Server controlled by hackers discovered

author-image
DQChannels Bureau
New Update

New Delhi

May 8, 2008

Finjan Inc, provider of secure web gateway products, has announced its
discovery of a server controlled by hackers (Crimeserver) containing more than
1.4GB of business and personal data stolen from infected PCs. The data consisted
of 5,388 unique log files. It included both e-mail communications and
web-related data.

Advertisment

The server contained 571 log files from the US, 621 from Germany, 322 from
France, 308 from India, 232 from Great Britain, 150 from Spain, 86 from Canada,
58 from Italy, 46 from the Netherlands and 1,037 from Turkey.

Finjan followed its company guidelines and promptly notified over 40 major
international financial institutions located in the US, Europe and India whose
customers were compromised as well as various law enforcements around the world.

Finjan's Malicious Code Research Center (MCRC) detected a Crimeserver,
which was used as a command and control for the Crimeware that was executed on
infected PCs. This Crimeserver was also used as the 'drop site' for private
information being harvested by that Crimeware.

Advertisment

The Command and Control applications on this Crimeserver enabled the hacker
to manage the actions and performance of his Crimeware, giving him control over
the uses of the Crimeware as well as its victims.

Since the stolen data was left unprotected on the Crimeserver, without any
access restrictions or encryption, the data were freely available for anyone on
the web, including criminal elements.

“This report provides a unique example of the type and amount of data today's
cybercriminals are collecting. Crimeware infected PCs are a serious business
problem that requires proactive action since it is no longer just a technical IT
problem. The existence of large amount of data on a server that hackers can
easily manage and control shows the rapid evolution of cybercrime,” said Yuval
Ben-Itzhak, CTO, Finjan. “We entered a new era in which criminals just need to
log into their 'data supplier' and download any information suitable for
them to conduct their crime,” he added.

Advertisment

According to Finjan, the fact that sensitive business and personal data in
more than 5,000 cases were compromised in a timeframe of less than one calendar
month indicates that the current numbers quoted in the industry reflect only the
tip of the Cybercrime iceberg.

The compromised data and the Command and Control applications were detected
using Finjan's patented active real-time code inspection technology while
diagnosing users' web traffic.