What the Tech logo
Welcome! Register for a free account (or login) > How does it work?
  1. Quickly register. It will only take 60 seconds.
  2. Start a new topic. Ask your question. Wait for an email reply.
  3. Is your system infected? Begin reading the malware removal guide.
register button
Reply to this topicStart new topic
> Thousands of sites infected - attack in progress
AplusWebMaster
post Apr 22 2008, 02:27 PM
Post #1


AplusWebMaster
*****

Group: Authentic Member
Posts: 4,561
Joined: 30-December 03
From: USA
Member No.: 1,643
Operating System: XP/SP3



FYI...

- http://securitylabs.websense.com/content/Alerts/3070.aspx
04.22.2008 - "...malicious JavaScript injection that compromised thousands of domains at the start of this month, just 2-3 weeks ago. The attackers have now switched over to a new domain as their hub for hosting the malicious payload in this attack. We have no doubt that the two attacks are related... In the last few hours we have seen the number of compromised sites increase by a factor of ten. This mass injection is remarkably similar to the attack we saw earlier this month. When a user browses to a compromised site, the injected JavaScript loads a file named 1.js which is hosted on hxxp ://www.nihao[removed].com The JavaScript code then redirects the user to 1.htm (also hosted on the same server). Once loaded, the file attempts 8 different exploits (the attack last April utilised 12). The exploits target Microsoft applications, specifically browsers not patched against the VML exploit MS07-004 as well as other applications. Ominously files named McAfee.htm and Yahoo.php are also called by 1.htm but are no longer active at the time of writing. There are further similarities too between the two mass attacks. Resident on the latest malicious domain is a tool used in the execution of the attack. An analysis of that tool can be found in the ISC diary entry here*... It appears that same tool was used to orchestrate this attack too. When we first started tracking the use of this domain, the malicious JavaScript was still making use of hxxp ://www.nmida[removed].com/... Sites of varying content have been infected including UK government sites, and a United Nations website as can be seen by the Google search... The number of sites affected is in the hundreds of thousands..."
* http://isc.sans.org/diary.html?n&storyid=4294
Last Updated: 2008-04-16 19:14:00 UTC

ph34r.gif ph34r.gif ph34r.gif

This post has been edited by AplusWebMaster: Jul 4 2009, 08:29 AM
Go to the top of the page
 
+Quote Post

Posts in this topic
- AplusWebMaster   Thousands of sites infected - attack in progress   Apr 22 2008, 02:27 PM
- - AplusWebMaster   FYI... Hundreds of thousands of SQL injections -...   Apr 24 2008, 02:57 PM
- - AplusWebMaster   FYI... (DO NOT visit the the sites mentioned in th...   Apr 25 2008, 09:55 AM
- - AplusWebMaster   For clarification: (Warning: We strongly suggest ...   Apr 26 2008, 05:49 AM
- - AplusWebMaster   FYI... SQL Injection Worm on the Loose - http://i...   May 7 2008, 04:57 AM
- - AplusWebMaster   FYI... New SQL Injection Attacks and New Malware:...   May 7 2008, 12:56 PM
- - AplusWebMaster   (Warning: We strongly suggest that readers NOT vis...   May 10 2008, 02:41 AM
- - AplusWebMaster   FYI... Mass File Injection Attack - http://isc.sa...   May 11 2008, 07:47 PM
- - AplusWebMaster   FYI... - http://www.techworld.com/security/news/i...   May 13 2008, 09:53 AM
- - AplusWebMaster   Warning: We strongly suggest that readers NOT visi...   May 14 2008, 04:13 AM
- - AplusWebMaster   (Warning: We strongly suggest that readers NOT vis...   May 14 2008, 12:54 PM
- - AplusWebMaster   FYI... Mass SQL Injection Attack Targets Chinese ...   May 19 2008, 05:36 AM
- - AplusWebMaster   More on the China/Taiwan SQL attacks... - http://...   May 19 2008, 11:33 AM
- - AplusWebMaster   Follow-up: - http://www.computerworld.com/comment...   May 19 2008, 03:24 PM
- - AplusWebMaster   FYI... (apologies for the long post - needed for d...   May 20 2008, 02:59 AM
- - AplusWebMaster   Warning: We strongly suggest that readers NOT visi...   May 20 2008, 08:00 PM
- - AplusWebMaster   FYI... Full list of Injected Sites - http://www.s...   Jun 2 2008, 05:22 AM
- - AplusWebMaster   FYI... New sql injection site with fastflux hosti...   Jun 2 2008, 08:23 PM
- - AplusWebMaster   And the list just keeps on growing... Full list o...   Jun 6 2008, 05:16 AM
- - AplusWebMaster   Ongoing growth... ugh. Full list of Injected Site...   Jun 12 2008, 02:06 AM
- - AplusWebMaster   FYI... SQL Injection: More of the same - http://i...   Jun 13 2008, 11:18 AM
- - AplusWebMaster   FYI... - http://preview.tinyurl.com/64qke6 June 1...   Jun 18 2008, 05:39 AM
- - AplusWebMaster   FYI... Microsoft SQL Injection Prevention Strateg...   Jun 25 2008, 05:50 AM
- - AplusWebMaster   FYI... - http://www.theregister.co.uk/2008/06/26/...   Jun 26 2008, 05:48 PM
- - AplusWebMaster   FYI... More SQL Injection with Fast Flux hosting ...   Jul 1 2008, 04:43 AM
- - AplusWebMaster   FYI... Detecting scripts in ASF files - http://is...   Jul 3 2008, 04:18 AM
- - AplusWebMaster   FYI... Sony PlayStation website hacked - http://w...   Jul 3 2008, 10:14 AM
- - AplusWebMaster   Update... 7.4.2008 - http://atlas.arbor.net/summa...   Jul 4 2008, 06:51 AM
- - AplusWebMaster   FYI... - http://www.shadowserver.org/wiki/pmwiki....   Jul 6 2008, 08:32 AM
- - AplusWebMaster   FYI.. Governmental, Healthcare, and Top Business ...   Jul 17 2008, 03:54 AM
- - AplusWebMaster   FYI... - http://preview.tinyurl.com/6mgej5 July 1...   Jul 19 2008, 05:24 AM
- - AplusWebMaster   FYI... SQL Injection List - Format Update - http:...   Jul 21 2008, 10:04 AM
- - AplusWebMaster   FYI... - http://isc.sans.org/diary.html?storyid=4...   Jul 24 2008, 05:17 AM
- - AplusWebMaster   FYI... SQL Injection Attacks Targeting Chinese-or...   Aug 8 2008, 07:36 AM
- - AplusWebMaster   FYI... More SQL Injections ...active NOW - http:/...   Aug 8 2008, 10:54 AM
- - AplusWebMaster   FYI... Sunkist site - mass JavaScript injection -...   Aug 22 2008, 07:08 PM
- - AplusWebMaster   FYI... - http://www.darkreading.com/document.asp?...   Aug 29 2008, 06:08 AM
- - AplusWebMaster   FYI... SQL injection ...BusinessWeek.com - http:/...   Sep 16 2008, 07:03 AM
- - AplusWebMaster   FYI... SQL threat: All Your (Data)base Are Belong...   Sep 18 2008, 03:48 AM
- - AplusWebMaster   FYI... ASPROX mutant - http://isc.sans.org/diary....   Sep 29 2008, 06:07 AM
- - AplusWebMaster   FYI... China Business Network Rail Site Infected ...   Oct 14 2008, 12:04 PM
- - AplusWebMaster   FYI... Adobe site - SQL injected... - http://www....   Oct 17 2008, 09:34 AM
- - AplusWebMaster   FYI... ECPAT NZ INC Courtesy Site: Mass Injection...   Nov 4 2008, 06:24 PM
- - AplusWebMaster   FYI... - http://www.viruslist.com/en/weblog?weblo...   Nov 8 2008, 03:43 PM
- - AplusWebMaster   Shadowserver - Full list of Injected Sites updated...   Nov 25 2008, 08:48 AM
- - AplusWebMaster   FYI... CBS website iFrame hack - http://www.infow...   Dec 1 2008, 12:40 PM
- - AplusWebMaster   FYI... Mass Injection on John Sands Greeting Card...   Dec 24 2008, 04:46 AM
- - AplusWebMaster   FYI... Multiple Chinese sites compromised... - ht...   Dec 31 2008, 01:42 PM
- - AplusWebMaster   FYI... Paris Hilton website infected with malware...   Jan 13 2009, 10:08 AM
- - AplusWebMaster   FYI... "Warning: We strongly suggest that re...   Jan 27 2009, 05:19 AM
- - AplusWebMaster   FYI... IEC website compromised - http://securityl...   Jan 27 2009, 10:36 AM
- - AplusWebMaster   FYI... - http://www.pcmag.com/article2/0,2817,233...   Jan 28 2009, 02:23 PM
- - AplusWebMaster   FYI... (It appears the hacks have been busy - CYA)...   Jan 30 2009, 09:04 AM
- - AplusWebMaster   FYI... - http://www-935.ibm.com/services/us/index...   Feb 3 2009, 11:57 AM
- - AplusWebMaster   FYI... Kaspersky USA site hacked... - http://www....   Feb 8 2009, 12:02 PM
- - AplusWebMaster   FYI... 500,000 Websites Hit By New Form Of SQL In...   Feb 27 2009, 10:53 AM
- - AplusWebMaster   FYI... DNS redirect attack - Puerto Rico - http:/...   Apr 29 2009, 11:05 AM
- - AplusWebMaster   FYI... SQL injections through Search Engine recon...   Apr 30 2009, 04:20 AM
- - AplusWebMaster   FYI... - http://preview.tinyurl.com/rbxxwa May 14...   May 15 2009, 05:42 AM
- - AplusWebMaster   More... - http://isc.sans.org/diary.html?storyid=...   May 18 2009, 01:50 PM
- - AplusWebMaster   FYI... - http://preview.tinyurl.com/qlr9ba 05-19-...   May 19 2009, 10:39 AM
- - AplusWebMaster   FYI... Gumblar/Martuz/Geno attack - http://isc.sa...   May 22 2009, 10:37 AM
- - AplusWebMaster   FYI... Mass Injection Compromises More than Twent...   May 29 2009, 05:02 PM
- - Shadab   So how are the webpages getting compromised in the...   May 29 2009, 11:30 PM
- - AplusWebMaster   QUOTE So how are the webpages getting compromised ...   May 30 2009, 02:49 AM
- - AplusWebMaster   FYI... - http://www.theregister.co.uk/2009/05/30/...   May 30 2009, 01:08 PM
- - AplusWebMaster   FYI... - http://securitylabs.websense.com/content...   Jun 1 2009, 10:23 PM
- - AplusWebMaster   FYI... Malware payload site changes to Shkarkimi ...   Jun 4 2009, 05:29 PM
- - AplusWebMaster   FYI... - http://blog.trendmicro.com/another-wave-...   Jun 7 2009, 04:02 AM
- - AplusWebMaster   FYI... - http://www.securityfocus.com/brief/970 2...   Jun 8 2009, 01:04 PM
- - AplusWebMaster   FYI... - http://windowssecrets.com/comp/090611#st...   Jun 11 2009, 04:32 AM
- - AplusWebMaster   FYI... Gumblar invades Best Buy - http://blog.tre...   Jul 3 2009, 06:17 AM
- - AplusWebMaster   FYI... SQL injection attacks hit 57K sites - http...   Aug 24 2009, 04:06 PM
- - AplusWebMaster   FYI... [Please DO NOT visit these domains as they ...   Aug 26 2009, 08:07 PM
- - AplusWebMaster   FYI... Another mass compromise attack - http://bl...   Aug 28 2009, 09:23 AM
- - AplusWebMaster   FYI... 2009 - Top Cyber Security Risks - http://w...   Sep 15 2009, 09:24 AM
- - AplusWebMaster   FYI... Gumblar attacks surge again - http://www.p...   Oct 21 2009, 03:17 AM
- - AplusWebMaster   FYI... 6 million pwnd - Mass web infections spike...   Oct 28 2009, 03:18 AM
- - AplusWebMaster   FYI... Media-servers.net compromised - http://sec...   Nov 5 2009, 01:09 PM
- - Doug   Happily, anyone protected by MVPS Hosts File alrea...   Nov 5 2009, 05:29 PM


Reply to this topicStart new topic

 


RSS Time is now: 13th March 2010 - 05:40 PM
Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk.
Member site: Alliance of Security Analysis Professionals | UNITE Against Malware
Memory Forums | Auto Repair Forum
© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy