Same Nigerian administrator we have seen before. Citadel 22.214.171.124 as a service.
This time he also seems to be offering older 126.96.36.199 ZeuS.
Why would one do such a thing? Maybe he thinks something is wrong with his copy of v188.8.131.52? Maybe he is testing something? I have no idea. I can only speculate.
IPv4 Network Whois:
inetnum: 184.108.40.206 - 220.127.116.11
descr: ICS Networks Solutions SRL
descr: I.Creanga 6v
descr: Chisinau 2069
descr: Moldova MD
Each directory appears to be organized by a username. That directory contains the control panel for its unique botnet. We have seen these names before.
"Obi" wins (loses?) this round with 153 bots.
Naughty Obi ...
"Dayo" testing out old ZeuS
More old ZeuS v18.104.22.168
blah, blah, blah...
Malware samples from this campaign:
NotesSome notes on the Nigerian Admin of this botnet as a Service.
He has VPN software (and at least one VPS) to help him mask his location, but he forgets to turn it on sometimes. You can see he is on the same network we have seen before:
inetnum: 22.214.171.124 - 126.96.36.199
descr: EMTS Limited / Etisalat Nigeria
person: Omar Bin Ashoor
address: Everest Court,
address: Plot 19, Zone L,
address: Federal Government Layout,
address: Banana Island,
address: Lagos 101241
I have seen them connect from 41.71.190.x network as well. This is VisaPhone NG, a CDMA/3G wireless internet provider. I had connected to one of their machines and see that they connect using a USB wireless network card. Mobile admins.
I have grabbed HTTP logs and grep the "Install" lines before. This shows the IP of the admin who installed these Botnets. Looks to be the same actor here.
'Strings' on the malware samples here:
C:\Program Files\XPERAZ-PC\Xpera Z\MsComCtl.oca
This is looking like his build/test environment. Since this machine shows up in logs he must be testing the builds and thats why his machine shows up in the logs of the botnet.
JS Unpack has seen this string too from another campaign.
That botnet IP looks familiar. Oh yeah, I took it down.
Nigerian Citadel Service Admin
Nick/name: Xperaz / Xperiaz