This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Malicious Website (via e-mail): Trojan Horse Exploit

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://www.websense.com/securitylabs/alert…php?AlertID=751
March 15, 2007 ~ "Websense Security LabsTM has received reports of new, malicious Web sites which are designed to install Trojan horses. The Web sites are hosted in Korea and Hong Kong. The sites attempt to exploit the Microsoft AdoDB / XML HTTP (MS06-014) vulnerability to download and install a Trojan downloader without end-user interaction. Users receive an email, written in German, requesting that they visit a Web site to verify their order number. Upon visiting the site, the malicious code is automatically downloaded and run, assuming the user is not patched for the Microsoft vulnerability. The original site, which is hosted in Korea, appears to have been compromised. An IFRAME pointing to the exploit code site is contained at the bottom of the original site. The site contains encoded JavaScript which, when decoded, runs the exploit code and downloads an .exe file, update.exe, from a server in Hong Kong…"

(Screenshots available at the URL above.)

<_<
FYI…

Viral Video…
> http://www.websense.com/securitylabs/blog/….php?BlogID=114
Mar 15 2007 ~ "This is a follow up post on our alert we added earlier today (see: http://www.websense.com/securitylabs/alert…php?AlertID=751 ). We have since discovered a different SPAM run that is using the same sites but with a different lure on a different compromised site. This version's lure is written in English, not German, and poses as a website that hosts video on the web. In particular it lures users to view something called the "Redneck Slingshot". One piece of irony is the subject of the SPAM lure is "must see viral video". Assuming users click on the link they are redirected to a site which is hosted in the United States, and was up at the time of this entry. The site appears to also have been compromised and is pointing to the same site that our previous alert outlined (see: http://www.websense.com/securitylabs/alert…php?AlertID=751 )."

:ph34r: