Forum Articles
  Welcome back Join CF
You are here You are here: Home | Forum | Java update

You are currently viewing our boards as a guest which gives you limited access to view most of the discussions, articles and other free features. By joining our Virgin Media community you will have full access to all discussions, be able to view and post threads, communicate privately with other members (PM), respond to polls, upload your own images/photos, and access many other special features. Registration is fast, simple and absolutely free so please join our community today.


Welcome to Cable Forum
Go Back   Cable Forum > Computers & IT > Security & Virus Discussion

FinSpy - Government/Law Enforcement Malware hacked and leaked
Reply
 
Thread Tools
Old 07-08-2014, 19:02   #1
Qtx
Inactive
 
Join Date: May 2012
Location: Probably outside the M25
Services: Sky Fibre Unlimited 40/10
Posts: 3,473
Qtx has a bronzed appealQtx has a bronzed appeal
Qtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appeal
FinSpy - Government/Law Enforcement Malware hacked and leaked

FinSpy that supplies police forces and governments around the world with infiltration and trojan abilities has been hacked (again).

Rather than explain it all, check out this sub on Reddit

The android and other phone trojans are part of a torrent listed on the above page. The whole package would be interesting for someone in the infosec industry or with this stuff as a hobby. You can see things like how they just re-sell Vupen exploits as infection vectors and such like.

Also on the antivirus side of things, one of the slides in the package shows that only Eset Antivirus would catch and stop the infection a few months ago. Even then, only on 32bit versions of windows and not 64bit versions, which will interest those from another security thread recently

https://www.dropbox.com/s/6fpd5rnwx0...y-PC-4.51.xlsm
Qtx is offline   Reply With Quote
Advertisement
Old 08-08-2014, 14:29   #2
Qtx
Inactive
 
Join Date: May 2012
Location: Probably outside the M25
Services: Sky Fibre Unlimited 40/10
Posts: 3,473
Qtx has a bronzed appealQtx has a bronzed appeal
Qtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appeal
Re: FinSpy - Government/Law Enforcement Malware hacked and leaked

That is the AV results in the link above by the way, in xls format. Will be interesting to see what happens as all the AV vendors now have a few versions of finspy to add to their definitions. So some people are going to get a definitions update and find they are infected with it. It's not hard for them to make it AV proof again but if they do it in a unique way for every client, it's a fair bit of work.

Following links somewhere on that subreddit you can find a torrent/magnet link with the webserver c&c code, finspy installs for all OS phones etc. Some stuff is pgp encrypted but a lot isn't.
Qtx is offline   Reply With Quote
Old 16-08-2014, 16:56   #3
Qtx
Inactive
 
Join Date: May 2012
Location: Probably outside the M25
Services: Sky Fibre Unlimited 40/10
Posts: 3,473
Qtx has a bronzed appealQtx has a bronzed appeal
Qtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appeal
Re: FinSpy - Government/Law Enforcement Malware hacked and leaked

Something seen in a writeup about packet interception and injection where Finspy was mentioned but the way they encapsulated how the injection works in to a few sentences was too good not to share:

Quote:
Binary Mode is a flag to enable detection of a windows binary PE header on the wire, modify it in transit and inject loader + payload into the download ahead of the real binary. The real icon is preserved. Upon execution, the downloaded file would run the loader which executed the payload then cleaned the downloaded file on disk, such that it was the originally requested file. By this time, the payload would be memory resident. Finally, the real binary would be executed. This technique would work even with self-checking binaries. Update Mode is a flag to simulate reponses of update checks for iTunes, WinAmp, and other popular applications at the time. These responses were served from FinFly and spoofed applications into updating with infected versions. It is possible to set both flags for a target. TrojanID is the payload to inject. FinFly could be loaded with several different trojans and a target dependent payload could be set. UTrojanID is the payload for update mode. These columns contain an ID which references the trojan from a simple RAM based filesystem created at load time with pre-built arrays. Compltd Count is the number of confirmed infections based on the fact that the target TCP/IP stack had acknowledged all the packets sent to it at the end of the session.
The Register now has an article on it: Time to ditch HTTP – govt malware injection kit thrust into spotlight
Qtx is offline   Reply With Quote
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 14:38.


Server: lithium.zmnt.uk
Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2026, vBulletin Solutions Inc.
All Posts and Content are © Cable Forum