[TUT] Exploring the botnets - behind the evil 02-28-2014, 12:39 PM
#1
NOTE:This tutorial was posted in another community, how ever it was made by me to share with both communities since i am a loyal member of both.
Before i begin
A few days ago, i was thinking to myself - what if my computer is a part of a huge botnet and i don't even know it, what if we are all part of one big botnet and is being controlled by someone, immediately i though to myself that this person is like the God of computers, the subject really worried me - so i decided to explore and research the Botnets, fast enough i found how amazing the malware behaves, its structure and its infection methods, and today i would like to share with you that information. (I would be providing unique botnet information, i would not be providing basic botnet information which are obvious functions that each botnet has.)
Botnets in general
A botnet is collecting of internet connected programs which control your computer(not always) and communicate with a server database to receive orders.
A server database could be an IRC channel or an HTTP database website.
But the botnets weren't evil at first, humans made them evil.
A long time ago Botnets were just bots controlling an IRC channel to help the channels admin to remove unwanted users, mode the channel and even play with the users!
But ofcurse some motherfucker decided it would be fun to use this method to create evil and earn money. It was 1999 when the first illegal botnet was invented with the name of "Pretty Park" coded in Delphi it used an mIRC vulnerabilities to gain access to your computer via backdoors, it had a few cool features:
The capability to retrieve usernames, passwords, and dial-up network
settings
The capability to update its own functionality
The capability to upload/download files
The capability to redirect (tunnel) traffic
The capability to launch a variety of DoS attacks
Incorporation of its own IRC client
The capability to retrieve the computer name, OS version, user infor-
mation, and other basic system information.
The capability to search for and retrieve e-mail addresses and ICQ
login name.
After that just shit ton of botnets were made, basing on the same exploits, the IRC exploits to use your computer as a bot and each time they became more advanced, more annoying and more malicious.A small list of bots that were made from 1999 - 2005:SubSeven Trojan/Bot,GT Bot, RBOT,SpyBot,PolyBot(You can guess why it got its name), well as much as like to detail each bot and its capabilities i wont because it would just take too much writing, if you are interested to read about the information then here: http://www.mediafire.com/view/qpp6h4aqp6...ations.pdf - A rather interesting book, i didn't finish it i only reached to page 150 if Im not wrong.
But as technology developed the botnets have developed as well, these days bots don't exploit the IRC clients, they mostly infect you when you run malicious programs, When the user of the computer executes an Infecting EXE its mostly likely a Trojan, who drops shit ton of bullshit into your computer besides connecting you to the botnet of curse. Most drop Keyloggers, Viruses, Worms just to make sure that the bot would live long enough, new Botnets write themselfs into the Master boot record to gain full control of the computer.
Botnet types
Today i would be writing about a few known botnets:
1.Citadel
2.Carberp
Lets Dissect some malware! *WARNING PUT YOUR GLOVES ON FOR SAFETY AND DISINFECTION*
![[Image: 11870592-a-surgeon-putting-on-gloves-iso...-white.jpg]](http://us.123rf.com/400wm/400/400/mscates/mscates1201/mscates120100012/11870592-a-surgeon-putting-on-gloves-isolated-on-white.jpg)
The Citadel Botnet
![[Image: citadel-logo-250.png]](http://sophosnews.files.wordpress.com/2013/06/citadel-logo-250.png)
Ah what a classic, based on the Zeus code citadel was an amazing botnet and still is of-course.
Just some cool information i found
The Citadel User Licenses agreement - http://pastebin.com/vk9A3mTS
Citadel commands - http://pastebin.com/VhmBsTwG
Citadel User Manual - http://pastebin.com/HZaGgPg5
The Botnet itself
The Citadel botnet, based on the Zeus botnet was released in 2012, offering a lot of awesome illegal functions. The origin of it is russia(WHAT A SHOCKER)
coded by Aquabox and first released in Exploits.in.
The price was 2390$ a pop, again what shocker. The Citadel creators claimed that they were not selling an "Eye candy" But a new improved and more functional Zeus variant, also offering their builder and some amazing services like the user manual which kind of impressed me because most botnets dont offer an Easy Install but of-course when it was leaked the skids just hyped all over it creating shitty and nubbish servers that were taken down by Microsoft in 4 seconds.
For unknown reasons the Citadel botnet only worked with English based computers, if the Citadel botnet detected a Russian or A Ukraine layout of language the botnet would destroy itself.I can assume this method was created to avoid being caught.
"If a Russian or Ukrainian layout is detected, the bot terminates. This is done to prevent installs on CIS systems. You may disagree, but that’s taboo for us. If you want to test the bot or develop your own injects – install an English-language system. We will provide URLs to download the OS image and VMWare to save you some time. " - Translated from russian.
