15.07.2013 Views

Report - CrySyS Lab

Report - CrySyS Lab

Report - CrySyS Lab

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

• The web page of bannetwork.org accidentally had a HTML tag “politnews”, and<br />

politnews.org was found to have similar structure and services like bannetwork.org.<br />

• Investigations on whois registration data revealed that the same person, Krepov Bogdan<br />

Serafimovich, registered two additional domains. These are planetanews.org and<br />

kortopla.org. Planetanews.org was found to be a functional C&C server, while kortopla.org is<br />

deregistered. This latter domain is currently sinkholed by our partners, and we do not know<br />

yet if it was used for rogue activities or not.<br />

• Investigations uncovered a sample in our malware repositories,<br />

539b0094e07e43bfced8a415ba5c84e3, that is related to a module of the TeamSpy kit. It has<br />

references to politnews.org and another domain, r2bnetwork.org, which is again expired, but<br />

the malware sample proves that it was used for C&C activity. The domain r2bdomain.org is<br />

currently sinkholed by our partners.<br />

The structure and services of the distinct C&C servers are similar, but each server is unique,<br />

containing some specific files and modules. We could not discover the internal structure of all C&C<br />

servers, but we are sure, that the listed domains are related to the TeamSpy activity (except for the<br />

deregistered kortopla.org, for which we have no such evidence). In the recent days we collaborated<br />

with multiple security companies and organizations, additional C&C servers were unveiled by their<br />

research.<br />

3.1 C&C whois information<br />

In this section we provide partial whois information for the discovered C&C domains.<br />

Domain Name:NEWSLITE.ORG<br />

Created On:27-Oct-2011 13:36:40 UTC<br />

Last Updated On:29-Oct-2012 05:40:58 UTC<br />

Expiration Date:27-Oct-2013 13:36:40 UTC<br />

Sponsoring Registrar:PDR Ltd. d/b/a PublicDomainRegistry.com (R27-LROR)<br />

Status:CLIENT TRANSFER PROHIBITED<br />

Registrant ID:DI_18504545<br />

Registrant Name:David van Cleve<br />

Registrant Organization:N/A<br />

Registrant Street1:Meester S. van Houtenstraat<br />

Registrant Street2:<br />

Registrant Street3:<br />

Registrant City:Assen<br />

Registrant State/Province:Assen<br />

Registrant Postal Code:9400-9409<br />

Registrant Country:AN<br />

Registrant Phone:+599.89261215320<br />

Registrant Phone Ext.:<br />

Registrant FAX:<br />

Registrant FAX Ext.:<br />

Registrant Email:vancleve_david@yahoo.nl<br />

Figure 6 – Politnews.org whois record<br />

8

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!