Clicky

Pages

Showing posts with label Zeus. Show all posts
Showing posts with label Zeus. Show all posts

Monday, July 21, 2014

CZ Solution Ltd. signed samples of Xtreme Rat, Zeus, Spy-Net, Gh0st, BozokRAT and other


Here are all samples (+ more) mentioned in this post by Fireeye : The Little Signature That Could: The Curious Case of CZ Solution"
All files are digitally signed with a "CZ Solutions" certificate making it easy to create a Yara or ClamAV signature.

A few Zeus samples seem to be still beaconing. Most are sinkholed.
The certificate is now revoked by VeriSign.

Enjoy




Thursday, December 23, 2010

Dec 23 Zeus/Zbot driven espionage using Merry Christmas card from spoofed jeff.jones@whitehouse.gov

  General File Information

#1 File: card.exe
Size: 177152
MD5:  A486EDD5D966FD167F9D8FA94087913E
SHA1 6cc60b1efb8d82b827634e7e42f2c3c981b1aff6
File Type:  exe
Distribution: Link in email message - download in zip archive
from http://iphonedevelopersdk.com/wp-admin/includes/card.zip (still active as of Jan 2, 2011)



#2 File: card.exe
Size: 179712 bytes
MD5: D51F45E1985DC69CC6BC2B3AE1DA48F1
SHA1 b3b6e3cf9d9e268d2c5d3e692721ed0cdd9e323d
File Type:  exe
Distribution: Link in email message - download in zip archive
from http://quimeras.com.mx/images/card.zip (not active) as seen at
http://jsunpack.jeek.org/dec/go?report=908cfa23d23391577a6a5834bf6377d327c7053b

Read more

Thursday, August 26, 2010

Aug 25 CVE-2010-1240 From Intelligence Fusion Centre with ZeuS trojan



Update: Please read detailed analysis of this and associated attacks   
Crime or Espionage? by Nart Villeneuve

 Download  as a password protected archive (contact me if you need the password)



Intelligence Fusion Centre
In support of NATO
RAF Molesworth, United Kingdom
Unit 8845 Box 300, Huntingdon
CAMBS PE28 0QB

FROM: Intelligence Fusion Centre
SUBJECT: Military operation of the EU

Additional information can be found in the following report:

http:// gnarus.mobi/media/EuropeanUnion_MilitaryOperations_EN. zip
http:// quimeras.com.mx/media/EuropeanUnion_MilitaryOperations_EN.ip

> EUROPEAN UNION
> EUROPEAN SECURITY AND DEFENCE POLICY
> Military operation of the EU
> EU NAVFOR Somalia
>
> This military operation, called EU NAVFOR Somalia - operation
> "Atalanta", is launched in support of Resolutions 1814 (2008), 1816
> (2008), 1838 (2008) and 1846 (2008) of the United Nations Security Council (UNSC) in order to contribute to:
> -  the protection of vessels of the WFP (World Food Programme) delivering food aid to displaced
>    persons in Somalia;
> -  the protection of vulnerable vessels cruising off the Somali coast, and the deterrence, prevention
>    and repression of acts of piracy and armed robbery off the Somali coast.
> This operation, which is the first EU maritime operation, is conducted
> in the framework of the European Security and Defence Policy (ESDP).
>
>
> More information and background documents available on
> http:// gnarus.mobi/media/EuropeanUnion_MilitaryOperations_EN. zip
> and
> http:// quimeras.com.mx/media/EuropeanUnion_MilitaryOperations_EN. zip
>
> ________________________________________
> PRESS - EU Council Secretariat Tel: +32 (0)2 281 7640 / 6319

