klog.exe - POC

Discussion in 'other anti-malware software' started by Kyle1420, Oct 24, 2010.

Thread Status:
Not open for further replies.
  1. Kyle1420

    Kyle1420 Registered Member

    0 detections...Just goes to show how ineffective some black listing is vs unknown..

    ~Virus Total results removed per Policy.~

    Also, Winpatrol didn't make a peep, How does your hips\bb fair?


    Download Poc here,
    http://www.mediafire.com/?z57l7dim13gl2rd
    (This will keylog and write to a log.txt file in the working directory once you close)
    It will not connect to the internet or anything else, only the above.
     
    Last edited by a moderator: Oct 24, 2010
  2. Hawk82

    Hawk82 Registered Member

    Zone Alarm Pro detects it...:cool:
     

    Attached Files:

  3. Meriadoc

    Meriadoc Registered Member

    I have PoC klog by Clandestiny, rootkitdotcom, I'm wondering is this the same or perhaps built from source code?
     
    Last edited: Oct 24, 2010
  4. Noob

    Noob Registered Member

    MD warned me ;)
     
  5. CloneRanger

    CloneRanger Registered Member

    @ Kyle1420

    Thanks for the POC :thumb:

    *

    Very large file 1.71 MB :eek:

    After allowing these alerts

    pg1.gif

    pg-k1.gif

    z1.gif

    It worked ;)

    klog.gif

    Closed the app and went to open the .txt log on my desktop, but had to click through these first

    bm.gif

    Usually things like that end up showing mainly garbage, but it actually showed what i typed into metapad.

    ...Testing Klog 12345........................ABCDE$£@+klog

    That's how it appeared, WITHOUT the dots, even though i'd typed

    Testing Klog 12345 ABCDE$£@+klog

    No big deal to reading it back though :D

    Prevx blocked trying to sign in here plus HTTPS Hotmail & https://www.startpage.com :thumb:
     
  6. LoneWolf

    LoneWolf Registered Member

    DefenseWall successfully blocks. :D
     

    Attached Files:

  7. harsha_mic

    harsha_mic Registered Member

    Comodo Firewall v5 successfully blocked the threat from logging the keystrokes...
     
  8. BoerenkoolMetWorst

    BoerenkoolMetWorst Registered Member

    KIS 2011 gives yellow warning about global windows hook, if you deny it fails, if allow it works, however logging the webbrowser is blocked by SafeOnline. Mamutu gives no warnings, even not in paranoid mode.
     
  9. jmonge

    jmonge Registered Member

    winpatrol plus didnt burk at all:D
     
  10. jmonge

    jmonge Registered Member

    spyshelter blocks it:D
     
  11. burebista

    burebista Registered Member

    Latest OA beta, and log.txt is empty after closing.
     

    Attached Files:

  12. crofttk

    crofttk Registered Member

    burk... My dog did that once. She barked and burped at the same time.:p
     
  13. jmonge

    jmonge Registered Member

  14. subset

    subset Registered Member

    What's the point of this PoC? It looks like script kiddie bloat.
    Does it require .NET Framework? Because it fails to run with naked XP SP3.
    With 7 I can read klog.exe, Install global message hook, Hook type: WH_KEYBOARD_LL. :p

    Cheers
     
  15. ELWIS1

    ELWIS1 Registered Member

    Prevx on maximum settings will not protect me. Added to the protected page. Trusteer Rapport protects example on ebay, but not at my bank because the bank is not their partner. My language is Polish, Windows service pack 3.
     
  16. Kernelwars

    Kernelwars Registered Member

    indeed. norton ate it soon I downloaded it:( its a one hungry killa:D
     
  17. moontan

    moontan Registered Member

    have you tried manually adding your bank to the protected list?
     
  18. ELWIS1

    ELWIS1 Registered Member

    Yes:)
     
  19. moontan

    moontan Registered Member

    i tried that too, it didn't work.
    oh well.
     
  20. m00nbl00d

    m00nbl00d Registered Member

    No idea about the one posted by Kyle1420, because mediafire will require me allow cookies (it gave me the shivers :D), but the one mentioned by Meriadoc is detected by MSE v2, avast! 5 and AVG 2011. All with definitions nearly 1 week old. I haven't checked virustotal. I have those three in a virtual machine and just decided to give it a run.

    If you could upload it to rapidshare instead? No cookies needed here. :)
     
  21. Meriadoc

    Meriadoc Registered Member

    Only took a cursory look I was hoping for some more info. Looks to be obfuscated some what, Python, a lot of String info...I did unpack the file to get any useful information, and run it in an anti-anti sandbox config.

    the one at rkdotcom is well know
     
    Last edited: Oct 24, 2010
  22. subset

    subset Registered Member

  23. Franklin

    Franklin Registered Member

    Can't run in a restricted sandbox and a default sandbox creates a logfile within the sandbox.

    Test.JPG
     
  24. Kyle1420

    Kyle1420 Registered Member

    Yes it was created with python, packed with py2exe and compressed with UPX. I apologize for the larger file size as I had to include the python interpreter to run on people's pc's who do not have python installed.
     
  25. CloneRanger

    CloneRanger Registered Member

    @ Kyle1420

    Hi, i hadn't initially realised that you'ld written this POC !

    Can you please comment on these from my earlier post ?

     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice