What the Tech logo
Welcome! Register for a free account (or login) > How does it work?
  1. Quickly register. It will only take 60 seconds.
  2. Start a new topic. Ask your question. Wait for an email reply.
  3. Is your system infected? Begin reading the malware removal guide.
register button
Reply to this topicStart new topic
> Thousands of sites infected - attack in progress
AplusWebMaster
post Apr 22 2008, 02:27 PM
Post #1


AplusWebMaster
*****

Group: Authentic Member
Posts: 4,575
Joined: 30-December 03
From: USA
Member No.: 1,643
Operating System: XP/SP3



FYI...

- http://securitylabs.websense.com/content/Alerts/3070.aspx
04.22.2008 - "...malicious JavaScript injection that compromised thousands of domains at the start of this month, just 2-3 weeks ago. The attackers have now switched over to a new domain as their hub for hosting the malicious payload in this attack. We have no doubt that the two attacks are related... In the last few hours we have seen the number of compromised sites increase by a factor of ten. This mass injection is remarkably similar to the attack we saw earlier this month. When a user browses to a compromised site, the injected JavaScript loads a file named 1.js which is hosted on hxxp ://www.nihao[removed].com The JavaScript code then redirects the user to 1.htm (also hosted on the same server). Once loaded, the file attempts 8 different exploits (the attack last April utilised 12). The exploits target Microsoft applications, specifically browsers not patched against the VML exploit MS07-004 as well as other applications. Ominously files named McAfee.htm and Yahoo.php are also called by 1.htm but are no longer active at the time of writing. There are further similarities too between the two mass attacks. Resident on the latest malicious domain is a tool used in the execution of the attack. An analysis of that tool can be found in the ISC diary entry here*... It appears that same tool was used to orchestrate this attack too. When we first started tracking the use of this domain, the malicious JavaScript was still making use of hxxp ://www.nmida[removed].com/... Sites of varying content have been infected including UK government sites, and a United Nations website as can be seen by the Google search... The number of sites affected is in the hundreds of thousands..."
* http://isc.sans.org/diary.html?n&storyid=4294
Last Updated: 2008-04-16 19:14:00 UTC

ph34r.gif ph34r.gif ph34r.gif

This post has been edited by AplusWebMaster: Jul 4 2009, 08:29 AM
Go to the top of the page
 
+Quote Post
 
Start new topic
Replies
AplusWebMaster
post Dec 24 2008, 04:46 AM
Post #2


AplusWebMaster
*****

Group: Authentic Member
Posts: 4,575
Joined: 30-December 03
From: USA
Member No.: 1,643
Operating System: XP/SP3



FYI...

Mass Injection on John Sands Greeting Card Company site
- http://securitylabs.websense.com/content/Alerts/3268.aspx
12.23.2008 - "Websense... has discovered that the Web site of John Sands Greeting Card Company is infected with a mass JavaScript injection that delivers a malicious payload. Multiple pages on the site has been found to contain the said malicious code... Acquired by American Greetings in 1996, the company was founded in 1837 by John Sands, the son of an English engraver. The company is Australia's second oldest registered company. In an effort to protect their visitors, Websense Security Labs has contacted John Sands Greeting Card Company and advised them on this incident..."

(Screenshot available at the Websense URL above.)