Headers
X-VirusChecked: Checked
X-Env-Sender: gnarusm@mail.thecopperstar.com
X-Msg-Ref: xxxxxxxxxxx
X-StarScan-Version: 6.2.4; banners=-,-,-
X-Originating-IP: [174.132.255.10]
X-SpamReason: No, hits=1.0 required=7.0 tests=BODY_RANDOMQ
Received: (qmail 15068 invoked from network); 26 Aug 2010 13:24:33 -0000
Received: from a.ff.84ae.static.theplanet.com (HELO mail.thecopperstar.com)
 (174.132.255.10)  by xxxxxxxxxx
 DHE-RSA-AES256-SHA encrypted SMTP; 26 Aug 2010 13:24:33 -0000
Received: from gnarusm by mail.thecopperstar.com with local (Exim 4.69)
 (envelope-from <gnarusm@mail.thecopperstar.com>) id 1OocRS-0006Y5-PR for
 XXXXXXXXXX; Thu, 26 Aug 2010 08:24:30 -0500
To: XXXXXXXXX
Subject: From Intelligence Fusion Centre to XXXXXXX
From: <ifc@ifc.nato.int>
Message-ID: <E1OocRS-0006Y5-PR@mail.thecopperstar.com>
Date: Thu, 26 Aug 2010 08:24:30 -0500
X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
X-AntiAbuse: Primary Hostname - mail.thecopperstar.com
 174.132.255.10
 Hostname:    a.ff.84ae.static.theplanet.com
ISP:    THEPLANET.COM INTERNET SERVICES
Organization:    THEPLANET.COM INTERNET SERVICES
Type:    Broadband
Assignment:    Static IP
Country:    United States
State/Region:    Texas
File name: EuropeanUnion_MilitaryOperations_EN.pdf
 http://www.virustotal.com/file-scan/report.html?id=5761e303d7bc027df47b5b01a3e4e8e186eb36d3a4f40956768231ef3bbcac46-1282832496
 Submission date: 2010-08-26 14:21:36 (UTC)
Current status: finished
Result: 11 /41 (26.8%)
Avast 4.8.1351.0 2010.08.26 PDF:Risk-A
Avast5 5.0.594.0 2010.08.26 PDF:Risk-A
BitDefender 7.2 2010.08.26 Exploit.PDF-Dropper.Gen
eSafe 7.0.17.0 2010.08.26 PDF.DropperExploit.Gen
eTrust-Vet 36.1.7818 2010.08.26 PDF/Pidief.RU
F-Secure 9.0.15370.0 2010.08.26 Exploit.PDF-Dropper.Gen
GData 21 2010.08.26 Exploit.PDF-Dropper.Gen
Kaspersky 7.0.0.125 2010.08.26 Trojan-Dropper.VBS.Pdfka.b
nProtect 2010-08-26.01 2010.08.26 Exploit.PDF-Dropper.Gen
PCTools 7.0.3.5 2010.08.26 Trojan.Dropper
SUPERAntiSpyware 4.40.0.1006 2010.08.26 -
Symantec 20101.1.1.7 2010.08.26 Trojan.Dropper
Additional informationShow all 
MD5   : 8b3a3c4386e4d59c6665762f53e6ec8e



   /Type /Action
   /S /Launch
   /Win /F (cmd.exe) 
   /P (
   /c echo Dim BinaryStream > vbs1.vbs && echo Set BinaryStream = CreateObject("ADODB.Stream")
 -------------------------------------------------
Windows XPSP2 Adobe Reader 9.1


Quick flash of CMD.exe black window and we are looking at a pretty new icon on the desktop exe.exe


 Files created
c:\windows\system32\ntos.exe  28C4648F05F46A3EC37D664CEE0D84A8
same directory as the original file - exe.exe  5fb94eef8bd57fe8e20ccc56e33570c5

And these are the classic signs of old Zeus and this is what it is.


File name:
exe.exe
http://www.virustotal.com/file-scan/report.html?id=33ac66e78d410d03f5644fb1569ea7d28e823561e00b86593d9022f554127c7e-1282847843
3 /41 (7.3%)
AntiVir     8.2.4.46     2010.08.26     TR/Crypt.XPACK.Gen2
PCTools     7.0.3.5     2010.08.26     Trojan.Zbot
Symantec     20101.1.1.7     2010.08.26     Trojan.Zbot
Additional information
Show all
MD5   : 5fb94eef8bd57fe8e20ccc56e33570c5

File name: ntos.exe
http://www.virustotal.com/file-scan/report.html?id=c61fdc96fb7861396d7aa99a26cb6dff3f92aeeccf93d212a8fa3e166adec6aa-1282850806
Submission date: 2010-08-26 19:26:46 (UTC)
Result: 4 /39 (10.3%)
AntiVir 8.2.4.46 2010.08.26 TR/Crypt.XPACK.Gen2
Panda 10.0.2.7 2010.08.26 Suspicious file
PCTools 7.0.3.5 2010.08.26 Trojan.Zbot
Symantec 20101.1.1.7 2010.08.26 Trojan.Zbot
Additional informationShow all
MD5   : 28c4648f05f46a3ec37d664cee0d84a8




Sunday, August 1, 2010

Zeus Trojan Research Links

Links to good ZeuS Trojan research papers (in no particular order). See update changes in Green

Malware Intelligence blog
  1. Nov. 7 2009  Special!!! ZeuS Botnet for Dummies - Jorge Mieres (Malware Intelligence blog)
  2. Jan 25, 2010  Leveraging ZeuS to send spam through social networks - Jorge Mieres (Malware Intelligence blog)
  3. Feb. 20, 2010  Facebook & VISA phishing campaign proposed by ZeuS - Jorge Mieres (Malware Intelligence blog)
  4. March 15, 2010 New phishing campaign against Facebook led by Zeus - Jorge Mieres (Malware Intelligence blog)
  5. Apr. 19, 2010 / 31.03.2010 ZeuS on IRS Scam remains actively exploited - Jorge Mieres (Malware Intelligence blog)
Abuse.ch

  1. Zeus Tracker
  2. April 3, 2010 ZeuS: Cybercriminals moving over to FastFlux Hosting
  3. March 10, 2010 -- Massive Drop in Number of Active Zeus C&C Servers
  4. March 18, 2010 -- And another Bulletproof Hoster goes Offline…

mdl4 by Mark

  1. May 3, 2010 Decrypting a ZeuS (ZBot) config
  2. Feb. 28, 2010 Reverse engineering a Facebook ZeuS infection
 Trusteer
  1. Sept 14, 2009 Measuring the in-the-wild effectiveness of Antivirus against Zeus 
  2. April 21, 2010 Trusteer Detects Rapid Spread of New Polymorphic Version of Zeus Online Banking Trojan (v.1.4)
SecureWorks
  1. March 11, 2010 ZeuS Banking Trojan Report  (v. 1.3.4.x and v. 1.4)
PaulDotCom - Security Weekly  
  1. June 23, 2010 Dennis Brown - Zeus/FreeZeus setup, technical details, etc   -- very interesting podcast with the most recent info
 Symantec
  1. May 3rd, 2010  A Brief Look at Zeus/Zbot 2 by Karthik Selvaraj
  2. Feb . 2010 Clash of the Titans: ZeuS v SpyEye   - 72 page analysis  - added Aug 1, 2010

Sophos
  1. Why won’t my sample run?  James Wyke
S21Sec
  1.  July 5, 2010 New features of ZeuS   Mikel Gastesi
  2. Apr 28, 2010 Killing the enemy  Mikel Gastes
  3. Apr 07, 2009 when a bot master goes mad - kill the os  Jozsef Gegeny
Eternal to-do.com  Jose Miguel Esparza
  1. Feb 2,2010 ZeuS spreading via Facebook Jose Miguel Esparza
  2. Nov 6, 2009 New ZeuS binary
  3. Oct 11, 2009 Detecting ZeuS
National Cyber Forensics and Training Alliance Canada / Computer Security Laboratory, Concordia University - added Aug 1, 2010
  1. On the Analysis of the Zeus Botnet Crimeware Toolkit by H. Binsalleeh,T. Ormerod, A. Boukhtouta, P. Sinha, A. Youssef, M. Debbabi, and L. Wang - Overview, functionality and RE of v.1.2.4.2
Secure Science Corporation and Michael Ligh - added Aug 1, 2010
  1. Nov. 13  2006[Prg] Malware Case Study 
TrustDefender Labs - added Aug 1, 2010
  1. May 6, 2010 Zeus 2.0 – Zeus trojan at its best – extending its reach to Windows Vista, 7 and Mozilla Firefox

From TrustDefender:
"How to detect that a system is compromised

Since the new variant of Zeus doesn’t use complex rootkit techniques, detection is relatively easy. Simply start the registry editor (regedit.exe) and check for an entry in the Run section of HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run.

The things to look out for are:
  • Name looks like a GUID (such as {26014332-876A-668A-546A-2A9930E39482})
  • Value is a filename in %USERDIR%\Application Data\\    (such as “C:\Documents and Settings\support\Application Data\Kyniin\yqypy.exe”)

How to remove Zeus v2

Removal of the Zeus v2 Trojan is also much easier since no complex rootkit techniques are used.
Simply locate the file that is being run from the above registry entry and delete the registry entry and the file. After a restart, your computer is clean. :-)
These are just a few links, please send me links to more good ZeuS research, I will include them. Thank you


Wednesday, July 14, 2010

ZeuS Version scheme by the trojan author

List of all official existing Zeus versions and the scheme description made by the author in his mother tongue.  The source is Damagelab.org but I can't find the original post, sorry - it was from this winter 2010. Many other versions like 1.3.1.1 and other random numbers are fakes - hex'd , slightly modified older versions. There is an English translation below, it is not perfect but *not* Google machine. Email me if you have any questions.

Read more about ZeuS here - Zeus Trojan Research Links

Q: Что значат цифры в версии ZeuS?
A: a.b.c.d
   a - полное изменение в устройстве бота.
   b - крупные изменения, которые вызывают полную или частичную несовместимость с предыдущими
       версиями бота.
   c - исправления ошибок, доработки, добавление возможностей.
   d - номер чистки от AV для текущей версии a.b.c.

Q: What do the numbers in the version of ZeuS mean?
A: a.b.c.d
   a - a complete change in the bot design
   b - the major changes that cause complete or partial incompatibility with the previous
       versions of the bot.
   c - correction of bugs, errors, refining, additional features.
   
d - number of cleaning for protection against AV for the current version abc


SCROLL DOWN TO SEE ENGLISH TRANSLATION
====================== = 5. История версий. = ======================
Условные метки:
[*] - изменение. [-] - исправление. [+] - добавление.

[Версия 1.2.0.0, 20.12.2008]
Общее:
[*] Более не будет документации в chm-файле, все будет писаться в этот файл.
[+] Теперь бот способен получать команды не только при отправки статуса, но и при отправки файлов/логов.
[+] Локальные данные, запросы к серверу, и файл конфигурации шифруются RC4 с ключом на ваш выбор.
[*] Полностью обновлен протокол бот--сервер. Возможно, понизится нагрузка на сервер.
Бот:
[-] Устранена ошибка, блокирующая бота на лимитированных ученых записях Windows.
[*] Написан новый PE-криптор, теперь PE-файл получается очень аккуратным и максимально имитирует результат работы MS Linker 9.0.
[*] Обновлен процесс сборки бота в билдере.
[*] Оптимизировано сжатие файла конфигурации.
[*] Новый формат бинарного файла конфигурации.
[*] Переписан процесс сборки бинарного файла конфигурации.
[*] Socks и LC теперь работают на одном порту.
Панель управления:
[*] Статус панели управления переведен в BETA.
[*] Изменены все таблицы MySQL.
[*] Начет постепенный перевод Панели Управления на UTF-8 (возможны временные проблемы с отображением символов).
[*] Обновлена геобаза.


[Версия 1.2.1.0, 30.12.2008]
Бот:
[*] BOFA Answers теперь отсылается как BLT_GRABBED_HTTP (было BLT_HTTPS_REQUEST).
[-] Мелкая ошибка при отправке отчетов.
[-] Размер отчета не мог превышать ~550 символов.
[-] Ошибка существующая с начала существования бота: низкий таймаут для отсылки POST-запросов, в результате чего блокировалась отсылка длинных (более ~1 Мб) отчетов на медленных соединениях (не стабильных), как теоретическое последствие - бот вообще переставал слать отчеты.
Общее:
[+] В случаи записи отчета типа BLT_HTTP_REQUEST и BLT_HTTPS_REQUEST в поле SBCID_PATH_SOURCE (в таблице будет path_source) добавляется путь URL.
Панель управления:
[*] Обновлен redir.php.


[Версия 1.2.2.0, 11.03.2009]
Бот:
[-] Устранена ошибка в HTTP-инжектах существующая на протяжении ВСЕХ версий бота. При использовании в программе асинхронного режима wininet.dll, был упущен момент синхронизации потоков создаваемых wininet.dll, в результате чего, при некоторых условиях происходило исключение.
[+] При срабатывании HTTP-инжекта, теперь также изменяются файлы в локальном кэше. Отсутствие этой доработки, позволяло не всегда срабатывать HTTP-инжектам.
[+] Уменьшен размер PE-файла.


[Версия 1.2.3.0, 28.03.2009]
Бот:
[-] Мелкие ошибки в крипторе, спасибо доблестным говноаналитикам из Avira.
Общее:
[*] Изменен протокол раздачи команд ботам.
Панель управления:
[*] Полностью переписана панель управления.
[*] Дизайн переписан на XHTML 1.0 Strict (под IE не работает).
[*] Бот теперь опять способен получать команды только при отправке отчета об онлайн-статусе (слишком высокая нагрузка).
[*] Обновлена геобаза.

[Версия 1.2.4.0, 02.04.2009]
Бот:
[+] При работе с HTTP, заголовок User-Agent теперь читается от Internet Explorer, а не является константой как раньше. Теоретически из-за постоянного User-Agent'а, запросы могли блокироваться провайдерами, или попадать под подозрение. Панель управления:
[-] Исправлена ошибка отображения отчетов, содержащих символы 0-31 и 127-159.


[Версия 1.2.5.0, 27.05.2009]
Бот:
[+] Незначительная оптимизация кода. Панель управления:
[-] Устранена уязвимость в gate.php, позволяющая записывать файлы в родительские директории.
[+] Добавлены запрещенные расширения в массив $bad_exts.
[+] В модуле botnet_bots, при изменение фильтра сохраняется текущая сортировка.

[Версия 1.2.6.0, 04.06.2009]
Бот:
[+] Перехват библиотеки nspr4.dll.

[Версия 1.2.7.0, 22.06.2009]
Общее:
[+] В отчеты добавляется имя пользователя, которому принадлежит процесс. Бот:
[+] Отключение фишинг-фильтра в IE7, IE8.

Версия 1.2.8.0, 05.10.2009]
Бот:
[+] За счет включения опции TCP_NODELAY, увеличена скорость работы Socks-сервера, и прочих встроенных протоколов. Это будет особенно заметно для протоколов, обменивающихся мелкими TCP-пакетами.
[+] При соединении с сервером через Wininet, не добавлялся HTTP-заголовок "Connection: close", когда это было необходимо. Из-за особенностей Wininet, это могло создать лишнею нагрузку на сервер (вероятно). Панель управления:
[*] Обновлена геобаза.


[Версия 1.2.9.0, 10.10.2009]
Бот:
[+] Добавлен граббер паролей для следующих FTP-клиентов: FlashFXP, Total Commander, WS_FTP FileZilla, FAR Manager, WinSCP, FTP Commander, Core FTP, SmartFTP.
[Версия 1.2.10.0, 17.10.2009] Панель управления:
[+] Полная интеграция "Jabber notifier".


Версия 1.3.0.0, 22.11.2009]
Бот:
[*] Перехват WinAPI методом сплайсинга.
[+] Полноценная работа в Windows Vista/7.
[*] Временно отключено скрытие файлов бота.
[*] Убран TAN-граббер.
[-] Исправлена ошибка дублирования отчетов в nspr4.dll.
[*] Сграбленные сертификаты теперь пишутся с именем grabbed_dd_mm_yyyy.pfx, и паролем в UTF-8. [*] Команда getcerts, получается сертификаты только из MY-хранилища, а не из всех. Т.к. получение сертификатов из всех хранилищ не имеет смысла.
[*] Изменено поведение граббера сертификатов.
[*] Переписан FTP/POP3 снифер, улучшено обнаружение логинов, сделана поддержка IPv6-адресов.
[*] Переписан перехват ввода клавиатуры, исправлен метод работы с интернациональными символами. [-] Исправлена ошибка в HTTP-фейках, которая могла привести к deadlock.
[*] Изменен способ генерации BotID.

[Версия 1.3.1.0, 29.11.2009]
Бот:
[-] Устранена серьезная ошибка, которая могла возникнуть при работе с файлом конфигурации.

[Версия 1.3.2.0, 11.01.2010]
Бот:
[-] Устранена серьезная ошибка, которая могла привести к deadlock в любом процессе (актуально только для билдов с поддержкой nspr4.dll).

[Версия 1.4.*]
[*] Полная несовместимость с предыдущими версиями.
[*] Поскольку ядро бота нацелено на Windows Vista+, в боте никогда не будут использоваться сплойты повышения привелегий и т.д. Бот работает в переделах одного пользователя. Тем неменее элементарные попытки заразить прочих пользователей Windows совершаются (обычно эффективно в случаях отключения UAC или запуск с из-под LocalSystem).
[+] Возможна работа с "Roaming User Accounts".
[*] Произвольные имена файлов, мютексов.
[*] Пайпы более не используются.
[*] Полностю переписано ядро бота, от процесса установки в систему до отсука в админку.
[+] При инсталяции, перекриптовывает свое тело, таким оброзом сохраняется уникальная копия exe-файла на каждом компьютере.
[+] Привязка бота к компьютеру, путем модификации/удаления некоторых данные в exe-файле. [+] Полноценная работа с x32 приложениями в Windows x64.
[+] Удаление исходного файла бота, после исполнения.
[+] Полноценная работа в "Terminal Services".
[+] При запуске из под пользователя LocalSystem, происходит попытка заражения всех пользовталей системы.
[*] Убрана опция StaticConfig.blacklist_languages.
[+] Имя ботнета ограничено 20 сиволами, и может содержать любые интернациональные символы.
[+] Файл Конфигурации читается как UTF8 ------------------------------ НЕ СДЕЛАНО ЕЩЕ. нет поддержки в buildcfg.cpp
[*] Убрана опция StaticConfig.url_compip.
[+] Нельзя обновить новую версию на старую.
[+] При обновлении бота происходит полное обновление немедленно, не дожидаясь перезагрузки.
[*] В данный момент из-за некторых соображений скрытие файлов бота не будет производиться вообще.
[*] Убран граббер Protected Storage, покольку начинася с IE7 он более не испольузуется им.
[*] С связи с не надежностью старой системы подсчета Инсталлов, бот имеет метку Инсталла при добавлении в базу.


Q: Каким оброзом генерируется Bot ID?
A: Bot ID состоит из двух частей: %name%_%number%, где name - имя компьютера (результат от GetComputerName), а number - некое число, генерируемое на основе некотрых уникальных данных ОС.

===========
= 5. Мифы =
===========
M: ZeuS использует DLL для своей работы.
A: Ложь. Существует только один исполняемый PE файл (exe). Dll, sys и т.д. не когда не было и  врятли когда-либо будет. Этот миф пошел в результате того, что в некоторых версия бота для хранения настроек, используются файлы с такими расширениями.


M: ZeuS использует COM (БХО) для перехвата Internet Explorer.
A: Ложь. Всегда для этого использовался перехват WinAPI из wininet.dll.