Ah just amazing service by the Citadel team
I found the Citadel service to be really nice, unlike most malware creators who just leave you to hang around without decent services, Citadel provided a nice service here are some examples
Translated from russian)
1.Collect data on specific companies and accounts of interest into a separate DB and a separate script. It has a nice layout, you can see the list of online bots and details of the collected accounts.
2.Receive automated Jabber alerts whenever a new account is added or a bot comes online. For convenience, the alert contains the IP
ORT for VNC connection.
3.Executable files auto-encryption module. Tired of manually encrypting your files or waiting for that encrypter to come back online? Automate the encryption task with this awesome auto-crypt module that will automatically refresh your botnets’ exe files. The script operates through Death’s jabber service called cbot. $15 per encryption.
4. Every client has the right to create an unlimited number of requests and suggestions for new module/functionality. These requests can be public or private (visible to you only).
Every client has the right to vote for ideas submitted by other members and to contribute money towards developing the module/functionality. Based on the voting results, the developers decide which module should be built.
Every client has the right to comment on requests and talk to other members. Now you can find partners and like-minded people and take an active part in product development discussions.
"You will really appreciate this new approach!"
"Demo access upon request (allow up to 24 hours). "
The most interesting thing that Citadel provided, were the web injections:
![[Image: webinject.png]](http://blog.malwarebytes.org/wp-content/uploads/2012/11/webinject.png)
The web injections claimed to be Legit window pop ups but well just by looking at it you can see its wrong. using this method the Citadel Bot Masters stole more than 15,000,000 million dollars. Of-course the FBI Launched an attack on the Citadel botnets and on one specific "John Doe" who was the botnet coder (ye rite fbi you got him :|) but 90% of botnets were taken down how ever the victims didnt really get their money back.
(The Citadel functions are located in the pastebins i posted and the list is just too large for me to talk about it, most of the functions are installed in each botnet but Citadel improved them a bit i guess)
Some Pictures
![[Image: citadelpanel5.png]](http://4.bp.blogspot.com/-v849N4lTS5U/UpVNapUp7TI/AAAAAAAAACg/p114dP7Y_zw/s640/citadelpanel5.png)
- If you owned the botnet you could login in to their store and purchase more exploits and plug ins and update your software.
- Probably another statistic fucntion that Citadel offered, showing the detection of the botnet in your bots using which Anti-Virus.
Carberp
Look whose back, its the Carberp gang! after thier arrest in 2012 they got back to distributing their botnet again.
- Carberp Advertising in Undergrounds.in ?
"We decided to resume sales after a long break due to the release of a new version of the bot bootkit.
Compared with the previous version improved stability, durability and functionality.
Also I want to note the appearance of the possibility of renting software.
All of our current clients, for whatever reason, have lost touch with us, can upgrade their assembly.
As an update will be given one of varitsy minimal assembly, according to previously purchased a complete set."(Translated from russian)
The price? 40,000 dollars a pop, this is a new version, an unleaked version, Carberp also appeared in Darkode.com
![[Image: darkode-carberp-xylibox-dot-com.png]](http://2.bp.blogspot.com/-r5EfN4_2_v0/UWP7NefM-DI/AAAAAAAADPA/CWZbFyeJ9sw/s400/darkode-carberp-xylibox-dot-com.png)
The carberp botnet hide itself inside the computer using a bootkit, also web injections Key loggers and providing a nice control panel.
http://malware.dontneedcoffee.com/2012/1...sance.html - Detailed advertising.
![[Image: screenshot_290.png]](http://4.bp.blogspot.com/-WG9BOI_mfd8/UMhXfJvmdDI/AAAAAAAADmI/dHWIQSk1SPk/s1600/screenshot_290.png)
Although the amazing features of the botnet, the panel wasnt that impressive design wise, although they provided a nice possibility that allowed you to add user groups, which allowed the botnet to be used by multiply users, and each group add a lot of functions to edit:
![[Image: 919bfd52e5ff60999d4e22bb944cc1bd.png]](http://gyazo.com/919bfd52e5ff60999d4e22bb944cc1bd.png)
- Statistics
A really amazing D&E:
![[Image: 27-06-2013+11-21-33.png]](http://1.bp.blogspot.com/-qyaLY-92LFQ/UcwELOPw8SI/AAAAAAAAi58/M30IA0ywZYU/s1600/27-06-2013+11-21-33.png)
A Ry-cycle bin:
![[Image: 679f0c211908a8a55dfc13c29011e67e.png]](http://gyazo.com/679f0c211908a8a55dfc13c29011e67e.png)
Summary
Well thats it guys, i would like to thank Xylibox and Malware dont drink coffee blogs for providing this information.
http://www.xylibox.com/2013/06/carberp-c.html - A blog by Xylibot who provides amazing information.
http://malware.dontneedcoffee.com/ - Amazing malware blog.
Hmm maybe i should talk about SypEye as well.
