Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 41 guests online
You are here:
Home
Features
/root
Finjan: Chinese Fill Void Left by Russian Business Network (RBN)
EH-Net
May 18, 2013, 08:47:31 PM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Features
>
/root
(Moderator:
don
) >
Finjan: Chinese Fill Void Left by Russian Business Network (RBN)
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: Finjan: Chinese Fill Void Left by Russian Business Network (RBN) (Read 11574 times)
0 Members and 1 Guest are viewing this topic.
don
Editor-In-Chief
Administrator
Hero Member
Offline
Posts: 4165
Editor-In-Chief
Finjan: Chinese Fill Void Left by Russian Business Network (RBN)
«
on:
December 20, 2007, 02:20:14 PM »
Nice little write-up by Jim Carr, SC Magazine’s west coast bureau chief:
Quote
An intricate network of servers operated by Chinese criminals has moved into the void created when the notorious Russian Business Network (RBN) shut down, according to a report from anti-crimeware vendor Finjan.
December's "Malicious Page of the Month" report from Finjan's Malicious Code Research Center (MCRC) notes that the RBN “has suddenly picked up from its St. Petersburg digs and diversified…spreading its activity to new chunks of IP addresses, with RBN-like activity almost immediately appearing on newly registered blocks of Chinese and Taiwanese IP addresses."
Iftach Amit, director of security for the MCRC, told SCMagazineUS.com that the Chinese group's activity is “an evolution of the Russian Business Network."
“All of the criminal activity over the internet has financial gain behind it, and if you shut down one part of the system, it's bound to bounce back because of market forces,” he said.
The report also noted that MI5, the United Kingdom's counter-intelligence agency, warned 300 U.K. chief executives and security experts of an increased risk from Chinese hackers following an attack on government servers.
Amit said Chinese cybercriminals scan the internet searching for vulnerable U.S. and European hosts at universities and government offices. The hackers then take advantage of misconfigured or unpatched systems, infecting them with IFRAME or JavaScript code, Amit said. The victim is then redirected to a series of sites containing IFRAMEs, including those belonging to the Chinese network.
Other trojans are then downloaded to the victim's compromised PC and another IFRAME sends personal data, such as banking authentication credentials, to the network of Chinese servers. That information is used for tracking and statistics, as well as online transactions, without user knowledge, said Amit.
"It's very sophisticated," he said. "They are able to circumvent many of the security measures the banks have taken."
Original SC Magazine story
HERE
.
Don
Logged
CISSP, MCSE, CSTA, Security+ SME
shawal
Jr. Member
Offline
Posts: 88
Re: Finjan: Chinese Fill Void Left by Russian Business Network (RBN)
«
Reply #1 on:
March 11, 2008, 04:16:36 PM »
Nice, the article is 3 months old, he did not present enough facts, just becuase RNB site is down that does not mean that they are out of biz. according to the wikipedia article there are still some reports till last month. that does not mean there will be no other underground networks surfacing. all i am saying as long as there are botnets, phising, vhising, farming, and harvesting scams, most likely these networks are behind them as means of renting attackes, and leasing computer resources time
Where would be the next sploits auction site?
Logged
RHCE, GIAC GCIH.
dean
Guest
Re: Finjan: Chinese Fill Void Left by Russian Business Network (RBN)
«
Reply #2 on:
March 11, 2008, 10:20:02 PM »
Quote from: shawal on March 11, 2008, 04:16:36 PM
Nice, the article is 3 months old, he did not present enough facts, just becuase RNB site is down....
Well, it was posted 3 months ago.The article was written after the RBN changed netblocks. They moved to Chinese ISPs. They moved again soon after due to preassure from the Chinese Government.
Rather than explain the relationship between the RBN, botherders, spammers, etc... and how the RBN provides services to them or purchases services from them go here:
http://rbnexploit.blogspot.com/
dean
Logged
Andrew Waite
Hero Member
Offline
Posts: 928
Re: Finjan: Chinese Fill Void Left by Russian Business Network (RBN)
«
Reply #3 on:
March 12, 2008, 10:38:56 AM »
Quote from: dean on March 11, 2008, 10:20:02 PM
Rather than explain the relationship between the RBN, botherders, spammers, etc... and how the RBN provides services to them or purchases services from them go here:
http://rbnexploit.blogspot.com/
Nice link, think I'll be spending a bit of time studying that. Can't explain why as I've never had enough time to investigate to deeply but botnets and associated 'naughtiness' has always peeked my interest.
Logged
--
http://www.infosanity.co.uk
--
http://blog.infosanity.co.uk
shawal
Jr. Member
Offline
Posts: 88
Re: Finjan: Chinese Fill Void Left by Russian Business Network (RBN)
«
Reply #4 on:
March 12, 2008, 11:01:20 AM »
RoleReversal,
please share your finding with us. I am also interested, having the possible ability to control the largest computional resources worldwide amazes me, specialy when it is a very heterogenous environment spreading over the globe. the financial, and business (Mob) side of it is also interesting to follow up ( how can people get away with murder?
)
Logged
RHCE, GIAC GCIH.
Andrew Waite
Hero Member
Offline
Posts: 928
Re: Finjan: Chinese Fill Void Left by Russian Business Network (RBN)
«
Reply #5 on:
March 12, 2008, 03:35:49 PM »
shawal,
the story that started my interest in botnet tracking was written by Steve Gibson of GRC.com. Basically it was a write-up of his investigations into a real life DDoS attack experienced by his company. Included the likes of detailed explanation of the attack experienced to writing a custom IRC bot to snoop on the attackers botnet command and control structure.
I've spent all afternoon trying to find a link to the story but everything I find points to a 404 error on the GRC site so it looks like it has been taken down for some reason. If you have as much luck as I did finding it PM me as I may have a saved copy on one of my works machines.
One of the botnet investigations I have undertaken myself was a an irc bot I cleaned from a client's server. Unfortunately I was unable to take the investigation as far as I would have liked as the c&c deactivated before it could be infiltrated. From packet traces obtained during the incident it appeared the bot was part of a spam sending network And wasn't very subtle, at random times of the day it would max out the server's 100Mb connection, made finding the issue childs play.
An aspect of the bot that I found rather amusing after pulling it's code apart is that it seemed to be programmed to throw random insults to the commandline. I am now the proud owner of a rather large file containing little more than insults about 'yo' mamma'
In response to your question about people getting away with murder, from experience in situations like this is can be very difficult, if not impossible, to find the true 'botmaster'. Often the best you can do is clean-up, inform any parties that have been involved in the investigation and try to prevent a similar intrusion next time. Regularly, the only machines/IPs/people that you can identify are just regular users like yourself, all blissfully unaware or trying to deal with the same issue.
I recently attended a seminar on forensic investigations where one of the talks was given by a member of a police 'cyber-crime' department. Before the talk I believed that the police force would largely ignore these types of activities but was impressed by the level of interest and available resources. I now intend to pass all findings of future investigation to the relevant authorities, something that was actively encouraged during the event.
If you intend to delve deeper into these areas I would highly recomment both the SANs Readin Room and archived webcasts, as well as the Honeynet project. A good starting point in incident response basics is "Dead Linux Machines do tell tales" (
http://www.sans.org/reading_room/whitepapers/honors/1491.php
)
Hope this rather long rant is of some interest/use, and happy hunting
Logged
--
http://www.infosanity.co.uk
--
http://blog.infosanity.co.uk
Andrew Waite
Hero Member
Offline
Posts: 928
Re: Finjan: Chinese Fill Void Left by Russian Business Network (RBN)
«
Reply #6 on:
March 13, 2008, 04:29:43 AM »
Sorry for responding to my own post.
as if by fate I have just received an email informing me that there is a new update for the cyber-ta's bothunter package (
www.cyber-ta.org/BotHunter
). I havent' had a chance to get this app through the change control process at work to give it a run through, but from reading the site I definitely want to. If anyone has any real-world experience of the tool can you let me know if it lives up to the hype?
Logged
--
http://www.infosanity.co.uk
--
http://blog.infosanity.co.uk
dean
Guest
Re: Finjan: Chinese Fill Void Left by Russian Business Network (RBN)
«
Reply #7 on:
March 13, 2008, 06:50:14 AM »
I would not consider it to be 'hype' but in answer to your question:
yes
dean
Logged
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
General Certification
: CPT Practical Submission
(0) by
z28power4u
OSCP - Offensive Security Certified Professional
: Class Scheduled 6/8 - Linux n00b
(5) by
MrTuxracer
Career Central
: Starter cert?
(0) by
Alert
Web Applications
: Nessus and Nikto
(4) by
Seen
Tutorials
: Need guidance
(7) by
impelse
Malware
: EICAR?
(2) by
SephStorm
Network Pen Testing
: Cracking salted MD5 hash
(4) by
n37sh@rk
CEH - Certified Ethical Hacker
: Passed my C|EH
(3) by
n37sh@rk
Mass Media
: EC-council hacked, irony at his best?
(0) by
j0rDy
Web Applications
: SQL Injection into an INSERT statement.
(6) by
eyenit0
Network Pen Testing
: Solution for sipXtapi INVITE Message CSeq Field Header Remote Overflow
(1) by
m0wgli
Web Applications
: dns
(2) by
H1t M0nk3y
Other
: BSides Boston
(0) by
3xban
Career Central
: InfoSec in Central, FL
(2) by
tturner
Web Applications
: Web vulnerability scanner
(4) by
H1t M0nk3y
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
Free Business and Tech Magazines and eBooks
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.