-------------------------------------------------------------------------------------------
Machine translation - it is quite bad, I am planning to make a better one later.



Q: How Bot ID is generated
A: Bot ID consists of two parts:% name% _% number%, where the name - the name of the computer (the result of GetComputerName), and the number - a certain number generated on the basis of unique data of the OS.
===========
= 5. Myths =
===========
M: ZeuS uses a DLL to their work. A: False. There is only one executable PE file (exe). Dll, sys, etc. not when there was no vryatli ever will. This myth came from the fact that in some version of the bot to store the settings used files with extensions.


M: ZeuS uses COM (BHO) to intercept Internet Explorer.
A: False. Always used
WinAPI from wininet.dll. for this interception

 ===================== 5. Version History (dates are in DD/MM/YY format). = ======================
Tags: [*] - change.
[-] - A correction. [+] - Add.

[Version 1.2.0.0, 20.12.2008]
Overall:
[*] There will be no more documentation in the chm-file, everything will be written to this file.
[+] Now the bot is able to receive commands not only when sending its status, but also when sending files / logs.
[+] Local data, server requests, and the configuration file are RC4 encrypted with the key of your choice.
[*] Completely updated bot <-> server protocol. Perhaps it will diminish the server load.
Bot:
[-] Fixed a bug that blocks the bot on limited Windows accounts.
[*] Written a new PE-cryptor, now PE-file is very neat and simulates the working result of MS Linker 9.0.
[*] Updated build process of the bot.
[*] Optimized compression of the configuration file.
[*] Introduced a new format of the binary configuration file.
[*] The build process of the binary configuration file is re-written.
[*] Socks and LC are now working on the same port.
Control Panel:
[*] Control panel status is now beta
[*] Changed all tables in MySQL.
[*] Started a gradual transfer of the Control Panel to UTF-8 (there may be temporary problems with some displaying characters).
[*] Updated geobase.

[Version 1.2.1.0, 30.12.2008]
Bot:
[*] BOFA Answers are now being sent as BLT_GRABBED_HTTP (was BLT_HTTPS_REQUEST).
[-] Small error when sending reports.
[-] The size of the report could not exceed about 550 characters.
[-] Error in existence since the bot introduction: a low timeout for sending POST-requests resulting in blocked long (more than ~ 1 Mb) reports on slow connections (unstable conections) and, as the theoretical implication, the bot would stop sending reports altogether.
Overall:
[+] When entering reports like BLT_HTTP_REQUEST and BLT_HTTPS_REQUEST into the field SBCID_PATH_SOURCE (would be path_source in the table) URL is now added.
Control Panel:
[*] Updated redir.php.



[Version 1.2.2.0, 11.03.2009]
Bot:
[-] Fixed a bug in HTTP-injections for all versions of the bot. When using asynchronous mode wininet.dll, it would miss the moment of the thread synchronization, which under certain conditions could cause an an exception. (ok, this is iffy and may need a better translation)
[+] when HTTP-injection occurs, the files in the local cache change too. Without this feature the HTTP-injections was not always triggered.
[+] Reduce the size of PE-file
[Version 1.2.3.0, 28.03.2009] 
Bot:
[-] Minor errors in the cryptor, thanks to the shit analysts from Avira.
Overall
[*] Changed the protocol of bot control commands.
Control Panel:
[*] Completely re-written Control Panel.
[*] Design rewritten to XHTML 1.0 Strict (does not work in IE).
[*] Bot again receives commands only when sending online status reports (utilization too high).
[*] Updated geobase.

Version 1.2.4.0, 02.04.2009]
Bot:
[+] When you work with HTTP, User-Agent string now shows as Internet Explorer and is not a constant value as before. Theoretically, never changing User-Agent queries could be blocked by providers or cause suspicions in the past.'
Control Panel:
[-] Fixed a bug in the display of reports containing characters 0-31 and 127-159
[Version 1.2.5.0,  27.05.2009]
Bot:
[+] Minor code optimization.
Control Panel:
[-] Fixed a vulnerability in gate.php allowing adding files to parent directories.
[+] Added new forbidden file extensions in the array $bad_exts.
[+] Changing filter in the botnet_bots module does not prevent from keeping the current sorting


[Version 1.2.6.0, 04.06.2009]
Bot:
[+] interception of nspr4.dll library.


