Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Security > Virus alerts

October 9th, 2012, 07:43 GMT · By

Experts Analyze Backdoor.Proxybox Malware, Attempt to Identify Mastermind

SHARE:

Adjust text size:

proxybox.name is utilized to sell access to the botnet
Enlarge picture
Each year hundreds of thousands of Internet users fall victim to the Backdoor.Proxybox malware. That is why Symantec experts have decided to thoroughly investigate the operation and the botnet that powers it.

They have found that although the Russian Proxybox service (proxybox.name) appears to be a legitimate proxy service, in reality, it hides a massive malicious campaign.

One of the first clues that revealed the service’s true purpose was the fact that the Proxybox offered access to its entire list of proxies – which sums up to thousands – for a measly price of $40 (31 EUR) per month.

An advertisement for the proxy service showed a link between four websites, specialized in proxies and malware distribution, all of them being operated by the same Russian cybercriminal.

The connection between the sites - vpnlab.ru, avcheck.ru, proxybox.name and whoer.net – is represented by static cross-linking advertisements, the same ICQ support number, and the same types of payment gateways.

After analyzing these payment accounts, researchers were led to a Ukrainian individual residing in Russia. For now, Symantec hasn’t provided any other details on the hacker’s identity because law enforcement is currently investigating the case.

As far as the actual Backdoor.Proxybox malware is concerned, experts found that the threat – first identified back in 2010 – comprises three main components: a rootkit, a payload and a dropper.

When the victim boots up the infected computer, the payload - responsible for turning the infected machine into a zombie - contacts its command and control server, whose address is hard-coded, and configures itself.

It appears that the controller is trying to ensure that the botnet’s size is kept at 40,000. In order to maintain this size, several mediums are utilized to distribute the malware, including some BlackHole web exploits.

The proxybox.name website is actually used to sell access to the botnet, the site being advertised on several underground forums specialized in commercializing exploits, malware and other malicious services.


1,248 hits
Link to this article · Print article · Send to friend

MUST-READ RELATED ARTICLES:


Security Firms Warn of Skype Spam That Leads to Ransomware via BlackHole 2.0 (Updated)

Most of the Mass Distributed Malware in Q3 2012 Were Banking Trojans, Study Finds

Cybercriminal Ring Seeks 100 Botmasters to Launch Trojan Attack on 30 US Banks

Cybercriminals Turn To Universal Man in the Browser Attacks to Steal Valuable Data [Video]

Site of Japanese Restaurant Wagamama Hijacked, Users Led to BlackHole

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM