Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 101 guests online
 
Advertisement

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Malwarearrow Assistance requested
EH-Net
May 19, 2013, 05:36:55 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Assistance requested  (Read 11091 times)
0 Members and 1 Guest are viewing this topic.
SephStorm
Hero Member
*****
Offline Offline

Posts: 530


View Profile WWW
« on: January 09, 2011, 07:13:16 PM »

Hi All,

I have a PC set up for pentesting, and I am still building it, finding programs ect. Two issues, 1. I am fairly certain I am getting good downloads from the official sites, except in one notable case, the windows binary is no longer maintained and of course now I have something listening I can see in netstat connection 220.90.198.65 port 1064 supposedly the JSTEL service. I have blocked the connection at the Windows Firewall, and redirected it to localhost through the hosts file, but I am not sure if this really is malicious, or a side effect of a legit program.

So I could use any advice on determining the nature of this connection.

2. because I am downloading applications that will be detected by my a/v, how can I distinguish between a hacking tool, and malware?
Logged

ziggy_567
Sr. Member
****
Offline Offline

Posts: 361


View Profile
« Reply #1 on: January 09, 2011, 07:48:13 PM »

The most reliable way of determining what the port is doing is to capture traffic on that port. If you think you've been rootkit'ed, set up a snort box...
Logged

--
Ziggy


eCPPT - GSEC - GCIH - GCUX - RHCE - SCSecA - Security+ - Network+
Data_Raid
Full Member
***
Offline Offline

Posts: 165



View Profile
« Reply #2 on: January 10, 2011, 03:34:36 PM »

That IP Address traces back to Korea:
http://whatismyipaddress.com/ip/220.90.198.65

Some additional info which might or might not be applicable (taken from http://www.pczone.com.tw/vbb3/archive/t-108256.html):

> download.microsoft.com
Server: query.ttn.net
Address: 202.145.138.1

Non-authoritative answer:
Name: a767.ms.akamai.net
Addresses: 220.90.198.90, 220.90.198.65, 220.90.198.83
Aliases: download.microsoft.com, download.microsoft.com.nsatc.net
download.microsoft.com.d4p.net, download.microsoft.com.georedirector.akadns.net

As ziggy_567 mentioned, capturing traffic and viewing the captured packets might give you an idea what connections are being created and the relative destination address.  You could also use TCPView from Sysinternals to gather more information about the connections on your computer: http://technet.microsoft.com/en-us/sysinternals/bb897437
Using TCPView, you can highlight the connection and view properties of that process (if possible) which might give you more information on what application created the connection.

Regarding setting up a lab, what I like to do is not install any A/V on the attacking/testing machine, I also make sure that this machine is isolated from the rest of my machines, I also ensure that this machine never connects to the internet once I'm done setting it up.
« Last Edit: January 10, 2011, 03:42:27 PM by Data_Raid » Logged

All men by nature desire knowledge.

Aristotle
SephStorm
Hero Member
*****
Offline Offline

Posts: 530


View Profile WWW
« Reply #3 on: January 10, 2011, 09:20:15 PM »

Yeah, Sam Spade told me a little about it Wink I am in Korea, which made me think the traffic was legit, all of those server do appear to be legitly tied to MS. I wonder if some MS program is phoning home?...
Logged

Third_Eye
Newbie
*
Offline Offline

Posts: 5



View Profile
« Reply #4 on: April 13, 2011, 09:32:21 AM »

i'll create small trojan file but i cannot send it in email to another party. because yahoo identified it is an virus. and i use obsidium and poison ivy to create undetectable trojan file but i cannot win it.

please help me to do this. this for my education

thank you    Huh
Logged

MCP,MCTS,MCITP,CIW,CCNA
WCNA
Full Member
***
Offline Offline

Posts: 187



View Profile
« Reply #5 on: April 13, 2011, 01:08:51 PM »

Open a command prompt and type "netstat -nao" (without the quotes). That'll give you the process IDs. You can then kill the Process ID of the offending program. You can also use ProcessHacker, a freeware program, that'll give more info but you have to know what you're doing with handles, etc. You could also install sandboxie and buster, start buster, load the program in sandboxie and then watch what the program is doing with buster.

There's bunches of other ways as well but those are the easiest for beginners. If you want to dig even deeper, try some of the tools listed in the Malware Cookbook (hint: look through the index on the Amazon page to see all the different tools).

Almost forgot- GMER and IceSword are good Windows tools you could try as well.
« Last Edit: April 13, 2011, 01:30:39 PM by WCNA » Logged

ISC2 Associate, WCNA, CWNA, OSCP, Network+
Third_Eye
Newbie
*
Offline Offline

Posts: 5



View Profile
« Reply #6 on: April 14, 2011, 06:14:13 AM »

I want to be a create undetectable trojan . ill create trojan file but it is detecting like virus how can i set this trojan undetectable. i ll tried to use poison ivy, obsidiumsetup and more how can i create this trojan file to undetectable virus.

please help me. sorry about my poor english sorry

thank you

 Huh
Logged

MCP,MCTS,MCITP,CIW,CCNA
SephStorm
Hero Member
*****
Offline Offline

Posts: 530


View Profile WWW
« Reply #7 on: April 14, 2011, 05:55:59 PM »

@Third eye,

No Malware stays undetectable. One a signature is made for the malware, then it can be detected and removed.

FYI, you may want to check the yahoo mail terms of service. I'm pretty sure that intentionally uploading malware is a violation.
Logged

Third_Eye
Newbie
*
Offline Offline

Posts: 5



View Profile
« Reply #8 on: April 18, 2011, 09:23:52 AM »

:::::   SephStorm

you are right. but how can i create this undetectable trojan i used obsidium also but it is not working please help me to resolve this problem

thanking you

 Roll Eyes
Logged

MCP,MCTS,MCITP,CIW,CCNA
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.056 seconds with 23 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.