BlackEnergy

BlackEnergy Malware was first reported in 2007 as an HTTP-based toolkit that generated bots to execute distributed denial of service attacks.[1] It was created by Russian hacker Dmyrtro Oleksiuk around 2007. Oleksiuk also utilized the alias Cr4sh.[2] In 2010, BlackEnergy 2 emerged with capabilities beyond DDoS. In 2014, BlackEnergy 3 came equipped with a variety of plug-ins.[3] A Russian-based group known as Sandworm (aka Voodoo Bear) is attributed with using BlackEnergy targeted attacks. The attack is distributed via a Word document or PowerPoint attachment in an email, luring victims into clicking the seemingly legitimate file.[4]

BlackEnergy 1 (BE1)

BlackEnergy's code facilitates different attack types to infect target machines. It is also equipped with server-side scripts which the perpetrators can develop in the command and control (C&C) server. Cybercriminals use the BlackEnergy bot builder toolkit to generate customized bot client executable files that are then distributed to targets via email spam and phishing e-mail campaigns.[5] BE1 lacks the exploit functionalities and relies on external tools to load the bot.[6] BlackEnergy can be detected using the YARA signatures provided by the United States Department of Homeland Security (DHS).

Key features

[6]

  • Can target more than one IP address per hostname
  • Has a runtime encrypter to evade detection by antivirus software
  • Hides its processes in a system driver (syssrv.sys)

Command types

  • DDoS attack commands (e.g. ICMP flood, TCP SYN flood, UDP flood, HTTP get flood, DNS flood, etc.)[1][clarification needed]
  • Download commands to retrieve and launch new or updated executables from its server
  • Control commands (e.g. stop, wait, or die)

BlackEnergy 2 (BE2)

BlackEnergy 2 uses sophisticated rootkit/process-injection techniques, robust encryption, and a modular architecture known as a "dropper".[7] This decrypts and decompresses the rootkit driver binary and installs it on the victim machine as a server with a randomly generated name. As an update on BlackEnergy 1, it combines older rootkit source code with new functions for unpacking and injecting modules into user processes.[7] Packed content is compressed using the LZ77 algorithm and encrypted using a modified version of the RC4 cipher. A hard-coded 128-bit key decrypts embedded content. For decrypting network traffic, the cipher uses the bot's unique identification string as the key. A second variation of the encryption/compression scheme adds an initialization vector to the modified RC4 cipher for additional protection in the dropper and rootkit unpacking stub, but is not used in the inner rootkit nor in the userspace modules. The primary modification in the RC4 implementation in BlackEnergy 2 lies in the key-scheduling algorithm.[7]

Capabilities

  • Can execute local files
  • Can download and execute remote files
  • Updates itself and its plugins with command and control servers
  • Can execute die or destroy commands

BlackEnergy 3 (BE3)

The latest full version of BlackEnergy emerged in 2014. The changes simplified the malware code: this version installer drops the main dynamically linked library (DLL) component directly to the local application data folder.[8] This variant of the malware was involved in the December 2015 Ukraine power grid cyberattack.[9]

Plug-ins

[3]

  • fs.dllFile system operations
  • si.dll — System information, “BlackEnergy Lite”
  • jn.dll — Parasitic infector
  • ki.dllKeystroke Logging
  • ps.dll — Password stealer
  • ss.dllScreenshots
  • vs.dll — Network discovery, remote execution
  • tv.dll — Team viewer
  • rd.dll — Simple pseudo “remote desktop”
  • up.dll — Update malware
  • dc.dll — List Windows accounts
  • bs.dll — Query system hardware, BIOS, and Windows info
  • dstr.dll — Destroy system
  • scan.dll — Network scan

