Torpig Botnet Harvests Online Banking Credentials

Posted by Elderly Care Expert | Wireless Security | Sunday 10 May 2009 3:05 am

In a post I did over the weekend, I talked about the fact that malicious code was not going to go away and it’s time to get rid of “username:/password:” log-in.  It’s not safe.

As I mentioned in that post, the most secure way to authenticate the online banking customer is to put a HomeATM 2.0 Certified PIN Entry Device in their hands.  ($12)  The bank issues the card, the bank issues the PIN, and now, instead of toasters, the bank issues our device.  End Result?: Complete 100% secure 2FA (two-factor authentication) log-in.  What that means to the banks and their customers is virtual elimination of  phishing (average cost $350) no  threat of DNS Hijacking, cloned cards could no longer be used and essentially no more ID Theft, thus no more emptying of bank accounts.   

Now, here comes a story about a botnet called Tropig  (also  known as Sinowa) a hard to detect malicious code used to infect PC’s and steal those very same username/password’s used at financial institutions.  Don’t say I didn’t warn you that this would happen and this is just the beginning…the worst is yet to come. 

Source: Computer World  Complete item: Click Here


Description:

Researchers from the University of California gained control over a well-known and powerful network of hacked computers for 10 days, gaining insight into how it steals personal and financial data.

The botnet, known as Torpig or Sinowal, is one of the more sophisticated networks that uses hard-to-detect malicious software to infect computers and subsequently harvest data such as email passwords and online banking credentials.

The researchers were able to monitor more than 180,000 hacked computers by exploiting a weakness within the command-and-control network used by the hackers to control the computers. It only worked for 10 days, however, until the hackers updated the command-and-control instructions, according to the researchers’ 13-page paper.

Still, that was enough of a window to see the data-collecting power of Torpig/Sinowal. In that short time, about 70GB of data were collected from hacked computers.

The researchers stored the data and are working with law enforcement agencies such as the US Federal Bureau of Investigation, ISPs and even the US Department of Defence to notify victims. ISPs also have shut down some Web sites that were used to supply new commands to the hacked machines, they wrote.

Torpig/Sinowal can pilfer user names and passwords from email clients such as Outlook, Thunderbird and Eudora while also collecting email addresses in those programs for use by spammers. It can also collect user names and passwords from web browsers.

Torpig/Sinowal can infect a PC if a computer visits a malicious Web site that is designed to test whether the computer has unpatched software, a technique known as a drive-by download attack. If the computer is vulnerable, a low-level piece of malicious software called a rootkit is slipped deep into the system.

The researchers found out that Torpig/Sinowal ends up on a system after it is first infected by Mebroot, a rootkit that appeared around December 2007.

Mebroot infects a computer’s Master Boot Record (MBR), the first code a computer looks for when booting the operating system after the BIOS runs. Mebroot is powerful since any data that leaves the computer can be intercepted.

Mebroot can also download other code to the computer.


Torpig/Sinowal is customized to grab data when a person visits certain online banking and other websites. It is coded to respond to more than 300 websites, with the top targeted ones being PayPal, Poste Italiane, Capital One, E-Trade and Chase bank, the paper said.

If a person goes to a banking website, a falsified form is delivered that appears to be part of the legitimate site, but asks for a range of data a bank would not normally request, such as a PIN (personal identification number) or a credit card number.

Websites using SSL (Secure Sockets Layer) encryption are not safe if used by a PC with Torpig/Sinowal, since the malicious software will grab information before it is encrypted, the researchers wrote.

Hackers typically sell passwords and banking information on underground forums to other criminals, who try to covert the data into cash. While it’s difficult to precisely estimate the value of the information collected over the 10 days, it could be worth between US$83,000 to $8.3 million, the research paper said.

There are ways to disrupt botnets such as Torpig/Sinowal.

