ZeuS/Zbot source code for sale? 2011-03-23 13:49:32 | Peter Kruse
[Updated] - 24.3.2011 15.15 CET
We can confirm that the source for Zbot/ZeuS is circulating. This comes from several different sources so we are confident this is the real deal. ZeuS is out in the open!
Apparently someone using the handle "IOO" is actively trying to sell ZeuS/zbot source code. For the past two weeks we have observed several individuals jumping the bandwagon announcing they have access to the Zbot/ZeuS source code and that it's for sale.
We are currently not able to verify any of these claims however this particular announcement has a picture attached which might prove that parts of the source code are indeed in the hands of IOO.
Prior to this there was several rumors that the Zeus/Zbot code was sold to the creator of SpyEye. This is also currently unconfirmed however what is curtain is the fact that someone besides the author of the ZeuS/Zbot has access to the code - and this we can document.
The screenshot below shows the builder while in the background parts of what appears to be the Zeus source code is shown.
Transcript of the post:
+------------------------------------+
Hey!
Selling full source code of the latest Zeus Bot from author for cheap price. I do not sell bins.
|SCREENSHOT FOR THE LULZ
|PAYMENT LR / WMZ / WU (Any verified escrow service accepted) |CONTACT INFA ICQ 60[removed]9345 JABBER ioo[at]ja[removed].com
PS. Awaiting for admin verification... +------------------------------------+
You should pay attention to the screen dump (posted above) which on the buttom left side is referring to a file named: "peinfector.cpp". This could be the child project of Zbot known as "Murofet", but again this is pure speculation on our side.
With the risk of starting another flood of rumours related to distribution of Zbot/ZeuS source code, this is very much "AS IS". None of this has been technically verified by CSIS Security Group.
Программное обеспечение выпуска и Windows Crack Обучение Нам-Dabei Guanyin Бодхисаттва Нам без митабха
Complete ZeuS sourcecode has been leaked to the masses
2011-05-09 13:57:27 | Peter Kruse
On the 23rd of March 2011 we posted a blog about the source code for the infamous crime kit ZeuS (Wsnpoem/Zbot) being sold on at least two dark market forums (see: http://www.csis.dk/en/csis/blog/3176/).
This weekend we found the complete source code for this crime kit being leaked to the masses on several underground forums as well as through other channels. We already collected several addresses from where it is being distributed in a compressed zip archive. We even compiled it in our lab and it works like a charm. When unzipped it looks like this:
We can hereby confirm that the complete ZeuS/Zbot source code is freely available for inspection, inspiration or perhaps to be compiled and used in future attacks.
ZeuS/Zbot is already considered as being amongst the most pervasive banking Trojan in the global threat landscape. It is an advanced crime kit and very configurable. With the release and leakage of the source code the ZeuS/Zbot could easily become even more widespread and an even bigger threat than it already is today.
Программное обеспечение выпуска и Windows Crack Обучение Нам-Dabei Guanyin Бодхисаттва Нам без митабха
Руководство пользователя
•Описание
◦Бот
◦Панель управления
•Файл конфигурации
◦HTTP-инжекты/HTTP-грабберы
•Панель управления
◦Настройка сервера
◦Установка
◦Обновление
◦Файл /system/fsarc.php
◦Команды, используемые в скриптах
•Работа с Backсonnect-сервером
•F.A.Q.
•История версий
Программное обеспечение выпуска и Windows Crack Обучение Нам-Dabei Guanyin Бодхисаттва Нам без митабха