Quantcast
Channel: XyliBox
Browsing index pages (129 articles)

Image may be NSFW.
Clik here to view.

BestAV (Fake Antispyware affiliate) exposed

Hello everyone, it's been a while.One of the first affiliate systems I ever infiltrated was BestAV, back in 2011, the same year I started XyliBox.Over the years i infiltrated most of the major FakeAV...

View Article


Image may be NSFW.
Clik here to view.

Citadel 0.0.1.1 (Atmos)

Guys of JPCERT, 有難う御座います!Released an update to their Citadel decrypter to make it compatible with 0.0.1.1 sample.Citadel 0.0.1.1 don't have a lot of documentation, so time as come to talk about...

View Article


Image may be NSFW.
Clik here to view.

Betabot retrospective

Some of you know Betabot.. if you don't: http://www.ic3.gov/media/2013/130918.aspx1.0.2.5 panel:Dashboard:extended information:Search options:Tasks:Remove bot:Terminate bot till next...

View Article

Image may be NSFW.
Clik here to view.

Alina 'sparks' source code review

I got on my hands recently the source code of Alina "sparks", the main 'improvement' that everyone is talking about and make the price of this malware rise is the rootkit feature.Josh Grunzweig did...

View Article

Image may be NSFW.
Clik here to view.

Tiberium/Consuella USPS money laundering service

Consuella was a 'USPS drop service' run by one of the Lampeduza administrator.This type of service is used to help credit card thieves to "cash out" by sending carded labels service overseas (or not)...

View Article


Image may be NSFW.
Clik here to view.

Cryptorbit locker

When Cryptorbit ransomware was targeting people i've visited themSQL database:Bad guy...

View Article

Image may be NSFW.
Clik here to view.

Captain Barbarossa

Captain Barbarossa, is used for Paypal phishing and sold as phishing kit, the kit include an admin panel.User is tricked with a fake Paypal login asking for details, here in German:Once infos are...

View Article

Image may be NSFW.
Clik here to view.

Phase (Win32/PhaseBot-A)

Small write-up about 'Phase' a malware who appeared and vanished very rapidly.I had a look on it with MalwareTech who wrote several stories, it was shown that Phase is in reality a 'new' version of...

View Article


Image may be NSFW.
Clik here to view.

Neutrino bot

Neutrino bot is a malware who appeared and vanished quickly like Phase.not worth the look anyway. Advert:Login:Task:Statistics:Clients:Files:Logs:Settings:

View Article


Image may be NSFW.
Clik here to view.

iBanking

iBanking is an android malware made to intercept voice and text informations.The panel is poorly coded.Login:Projects:Phone list:SMS List:All SMS (Incomming)All SMS (Outgoing):Call list...

View Article

Image may be NSFW.
Clik here to view.

i/o

Wow, it's been a awhile since i haven't written anything new here...So to answer many questions.. no i'm not dead, and will try to get active again a bit next year.I'm not writing this due to...

View Article

Image may be NSFW.
Clik here to view.

Install service for Malware affiliates and individuals

This install service was running since a long time but the server recently died.People targeted are from Russia, Ukraine, Belarus, Kazakhstan, and Uzbekistan.Login:Statistics by days:(Date, Unique...

View Article

Image may be NSFW.
Clik here to view.

ATSEngine

ATSEngine injects can be found oftenly inside Zeus configs, it makes the webinjects more dynamic because most of the content is located remotely and can be updated much easily instead of sending new...

View Article


Image may be NSFW.
Clik here to view.

Android.Trojan.Rubobi.A (SmsPiratBot)

Another Android botnet dumped recently.This malware can send and intercept sms from bots.Like most of android botnets, they are used mainly to target mobile banks like Sberbank (www.sberbank.ru - the...

View Article

Image may be NSFW.
Clik here to view.

Lame scareware

I've found a sample yesterday downloaded via this url: skyways.co/play.exe, console application, and ugly code + scareware and third party FakeAV call center.All the following was so lame that i need...

View Article


Image may be NSFW.
Clik here to view.

Android/FakeToken.A

OTP forwarder dumped months ago.Login:Statistics:Bots:Bot:Passwords:Send a command:Commands sent:Apps:Apps...

View Article

Image may be NSFW.
Clik here to view.

ZeusVM and steganography

Months ago, researchers observed an evolution of ZeusVM, time to get back on this family.For informations,The first ZeusVM sample i've seen using steganography was the 21 November 2013.The IP of the...

View Article


Image may be NSFW.
Clik here to view.

Carberp Remote Code Execution: Carpwned

Everyone are looking at the Carberp source, bootkit and other components but did people investigated the panels source ?I don't know who did the PHP but he deserve a medal, it's more easy to hack than...

View Article

Image may be NSFW.
Clik here to view.

Carberp C&C

And here we go, first Carberp panel i break from the leak, surely a test one, gateway was badly configured like domains.Login:To view the login page sometime you need a special key...

View Article

Image may be NSFW.
Clik here to view.

Zeus 1.1.3.4

RSA FirstWatch throw me recently a sample of a 'new' Zeus variant.I didn't really check all the changes that were made but seem it's nothing more than just a standard Zeus v2.But wait, it communicates...

View Article
Browsing index pages (129 articles)


Latest Images