ph34r.gif ph34r.gif
Go to the top of the page
 
+Quote Post

Posts in this topic
- AplusWebMaster   Thousands of sites infected - attack in progress   Apr 22 2008, 02:27 PM
- - AplusWebMaster   FYI... - http://preview.tinyurl.com/6mgej5 July 1...   Jul 19 2008, 05:24 AM
- - AplusWebMaster   FYI... SQL Injection List - Format Update - http:...   Jul 21 2008, 10:04 AM
- - AplusWebMaster   FYI... - http://isc.sans.org/diary.html?storyid=4...   Jul 24 2008, 05:17 AM
- - AplusWebMaster   FYI... SQL Injection Attacks Targeting Chinese-or...   Aug 8 2008, 07:36 AM
- - AplusWebMaster   FYI... More SQL Injections ...active NOW - http:/...   Aug 8 2008, 10:54 AM
- - AplusWebMaster   FYI... Sunkist site - mass JavaScript injection -...   Aug 22 2008, 07:08 PM
- - AplusWebMaster   FYI... - http://www.darkreading.com/document.asp?...   Aug 29 2008, 06:08 AM
- - AplusWebMaster   FYI... SQL injection ...BusinessWeek.com - http:/...   Sep 16 2008, 07:03 AM
- - AplusWebMaster   FYI... SQL threat: All Your (Data)base Are Belong...   Sep 18 2008, 03:48 AM
- - AplusWebMaster   FYI... ASPROX mutant - http://isc.sans.org/diary....   Sep 29 2008, 06:07 AM
- - AplusWebMaster   FYI... China Business Network Rail Site Infected ...   Oct 14 2008, 12:04 PM
- - AplusWebMaster   FYI... Adobe site - SQL injected... - http://www....   Oct 17 2008, 09:34 AM
- - AplusWebMaster   FYI... ECPAT NZ INC Courtesy Site: Mass Injection...   Nov 4 2008, 06:24 PM
- - AplusWebMaster   FYI... - http://www.viruslist.com/en/weblog?weblo...   Nov 8 2008, 03:43 PM
- - AplusWebMaster   Shadowserver - Full list of Injected Sites updated...   Nov 25 2008, 08:48 AM
- - AplusWebMaster   FYI... CBS website iFrame hack - http://www.infow...   Dec 1 2008, 12:40 PM
- - AplusWebMaster   FYI... Mass Injection on John Sands Greeting Card...   Dec 24 2008, 04:46 AM
- - AplusWebMaster   FYI... Multiple Chinese sites compromised... - ht...   Dec 31 2008, 01:42 PM
- - AplusWebMaster   FYI... Paris Hilton website infected with malware...   Jan 13 2009, 10:08 AM
- - AplusWebMaster   FYI... "Warning: We strongly suggest that re...   Jan 27 2009, 05:19 AM
- - AplusWebMaster   FYI... IEC website compromised - http://securityl...   Jan 27 2009, 10:36 AM
- - AplusWebMaster   FYI... - http://www.pcmag.com/article2/0,2817,233...   Jan 28 2009, 02:23 PM
- - AplusWebMaster   FYI... (It appears the hacks have been busy - CYA)...   Jan 30 2009, 09:04 AM
- - AplusWebMaster   FYI... - http://www-935.ibm.com/services/us/index...   Feb 3 2009, 11:57 AM
- - AplusWebMaster   FYI... Kaspersky USA site hacked... - http://www....   Feb 8 2009, 12:02 PM
- - AplusWebMaster   FYI... 500,000 Websites Hit By New Form Of SQL In...   Feb 27 2009, 10:53 AM
- - AplusWebMaster   FYI... DNS redirect attack - Puerto Rico - http:/...   Apr 29 2009, 11:05 AM
- - AplusWebMaster   FYI... SQL injections through Search Engine recon...   Apr 30 2009, 04:20 AM
- - AplusWebMaster   FYI... - http://preview.tinyurl.com/rbxxwa May 14...   May 15 2009, 05:42 AM
- - AplusWebMaster   More... - http://isc.sans.org/diary.html?storyid=...   May 18 2009, 01:50 PM
- - AplusWebMaster   FYI... - http://preview.tinyurl.com/qlr9ba 05-19-...   May 19 2009, 10:39 AM
- - AplusWebMaster   FYI... Gumblar/Martuz/Geno attack - http://isc.sa...   May 22 2009, 10:37 AM
- - AplusWebMaster   FYI... Mass Injection Compromises More than Twent...   May 29 2009, 05:02 PM
- - Shadab   So how are the webpages getting compromised in the...   May 29 2009, 11:30 PM
- - AplusWebMaster   QUOTE So how are the webpages getting compromised ...   May 30 2009, 02:49 AM
- - AplusWebMaster   FYI... - http://www.theregister.co.uk/2009/05/30/...   May 30 2009, 01:08 PM
- - AplusWebMaster   FYI... - http://securitylabs.websense.com/content...   Jun 1 2009, 10:23 PM
- - AplusWebMaster   FYI... Malware payload site changes to Shkarkimi ...   Jun 4 2009, 05:29 PM
- - AplusWebMaster   FYI... - http://blog.trendmicro.com/another-wave-...   Jun 7 2009, 04:02 AM
- - AplusWebMaster   FYI... - http://www.securityfocus.com/brief/970 2...   Jun 8 2009, 01:04 PM
- - AplusWebMaster   FYI... - http://windowssecrets.com/comp/090611#st...   Jun 11 2009, 04:32 AM
- - AplusWebMaster   FYI... Gumblar invades Best Buy - http://blog.tre...   Jul 3 2009, 06:17 AM
- - AplusWebMaster   FYI... SQL injection attacks hit 57K sites - http...   Aug 24 2009, 04:06 PM
- - AplusWebMaster   FYI... [Please DO NOT visit these domains as they ...   Aug 26 2009, 08:07 PM
- - AplusWebMaster   FYI... Another mass compromise attack - http://bl...   Aug 28 2009, 09:23 AM
- - AplusWebMaster   FYI... 2009 - Top Cyber Security Risks - http://w...   Sep 15 2009, 09:24 AM
- - AplusWebMaster   FYI... Gumblar attacks surge again - http://www.p...   Oct 21 2009, 03:17 AM
- - AplusWebMaster   FYI... 6 million pwnd - Mass web infections spike...   Oct 28 2009, 03:18 AM
- - AplusWebMaster   FYI... Media-servers.net compromised - http://sec...   Nov 5 2009, 01:09 PM
- - Doug   Happily, anyone protected by MVPS Hosts File alrea...   Nov 5 2009, 05:29 PM


Reply to this topicStart new topic

 


RSS Time is now: 21st March 2010 - 08:34 AM
Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk.
Member site: Alliance of Security Analysis Professionals | UNITE Against Malware
Memory Forums | Auto Repair Forum
© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy