
SonicWALL UTM Research team has been continuously monitoring newer variants of the SpyEye bots in the wild. In our detailed analysis of the SpyEye crimeware toolkit we found it to be very similar to Zeus in terms of functionality and features.
SpyEye is a web-based crimeware toolkit that was first released in early January, 2010 on underground forums. It is written in C++ and the size of the compiled bot was approximately 60KB in the first version. The newer version of SpyEye includes compression options which further reduces the size of the compiled binary to ~40KB. The main objective of this bot like Zeus is to steal financial information that includes banking credentials & credit card numbers as well as other sensitive information from victim machine.
SpyEye contains many interesting features which are listed below with the most notable being its ability to kill Zeus bot infection on the victim machine. This feature was not originally present but was added in version 1.0.7 onwards. This bot functions in ring3 mode like Zeus and runs hidden from the task manager, file explorer and other user-mode monitoring applications. Screenshot below shows SpyEye v1.0.7 toolkit in action:
SpyEye version 1.0.7 toolkit features:
The build and configuration file generated by the tool kit can be seen here:
Screenshot of SpyEye web control panel main page:
Screenshot showing the status of various bots and tasks (posted by the author):
Network traffic generated by the BOT
GET /gate.php?guid=USERNAME!COMPUTERNAME!24B5EF92&ver=10120&stat=ONLINE&ie=7.0.5730.13&os=5.1.2600&ut=Admin&cpu=19&ccrc=2F9360E0&md5=b97f34389d7e16b2ff9868ae1130b628
UPDATE
PATH=http://(REMOVED)/bin/ups.exe
The SpyEye toolkit is currently offered on underground forums for $500 with extra charges for newer features. The toolkit is continuously being updated with more sophisticated features and could be potential contender of surpassing Zeus and becoming king of crimware toolkits in future.
SonicWALL Gateway AntiVirus provides protection against SpyEye bot via GAV: SpyeEye.KD (Trojan), GAV: SpyEyes.DG_2 (Trojan) and GAV: Suspicious#spyeye (Trojan) signatures.
Share This Article

An Article By
An Article By
Security News
Security News