Video Screencast Help
Search Video Help Close Back
to help
Not able to make it to Vision this year? Get a sampling in the Best of Vision on Demand group.

Moving from Fame to Fortune

Created: 02 May 2009 | 10 comments
khaley's picture
+3 7 Votes
Login to vote

What changed everything was when the hackers, miscreants and ne'er-do-wells moved from fame to fortune. Once these guys figured out you could make money, malware became crimeware and nobody writes malware for bragging rights anymore. It’s for the moola.

So it’s been hard to explain Conficker/Downadup. It’s been plenty famous. But it wasn’t doing anything to make money. That changed shortly after the E variant came out. (If you can’t keep the varinants straight, don’t feel bad. Most people can’t. Want to see a terrific visual explanation? Check out the video Ben Narhorney put together to explain it all. You can see it on the Symantec Security Response YouTube channel. There are other great videos there too.

So how did Conficker move to fortune? Well it wasn’t by changing its own behavior. It was much more simple than that. It downloaded another well know piece of malware; Waledac. W32.Waledac can steal information from a machine, send spam from the machine and download additional files. And download additional files it did. The most popular way bad guys are making money on the internet right now is misleading application. And sure enough, on Conficker infected machines up pops a misleading application called Spyware Protect 2009.

imagebrowser image

Undoubtedly this is not the last use for these machines for fortune we’ll see. My prediction is that once they’ve drained as many dollars as they can out of the owners of these machines they'll start using them to drain money from non-infected machines. Most likely via spam. When we start seeing this happen we’ll let you know.

Comments

Nel Ramos's picture
03
May
2009
2 Votes +2
Login to vote

As their nasty business

As their nasty business grows, so does their capitalization to R&D. Time might come when the hackers would be having the same infrastructure as the software houses that prevents them from making damage. If it happens them what a gloomy future it would be. Just my thoughts. 

Nel Ramos

mon_raralio's picture
18
May
2009
1 Vote +1
Login to vote

.

R&D - they already have forums like this, maybe even had since the bbc days. Perhaps, even more.
I'm not sure about the infrastructure though. Some might have their own server filled with virtual machines, some use botnets for data mining, and a lot use the free web pages with many adverts, where you can create a web page, have it on the internet and not pay anything - which means anonymity.

“Your most unhappy customers are your greatest source of learning.”

Tejas Shah's picture
06
May
2009
2 Votes +2
Login to vote

Is there any way we can see

Is there any way we can see what kind of packets are going thro the Network cards, especially the one which goes on the internet?

Om_123's picture
06
May
2009
1 Vote +1
Login to vote

yes for sure

go to this url http://www.paessler.com/network_monitoring_tool to know more about netflow

Nel Ramos's picture
06
May
2009
1 Vote +1
Login to vote

@Om_123: Nice tools! PRTG

@Om_123: Nice tools! PRTG Network Monitor V7 is good. How different is this with wireshark and the other free net monitoring tools...
thanks...

Nel Ramos

mon_raralio's picture
18
May
2009
1 Vote +1
Login to vote

Wireshark shows you the

Wireshark shows you the packets being sent or delivered on your eth. Network Monitor measures usage and speed.

“Your most unhappy customers are your greatest source of learning.”

Om_123's picture
06
May
2009
0 Votes 0
Login to vote

re

just frwd me ur mail id ill reply it 2 u

mon_raralio's picture
18
May
2009
1 Vote +1
Login to vote

@Tejas: The above mentioned

@Tejas: The above mentioned softwares could do the trick, but getting the packets coming from the internet and not just your local PC in a network is a tall order. They need to collect information from an ethernet device, so to do what you wanted - you'd have to setup a collector in the WAN side and with the way the WAN is routed, you'd mostly get broadcasts.

“Your most unhappy customers are your greatest source of learning.”

Nel Ramos's picture
21
May
2009
1 Vote +1
Login to vote

We use wireshark only to

We use wireshark only to troubleshoot but not for monitoring since you could not get any fast intelligent information in one glance.   

Nel Ramos

Sheila Marie's picture
06
Jun
2009
0 Votes 0
Login to vote

Are there other monitoring

Are there other monitoring tools that is free to use..
thanks...