BPC Squad Bank Paypal And Cards | Carders Forum | Carding Forum

- Advertisement Area (For purchasing Ads or Banner contact ) Jabber [email protected] -(Telegram : @bpclover) -




Jerry's Store Excellent bases | AVS checker
Cerberux.CC The king shop with new checker feature attached + high quality spam cards direct from inbox.
Algae For Sale Global rare CC, Best Quality
CC+CVV Private Base Wholesale & Retail | Rare BINs
Bankman.biz Merchants, Banks US/EU, Crypto
BIGSTACKS DUMPS+PINS, EBT+PINS, CC+CVV




- Advertisement Area (For purchasing Ads or Banner contact )-Jabber-[email protected]

Best Regards
BPC Team







-BPCFORUM-  Registration Opened ####.


We are the Best one Carding Forum on Internet And you choose the right place to start Carding World so Enjoy your time with bpc , Also bpc is not responsible for any kind of post Because we are not a post owner So all stuff you will use at your own risk and If you face any kind of problem please feel free to contact with us.. Telegram : @bpclover
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5


Newly Found Malware Uses 7 NSA Hacking Tools, Where WannaCry Uses 2
#1
A security researcher has identified a new strain of malware that also spreads itself by exploiting flaws in Windows SMB file sharing protocol, but unlike the WannaCry Ransomware that uses only two leaked NSA hacking tools, it exploits all the seven.[Image: EternalRocks-windows-smb-nsa-hacking-tools.png]

Last week, we warned you about multiple hacking groups exploiting leaked NSA hacking tools, but almost all of them were making use of only two tools: EternalBlue and DoublePulsar.

Now, Miroslav Stampar, a security researcher who created famous 'sqlmap' tool and now a member of the Croatian Government CERT, has discovered a new network worm, dubbed EternalRocks, which is more dangerous than WannaCry and has no kill-switch in it.
Unlike WannaCry, EternalRocks seems to be designed to function secretly in order to ensure that it remains undetectable on the affected system.

However, Stampar learned of EternalRocks after it infected his SMB honeypot.

The NSA exploits used by EternalRocks, which Stampar called "DoomsDayWorm" on Twitter, includes:

  1. EternalBlue — SMBv1 exploit tool
  2. EternalRomance — SMBv1 exploit tool
  3. EternalChampion — SMBv2 exploit tool
  4. EternalSynergy — SMBv3 exploit tool
  5. SMBTouch — SMB reconnaissance tool
  6. ArchTouch — SMB reconnaissance tool
  7. DoublePulsar — Backdoor Trojan
[size=undefined]

As we have mentioned in our previous articles, SMBTouch and ArchTouch are SMB reconnaissance tools, designed to scan for open SMB ports on the public internet.

Also Read: WannaCry Ransomware Decryption Tool Released

Whereas EternalBlue, EternalChampion, EternalSynergy and EternalRomance are SMB exploits, designed to compromise vulnerable Windows computers.

And, DoublePulsar is then used to spread the worm from one affected computers to the other vulnerable machines across the same network.
Stampar found that EternalRocks disguises itself as WannaCry to fool security researchers, but instead of dropping ransomware, it gains unauthorized control on the affected computer to launch future cyber attacks.

Here's How EternalRocks Attack Works:

EternalRocks installation takes place in a two-stage process.

During the first stage, EternalRocks downloads the Tor web browser on the affected computers, which is then used to connect to its command-and-control (C&C) server located on the Tor network on the Dark Web.[/size]

Quote:"First stage malware UpdateInstaller.exe (got through remote exploitation with second stage malware) downloads necessary .NET components (for later stages) TaskScheduler and SharpZLib from the Internet, while dropping svchost.exe (e.g. sample) and taskhost.exe (e.g. sample)," Stampar says.
[size=undefined]
According to Stampar, the second stage comes with a delay of 24 hours in an attempt to avoid sandboxing techniques, making the worm infection undetectable.

After 24 hours, EternalRocks responds to the C&C server with an archive containing the seven Windows SMB exploits mentioned above.[/size]

Quote:"Component svchost.exe is used for downloading, unpacking and running Tor from archive.torproject.org along with C&C (ubgdgno5eswkhmpy.onion) communication requesting further instructions (e.g. installation of new components)," Stampar adds.
[size=undefined]
All the seven SMB exploits are then downloaded to the infected computer. EternalRocks then scans the internet for open SMB ports to spread itself to other vulnerable systems as well.

अभी तो बहुत 'भसड़' होने वाली है!

If you are following The Hacker News coverage on WannaCry Ransomware and the Shadow Brokers leaks, you must be aware of the hacking collective's new announcement of releasing new zero-days and exploits for web browsers, smartphones, routers, and Windows operating system, including Windows 10, from next month.

The exclusive access to the upcoming leaks of zero-days and exploits would be given to those buying subscription for its 'Wine of Month Club.' However, the Shadow Brokers has not yet announced the price for the subscription.

Since the hackers and state-sponsored attackers are currently waiting for new zero-days to exploit, there is very little you can do to protect yourself from the upcoming cyber attacks.

If you want to know every minute update about the latest cyber threats before they hit your system, make sure you are following The Hacker News on Twitter and Facebook, or subscribe to our newsletter.[/size]


GREENDUMPS24.COM
Find Rate
Reply

#2
yo this shit is real...
Find Rate
Reply


Digg   Delicious   Reddit   Facebook   Twitter   StumbleUpon  


Possibly Related Threads…
Thread Author Replies Views Last Post
  New MacOS Malware, Signed With Legit Apple ID, Found Spying On HTTPS Traffic GreenDumps24 3 3,576 08-15-2018, 11:24 AM
Last Post: dinikemize
  NEWS More Hacking Groups Found Exploiting SMB Flaw Weeks Before WannaCry GreenDumps24 2 5,164 08-02-2017, 01:53 PM
Last Post: newyear
  Hi DEAR USER'S, try my services and stay with me forever :) FIRE MALWARE/BOT Humble wolf 2 5,075 08-02-2017, 01:52 PM
Last Post: newyear
  Adwind RAT Returns! Cross-Platform Malware Targeting Aerospace Industries GreenDumps24 1 2,430 08-02-2017, 01:50 PM
Last Post: newyear
  NEWS WannaCry Ransomware: Everything You Need To Know Immediately GreenDumps24 1 2,435 05-23-2017, 06:54 PM
Last Post: czop1223
  NEWS Protect Against WannaCry: Microsoft Issues Patch for Unsupported Windows (XP,..+ GreenDumps24 1 2,531 05-23-2017, 06:53 PM
Last Post: czop1223
  Malware Hunter — Shodan's new tool to find Malware C&C Servers GreenDumps24 0 1,980 05-03-2017, 07:49 AM
Last Post: GreenDumps24
  NEWS Malware Bricking Insecure IoT Devices Could Be a Vigilante Tool Against Botnets GreenDumps24 1 2,223 04-28-2017, 11:02 PM
Last Post: aSpi
  NEWS ANOTHER RUSSIAN HACKER ARRESTED IN SPAIN REPORTEDLY OVER U.S. ELECTION HACKING GreenDumps24 0 2,078 04-10-2017, 09:49 AM
Last Post: GreenDumps24
  NEWS WIKILEAKS REVEALS CIA'S GRASSHOPPER WINDOWS HACKING FRAMEWORK GreenDumps24 0 2,292 04-09-2017, 07:21 PM
Last Post: GreenDumps24



Users browsing this thread:
1 Guest(s)

 
Carding forum