This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Malicious Website: Super Bowl XLI / Dolphin Stadium

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://www.websense.com/securitylabs/alert…php?AlertID=733
February 02, 2007 ~ "Websense® Security Labs™ has discovered that the official website of Dolphin Stadium has been compromised with malicious code. The Dolphin Stadium is currently experiencing a large number of visitors, as it is the home of Sunday's Super Bowl XLI. The site is linked from numerous official Super Bowl websites and various Super Bowl-related search terms return links to the site. A link to a malicious javascript file has been inserted into the header of the front page of the site. Visitors to the site execute the script, which attempts to exploit two vulnerabilities: MS06-014 and MS07-004. Both of these exploits attempt to download and execute a malicious file.
The file that is downloaded is a NsPack-packed Trojan keylogger/backdoor, providing the attacker with full access to the compromised computer. The filename is w1c.exe and its MD5 is ad3da9674080a9edbf9e084c10e80516

We have notified the owner's of the site, but the site is currently still malicious.

Please do not visit the site until it has been cleaned.
* http://www.microsoft.com/technet/security/…n/MS06-014.mspx
* http://www.microsoft.com/technet/security/…n/MS07-004.mspx

(Site screenshot available at the Websense URL above.)

:ph34r:
FYI…

- http://isc.sans.org/diary.html?storyid=2151
Last Updated: 2007-02-03 16:11:29 UTC
"…UPDATE:
McAfee has released updated signatures to detect Backdoor-DKT:
http://vil.nai.com/vil/content/v_141405.htm#tab7
Other AV vendors should have specific signatures by now as well.
UPDATE2:
A similar (identical?) exploit is served by the following domains. At this point, the best defense (after patching) is to block these domains and monitor DNS requests for them. Infected machines will try to call home to them.
w1c.cn, dv521.com, natmags.co.uk, bc0.cn, 137wg.com, newasp.com.cn
dv521.com was the domain used in the dolphinstadium.com defacement. Thanks to the cooperation from Xin-Net, the domain is no longer resolving. But there is always a chance that it will come back…"

.
FYI…

Super Bowl Infection - More Sites
- http://isc.sans.org/diary.html?storyid=2166
Last Updated: 2007-02-04 21:17:53 UTC
"On Friday we reported that the Dolphins Stadium (home of the 2007 Super Bowl) was infected with a scripted pointer to malware that exploited two patchable Microsoft Windows vulnerabilities. While doing research on that issue, we uncovered many more sites that contain similar references. Here is a list of the some of the ones we found, many have already been cleaned up but many have not. System administrators might want to check their network flow logs for any traffic to these sites, and for any traffic to the five sites that hosted the hostile Java script.
It looks like the "1.js" intrusions happened around the first of January while the "3.js" intrusions occured near the end of January. We cannot find any evidence of a "2.js" or "4.js" script…
(Referenced sites shown at the URL above)
A common theme seems to be an attack on hospital or medical care sites, although that is not completely the case. We checked to see if this was a mass attack on one service provider but other than a lot of *.squizzle.com sites it does not appear to be this type of attack."

:ph34r:
FYI…

More code injection sites 8.js
- http://isc.sans.org/diary.html?storyid=2178
Last Updated: 2007-02-06 22:55:53 UTC
"We have discovered more defacements / code-injection similar to the superbowl site defacement. If you google for script 8.js you will find that 1.js and 3.js were not the only java script’s used in this fashion. This version appears to have been targeted a bit at gaming sites although there are a few medical sites including an “anonymous expert HIV/AIDS counseling” site with this defacement… The concept of a website having additional content or having portions of the content replaced was usually looked at as embarrassing but not a major threat. In my opinion with the recent trend to perform “silent defacements” with malicious code injection, world writable content areas should be treated as a threat. The only malicious version of 8.js I have seen so far is hosted on 001yl.com … The stuff I pulled from 001y.com is very similar to the 3.js defacement we discussed in the dolphinstadium site write-ups. 8.js uses a hidden iframe to hide its reference to qq.htm… qq.htm uses several hidden iframes to call happy1.htm, happy2.htm, happy3.htm from 001yl.com , h.js from zj5173.com and a counter at s102 .cnzz .com. Each happy1.htm (and 2 and 3) had pointers to zj5173.com/2.exe - h.js injects zj5173.com/3.js into a cookie. - 3.js uses another hidden iframe to call zj5173.com/1.htm -
1.htm uses a VML overflow from hackwm.com to run some shell code.
2.exe is not currently well detected the virus scanning engines at virus total…"

(More detail at the ISC URL above.)

:ph34r:
FYI…

- http://isc.sans.org/diary.html?storyid=2166
Last Updated: 2007-02-07 18:52:55 UTC …(Version: 3)
[See the updates (dtd. 2/7/2007)]

~ and:

…Possible Vector for …Malicious JavaScript Insertion
- http://isc.sans.org/diary.html?storyid=2187
Last Updated: 2007-02-07 21:41:45 UTC ~ "We've received information that the likely common vector for how the web sites were compromised appears to be through the use of Dreamweaver. There is not a flaw in Dreamweaver that was exploited. It was a case of lazy programming on the parts of site developers who did not do a good job of "input validation" so attackers were able to do "sql injection" attacks."

:(
FYI…

- http://isc.sans.org/diary.html?storyid=2151
Last Updated: 2007-02-08 16:58:49 UTC ~ "…UPDATE4:
Updating our earlier update :-), the 3.js off the Natmags site downloads an ad.htm file which is clearly an exploit, as can be shown with a little PERL-fu to make it readable:
cat ad.htm | perl -pe 's/(.)/chr(ord($1)&127)/ge'
The corresponding www .exe is no longer available on the server though (or doesn't download)."

.
FYI…

- http://preview.tinyurl.com/2dxbkq
(9 February 2007) ~ " 'According to the Korea Information Security Agency, 1,000 Korean online game-related web sites were infected with malware, resulting in 92,000 infected PCs. KISA has informed the sites of the problem and urged them to cleanse their sites of the malware. The attackers' aim was apparently to intercept gamers' IDs and passwords. KISA says 620,000 PCs were attacked targeting a known flaw in Microsoft Windows, but most were protected as they had applied the latest Microsoft patches. The agency also urged computer users to obtain automatic security updates…'
[Editor's Note (Ullrich): Would be nice to have US-Cert issue a similar statement for the dolphinstadium.com site. The numbers are similar, and the goal was similar, as well. Maybe it was even the same group.]"

.