<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
	xmlns:media="http://search.yahoo.com/mrss/"
>

<channel>
	<title>Fortinet Security Blog &#187; cybercrime</title>
	<atom:link href="http://blog.fortinet.com/tag/cybercrime/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.fortinet.com</link>
	<description>Real Time Network Protection</description>
	<lastBuildDate>Fri, 27 Jan 2012 11:59:33 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1.3</generator>
	<!-- podcast_generator="podPress/8.8" -->
		<copyright>&#xA9;Fortinet Product Marketing </copyright>
		<managingEditor>rpopko@fortinet.com (Fortinet Product Marketing)</managingEditor>
		<webMaster>rpopko@fortinet.com(Fortinet Product Marketing)</webMaster>
		<category>Fortinet Product Information</category>
		<ttl>1440</ttl>
		<itunes:keywords>forti-gate, anti-spam, anti-virus, fortigate</itunes:keywords>
		<itunes:subtitle>The latest news and information about Fortinet products and services for Real Time Network Protection.</itunes:subtitle>
		<itunes:summary>Fortinet is a leading provider of Unified Threat Management (UTM) network security solutions for enterprise and service provider environments. The Fortinet FortiCast delivers news, information, and tutorials about products, services, and industry trends. Fortinet's FortiGate product line and FortiGuard security subscription services provide an array of integrated network security functions including antivirus, firewall, virtual private networking, intrusion prevention (IPS), web filtering, antispam and traffic optimization. </itunes:summary>
		<itunes:author>Fortinet Product Marketing</itunes:author>
		<itunes:category text="Technology"/>
<itunes:category text="Technology">
  <itunes:category text="Tech News"/>
</itunes:category>
		<itunes:owner>
			<itunes:name>Fortinet Product Marketing</itunes:name>
			<itunes:email>rpopko@fortinet.com</itunes:email>
		</itunes:owner>
		<itunes:block>No</itunes:block>
		<itunes:explicit>no</itunes:explicit>
		<itunes:image href="http://blog.fortinet.com/wp-content/uploads/2009/01/forticast-300x300.jpg" />
		<image>
			<url>http://blog.fortinet.com/wp-content/uploads/2009/01/forticast-144x144.jpg</url>
			<title>Fortinet Security Blog</title>
			<link>http://blog.fortinet.com</link>
			<width>144</width>
			<height>144</height>
		</image>
		<item>
		<title>SpyEye Exposes Mules</title>
		<link>http://blog.fortinet.com/spyeye-exposes-mules/</link>
		<comments>http://blog.fortinet.com/spyeye-exposes-mules/#comments</comments>
		<pubDate>Wed, 10 Nov 2010 20:07:23 +0000</pubDate>
		<dc:creator>GLovet</dc:creator>
				<category><![CDATA[Antivirus]]></category>
		<category><![CDATA[Research]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Banker]]></category>
		<category><![CDATA[Banking Trojan]]></category>
		<category><![CDATA[cyber crime]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[Drops]]></category>
		<category><![CDATA[Mules]]></category>
		<category><![CDATA[SpyEye]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[Zeus]]></category>

		<guid isPermaLink="false">http://blog.fortinet.com/?p=1914</guid>
		<description><![CDATA[In prevision of the anticipated merge between the two infamous banking malware ZeuS and SpyEye, our Threat Analyst Kyle Yang spent some time dissecting the most current version of SpyEye we could get our hands on (W32/SpyEye.C!tr.spy). While SpyEye shares some similarities with ZeuS (encrypted/compressed configuration file, updateable injection scripts, drop zones, update zones for [...]]]></description>
			<content:encoded><![CDATA[<p>In prevision of the anticipated<a href="http://krebsonsecurity.com/2010/10/spyeye-v-zeus-rivalry-ends-in-quiet-merger/"> merge between the two infamous banking malware ZeuS and SpyEye</a>, our Threat Analyst Kyle Yang spent some time dissecting the most current version of SpyEye we could get our hands on (W32/SpyEye.C!tr.spy).</p>
<p>While SpyEye shares some similarities with ZeuS (encrypted/compressed configuration file, updateable injection scripts, drop zones, update zones for binary and config update, etc &#8230;), an extra feature quickly caught our attention: SpyEye connects to a &#8220;log server&#8221; that is different than the server where it fetches updates from, where fraudulent transactions done by the trojan are logged:</p>
<p style="text-align: center;"><img class="aligncenter size-full wp-image-1916" src="http://blog.fortinet.com/wp-content/uploads/2010/11/admin_log_file_succe.jpg" alt="" width="486" height="389" /></p>
<p>Of course, because most banks today won&#8217;t allow transactions initiated online to be transnational, the recipients of such transfers are what we call &#8220;mules&#8221; (in the money laundering jargon) or &#8220;drops&#8221; (in the jargon used by cybercriminals themselves) &#8211; intermediaries between the victim and the cyber criminals, living in the victim&#8217;s country.</p>
<p>Unsurprisingly, the drops are not hardcoded in the trojan&#8217;s binary, but simply configured in the log server itself:</p>
<p style="text-align: center;"><img class="aligncenter size-full wp-image-1917" src="http://blog.fortinet.com/wp-content/uploads/2010/11/admin_inin.jpg" alt="Note: Names and account numbers were modified to dumb values for the screenshot" width="536" height="337" /></p>
<p>Note that the names and account numbers were modified to dumb values for the screenshot. However, the rest of the drop info was untouched, which prompts comments on two items:</p>
<ul>
<li><strong>Transfer limits</strong>: Those are relatively low, possibly to stay &#8220;under the radar.&#8221; Transferring a large sum of money &#8220;by small chunks&#8221; in order to avoid the new anti-laundering legislation (where mandatory records and reports are needed for large sums, etc&#8230;) is called &#8220;smurfing&#8221;. While the chunk limit in the USA is $10,000, thus well above the ~1000  upper limit used by SpyEye, we are not sure these are dollars. They could be British Pounds, and in UK there is no chunk limit: any suspicious transaction must be reported. Or&#8230; the SpyEye upper limit may simply reflect the amount of trust the cybercriminals have in each particular drop.</li>
</ul>
<ul>
<li><strong>A percentage:</strong> It very likely represents the share taken by each of the two parties (the mule and the cybercriminal) on the transfers. Now, given the unbalance (90% &#8211; 10%) it creates, the question is: who gets 10%, and who gets 90%? Some years ago, the question would have been quickly resolved, with the cybercriminals usually taking the bigger piece of cake &#8211; which would seem normal, as he/she was the one putting the most effort into the whole operation. But with <a href="http://yro.slashdot.org/story/10/09/30/2246229/US-NY-Bust-92-Mules-In-ZeuS-Trojan-Crime-Ring">the large &#8220;mule busting&#8221; operations</a> conducted in UK and US lately, it is fairly possible that the odds got inverted,which would seem&#8230; normal &#8211; given the risks now involved for each party. That would at least indicate that while mule busting operations lead by law enforcement do not catch the bigger fishes, warmly sheltered under the complexities of transnational judiciary operations, it does contribute to make them less rich.</li>
</ul>
<p>Kyle will address some technical points in an upcoming post.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.fortinet.com/spyeye-exposes-mules/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Papers of VB2009</title>
		<link>http://blog.fortinet.com/papers-of-vb2009/</link>
		<comments>http://blog.fortinet.com/papers-of-vb2009/#comments</comments>
		<pubDate>Thu, 29 Oct 2009 18:03:14 +0000</pubDate>
		<dc:creator>DMaciejak</dc:creator>
				<category><![CDATA[Research]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[conference]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[paper]]></category>
		<category><![CDATA[sql injection]]></category>
		<category><![CDATA[threat level]]></category>
		<category><![CDATA[virus bulletin]]></category>

		<guid isPermaLink="false">http://blog.fortinet.com/?p=684</guid>
		<description><![CDATA[The papers Bryan, Guillaume and I presented at Virus Bulletin 2009 have been available on the FortiguardCenter since yesterday: &#8216;I am not a numero!&#8217;: assessing global security threat levels &#8211; Bryan Lu Fighting cybercrime: technical, juridical, and ethical challenges &#8211; Guillaume Lovet Botnet-powered SQL injection attacks: a deeper look within &#8211; David Maciejak &#38; Guillaume [...]]]></description>
			<content:encoded><![CDATA[<p>The papers Bryan, Guillaume and I presented at Virus Bulletin 2009 have been available on the FortiguardCenter since yesterday:</p>