[Version 1.2.7.0, 22.06.2009]
Overall:
[+] Added the name of the user- process owner into the reports
Bot:
[+] Ability to disable the phishing filter in IE7, IE8.


[Version 1.2.8.0, 05.10.2009]
Bot:
[+] By including option TCP_NODELAY, increased speed of the Socks-server, and other built-in protocols. This is particularly noticeable for the protocols, exchanging small TCP-packets.
[+] When connecting to the server via Wininet, HTTP-header "Connection: close" was not added when needed. This could possibly create an unnecessary load on the server.
Control Panel:
[*] Updated geobase.

Version 1.2.9.0, 10.10.2009]

Bot:
[+] Added grabber passwords for the following FTP-Client: FlashFXP, Total Commander, WS_FTP FileZilla, FAR Manager, WinSCP, FTP Commander, Core FTP, SmartFTP.

[Version 1.2.10.0, 17.10.2009]

The control panel:
[+] Full integration of "Jabber notifier". 
Version 1.3.0.0, 22.11.2009]
Bot:
[*] Intercept of WinAPI by means of splicing
[+] Fully functional in Windows Vista /windows 7.
[*] Temporarily disabled hiding of bot files. 
[*] Removed TAN-grabber. 
[-] Fixed duplicate records in nspr4.dll.
[*] Intercepted certificates are now entered as grabbed_dd_mm_yyyy.pfx, and password in UTF-8. 
[*] Command "getcerts" allows to get certificates only from MY-store, not from all locations because obtaining certificates from all the stores does not make sense. 
[*] Changed behavior of the certificates grabbers.
[*] Rewrote FTP/POP3 sniffer, improved detection of logins, introduced support for IPv6-addresses.
[*] Rewrote keyboard input interception feature, fixed methods of working with international symbols.
[-] Fixed bug in HTTP-fakes, which could lead to deadlock. 
[*] Changed the way of generating BotID.

 [Version 1.3.1.0, 29.11.2009]
Bot:
[-] Fixed a bug that could occur with the configuration file.

Version 1.3.2.0, 11.01.2010]
Bot:
[-] Fixed a serious bug, which could lead to a deadlock in any process (relevant only for builders with nspr4.dll support).

[Version 1.4 .*]  

[*] Full incompatibility with all the previous versions.
[*] Since the core of the bot is targeted to Windows Vista+, the bot will never use exploits for increasing privileges, etc. The bot works within one user account, however it will attempt to infect other Windows users (usually effective if you disable UAC or start it as LocalSystem).
[+] Ability to work with "Roaming User Accounts".
[*] Random file names, mutexes
[*] Pipe no longer used.
[*] The core of the bot has been completely changed. Everything - from the installation to the callback process.  
[+] As it installs itself, it re-encrypt itself so every computer has a unique copy of the exe file
[+] Binding bot to a computer by modifying / deleting some data in the exe file.
[+] Fully functional work with x32 applications in Windows x64.
[+] Delete the original file after the execution.
[+] Fully functionalin the "Terminal Services".
[+] When running as LocalSystem, it tries to infect all windows users
[*] Removed StaticConfig.blacklist_languages option.
[+] Name of the botnet is limited to 20 of characters, and may contain any international characters
[+] Configuration File is read as UTF8 ------------------------------ NOT DONE YET. no support in buildcfg.cpp
[*] Removed staticConfig.url_compip option.
[+] Can not be used to upgrade an older version
[+] the bot update happens instantly, not need to wait for a reboot.  
[*] At the moment, after condidering some aspects, decided not to hide the bot files
[*] Removed the Protected Storage grabber because IE7+ is not using it
[*] Since the old system had reliability issues with the way installs were counted, the bot will now have an install marker when added to the database.