Quantcast
Viewing all articles
Browse latest Browse all 185

Inside Styx - Exploit Kit Control Panel

Image may be NSFW.
Clik here to view.
(Lorenz-84 - For the thumbnail)
Image may be NSFW.
Clik here to view.
Styx Logo


In this post we'll just see how the panel looks like.
If you want to know more about the price and exploits included see the "Read more" part at the end.

However here is how look a successful attack with last (known to me) integrated exploit :

Image may be NSFW.
Clik here to view.
Urausy pushed by Styx Using CVE-2013-2423 with Security Bypass (jnlp) - 2013-04-27 
Here is the login screen.
Image may be NSFW.
Clik here to view.
Open, Seasam - Login Screen
The Lorenz-84 is animated :


Image may be NSFW.
Clik here to view.
Statistics - Global - Styx
Image may be NSFW.
Clik here to view.
All menus - Styx
Image may be NSFW.
Clik here to view.
Statistics - Country - Styx
Image may be NSFW.
Clik here to view.
Statistics - Browser & OS - Styx
Those stats raise some questions. But I don't have the answer.
(i tried to land with IE10 last java...nothing terrible happen but I already badly failed in recognizing new bullet)

Image may be NSFW.
Clik here to view.
Flow - Styx
(No Traffic. So Empty)
Image may be NSFW.
Clik here to view.
Settings - Domains - Styx
Image may be NSFW.
Clik here to view.
Settings - Files - Styx
Image may be NSFW.
Clik here to view.
Settings - Filters - Styx
(hello "402 Payment Required" :)  )

Image may be NSFW.
Clik here to view.
Settings - Notifications - Styx
Image may be NSFW.
Clik here to view.
Settings - API - Styx
(Unfolded : /api/stats_global)
At the bottom of the API page :


Which you can get here : styxAPI-samples.7z
(unmodified files - Owncloud via Goo.gl - just remove the .zip extension)

Image may be NSFW.
Clik here to view.
"Another problem with your file, my Lord. Captain Checker says it's NOT ok"
Screenshot of StyxAPI sample.php
Image may be NSFW.
Clik here to view.
Settings - Global Settings - Styx
Image may be NSFW.
Clik here to view.
Settings - Global Settings - Show BL Weigths - Styx


And we'll finish by the 404 (have to admit i love it - Lorenz-84 rotating here too)

Image may be NSFW.
Clik here to view.
Great job!
You've just broke it.

Styx Panel in one word ?
Professional.

Read more :
Presentation :
Crossing the Styx ( Styx Sploit Pack 2.0 ) - Meet CVE-2012-4969 via JS heapspray - 2012-12-22
Last integrated exploits :
CVE-2013-2423 integrating Exploit Kits (search for Styx) - 2013-04-23
CVE-2013-1493 (jre17u15 - jre16u41) integrating Exploit Kits (search for Styx) - 2013-03-09
CVE-2013-0431 (java 1.7 update 11) ermerging in Exploit Kits (search for Styx) - 2013-02-25
For fast network sigs :
Styx Exploit Kit by @malwaresigs
How is it being used :
The path to infection - Eye glance at the first line of "Russian Underground" - 2012-12-05

Some References :
An Overview of Exploit Packs - Contagio  - Mila
Wild Wild West - Kahu Security

Viewing all articles
Browse latest Browse all 185

Trending Articles