On February 17th the CNN published an interesting article, where some Syrian's regime opponents claimed that the government was using a Trojan to monitor and disrupt the protestor's network. If there is some abnormality detected on your computer HijackThis will save them into a logfile.

We have examined just one possible case, the backdoor can be stored anywhere, with any name, packed with any packer.

Post that log in your next reply.Note:Do not mouseclick combofix's window whilst it's running. When I read this news, my first reaction was to be really shocked.

Hi there, stranger! Register now! This is the password we've setup during the configuration step!

Just paste your complete logfile into the textbox at the bottom of this page. Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe" [2007-03-27 15:22]


C:\Documents and Settings\Bondy\Start Menu\Programs\Startup\
Nokia Connectivity Framework Lite.lnk - C:\Nokia\Tools\Nokia_Connectivity_Framework\bin\NCFStart.exe [2007-08-07 18:20:06]
UMScheduler 2.0.lnk - C:\Nokia\Update_Manager\bin\UMScheduler.exe [2007-08-07 18:20:37]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgwlntf]
avgwlntf.dll 2007-08-08

Did he support the government? Did the government really choose DarkComet to fight the opposition? Configuring the Downloader This is the easy part: simply go back to DarkCometRAT and choose Edit Server Downloader, you'll have to just setup the web server address where your backdoor is

This is fun but out of the scope of this article, maybe we'll analyze some keylogging detection techniques in a future article. Server Analysis Retrieve the malicious file from the url pointed by the downloader and take a clean snapshot of your Virtual Machine, a Windows 7 32-bit in my case. Let's now run GMER, a popular rootkit detector, on our system. My software was never designed for these kinds of uses.

In this way we'll be able to decrypt the network traffic of an infected machine and even to take control of an already infected target, in order to remove the malware Trojans DarkComet used in Syrian Conflict? Please try the request again.

Decide if you want to change the icon or mess up with the victim's hosts file and go to the Build Module section. in Computer Science at the University of Maryland, College Park. akmal hi, mind sharing the source code to decrypt the traffic?

2007-07-16 14:54

d-------- C:\DOCUME~1\Bondy\SapWorkDir
2007-07-16 14:40 640,512 --a------ C:\WINDOWS\system32\oc30.dll
2007-07-16 14:40 533,504 --a------ C:\WINDOWS\system32\vtssdl32.dll
2007-07-16 14:40 51,712 --a------ C:\WINDOWS\system32\ole2prox.dll
2007-07-16 14:40 44,544 --a------ C:\WINDOWS\system32\msxml4a.dll
2007-07-16 14:40 153,600 --a------ C:\WINDOWS\system32\tlbinf32.dll
in computer science from the University of Maryland, College Park, a B.S.

Q: How did you find out and what was your first reaction to the news? Relating to cyber-warfare, he has written the paper "Stuxnet: Cyberwar Revolution in Military Affairs" published in Small Wars Journal and "The 2008 Russian Cyber-Campaign Against Georgia" published in Military Review. Probably even more surprising should also be the fact that a public tool doesn't get a 43/43 detection rate.

Just don't forget to check the Persistence Installation option.

Post that log in your next reply.Note:Do not mouseclick combofix's window whilst it's running. It's a stream cipher, so you won't have to deal with padding, easy to understand, short and fast.

At least by using GMER's file manager we see that the original file is still on the desktop but hidden to the view: C:\Users\Quequero\Desktop>attrib server.exe A SH I C:\Users\Quequero\Desktop\server.exe Should you I was also afraid because there is a real war going on in Syria, so it was very serious. Trying to find the password in the executable will get you nowhere, for the simple reason that the original password is encrypted.

Then point your debugger to the installation path and run it. Also you can spend some time studying the binary to understand how some of the functions are implemented, like the HTTP flood or the upload and run feature.

Before running the file we may want to take a snapshot of the registry and of our documents and tmp directory in order to understand which files and registry entries are Register a free account to unlock additional features at BleepingComputer.com Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Even for an advanced computer user. That may cause it to stall.C:\affidlol.exe

An in-depth discussion is provided on the Russian Business Network's (RBN) role in global cyber crime as well as new evidence on how these criminals steal, package, buy, sell, and profit Then we have the algorithm: RC4 is an algorithm loved almost by everyone.

Combining the best of investigative journalism and technical analysis, Cyber Fraud: Tactics, Techniques, and Procedures documents changes in the culture of cyber criminals and explores the innovations that are the result