66
1 Information Weapon: Concepts, Means, Methods …
• Supports the HTTP protocol and emulates a web server (i.e., the Trojan can be
controlled using a browser);
• Plays audio files;
• Intercepts, saves, and then sends lines entered from the keyboard when the
computer was connected to the network, etc.
Also, the Trojan provides for expansion of the list of functions using plug-in
resources. They can be transmitted to a “server” and installed there as part of the
Trojan and then perform almost any actions on the infected computer.
Damage Information Reporting Tool (D.I.R.T.)
According to the official policy of Codex Data Systems Inc., D.I.R.T. developer, it is
intended for use only by law enforcement agencies and, depending on the configuration, costs from 2 to 200 thousand US dollars. However, according to some independent experts, D.I.R.T. is not much better than the well-known free hacker programs,
such as Back Orifice.
According to its developers, D.I.R.T. is used to fight against terrorism, child
pornography, and drug trafficking. However, experts see a serious danger in the
application of such a powerful system of monitoring and remote administration for
industrial espionage and information warfare.
Contrary to the marketing policy of Codex Data Systems, many experts believe
that D.I.R.T. is nothing short of a Trojan. Back in 1998, many antivirus companies
did not know-how to react to the fact of D.I.R.T. appearance. Nevertheless, some of
them took a decisive step and included D.I.R.T. in their virus databases. For instance,
Kaspersky Lab and Trend Micro antivirus programs identify the coredll.dat file,
which is a component of D.I.R.T., as a Trojan called Trojan.PSWJohar, or simply
JOHAR. Moreover, the client part of D.I.R.T., which is installed on the monitored
computer, has the same files as JOHAR (desktop.exe, desktop.log, and desktop.dll)
by default.
Let us briefly consider D.I.R.T. operation principles.
The system consists of the client and server parts. The main functions of the
program are intercepting all keystrokes and sending information to a given e-mail
address, which is controlled by D.I.R.T. command center, while remaining unnoticed by the user. At the same time, there is no need for physical access to the
client computer. Additional features of D.I.R.T. include remote access to files via the
Internet or local network, remote control of the system (running programs, editing the
registry, etc.), possibility to intercept information in real-time mode, remote screen
capture, and sound monitoring (provided a microphone is connected to the client
computer).
The basis of the client component is a bug, built into any ordinary executable file,
or a Microsoft Office document to remain undetected. When the infected file is run,
the bug is activated and invisibly installed in the system. Its tasks include intercepting
keystrokes, executing commands received from the server, sending encrypted report
files to a specified e-mail address.
1 Information Weapon: Concepts, Means, Methods …
• Supports the HTTP protocol and emulates a web server (i.e., the Trojan can be
controlled using a browser);
• Plays audio files;
• Intercepts, saves, and then sends lines entered from the keyboard when the
computer was connected to the network, etc.
Also, the Trojan provides for expansion of the list of functions using plug-in
resources. They can be transmitted to a “server” and installed there as part of the
Trojan and then perform almost any actions on the infected computer.
Damage Information Reporting Tool (D.I.R.T.)
According to the official policy of Codex Data Systems Inc., D.I.R.T. developer, it is
intended for use only by law enforcement agencies and, depending on the configuration, costs from 2 to 200 thousand US dollars. However, according to some independent experts, D.I.R.T. is not much better than the well-known free hacker programs,
such as Back Orifice.
According to its developers, D.I.R.T. is used to fight against terrorism, child
pornography, and drug trafficking. However, experts see a serious danger in the
application of such a powerful system of monitoring and remote administration for
industrial espionage and information warfare.
Contrary to the marketing policy of Codex Data Systems, many experts believe
that D.I.R.T. is nothing short of a Trojan. Back in 1998, many antivirus companies
did not know-how to react to the fact of D.I.R.T. appearance. Nevertheless, some of
them took a decisive step and included D.I.R.T. in their virus databases. For instance,
Kaspersky Lab and Trend Micro antivirus programs identify the coredll.dat file,
which is a component of D.I.R.T., as a Trojan called Trojan.PSWJohar, or simply
JOHAR. Moreover, the client part of D.I.R.T., which is installed on the monitored
computer, has the same files as JOHAR (desktop.exe, desktop.log, and desktop.dll)
by default.
Let us briefly consider D.I.R.T. operation principles.
The system consists of the client and server parts. The main functions of the
program are intercepting all keystrokes and sending information to a given e-mail
address, which is controlled by D.I.R.T. command center, while remaining unnoticed by the user. At the same time, there is no need for physical access to the
client computer. Additional features of D.I.R.T. include remote access to files via the
Internet or local network, remote control of the system (running programs, editing the
registry, etc.), possibility to intercept information in real-time mode, remote screen
capture, and sound monitoring (provided a microphone is connected to the client
computer).
The basis of the client component is a bug, built into any ordinary executable file,
or a Microsoft Office document to remain undetected. When the infected file is run,
the bug is activated and invisibly installed in the system. Its tasks include intercepting
keystrokes, executing commands received from the server, sending encrypted report
files to a specified e-mail address.
