EvilZone

Programming and Scripting => Assembly - Embedded => : covetous.eyes January 26, 2013, 09:22:29 PM

: [FASM+PB] Democode for Bank Robbing ;-)
: covetous.eyes January 26, 2013, 09:22:29 PM

I coded some funny demo what robbing a bank  :P  . (iBank software from ex-USSR)
Algorithm:
   * identify software «iBank 2» in JavaVM SE
   * inject DLL in JavaVM SE
   * save all keypass in file by keyloggers
   * splice WinAPI GetFileAttributesExW
   * in new spliced GetFileAttributesExW finding signature "iBKS" on beginning of file.
   * save results of work «iBank 2» (screenshot, keylog,  keystore)
   * open "robbed" in folder


SourceCode In FASM + PureBASIC  :D  Sourcedode in Pastebin: DLL (http://pastebin.com/BDHxuH21),  EXE (http://pastebin.com/XHbN8wJH)

Sorry for my English.

: Re: [FASM+PB] Democode for Bank Robbing ;-)
: Kulverstukas January 26, 2013, 09:44:56 PM
I don't get this... maybe put up a screenshot of how it works?
: Re: [FASM+PB] Democode for Bank Robbing ;-)
: covetous.eyes January 26, 2013, 10:27:50 PM
It simple one what inject DLL in Java SE (only x86) memory space  then save filekey, screenshot and keypress.  You can test it on this site - https://my.ukrsibbank.com/ua/sme/operations/staraccess/login/. But you haven`t key. It`s not problem because all real keys for iBank has signatire iBKS in begginning of file (you can create in text exitor this "key". Of course, this "key" is invalid but for test it`s ok). This program has not user interface(only icon in taskbar with "Exit" option).
Firstly program show messagebox with text "I`m found running iBank2`s login window"
Then you open your bank key and write your password what my injected DLL save in own folder. When you close "iBank2`s login window", then you will see one of these message: on good way - "Now user have closing iBank2`s login window.\nNow bank is robbed! :-)" or in bad way - "Now user have closing iBank2`s login window,\nbut it don`t use file key"(if user logged in by USB token or another sucks).  In good way this demo open forder with 3 files: screenshot, keystore and keylog.
: Re: [FASM+PB] Democode for Bank Robbing ;-)
: Zesh January 26, 2013, 10:37:05 PM
I don't get this... maybe put up a screenshot of how it works?

Yeah...I don't understand this myself :P
: Re: [FASM+PB] Democode for Bank Robbing ;-)
: covetous.eyes January 26, 2013, 10:40:55 PM
Then more simple: it`s banker(trojan horse for bank robbing) what has not rootkit but has messageboxes in main functions :)
: Re: [FASM+PB] Democode for Bank Robbing ;-)
: IFailStuff January 26, 2013, 11:16:50 PM
What is the goal/action/point of this app?
: Re: [FASM+PB] Democode for Bank Robbing ;-)
: covetous.eyes January 26, 2013, 11:52:51 PM
What is the goal/action/point of this app?

Steal key from bank java applet and show you it.
: Re: [FASM+PB] Democode for Bank Robbing ;-)
: techb January 27, 2013, 01:28:33 AM
So it's a keylogger.
: Re: [FASM+PB] Democode for Bank Robbing ;-)
: Kulverstukas January 27, 2013, 10:43:31 AM
I am still having some hard time understanding wtf it really is. And your grammar isn't helping too.\
Also what kind of a fucked up bank uses applets for internet banking!
: Re: [FASM+PB] Democode for Bank Robbing ;-)
: z3ro January 27, 2013, 11:27:34 AM
 ???
: Re: [FASM+PB] Democode for Bank Robbing ;-)
: covetous.eyes January 27, 2013, 12:56:57 PM
Also what kind of a fucked up bank uses applets for internet banking!

Many banks from ex-USSR use "iBank". iBank uses applets for internet banking.
BIFIT is company, what developed "iBank" http://www.bifit.com/ru/ - (in russian)
: Re: [FASM+PB] Democode for Bank Robbing ;-)
: Zesh January 27, 2013, 06:02:11 PM
So I can use this to hack banks from the ex-USSR? :P
: Re: [FASM+PB] Democode for Bank Robbing ;-)
: covetous.eyes January 27, 2013, 09:28:05 PM
So I can use this to hack banks from the ex-USSR?

No, you can use this to hack client of banks from the ex-USSR :)
: Re: [FASM+PB] Democode for Bank Robbing ;-)
: Zesh January 27, 2013, 10:10:10 PM
No, you can use this to hack client of banks from the ex-USSR :)

Lol, time to hack some ex-USSR clients! :P
: Re: [FASM+PB] Democode for Bank Robbing ;-)
: Stackprotector February 25, 2013, 08:00:03 PM
lol guys, there is not much to this to not understand. You go to a bank and you sneak in the vault and steal the keys from within. It's just like that