It would be nice if you help me find grammatical errors because i already found a few.
Before i begin
A few days ago, i was thinking to myself - what if my computer is a part of a huge botnet and i don't even know it, what if we are all part of one big botnet and is being controlled by someone, immediately i though to myself that this person is like the God of computers, the subject really worried me - so i decided to explore and research the Botnets, fast enough i found how amazing the malware behaves, its structure and its infection methods, and today i would like to share with you that information. (I would be providing unique botnet information, i would not be providing basic botnet information which are obvious functions that each botnet has.)
Botnets in general
A botnet is collecting of internet connected programs which control your computer(not always) and communicate with a server database to receive orders.
A server database could be an IRC channel or an HTTP database website.
But the botnets weren't evil at first, humans made them evil.
A long time ago Botnets were just bots controlling an IRC channel to help the channels admin to remove unwanted users, mode the channel and even play with the users!
But ofcurse some motherfucker decided it would be fun to use this method to create evil and earn money. It was 1999 when the first illegal botnet was invented with the name of "Pretty Park" coded in Delphi it used an mIRC vulnerabilities to gain access to your computer via backdoors, it had a few cool features:
The capability to retrieve usernames, passwords, and dial-up network
settings
The capability to update its own functionality
The capability to upload/download files
The capability to redirect (tunnel) traffic
The capability to launch a variety of DoS attacks
Incorporation of its own IRC client
The capability to retrieve the computer name, OS version, user infor-
mation, and other basic system information.
The capability to search for and retrieve e-mail addresses and ICQ
login name.
After that just shit ton of botnets were made, basing on the same exploits, the IRC exploits to use your computer as a bot and each time they became more advanced, more annoying and more malicious.A small list of bots that were made from 1999 - 2005:SubSeven Trojan/Bot,GT Bot, RBOT,SpyBot,PolyBot(You can guess why it got its name), well as much as like to detail each bot and its capabilities i wont because it would just take too much writing, if you are interested to read about the information then here: http://www.mediafire.com/view/qpp6h4aqp6...ations.pdf - A rather interesting book, i didn't finish it i only reached to page 150 if Im not wrong.
But as technology developed the botnets have developed as well, these days bots don't exploit the IRC clients, they mostly infect you when you run malicious programs, When the user of the computer executes an Infecting EXE its mostly likely a Trojan, who drops shit ton of bullshit into your computer besides connecting you to the botnet of curse. Most drop Keyloggers, Viruses, Worms just to make sure that the bot would live long enough, new Botnets write themselfs into the Master boot record to gain full control of the computer.
Botnet types
Today i would be writing about a few known botnets:
1.Citadel
2.Carberp
Lets Dissect some malware! *WARNING PUT YOUR GLOVES ON FOR SAFETY AND DISINFECTION*
![[Image: 11870592-a-surgeon-putting-on-gloves-iso...-white.jpg]](http://us.123rf.com/400wm/400/400/mscates/mscates1201/mscates120100012/11870592-a-surgeon-putting-on-gloves-isolated-on-white.jpg)
The Citadel Botnet
![[Image: citadel-logo-250.png]](http://sophosnews.files.wordpress.com/2013/06/citadel-logo-250.png)
Ah what a classic, based on the Zeus code citadel was an amazing botnet and still is of-course.
Just some cool information i found
The Citadel User Licenses agreement - http://pastebin.com/vk9A3mTS
Citadel commands - http://pastebin.com/VhmBsTwG
Citadel User Manual - http://pastebin.com/HZaGgPg5
The Botnet itself
The Citadel botnet, based on the Zeus botnet was released in 2012, offering a lot of awesome illegal functions. The origin of it is russia(WHAT A SHOCKER)
coded by Aquabox and first released in Exploits.in.
The price was 2390$ a pop, again what shocker. The Citadel creators claimed that they were not selling an "Eye candy" But a new improved and more functional Zeus variant, also offering their builder and some amazing services like the user manual which kind of impressed me because most botnets dont offer an Easy Install but of-course when it was leaked the skids just hyped all over it creating shitty and nubbish servers that were taken down by Microsoft in 4 seconds.
For unknown reasons the Citadel botnet only worked with English based computers, if the Citadel botnet detected a Russian or A Ukraine layout of language the botnet would destroy itself.I can assume this method was created to avoid being caught.
"If a Russian or Ukrainian layout is detected, the bot terminates. This is done to prevent installs on CIS systems. You may disagree, but that’s taboo for us. If you want to test the bot or develop your own injects – install an English-language system. We will provide URLs to download the OS image and VMWare to save you some time. " - Translated from russian.
Ah just amazing service by the Citadel team

I found the Citadel service to be really nice, unlike most malware creators who just leave you to hang around without decent services, Citadel provided a nice service here are some examples
Translated from russian)1.Collect data on specific companies and accounts of interest into a separate DB and a separate script. It has a nice layout, you can see the list of online bots and details of the collected accounts.
2.Receive automated Jabber alerts whenever a new account is added or a bot comes online. For convenience, the alert contains the IP
ORT for VNC connection. 3.Executable files auto-encryption module. Tired of manually encrypting your files or waiting for that encrypter to come back online? Automate the encryption task with this awesome auto-crypt module that will automatically refresh your botnets’ exe files. The script operates through Death’s jabber service called cbot. $15 per encryption.
4. Every client has the right to create an unlimited number of requests and suggestions for new module/functionality. These requests can be public or private (visible to you only).
Every client has the right to vote for ideas submitted by other members and to contribute money towards developing the module/functionality. Based on the voting results, the developers decide which module should be built.
Every client has the right to comment on requests and talk to other members. Now you can find partners and like-minded people and take an active part in product development discussions.
"You will really appreciate this new approach!"
"Demo access upon request (allow up to 24 hours). "
The most interesting thing that Citadel provided, were the web injections:
![[Image: webinject.png]](http://blog.malwarebytes.org/wp-content/uploads/2012/11/webinject.png)
The web injections claimed to be Legit window pop ups but well just by looking at it you can see its wrong. using this method the Citadel Bot Masters stole more than 15,000,000 million dollars. Of-course the FBI Launched an attack on the Citadel botnets and on one specific "John Doe" who was the botnet coder (ye rite fbi you got him :|) but 90% of botnets were taken down how ever the victims didnt really get their money back.
(The Citadel functions are located in the pastebins i posted and the list is just too large for me to talk about it, most of the functions are installed in each botnet but Citadel improved them a bit i guess)
Some Pictures
![[Image: citadelpanel5.png]](http://4.bp.blogspot.com/-v849N4lTS5U/UpVNapUp7TI/AAAAAAAAACg/p114dP7Y_zw/s640/citadelpanel5.png)
- If you owned the botnet you could login in to their store and purchase more exploits and plug ins and update your software.
- Probably another statistic fucntion that Citadel offered, showing the detection of the botnet in your bots using which Anti-Virus.Carberp
Look whose back, its the Carberp gang! after thier arrest in 2012 they got back to distributing their botnet again.
- Carberp Advertising in Undergrounds.in ? "We decided to resume sales after a long break due to the release of a new version of the bot bootkit.
Compared with the previous version improved stability, durability and functionality.
Also I want to note the appearance of the possibility of renting software.
All of our current clients, for whatever reason, have lost touch with us, can upgrade their assembly.
As an update will be given one of varitsy minimal assembly, according to previously purchased a complete set."(Translated from russian)
The price? 40,000 dollars a pop, this is a new version, an unleaked version, Carberp also appeared in Darkode.com
![[Image: darkode-carberp-xylibox-dot-com.png]](http://2.bp.blogspot.com/-r5EfN4_2_v0/UWP7NefM-DI/AAAAAAAADPA/CWZbFyeJ9sw/s400/darkode-carberp-xylibox-dot-com.png)
The carberp botnet hide itself inside the computer using a bootkit, also web injections Key loggers and providing a nice control panel.
http://malware.dontneedcoffee.com/2012/1...sance.html - Detailed advertising.
![[Image: screenshot_290.png]](http://4.bp.blogspot.com/-WG9BOI_mfd8/UMhXfJvmdDI/AAAAAAAADmI/dHWIQSk1SPk/s1600/screenshot_290.png)
Although the amazing features of the botnet, the panel wasnt that impressive design wise, although they provided a nice possibility that allowed you to add user groups, which allowed the botnet to be used by multiply users, and each group add a lot of functions to edit:
![[Image: 919bfd52e5ff60999d4e22bb944cc1bd.png]](http://gyazo.com/919bfd52e5ff60999d4e22bb944cc1bd.png)
- Statistics A really amazing D&E:
![[Image: 27-06-2013+11-21-33.png]](http://1.bp.blogspot.com/-qyaLY-92LFQ/UcwELOPw8SI/AAAAAAAAi58/M30IA0ywZYU/s1600/27-06-2013+11-21-33.png)
A Ry-cycle bin:
![[Image: 679f0c211908a8a55dfc13c29011e67e.png]](http://gyazo.com/679f0c211908a8a55dfc13c29011e67e.png)
Summary
Well thats it guys, i would like to thank Xylibox and Malware dont drink coffee blogs for providing this information.
http://www.xylibox.com/2013/06/carberp-c.html - A blog by Xylibot who provides amazing information.
http://malware.dontneedcoffee.com/ - Amazing malware blog.
Hmm maybe i should talk about SypEye as well.
It would be nice if you help me find grammatical errors because i already found a few.

![[+]](https://sinister.li/images/modern/collapse_collapsed.png)