Untorpig
Author(s)
Don Jackson
Latest Version
2.4
Description
Untorpig is a program to decode/decrypt data in Torpig HTTP traffic logs.
Torpig is a sophisticated spyware and information stealing Trojan that can be
used to perform post-authentication
man-in-the-middle (MitM) content manipulation attacks. In other words, it can basically change
anything sent or received between your browser
and a web server in any HTTP session, even those encrypted by TLS/SSL. This
capability is often used in difficult-to-detect phishing attacks.
Torpig is also known as Anserin or Sinowal. It has been combined with a boot
sector rootkit known as Mebroot.
Torpig encodes the data it steals from the infected machine before sending
it to the stolen data repository on a server controlled by the attackers.
In order to develop an efficient incident response to Torpig infection, it's
important to be able to decode the data so that one can tell what was stolen
or exposed.
Requirements
Untorpig requires Perl 5.6.1 or later. It has been tested on various Linux and Win32 systems.
No Support, No Warranty
SecureWorks cannot provide support for this software, but feedback is appreciated.
License Agreement
Copyright (C) 2005 - 2008 SecureWorks, Inc.
This end user license agreement is a legal agreement (hereinafter "Agreement") between SecureWorks, Inc. (SecureWorks) and you, either an individual or a single entity, (hereinafter "Licensee"). This Agreement covers all software, the associated media, any printed materials, data, files and information and any "online" or electronic documentation ("Software") which it accompanies.
By clicking the "AGREE AND DOWNLOAD..." checkbox on the Reasearch/Tools page, Licensee agrees to be bound by the terms of this Agreement. If Licensee does not agree with any term or condition, do not download, order, open, install or use the Software.
This software program is free software subject to compliance by Licensee with the terms and conditions of the GNU General Public License version 3. License should receive with the Software download a copy of the GNU General Public License along with this program. If not, please see http://www.gnu.org/licenses/ for a copy of the GNU General Public License version 3.
Licensee acknowledges and agrees that SecureWorks owns and retains all copyrights, trademarks, trade secrets and other proprietary rights in and to the Software. This Agreement conveys to Licensee only a non-exclusive and limited right of use, revocable in accordance with the terms and conditions of this Agreement.
Provision of any Software under this Agreement is "as-is" and shall not create any obligation for SecureWorks to continue to develop, productize, support, repair, offer for sale or in any other way continue to provide or develop Software either to Licensee or to any other party. Without limiting the generality of the foregoing. SecureWorks does not warrant that the Software, its use, operation or Licensee's ability to use the Software will be uninterrupted or error-free or that all Software errors will be corrected.
Disclaimer of Warranty.
EXCEPT WHEN OTHERWISE STATED IN WRITING SECUREWORKS PROVIDES THE PROGRAM "AS IS" WITHOUT WARRANTY OF ANY KIND, EITHER EXPRESSED OR IMPLIED, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY, NONINFRINGEMENT AND FITNESS FOR A PARTICULAR PURPOSE. THE ENTIRE RISK AS TO THE QUALITY AND PERFORMANCE OF THE PROGRAM IS WITH LICENSEE AND LICENSEE SHOULD NOT RELY IN ANY WAY ON THE CORRECT FUNCTIONING OR PERFORMANCE OF SOFTWARE. SHOULD THE PROGRAM PROVE DEFECTIVE OR UNSATISFACTORY, LICENSEE ASSUMES THE COST OF ALL NECESSARY SERVICING, REPAIR, CORRECTION OR RECOVERY FROM SECURITY BREACH, DATA LOSS OR DATA ERRORS.
Limitation of Liability.
IN NO EVENT UNLESS REQUIRED BY APPLICABLE LAW OR AGREED TO IN WRITING WILL SECUREWORKS, OR ANY OTHER PARTY WHO MODIFIES AND/OR CONVEYS THE PROGRAM AS PERMITTED ABOVE, BE LIABLE TO LICENSEE FOR DAMAGES, INCLUDING ANY GENERAL, SPECIAL, INCIDENTAL OR CONSEQUENTIAL DAMAGES ARISING OUT OF THE USE OR INABILITY TO USE THE PROGRAM (INCLUDING BUT NOT LIMITED TO LOSS OF DATA OR DATA BEING RENDERED INACCURATE OR LOSSES SUSTAINED BY LICENSEE OR THIRD PARTIES OR A FAILURE OF THE PROGRAM TO OPERATE WITH ANY OTHER PROGRAMS), EVEN IF SUCH SECUREWORKS HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
Licensee acknowledges that Software is of U. S. origin. Recipient agrees to comply with all applicable international and national laws that apply to the Software, including the U. S. Export Administration Regulations, as well as end-user, end-use and destination restrictions issued by U. S. and other governments. This agreement shall be governed by the laws of the State of Georgia.
END OF TERMS AND CONDITIONS