Posts

Showing posts with the label zeusvm

ZeusVM and steganography

Image
ZeusVM and steganography Months ago, researchers observed an evolution of ZeusVM, time to get back on this family. For informations, The first ZeusVM sample ive seen using steganography was the 21 November 2013. The IP of the C&C have Russian origin: 212.44.64.202 A Sutra TDS who redirect on Nuclear Exploit pack was pushing the payload, Roman of abuse.ch blacklisted 212.44.64.202 one month later on his Zeus tracker. The first guy who publicly wrote about ZeusVM change is probably Jerome Segura of Malwarebytes. Actually the latest version ive saw in the wild is 1.0.0.5, and if you want a hash: e4c31d18b92ad6e19cb67be2e38c3bd1 (sample is fresh of today) Lets have a look on the first server that ive see now... 212.44.64.202. Pony, Multilocker, Mailers, Grum and an older version of ZeusVM (without steganography) was also hosted on this server but that not the topic. The filename of login scripts and ZeusVM configs were hardnamed in russian, like: borodinskoesrajenie.jpg (http://en.wiki...