<p><a id="fwgd" title="'I am not a numero!': assessing global security threat levels" href="http://www.fortiguard.com/papers/VB2009_I_am_Not_a_Numero_-_Assessing_Global_Security_Threat_Levels.pdf">&#8216;I am not a numero!&#8217;: assessing global security threat levels</a> &#8211; Bryan Lu</p>
<p><a id="hy:2" title="Fighting cybercrime: technical, juridical, and ethical challenges" href="http://www.fortiguard.com/papers/VB2009_Fighting_Cybercrime_-_Technical,Juridical_and_Ethical_Challenges.pdf">Fighting cybercrime: technical, juridical, and ethical challenges</a> &#8211; Guillaume Lovet</p>
<p><a id="xo4k" title="Botnet-powered SQL injection attacks: a deeper look within" href="http://www.fortiguard.com/papers/VB2009_Botnet-Powered_SQL_Injection_Attacks_-_A_Deeper_Look_Within.pdf">Botnet-powered SQL injection attacks: a deeper look within</a> &#8211; David Maciejak &amp; Guillaume Lovet</p>
<p>It&#8217;s the 4th year in a row that Fortinet has had at least one paper in the line-up, but the first time we hit a count of three presentations.</p>
<p>The conference was held last month in Geneva, Switzerland, and was quite exciting (see program <a id="lajo" title="here" href="http://www.virusbtn.com/conference/vb2009/programme">here</a>). Despite the economic situation, the number of attendants hit a record high this year &#8211; which was perceptible during the keynote presentation, but less so afterwards. It seems as if over time people are considering the conference more as a social and professional networking event than a presentation-driven one.</p>
<p>We did follow some presentations in the corporate and technical tracks, the latter slightly more crowded. There were some nice discussions around current topics such as <a id="o9vm" title="cloud computing" href="http://www.virusbtn.com/conference/vb2009/abstracts/RaduRagragio.xml">cloud computing</a> (Marian Radu and Hilda Larina Ragragio from <em>Microsoft</em>) or <a id="e16s" title="malware sandboxing" href="http://www.virusbtn.com/conference/vb2009/abstracts/Mandl.xml">malware sandboxing</a> (Thomas Mandl <em> Secure Business Austria/IKARUS Security Software, </em>Florian Nentwich <em> IKARUS Security Software</em>, Ulrich Bayer and Engin Kirda from <em>Vienna University of Technology/Institute Eurecom</em>), as well as more traditional <a id="sezm" title="static analysis" href="http://www.virusbtn.com/conference/vb2009/abstracts/DimakilingSengWu.xml">static analysis</a> (Elda Dimakiling,  Francis Allan Tan Seng and Scott Wu from  Microsoft) and <a id="ysws" title="botnet history" href="http://www.virusbtn.com/conference/vb2009/abstracts/LastMinute6.xml">botnet history</a> (<em>Erik Wu and Gunter Ollmann, Damballa</em>). I got particularly interested by the in-depth looks at some threats like <a id="g00r" title="Koobface" href="http://www.virusbtn.com/conference/vb2009/abstracts/LastMinute2.xml">Koobface</a> (Ryan Flores, Joey Costoya and Jonell Baltazar from Trend Micro) or vulnerabilities like MS08-067. Guillaume also shared a good presentation on poorly-known aspects of <a id="fqz3" title="fighting cyber-crime" href="http://www.virusbtn.com/conference/vb2009/abstracts/Lovet.xml">fighting cyber-crime</a>. Threats leveraging popular Internet web sites also had the honor of multiple presentations this year (especially <a id="kak1" title="Twitter" href="http://www.virusbtn.com/conference/vb2009/abstracts/LastMinute3.xml">Twitter</a> and <a id="ggpa" title="Facebook" href="http://www.virusbtn.com/conference/vb2009/abstracts/LastMinute2.xml">Facebook</a>).</p>
<p>In the upcoming events, I would love to see more discussion around mobile security. Besides the <a id="dlct" title="&quot;iPhone v3 malware vector&quot;" href="http://www.virusbtn.com/conference/vb2009/abstracts/LastMinute1.xml">&#8220;iPhone v3 malware vector&#8221;</a> presentation (Marius van Oers from McAfee), the only other one was &#8220;Mobile malware/security: iPhone in the enterprise,&#8221; but unfortunately, it was canceled. Nonetheless, this year&#8217;s  vintage of the iconic conference of the AV industry was good, and as always a perfect occasion to put faces on various names (and beers into various faces). I hope the 2010 one will be just as good, so&#8230; see you in Vancouver ?</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.fortinet.com/papers-of-vb2009/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

