Showing posts with label Trace the hackers. Show all posts
Showing posts with label Trace the hackers. Show all posts

Monday, 11 November 2013

Detecting and Tracing Malware

Briefing Information:

  • In this tutorial I will show you how to detect malware and trace it via packet sniffing.

Things you need:
  • VMWare - This is highly recommended. If you dont have it, use torrents or google to find a good installation with a working key. I am also providing this. Smile
          Download VMWare (click here)

     Key : 5F2X0-8H3EQ-0ZYD0-928QP-9232Z

PART 1 - Setting up:
  • Download and Install VMWare, install the operating system of your choice.
  • Download WireShark. Make sure you install WinPcap with it if you dont already have it installed.
  • Download Sandboxie. install it, no need for the full version at the moment. 
PART 2 - Detecting malware:

**I RECOMMEND THAT YOU DO THIS IN VMWARE. This is more important for part 3 but still recommended**

For this tutorial, I recommend you use your own malware until you know what your doing. I will be using an IRC bot for this example.

Basically what we are doing first is using Sandboxie to detect if a file has a backdoor in it. I will show you two examples first, Example 1 is putty by itself (clean). Example 2 will be putty with a binded file (backdoor).

1) Right click on the program you want to run, and select "Run Sandboxed" (the free version will make u wait like 5 sec then just hit continue or whatever if it asks)

NOTE: IT WILL OPEN THE PROGRAM. DO NOT WORRY YOU ARE SAFE!!! this is what sandboxie is for!

2) Here is where I show you the difference in binded files. Bring up the sandboxie window if its not up already and you should see something similar to the screens below.

Example 1 - A non-binded file.



Example 2 - Infected file (Backdoor binded to it)


Note the difference. Its pretty obvious. You WILL NOT see this program running, but you will see the main program running. Dont worry you are still safe! remember, sandboxie is keeping you safe.

This is not the only method for detecting malware but it is one of the easiest. I use sandboxie on EVERYTHING I download. You would be suprised how much bullshit I find!

Also, this method will is great for finding binded files, but if the file is a virus and not binded it may be hard to tell if its actually a virus. Sometimes it will download a file and run it, which will then show up in the list a few seconds later. I advise you to run the steps from PART 3 if you have any suspicion on a download.

PART 3 - Tracing the C&C (Command and Control) Center:

Ok, now that you have detected the binded file, lets trace it to see where it leads. I will give some ideas you can do with what you get out of the tracing at the end of this tutorial.

NOTE: Certain things encrypted for SSL connections may not exactly be tracable. 

NOTE 2: If the file is not binded, this is a great way of determining if its malware or a legit program! if its malware, its making a bad connection and you can figure that out by what info this method gives you!

Lets begin with the fun part! I highly recommend that you do this in VMWare. I will explain more on why momentarily.

1) This isn't exactly mandatory but you really should close ALL open programs that access the internet in some way. (Browsers, Dropbox, stuff like that connected to the internet. This is where VMWare comes in handy. If you do this on a clean install on VMWare, theres nothing needed to close and it makes the next steps alot easier.

2) Open Wireshark. Select your working connection in the Interface List. See image below.


3) Now that you have WireShark open you should be seeing some packets up on the screen... If you give it a quick test and open a browser, you will see the packets as they come in. (probably a shitload of them)

Wireshark Screen:


4) Now, run your binded program in sandboxie. When the malware runs in sandboxie, it will be trying to connect to its C&C. Your WireShark will be adding packets to its list. We will see the packet its sending and thats how we will trace the malware. It may take a bit to find depending on how many packets are coming in, Where its connecting to etc..

In my example I am using an IRC bot, So thats what we will be looking for! The best way to find what your looking for is by IP. If you dont have anything open you will get a few packets with the same IP's over and over, once you open the malware, the new ip should be fairly easy to spot (again, i say easy if your on vmware with nothing else running)

Here is how It looks when i find the evil IP.

5) Now that we have found the C&C IP, lets go a step further with it! Right click the IP, and select "Follow TCP Stream". It will bring up a screen with some info as shown below. This will give you an idea on what type of malware it is. The information shown will vary depending on the malware, here is how an IRC bot looks.

This also gives other info such as irc server build, how many infects on server etc... As of this point you have successfully traced malware back to its C&C server. CONGRATS!!!

This is just the beginning of what you can do! There are a few things you can do from here.

1) If an irc server and its not secure, you can easily get on and steal someones bots.

2) DDOS. you have the fuckers ip address, if they are using a RAT or something like that, its most likely off their home connection so you can feel free to knock them offline for as long as you wish Big Grin

3) Report the IP or DNS. Especially useful for white hats. IF they are using a no-ip, report their DNS, with proof its almost guaranteed that they will IP ban them. I am actually banned from no-ip for this reason Big Grin

4) Think about it... Im sure you can find something to do with the information you find.


EDIT: Here is an example of a RAT:
  • This is the no-ip connection

  • This is what the TCP stream of BlackShades RAT looks like.

I hope this has helped you learn something new.

Thanks for visiting my BLOG!

