Re: Backdoor:Win32/Hackdef.E

From: Marco Monicelli (marco.monicelli_at_marcegaglia.com)
Date: 10/27/05

  • Next message: Jeffrey Leggett: "RE: Backdoor:Win32/Hackdef.E"
    To: Yeyerolling1@aol.com
    Date: Thu, 27 Oct 2005 14:11:21 +0200
    
    

    Actually it's exactly like I said:

    (Quote from my previous email)
     but it's now too famous around so AV
     should be now updated to recognize it or at least a standard version
     (End of Quote)

     The file you download from the website is the standard one. If you just
     had a look at the videoclip found on the link I gave, you could have seen
     an example of How To make it undetectable. And there are other different
     ways of achieving that goal.

     Cheers

     Yog-Sotho

    this is what i do with hacker defender in Active Directory

    1) download Hacker Defender from the link on Rookit.com

    2) Use Software restriction to get a hash and put a policy

    3) the tools, KHS, FHS, ICE Sword, rkdetector, can find the presencd

    4) Macafee can also find and remove the rootkit

    In a message dated 10/27/2005 2:41:35 AM Central Daylight Time,
    marco.monicelli@marcegaglia.com writes:
     Dear Alex,

     that is not really a simple trojan.... it's a Windows Rootkit and its name
     is Hackdefender. You can gather many usefull information about it on
     www.rootkits.com. It's a smart rootkit which uses a technique based on
     changing words inside the rootkit's files in order to fool AV. And I must
     admit it does the job pretty good but it's now too famous around so AV
     should be now updated to recognize it or at least a standard version (it
     can be customized to become undetected).

     For your fun and knowledge, here's a link to a AVI file which shows you
     how
     it beats the AV defences.

     http://rapidshare.de/files/6816080/hxdef_defeating_modern_detectors.rar.html

     Cheers

     Yog-Sotho

     After installing October's MS Malicious Software Removal tool, a
     couple of server, one behing a Sonicwall TZ170 firewall have shown he
     presence of Win32/Hackdef.E and Win32/Hackdef.T. The MS tools they
     have been removed.

    ------------------------------------------------------------------------------
    Audit your website security with Acunetix Web Vulnerability Scanner:

    Hackers are concentrating their efforts on attacking applications on your
    website. Up to 75% of cyber attacks are launched on shopping carts, forms,
    login pages, dynamic content etc. Firewalls, SSL and locked-down servers are
    futile against web application hacking. Check your website for vulnerabilities
    to SQL injection, Cross site scripting and other web attacks before hackers do!
    Download Trial at:

    http://www.securityfocus.com/sponsor/pen-test_050831
    -------------------------------------------------------------------------------


  • Next message: Jeffrey Leggett: "RE: Backdoor:Win32/Hackdef.E"

    Relevant Pages

    • RE: Pre-Scanning for Marketing
      ... installer there were some Security issue, ... vulnerabilities are easily and efficiently identified. ... Audit your website security with Acunetix Web Vulnerability Scanner: ... Up to 75% of cyber attacks are launched on shopping carts, ...
      (Pen-Test)
    • Re: Hacking to Xp box
      ... I think there was a misunderstanding in the firewall point: ... you need to find some vulnerability that could be ... > restricts most of the attacks that use anonymous connections. ... > Audit your website security with Acunetix Web Vulnerability ...
      (Pen-Test)
    • Re: Whitespace in passwords
      ... input password is alphanumeric + special characters -- chances are strong ... >> Hackers are concentrating their efforts on attacking applications on ... Up to 75% of cyber attacks are launched on shopping ... >> your website for vulnerabilities to SQL injection, ...
      (Pen-Test)
    • RE: Penetration test of 1 IP address
      ... You could use a whole sleth of tools on some server, ... Audit your website security with Acunetix Web Vulnerability Scanner: ... Check your website for vulnerabilities to SQL injection, ... Up to 75% of cyber attacks are launched on shopping ...
      (Pen-Test)
    • RE: Penetration test of 1 IP address
      ... Before I do anything very intrusive I personally go to the website ... Also remember once you have found a vulnerability, ... Hackers are concentrating their efforts on attacking applications on ... Up to 75% of cyber attacks are launched on shopping ...
      (Pen-Test)