Editor’s Note:  The easiest way to disrupt the botnet is to utilize HomeATM’s PCI 2.0 Certified SafeTPIN with 3DES end-to-end encryption (including the Track 2 data) and Protected by DUKPT key management.  Use our device and you’ll have no worries.  Either that or stop shopping online!

NEVER TYPE ANY OF YOUR FINANCIAL INFORMATION INTO A PC OR WEB BROWSER!


The botnet code includes an algorithm that generates domain names that the malware calls on for new instructions.

Security engineers have often been able to figure out those algorithms to predict which domains the malware will call on, and preregister those domains to disrupt the botnet. It is an expensive process, however. The Conficker worm, for example, can generate up to 50,000 domain names a day.

Registrars, companies that sell domain name registrations, should take a greater role in cooperating with the security community, the researchers wrote. But registrars have their own issues.

URL to see the Your Botnet is My Botnet Analysis of a Takeover report :

http://www.cs.ucsb.edu/~seclab/projects/torpig/index.html

ABSTRACT

Botnets, networks of malware-infected machines that are controlled by an adversary, are the root cause of a large number of security threats on the Internet. A particularly sophisticated and insidioustype of bot is Torpig, a malware program that is designed to harvestsensitive information (such as bank account and credit carddata) from its victims. In this paper, we report on our efforts totake control of the Torpig botnet for ten days. Over this period, we observed more than 180 thousand infections and recorded more than 70 GB of data that the bots collected. While botnets have been “hijacked” before, the Torpig botnet exhibits certain properties that make the analysis of the data particularly interesting. First, it is possible (with reasonable accuracy) to identify unique bot infectionsand relate that number to the more than 1.2 million IP addresses that contacted our command and control server. This shows that botnet estimates that are based on IP addresses are likely to report inflated numbers. Second, the Torpig botnet is large, targets a variety of applications, and gathers a rich and diverse set of information from the infected victims. This opens the possibility to perform interesting data analysis that goes well beyond simply counting the number of stolen credit cards.

1. INTRODUCTION
Malicious code (or malware) has become one of the most pressing security problems on the Internet. In particular, this is true for bots [3], a type of malware that is written with the intent of taking control over hosts on the Internet. Once infected with a bot, the victim host will join a botnet, which is a network of compromised machines that are under the control of a malicious entity, typically referred to as the botmaster. Botnets are the primary means for cyber criminals to carry out their nefarious tasks, such as sending spam mails [30], launching denial-of-service attacks [24], or stealing personal data such as mail accounts or bank credentials [14,32].  This reflects the shift from an environment in which malware was
developed for fun to the current situation, where malware is spread for financial profit.

Given the importance of the problem, significant research efforthas been invested to gain a better understanding of the botnet phenomenon [8, 29], to study the modus operandi of cyber criminals[19, 22], and to develop effective mitigation techniques [10, 11]. One popular approach to analyze the activities of a botnet is to join it (that is, to perform analysis from the inside). To achieve this, researchers typically leverage honeypots, honey clients, or spamtraps to obtain a copy of a malware sample. The sample is then executed in a controlled environment, which makes it possible to observe the traffic that is exchanged between the bot and its command and control (C&C) server(s). In particular, one can record the
commands that the bot receives and monitor its malicious activity.

Reblog this post [with Zemanta]

Share and Enjoy:
  • Digg
  • del.icio.us
  • Facebook
  • Google
  • Live
  • MySpace
  • Reddit
  • StumbleUpon
  • Technorati
  • TwitThis

75 Comments »

  1. Trackback by naruto hentai comics — April 13, 2010 @ 10:18 am

    naruto hentai comics…

    Home- Hentai Videos- Anime- Movies- Tv Shows Isaku Respect vol. 2* Uncensored*…

  2. Trackback by The Simpsons Hentai - The Simpsons Porn - The Simpsons xxx — April 17, 2010 @ 6:10 am

    The Simpsons Hentai - The Simpsons Porn - The Simpsons xxx…

    Here is a very unique sort of Simpsons in shape of porn anime….

  3. Trackback by Casino 1273898772 — May 15, 2010 @ 7:17 am

    Casino 1273898772…

    Casino 1273898772…

  4. Trackback by NARUTO HENTAI VIDEOS — June 5, 2010 @ 6:07 am

    NARUTO HENTAI VIDEOS…

    Home- Hentai Videos- Anime- Movies- Tv Shows Isaku Respect vol. 2* Uncensored*…

  5. Trackback by the simpsons hentai — August 11, 2010 @ 8:58 am

    the simpsons hentai…

    All exact, this is some hot shot for you… Ready with preludes furry cat soon wont hesitate to get on largest of ruttish candle and hop it while taking off all clothes and getting seted up to take her tasty feet of terrible wild fucking. Now sexy furr…

  6. Trackback by Family Guy xxx — September 9, 2010 @ 12:58 pm

    Family Guy xxx…

    Hot family guy hentai sex adult family guy…

  7. Trackback by Get Rid of Hemroids — April 19, 2011 @ 2:15 pm

    Recommended Sites…

    [...]below you can check out my links page http://www.hemorrhoidtreatmentcurerelief.com/my-favourite-sites/ with some good websites that I think you should definitely go visit[...]…

  8. Trackback by Related Resources — April 27, 2011 @ 1:35 pm

    Interesting Article…

    [...]some interesting sites worth visitng. We recommend all our readers go and check these out[...]……

  9. Trackback by eBook Reader — May 9, 2011 @ 7:26 pm

    What is an eBook…

    [...]the new electronic book format is taking the market by storm[...]…

  10. Trackback by Dark Under Eye Cream — May 9, 2011 @ 10:51 pm

    About Dark Under Eye…

    [...]Dark Under Eye is a leading provider of hydryolyze[...]…

  11. Trackback by Diabetic Tips — May 12, 2011 @ 1:26 am

    Glucose Monitors…

    [...]blood glucose levels are key to keeping a healthy body[...]…

  12. Trackback by Meratol reviews — May 12, 2011 @ 9:23 am

    Trackback…

    [...]we find pleasure in linking to other places on the interwebz, even though those places don’t happen to be similar to us, by pointing them out. Here are a couple URLs worth browsing[...]…

  13. Trackback by Cheap Suits For Men — May 13, 2011 @ 2:02 am

    Online Kasper Suits Petite…

    [...]these are some listings to web pages which I connect to as we believe they really are definitely worth browsing[...]…

  14. Trackback by free xbox 360 — May 13, 2011 @ 2:45 am

    Get it…

    [...]Here is another great site[...]…

  15. Trackback by Online casino — May 13, 2011 @ 2:45 am

    Get it…

    [...]Cool info[...]…

  16. Trackback by free stuff — May 13, 2011 @ 9:09 am

    Catch it…

    [...]Cool website[...]…

  17. Trackback by free website — May 13, 2011 @ 3:57 pm

    Get it…

    [...]Here is another great site[...]…

  18. Trackback by Great Wolf Lodge Coupons — May 14, 2011 @ 12:10 pm

    Travel Deals…

    [...]These following online sites are really numerous internet sites that interested our administrator, therefore make sure you have a look at them[...]…

  19. Trackback by Cat Suits For Women — May 14, 2011 @ 12:27 pm

    The Best Cat Suits For Women…

    [...]following are several references to internet sites which I link to since we think they really are definitely worth checking out[...]…

  20. Trackback by Alan Leong — May 14, 2011 @ 8:27 pm

    Alan Leong…

    [...]It is a very nice page I come by while shopping for cheap stuff for my store. Very pretty.[...]…

  21. Trackback by Herbal Colon Cleanse — May 15, 2011 @ 2:48 am

    Colon Cleanse Review Site…

    [...]while the sites we link to below are completely unrelated to ours, we think they are worth a read, so have a look[...]…

  22. Trackback by Free Ebooks — May 15, 2011 @ 11:41 am

    Download Ebooks…

    [...]sidebars in blogs can serve different purposes, check out how these sites use[...]…

  23. Trackback by OpenOffice Download — May 15, 2011 @ 10:21 pm

    OpenOffice Download…

    [...]below are a handful of hyper-links to webpages that we connect to as we think there’re worthwhile visiting[...]…

  24. Trackback by smokeless cigarette products — May 16, 2011 @ 4:31 pm

    Mens Health and Fitness…

    [...]here are several links to sites that we link to because we think they are worth visiting[...]…

  25. Trackback by Remit to India — May 17, 2011 @ 2:05 am

    ICICI Money to India…

    [...]listed here are a couple of url links to webpages we link to because we believe there’re worthwhile checking out[...]…

  26. Trackback by Acnezine — May 17, 2011 @ 7:17 am

    Acnezine - laser acne…

    [...] the following are a couple of links to sites that we connect to simply because we believe they are simply worth visiting [...]…

  27. Trackback by Carly Yu — May 17, 2011 @ 9:17 am

    Dan Garrett …

    [...]here are some links to sites that we link to because we think they are worth visiting[...]…

  28. Trackback by Free games — May 17, 2011 @ 1:41 pm

    Get it…

    [...]Here is another great site[...]…

  29. Trackback by Cat Suits For Women — May 17, 2011 @ 11:08 pm

    Online Kasper Suits Petite…

    [...]listed below are several url links to internet websites which we connect to since we feel they will be seriously worth browsing[...]…

  30. Trackback by OpenOffice Download — May 18, 2011 @ 2:29 am

    OpenOffice Download…

    [...]here are a couple of web links to websites online I always connect to as we believe they really are worthwhile checking out[...]…

  31. Trackback by Colon Cleanse Home Remedies — May 18, 2011 @ 1:52 pm

    Official Colon Cleanse…

    [...]here are some links to sites that we link to because we think they are worth visiting[...]…

  32. Trackback by Glucose Monitor — May 18, 2011 @ 5:56 pm

    Free Glucose Monitor…

    [...]through the Diabetic Connect program[...]…

  33. Trackback by Black Under Eye — May 18, 2011 @ 11:50 pm

    Face Wrinkles…

    [...]smoothed out with hydroxatone’s patented formula[...]…

  34. Trackback by ICICI Bank — May 19, 2011 @ 5:38 am

    ICICI Money to India…

    [...]listed here are several web page links to web sites that we link to as we think they are truly worth browsing[...]…

  35. Trackback by Cat Suits For Women — May 19, 2011 @ 5:38 am

    Cheapest Kasper Suits…

    [...]below are several web links to internet websites which I link to as we believe these are worthwhile checking out[...]…

  36. Trackback by Wordpress Themes — May 19, 2011 @ 8:08 am

    Review Site…

    [...]the time to read or visit the content or sites we have linked to below the[...]…

  37. Trackback by Emory Doyle — May 19, 2011 @ 1:07 pm

    Victoria Cole …

    [...]Blackjack is one of the most widely played casinos baking game in this world[...]…

  38. Trackback by OpenOffice Download — May 19, 2011 @ 1:15 pm

    OpenOffice Download…

    [...]here are a handful of url links to internet websites I always connect to since we think these are worth browsing[...]…

  39. Trackback by American Airlines Promotion Code — May 19, 2011 @ 11:20 pm

    Travel Offers…

    [...]couple of internet sites which are detailed under, through our mindset are surely truly worth checking out[...]…

  40. Trackback by Kasper Suits Petite — May 20, 2011 @ 7:28 pm

    Cheap Kasper Suits…

    [...]listed here are several url links to online sites I always link to seeing as we believe they will be well worth checking out[...]…

  41. Trackback by OpenOffice Download — May 22, 2011 @ 1:57 am

    OpenOffice Download…

    [...]below are a couple of web links to web-sites that we connect to seeing that we feel they will be well worth checking out[...]…

  42. Trackback by Kasper Suits Petite — May 22, 2011 @ 2:06 am

    Cheap Kasper Suits…

    [...]what follows are a few url links to websites I always link to seeing as we think they will be well worth checking out[...]…

  43. Trackback by Non-camera Phone — May 22, 2011 @ 2:40 pm

    M1 Student Price…

    [...]for sure. For sure, I would be buying a BlackBerry soon. I had assumed it would be compatible[...]…

  44. Trackback by Lufthansa Promotion Code — May 23, 2011 @ 9:13 am

    Travel Offers…

    [...]These following websites are actually a few sites that attracted our own admin, thus you should have a look at them[...]…

  45. Trackback by OpenOffice Download — May 23, 2011 @ 9:29 am

    OpenOffice Download…

    [...]these are a few web links to sites I always link to as we feel there’re well worth checking out[...]…

  46. Trackback by Minority Women Scholarships — May 23, 2011 @ 6:07 pm

    The Best Scholarships for Minorities…

    [...]the following are a couple of web links to websites online I always link to seeing that we think they will be worth browsing[...]…

  47. Trackback by Scholarships for Women Over 40 — May 24, 2011 @ 3:39 pm

    Get Scholarships for Minorities…

    [...]these are several hyper-links to web pages which I link to as we feel there’re worth browsing[...]…

  48. Trackback by Teressa Silver — May 24, 2011 @ 10:36 pm

    Lu Paredes …

    [...]homeowners insurance Georgia is similar to insurance as we cover for our life gives us money safeguarding ourselves[...]…

  49. Trackback by Scholarships for Hispanics — May 25, 2011 @ 5:21 am

    Get Scholarships for Minorities…

    [...]listed below are some web page links to places which I link to since we think they are seriously worth checking out[...]…

  50. Trackback by ICICI Money to India — May 25, 2011 @ 7:50 pm

    ICICI Money to India…

    [...]in the following are a few urls to internet sites we connect to because we believe there’re truly worth checking out[...]…

  51. Trackback by Anonymous — May 26, 2011 @ 12:07 am

    Ali Young …

    [...]The people may not able to get fear for the insurance agents and the companies may not be able to cheat the people[...]…

  52. Trackback by ICICI Bank India — May 26, 2011 @ 10:26 pm

    ICICI Money to India…

    [...]here are several links to webpages that we connect to seeing that we believe they’re definitely worth browsing[...]…

  53. Trackback by Left Handed Scholarships — May 27, 2011 @ 4:28 am

    The Best Scholarships for Minorities…

    [...]following are a couple of url links to online websites which we connect to as we believe they are seriously worth browsing[...]…

  54. Trackback by ICICI Money to India — May 28, 2011 @ 1:26 am

    ICICI Money to India…

    [...]below are several listings to online sites that we connect to for the fact we think they are seriously worth checking out[...]…

  55. Trackback by Dwight Haynes — May 28, 2011 @ 6:52 am

    Phoebe Mercer…

    [...]Generally one product has realese in several times include so many thing of it[...]…

  56. Trackback by Scholarships for Women Over 40 — May 28, 2011 @ 7:03 am

    Get Scholarships for Minorities…

    [...]right here are several web page links to online sites which I link to for the fact we believe these are really worth browsing[...]…

  57. Trackback by M1 Packages — May 30, 2011 @ 1:16 am

    M1 BlackBerry…

    [...]we found these web pages which are very cool. Hey, we also know their admins![...]…

  58. Trackback by Scholarships for Women Over 40 — May 30, 2011 @ 1:54 pm

    Money for College-Scholarships for Minorities…

    [...]below are a few web links to webpages I always link to since we believe there’re worthy of browsing[...]…

  59. Trackback by Kasper Suits — May 31, 2011 @ 2:04 pm

    Discount Kasper Suits…

    [...]these are a few references to internet websites we link to because we think these are seriously worth browsing[...]…

  60. Trackback by Scholarships for Minorities — May 31, 2011 @ 5:25 pm

    The Best Scholarships for Minorities…

    [...]what follows are a handful of urls to internet sites that we link to because we feel there’re definitely worth browsing[...]…

  61. Trackback by how to improve eyesight — June 1, 2011 @ 2:18 pm

    Things You Should Know About…

    [...]I operate a somewhat hot pop star gossip website, and to remain in the know, I utilize market pulse tools.Your property has been firing up time-tested Alexa triggers, and I figured I’d check it out and check if I could discover what all of the bu…

  62. Trackback by Scholarships for African Americans — June 2, 2011 @ 5:24 pm

    The Best Scholarships for Minorities…

    [...]listed below are a couple of links to online sites which I connect to for the fact we think they are well worth browsing[...]…

  63. Trackback by College Scholarships for Women — June 3, 2011 @ 1:19 am

    Get Scholarships for Minorities…

    [...]in the following are a couple of links to internet websites we connect to seeing as we believe they will be definitely worth visiting[...]…

  64. Trackback by Left Handed Scholarships — June 3, 2011 @ 2:18 pm

    Apply for Scholarships for Minorities…

    [...]in the following are a few web links to internet pages we link to seeing as we think they are worth browsing[...]…

  65. Trackback by and — June 3, 2011 @ 4:26 pm

    Ken…

    [...]These products are available in different strengths. You can choose yours according to your problem[...]…

  66. Trackback by Scholarships for Minorities — June 3, 2011 @ 10:28 pm

    The Best Scholarships for Minorities…

    [...]listed here are some links to web pages which we connect to for the fact we think they really are well worth visiting[...]…

  67. Trackback by Streaming TV to PC — June 3, 2011 @ 10:43 pm

    [...] our site list of interesting sites on the web[...]…

    [...] Top news, thought we could combine a few not related data, yet still worth looking!!![...]…

  68. Trackback by Left Handed Scholarships — June 4, 2011 @ 10:10 am

    Money For College Scholarships for Minorities…

    [...]listed below are several links to online websites that we link to seeing as we believe they are really worth checking out[...]…

  69. Trackback by CNA Certification Test — June 4, 2011 @ 10:32 pm

    CNA Certification…

    [...]these are some fantastic sites that you should check out[...]…

  70. Trackback by Scholarships for Minorities — June 5, 2011 @ 12:39 pm

    Money For College Scholarships for Minorities…

    [...]listed below are a handful of references to internet websites which I connect to since we think these are truly worth visiting[...]…

  71. Trackback by property and casualty insurance test — June 5, 2011 @ 5:40 pm

    The best website……

    [...]here are some links to sites that we link to because we think they are worth visiting[...]……

  72. Trackback by best ghost movies — June 5, 2011 @ 7:53 pm

    ghost movie…

    [...]below you’ll find the link to some sites that we think you should visit[...]…

  73. Trackback by Minority Women Scholarships — June 6, 2011 @ 12:30 am

    Get Scholarships for Minorities…

    [...]in the following are a couple of listings to websites online we connect to seeing as we feel they will be worthy of checking out[...]…

  74. Trackback by Scholarships for Women Over 40 — June 7, 2011 @ 1:46 am

    Money for College-Scholarships for Minorities…

    [...]below are a handful of references to internet websites which I connect to for the fact we think they are worthwhile visiting[...]…

  75. Trackback by Kasper Suits — June 7, 2011 @ 2:23 am

    Discount Kasper Suits…

    [...]here are a few references to internet sites which we connect to for the fact we think they are worthy of checking out[...]…

RSS feed for comments on this post. TrackBack URI

Leave a comment

You must be logged in to post a comment.