Sunday, 10 November 2013

Reverting Keyloggers and Stealers

What is Reverting?
  • Reverting generally means reversing an action or undoing the changes. Here in our case, reverting would be more of reversing the action.
For this we will need a keylogger server using ftp. It can be found on warez sites, youtube etc. You basically need the following things:
  • Keylogger, passstealer
  • Cain and Abel
  • Virtual machine (so you don't get infected, and what if the hacker is using better protocol that would be epic fail).

Getting Started:

1) Execute the keylogger on your virtual machine.



2) Now run Cain and Abel and do the following things as per stated order.
  
      Dowload Cain and Abel  (click here)


3) Wait for sometime and then check back the passwords area.


As you can see the keylogger used ftp protocol to transfer the logs. Ftp protocol isn't very safe since it doesn't encrypt the data. Anyways you should see the IP address where your PC is sending packets. And also the username and password. This might not work if the server is using other protocol like http, smtp, etc. you'll most probably get junk values in user and pass box if those protocols are used.


Guess what its our very own DRIVEHQ.com . Now login using ftp password that we got from the sniffer and get going. I would recommend to steal the logs quietly like a ninja, so you can get others logs as well. Of course you can change the pass if you want but it won't send any further logs.
after reading this i will bet you this Wink

first of all before hackers make their keyloggers and searching for victim but after this u guys will be searching for the keyloggers and hack the hacker back! MEGA OWNED Troll

Thanks for visiting my BLOG!

Saturday, 26 October 2013

Trace the hackers

Trace the Hacker | Trace down the Trojan Horse attacker in few simple steps | 
 
What is a RAT?

RAT: So basically Rat is known as a Remote administrator tool. It Is
Used to hack remote A PC without any authentication. There are so many
Similar Rat tools Available Online . Rat Allows a Remote attacker to
control the infected Computer according to his own wish and Way to carry
out many kind of malicious & illegal activity as he has the
complete administrator rights of the Remote Computer . Remote
administration tool like dark comment is installed on victim’s Computer
without the victim’s knowledge.



Basic Functions of RAT are -

⦁ Capture Webcam images
⦁ Turn Firewall on/off
⦁ Simple Pranks by deleting files & turning off computer
⦁ Let's us execute virus in the victim’s PC
⦁ Enables us to download files from victim’s PC
⦁ DDos from victim’s PC

Below are some names of different types of RAT Software’s -
Dark Comet RAT
Black shades RAT
Xtreme RAT
Cybergate RAT
Sub Seven
Pain RAT
JRAT
Net Devil
Apocalypse RAT
Shark RAT
Back Orifice
Bandook RAT
Bifrost
LANfiltrator
Optix Pro
ProRat


So This Were Some Basic Information About The Rat.Let's now move to the our main Topic Tracing The Hacker.

Requirements :



1. TCPView <=== Click And Download This
2. Knowledge about process running in windows
3. Little Knowledge About Rats
4. Brain

First Of All let's Assume that You Are The victim Of A rat. You realized
it when you started noticing some unusual activities taking place on
your computer. like some of the programs get closed without your
permission , Your webcam start automatically, PC shuts downs
automatically and other things !.

So while the hacker is connected to your PC, he is in danger too as he
can be traced easily. Now we are going to use a tool which can help us
to find the attackers IP address, Geographical Location and a lot more
information about the attacker.

TCPView: It is program that shows the complete detailed listings of all
TCP and UDP endpoints on your system, it including the local, remote
addresses and state of TCP connections. As almost all remote hacks are
prepared over the Internet, you will be able to use TCPView Which Will
Help You To Find If Any Remote PC Is Connected To Your PC. In Simple
Language It Allows us to view all the TCP/IP connections on your
Computer.

So Download TCP View from the below given link and extract all the files on the Desktop And then Start TCPView.




Now as you can see in the screenshot above it displays all of the active
TCP/IP connections on your computer. If there is a remote user
connected to your computer at this time, then TCPView will show their
connection, IP address & other details



 So here I have Infected my own computer with my own RAT. As you can see
in the image a Reverse Connection has been Established on the ip
127.0.0.1 which is localhost. Here as an Attacker i am using local host
ip address for the reverse connection. But In Your case the attacker
will use the static IP address So that he will be Connected to Your PC
Permanently. In the image also Check the Port No. 1604 ! Looking Odd
?? Actually there is no Service which runs on the Port No. 1604 For
More Info you can Check On Google. So Once you have Found out the
attackers IP Address now its time to locate the infected file, where it
is placed! . To Locate the Infected RAT file Just Double Click On It and
you Can also Kill the Connection now . So Just Right Click On the
Unknown Connection and Kill the Task & then you are completely
done!. You computer is now disinfected & you also got the IP Address
of the attacker.
 
Here's the screenshot of the Location of the RAT file that you the Victim Installed Our PC.


Later you can do whatever you want to do with the attackers IP Address.
Report it to the cyber police or Attack him back & blah blah !!
 
Be Safe! Keep Hacking !


Thanks 4 visiting my BLOG!!