This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Nine-Ball - mass injection, malicious site, malicious code...

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

Nine-Ball - mass injection, malicious site, malicious code
- http://securitylabs.websense.com/content/Alerts/3421.aspx
06.16.2009 - "Websense… has detected another large mass injection attack in the wild after the Beladen and Gumblar attacks. We are calling this mass compromise Nine-Ball because of the final landing site. We have been tracking the Nine-Ball mass compromise since 6/03/2009. To date, over 40,000 legitimate Web sites have been compromised with obfuscated code that leads to a multi-level redirection attack, ending in a series of drive-by exploits that if successful install a trojan downloader on the user's machine… If a user visits one of the infected sites, they are redirected through a series of different sites owned by the attacker and brought to the the final landing page containing the exploit code (the redirection path is shown below). The final landing page records the visitors's IP address. When visited for the first time, the user is directed to the exploit payload site. But when visited again from the same IP address, the user is directed to the benign site of ask.com… After redirection, the exploit payload site returns highly obfuscated malicious code. The malicious code attempts to exploit MS06-014 (targeting MDAC) and CVE-2006-5820 (targeting AOL SuperBuddy), as well as employing exploits targeting Acrobat Reader and QuickTime. The MS06-014 exploit code will download a Trojan dropper with low AV detection rate*. This dropper drops a dll with the name SOCKET2.DLL to Windows' system folder. This file is used to steal user information. The malicious PDF file, served by the exploit site, also has very low AV detection rate**…"
* http://www.virustotal.com/analisis/62254bf…68f7-1245137075
File l.php … Result: 7/40 (17.50%)

** http://www.virustotal.com/analisis/f956507…d894-1245160253
File PDF.php … Result: 3/41 (7.32%)

(Screenshot available at the Websense URL above.)

:ph34r: <_< :ph34r:
FYI…

- http://preview.tinyurl.com/nz8pu2
2009-06-17 E-week.com - "… "We are not releasing the names of the sites compromised," said Stephan Chenette, manager of threat research at Websense. "We've attempted to contact a subset of the compromised sites to let them know that they've been infected … No particular vertical was targeted"… in a bid to sniff out security researchers, the compromised sites are set to check if they have been visited more than once by the same IP address. If a visitor has been to the site more than once, he or she will be directed to ask.com instead of to the attack site. While Nine-Ball is the third mass Website compromise report to make headlines in recent weeks, Chenette said it appears to be distinct from the others. "The Nine-Ball mass compromise is not related to either Beladen or Gumblar, but like the previous mass compromises, many of the machines owned by the attacker are located in the Ukraine," Chenette said…"

:ph34r: :ph34r:
FYI…

- http://securitylabs.websense.com/content/Blogs/3422.aspx
06.22.2009 - "… Nine-Ball attack compromised over 40,000 legitimate Web sites in an ongoing campaign… By analyzing the tens of thousands of Web sites compromised in this attack we can see that the majority of infected sites are in the United States (71%)… A confusing factor for most who attempt to analyze this attack is that there is no clear single malicious redirection path. Users who visit an infected site are silently taken through a series of varied redirectors and the final landing page is not always the same… The valid string, in the Nine-Ball attacks, is an iframe. When this iframe is interpreted by the browser, the browser silently visits the iframe location… Once exposed to a Nine-Ball exploit site, several exploits will be delivered to the user's browser. Among them are:
• MS06-014 (MDAC)
• CVE-2006-5820 (AOL SuperBuddy)
• CVE-2007-0015 (QuickTime)
• Adobe Acrobat Reader,
The exploit code that targets Acrobat Reader will download a malicious PDF file from the exploit site. The PDF file integrates 3 vulnerabilities:
• CVE-2008-1104
• CVE-2007-5659
• CVE-2009-0927 …"

(Screenshots available at the URL above.)

:ph34r: <_< :ph34r:
More on Nine-ball…

- http://blog.trendmicro.com/another-messy-m…romise-emerges/
June 22, 2009 - "… Trend Micro was alerted of the emergence of another mass compromise, dubbed Nine Ball, for the same reason Gumblar was named Gumblar, only that this time, the Nine Ball domain is only one of hundreds of landing pages users can be redirected to… the infection starts when a user accesses a compromised site that automatically redirects him/her to several sites. These sites were actually a trio of malicious domains (specific .KZ and .TW sites) constantly used by attackers in their scheme of redirecting users to a malicious IP address registered somewhere in Ukraine. The chain ends when the user’s browser lands on a page that contains exploits for vulnerabilities in various software including Adobe Acrobat, Adobe Shockwave… Both PDF and SWF files lead to binary payload that look similar to a new kind of information stealer detected as TSPY_SILENTBAN.U. TSPY_SILENTBAN.U installs itself as a Browser Helper Object (BHO) on the affected system and monitors Internet activity. Gathered information are then sent to a remote user using HTTP POST. Note that as of the writing, the binary payload retrieved from the attack uses this spyware. It is more likely that in future attacks, other payloads can be used… Information on the vulnerabilities exploited in this attack can be found on the following pages:
http://web.nvd.nist.gov/view/vuln/detail?v…d=CVE-2009-0927
Last revised:04/28/2009
http://web.nvd.nist.gov/view/vuln/detail?v…d=CVE-2007-5659
Last revised:11/25/2008
http://web.nvd.nist.gov/view/vuln/detail?v…d=CVE-2007-2496
Last revised:11/15/2008 …"

:ph34r: <_<