- http://blog.trendmic...serves-malware/
February 28, 2008 - "Sports fan sites being compromised by malicious authors is not unheard of. We’ve seen it happen to a Jets fan site in early January this year, and we’re seeing it again in another fan site – this time of Arsenal, a popular English soccer team. The compromised Web site in this case is Onlinegooner.com, which was reported by ScanSafe OI to be “maliciously active.” STAT* confirmed that the fan site had been injected with malicious code..."
* http://preview.tinyurl.com/ytkm9m
February 22, 2008 (Scansafe blog) - "...STAT discovered the site had been the victim of a code injection compromise. Visitors to the site are subjected to exploits which lead to the initial download of malware ...(hosted in Thailand). That malware then attempts to download additional malicious files ...(hosted in Hong Kong) and ...(another, hosted in Moscow, Russia). Installed malware includes a kernel-mode rootkit, keylogger, backdoor, and a DNS client used for ARP poisoning and DNS spoofing (Man-in-the-Middle attacks). Capabilities of the DNS client include intercepting, interpreting and rerouting of MX (email), NS (specifies authoritative nameservers), A (resolves hostnames to IP address), CNAME (resolves multiple hostnames to a single IP), and PTR (reverse lookups). Detection among traditional antivirus vendors is extremely low with only 8/31 scanners detecting the initially downloaded malware and 4/31 scanners detecting the maliciously installed DNS client used in the man-in-the-middle attacks. The attack itself is silent thus visitors to the site who have been impacted will unlikely be aware that some pretty severe malware has just been foisted onto their system..."
Leading nominee for "Worst 'drive-by download' of the Year"...


Edited by AplusWebMaster, 17 April 2008 - 09:20 AM.