Technical Report: "Learning More About the Underground Economy: A Case-Study of Keyloggers and Dropzones"

CWSandbox
In the last few months, we analyzed quite a few malware samples that are related to stealing of banking credentials. These keyloggers are used by attackers to harvest sensitive information like credit cards numbers, username/password combinations and similar data from an infected machine. We developed some techniques to automatically find the dropzones, i.e., the server that is used by the bad guys to send the stolen information to. The following picture illustrates the attack process:



The basic idea of our approach is to use honeypots to automatically collect malware samples, perform dynamic analysis with the help of CWSandbox and a user simulation, and use the observed data to find the dropzone in an automated way. Using these techniques, we were able to find more than 300 dropzones and we were also able to fully access more than 70 dropzones. We found stolen information from more than 170,000 victims (33 GB of data) and also analyzed this data: Within the dropzone data, we found more than 10,000 bank accounts with full information, more than 140,000 e-mail passwords for large portals and some other interesting infos.

Today we published a technical report that summarizes our findings.

Abstract: We study an active underground economy that trades stolen digital credentials.We present a method with which it is possible to directly analyze the amount of data harvested through these types of attacks in a highly automated fashion. We exemplify this method by applying it to keylogger-based stealing of credentials via dropzones, anonymous collection points of illicitly collected data. Based on the collected data from more than 70 dropzones, we present the first empirical study of this phenomenon, giving many first-hand details about the attacks that were observed during a seven-month period between April and October 2008. This helps us better understand the nature and size of these quickly emerging underground marketplaces.

Trackbacks

  1. PingBack

Comments

Display comments as (Linear | Threaded)

  1. MysteryFCM says:

    Nicely done :o) (OOI, I presume you notified the banks/victims that were affected?)

  2. Thorsten Holz says:

    Yes, we notified the victims with the help of AusCERT - basically we handed over the data to them and they then took care of the notification process. Very sensitive topic, but I hope we did the right thing.

  3. MysteryFCM says:

    heh I figured as much (tis what I do when I come across that stuff), but figured I'd get it clarified for anyone else wondering :o)

  4. Thorsten says:

    I have added a quick description of how we handle the data in my second posting - it should clarify our proceedings :)

    Thanks for your comment!

  5. katsumi says:

    Reference [4] is not available.

  6. Thorsten Holz says:

    As you may have noticed, all old postings are gone - but hopefully they come back eventually :)

  7. Bart says:

    For senhor Katsumi:
    http://74.125.77.132/search?q=cache:Q8WhLeG4BBMJ:https://honeyblog.org/archives/194-CCpower-Only-Scam.html+inurl:CCpower-Only-Scam&hl=en&ct=clnk&cd=1&gl=uk&client=firefox-a


    peace!

  8. katsumi says:

    thank you, bart!
    ..made me remember a comic at xkcd.
    http://xkcd.com/500/
    :)


Add Comment


E-Mail addresses will not be displayed and will only be used for E-Mail notifications

To prevent automated Bots from commentspamming, please enter the string you see in the image below in the appropriate input box. Your comment will only be submitted if the strings match. Please ensure that your browser supports and accepts cookies, or your comment cannot be verified correctly.
CAPTCHA 1CAPTCHA 2CAPTCHA 3CAPTCHA 4CAPTCHA 5