References

  1. ^ a b Nazario, Jose (October 2007). "BlackEnergy DDoS Bot Analysis" (PDF). Arbor Networks. Archived from the original (PDF) on 21 February 2020. Retrieved 17 April 2019.
  2. ^ Greenberg, Andy (2019). Sandworm: a new era of cyberwar and the hunt for the Kremlin's most dangerous hackers. New York: Doubleday. ISBN 978-0-385-54440-5.
  3. ^ a b "Updated BlackEnergy Trojan Grows More Powerful - McAfee Blogs". 14 January 2016.
  4. ^ "Details on August BlackEnergy PowerPoint Campaigns". 4 October 2014.
  5. ^ "BlackEnergy APT Malware - RSA Link". community.rsa.com. 23 March 2016.
  6. ^ a b Khan, Rafiullah; Maynard, Peter; McLaughlin, Kieran; Laverty, David M.; Sezer, Sakir (1 October 2016). Threat Analysis of BlackEnergy Malware for Synchrophasor based Real-time Control and Monitoring in Smart Grid (PDF). Proceedings of the 4th International Symposium for ICS & SCADA Cyber Security Research 2016. doi:10.14236/ewic/ICS2016.7. Archived from the original (PDF) on 20 October 2016. Retrieved 5 November 2022.
  7. ^ a b c Joe Stewart (3 March 2010). "BlackEnergy Version 2 Threat Analysis". www.secureworks.com.
  8. ^ "ThreatSTOP Report: BlackEnergy" (PDF). threatstop.com. 7 March 2016. Archived (PDF) from the original on 28 May 2022. Retrieved 5 November 2022.
  9. ^ Cherepanov A., Lipovsky R. (7 October 2016). "BlackEnergy – what we really know about the notorious cyber attacks" (PDF).

Read other articles:

Konflik proksi Iran-Arab Saudi. Konflik proksi Iran–Arab Saudi adalah istilah yang mengacu kepada perebutan kekuasaan regional yang berlangsung antara Iran dan Arab Saudi.[1] Kedua negara tersebut telah memberikan bantuan untuk pihak-pihak yang saling bertikai dalam berbagai konflik di Timur Tengah, seperti di Suriah,[2][3][4] Yaman,[5][6] dan Irak,[7] serta di Asia Tengah[8] dan Asia Selatan.[9][10] Konflik yan...

 

Ini adalah nama Batak Toba, marganya adalah Siallagan. Hisar Siallagan Kepala BNNP Kalimantan Utara Informasi pribadiLahir26 Mei 1970 (umur 53)Ambon, MalukuSuami/istriVivi OktarinaAnakDaniel Kevin Pandapotan SiallaganNathaniel Farrell SiallaganMatthew Petra SiallaganAlma materAkademi Kepolisian (1992)Karier militerPihak IndonesiaDinas/cabang Badan Narkotika NasionalMasa dinas1992—sekarangPangkat Brigadir Jenderal PolisiSatuanReserseSunting kotak info • L • B Bri...

 

This article is about the play. For the film, see Revengers Tragedy. Title page of The Revenger's Tragedy The Revenger's Tragedy is an English-language Jacobean revenge tragedy which was performed in 1606, and published in 1607 by George Eld. It was long attributed to Cyril Tourneur, but The consensus candidate for authorship of The Revenger’s Tragedy at present is Thomas Middleton, although this is a knotty issue that is far from settled.[1] A vivid and often violent portrayal of l...

Batalyon Zeni Tempur 11/Durdhaga WighraDibentuk13 Juni 1959NegaraIndonesiaCabangZeniTipe unitSatuan Bantuan TempurPeranPasukan Prasarana MiliterBagian dariKodam JayaMarkasJakarta TimurJulukanYonzipur 11/DWMotoDurdhaga WighraBaretHijauMaskotSemut HitamUlang tahun13 Juni Batalyon Zeni Tempur 11/Durdhaga Wighra atau Yon Zipur 11/DW sebelumnya bernama Batalayon Zeni Konstruksi 11/Durdhaga Wighra adalah sebuah satuan bantuan tempur TNI-AD yang di bentuk pada 13 Juni 1959. Yonzipur 11/DW merupakan ...

 

Angelos Basinas Informasi pribadiTanggal lahir 3 Januari 1976 (umur 48)Tempat lahir Chalkida, YunaniTinggi 1,84 m (6 ft 1⁄2 in)Posisi bermain Defensive midfielderInformasi klubKlub saat ini PortsmouthNomor 33Karier senior*Tahun Tim Tampil (Gol) 1995–20052006–20082008–20092009– PanathinaikosRCD MallorcaAEK AthensPortsmouth 324 (44)075 0(1)014 0(0)004 0(0) Tim nasional‡1999– Yunani 100 0(7) * Penampilan dan gol di klub senior hanya dihitung dari liga domes...

 

Cet article est une ébauche concernant une chanson française et le Concours Eurovision de la chanson. Vous pouvez partager vos connaissances en l’améliorant (comment ?) selon les recommandations des projets correspondants. Monts et Merveilles Chanson de Louisa Baïleche auConcours Eurovision de la chanson 2003 Sortie 2003 Langue Français Genre Chanson française Auteur-compositeur Hocine Hallaf Chansons représentant la France au Concours Eurovision de la chanson Il faut du t...

BarbadosBarbados (Inggris) Bendera Lambang Semboyan: Pride and Industry(Indonesia: Harga Diri dan Industri)Lagu kebangsaan:  In Plenty and In Time of Need (Indonesia: Dalam Banyak dan Pada Saat Dibutuhkan) Perlihatkan BumiPerlihatkan peta Bendera Ibu kota(dan kota terbesar)Bridgetown13°05′52″N 59°37′06″W / 13.09778°N 59.61833°W / 13.09778; -59.61833Bahasa resmiInggrisBahasa asliBajanKelompok etnik (2010[1])92.4% Hitam3.1% Multirasial...

 

TV series or program Supa Team 4Supa Team 4 cover posterGenre Superhero[1] Action-Comedy[2] Created byMalenga MulendemaVoices of Zowa Ngwira Namisa Mdlalose Kimani Arthur Nancy Sekhokoane Pamela Nomvete John McMillan Linda Sokhulu Opening themeSampa the GreatCountry of origin South Africa United Kingdom France Original languageEnglishNo. of seasons2No. of episodes16ProductionExecutive producers Malenga Mulendema Anthony Silverston Mike Buckland Tom van Waveren Edward Galton A...

 

Cet article est une ébauche concernant le Concours Eurovision de la chanson et l’Allemagne. Vous pouvez partager vos connaissances en l’améliorant (comment ?) ; pour plus d’indications, visitez le projet Eurovision. Allemagneau Concours Eurovision 2020 Données clés Pays  Allemagne Chanson Violent Thing Interprète Ben Dolic Langue Anglais Sélection nationale Radiodiffuseur NDR Type de sélection Sélection interne Date 27 février 2020 Concours Eurovision de la chan...

Градлон Великийвалл. Erbin ap Cynan корн. Erbin ap Conan лат. Urbanus Gratian Gradlonus брет. Gradlon mab Konan Герцог Арморики 395 — 434 Предшественник Конан Мериадок Преемник Саломон I Смерть 434(0434) Отец Конан Мериадок Мать Дарерка Ирландская Супруга Тигридия Дети сыновья: Саломон I и Гвидол дочь...

 

British educational charity Royal Television SocietyAbbreviationRTSFormation7 September 1927; 96 years ago (1927-09-07)TypeTelevision organisationHeadquartersLondon, EC4United KingdomRegion served United Kingdom and IrelandMembership 5030 (2019)[1]Official language EnglishRoyal PatronCharles IIIChief executiveTheresa WiseWebsitewww.rts.org.uk The Royal Television Society (RTS) is a British-based educational charity for the discussion, and analysis of television in al...

 

هذه المقالة يتيمة إذ تصل إليها مقالات أخرى قليلة جدًا. فضلًا، ساعد بإضافة وصلة إليها في مقالات متعلقة بها. (أغسطس 2019) (501546) 2014 JJ80 المكتشف مقراب بان ستارز  موقع الاكتشاف مرصد هاليكالا  تاريخ الاكتشاف 2014،  و9 يوليو 2013  الأسماء البديلة 2014 JJ80  فئةالكوكب الصغير جرم ورا�...

Filipino veggie burger Coconut burgerAlternative namesSapal burger; Niyog burger; Sapal ng niyog burger; Coco burgerCourseMain dishPlace of originPhilippinesServing temperaturehot, warmMain ingredientsSapal (coconut pulp) Coconut burger, also known as sapal burger or niyog burger, is a Filipino veggie burger made with shredded coconut pulp (sapal), which are the by-products of traditional coconut milk extraction in Filipino cuisine. It is considered an ovo-vegetarian dish, but not vegan since...

 

坐标:43°11′38″N 71°34′21″W / 43.1938516°N 71.5723953°W / 43.1938516; -71.5723953 此條目需要补充更多来源。 (2017年5月21日)请协助補充多方面可靠来源以改善这篇条目,无法查证的内容可能會因為异议提出而被移除。致使用者:请搜索一下条目的标题(来源搜索:新罕布什尔州 — 网页、新闻、书籍、学术、图像),以检查网络上是否存在该主题的更多可靠来源...

 

Italian prisoners after the Battle of Caporetto Around 600,000 Italian soldiers were taken prisoner during the First World War, about half in the aftermath of Caporetto. Roughly one Italian soldier in seven was captured, a significantly higher number than in other armies on the Western Front.[1][2] About 100,000 Italian prisoners of war never returned home, having succumbed to hardship, hunger, cold and disease (mainly tuberculosis).[3][4]: 126 ...

This article lacks an overview of its topic. You can help by writing the lead section. (July 2012) German automaker Opel has shown more concept cars than production cars since 1965.[1] Year Concept name Place Comments Image 1965 Opel Experimental GT Coupé 1968 Opel Elektro GT Coupé 1969 Opel Aero GT Coupé 1975 Opel GT2 Coupé 1981 Opel Tech 1 Hatchback 1983 Opel Junior Frankfurt Motor Show City car 1992 Opel Twin Geneva Motor Show 1995 Opel Maxx Geneva Motor Show City car 1996 Ope...

 

Italian cardinal This article is about the Catholic Cardinal. For the artist, see Cesare Monti (painter). His EminenceCesare MontiCardinal, Archbishop of MilanChurchCatholic ChurchSeeMilanAppointed20 December 1632Term ended16 August 1650PredecessorFederico BorromeoSuccessorAlfonso LittaOther post(s)Cardinal Priest of Santa Maria in TraspontinaOrdersConsecration28 January 1630 (Bishop)by Giovanni PamphiliCreated cardinal28 Nov 1633Personal detailsBorn(1593-05-05)5 May 1593MilanDied16 Augu...

 

Artikel ini tidak memiliki referensi atau sumber tepercaya sehingga isinya tidak bisa dipastikan. Tolong bantu perbaiki artikel ini dengan menambahkan referensi yang layak. Tulisan tanpa sumber dapat dipertanyakan dan dihapus sewaktu-waktu.Cari sumber: Grimoire – berita · surat kabar · buku · cendekiawan · JSTOR Grimoire (/ɡrɪmˈwɑːr/) adalah buku teks sihir, biasanya termasuk petunjuk tentang cara untuk membuat objek sihir seperti jimat dan amulet...

Road in China Jixi–Jiansanjiang Expressway鸡西-建三江高速公路Jijian Expressway鸡建高速公路Route informationAuxiliary route of G11Major junctionsNorth end G1012 in Fujin City, Jiamusi, HeilongjiangSouth end G11 in Didao District, Jixi, Heilongjiang LocationCountryChina Highway system National Trunk Highway System Primary Auxiliary National Highways Transport in China ← G1113→ G1116 The G1115 Jixi–Jiansanjiang Expressway (Chinese: 鸡西—建三江高速�...

 

City and main freight port of Chile City and Commune in Valparaíso, ChileSan AntonioCity and CommunePanorama of the port of San Antonio, before the construction of a mall which obstructed the view of the port. Coat of arms San AntonioLocation in ChileNickname: Principal Port (Puerto Principal)Coordinates (city): 33°35′36″S 71°37′18″W / 33.59333°S 71.62167°W / -33.59333; -71.62167CountryChileRegionValparaísoProvinceSan AntonioFounded1894Government...