTEXT message. There's even hooks[1].
But that's about all I know. Haven't written a desktop app in > 10 years.
[1] http://msdn.microsoft.com/en-us/library/ms644990%28v=vs.85%2...
FWIW, the 1Password website (http://help.agile.ws/1Password3/security.html) mentions copy and paste in the context of other password managers that require you to copy/paste:
> Not only is this manual work inconvenient, but as soon as “copy and paste” are mentioned, you become vulnerable to keyloggers and phishing attacks.
I have used the same trick sometimes when nobody could remember the FTP credentials, but they were stored in the FTP program and a connection to the FTP server was still possible. Sometimes the guy with access to the admin panel is just not available, so a possible solution is to use Wireshark to retrieve the password, which is usually transmitted without encryption.