<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: 8v8]]></title>
    <link>http://securityratty.com/tag/8v8</link>
    <description></description>
    <pubDate>Wed, 09 Jan 2008 15:04:58 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Malware Serving Exploits Embedded Sites as Usual]]></title>
      <link>http://securityratty.com/article/5defb698a8c4f8f520e93bbc5e46b42d</link>
      <guid>http://securityratty.com/article/5defb698a8c4f8f520e93bbc5e46b42d</guid>
      <description><![CDATA[The combination of the recent RealPlayer exploit and MDAC is a fad, but the very same is getting embraced in the short-term by malicious parties in China that have also started combining the Internet...]]></description>
      <content:encoded><![CDATA[<a href="http://bp2.blogger.com/_wICHhTiQmrA/R4VbBT8-MtI/AAAAAAAABTg/x9ErgYXAvEc/s1600-h/ms07-004.jpg"><img id="BLOGGER_PHOTO_ID_5153625426689405650" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="" src="http://bp2.blogger.com/_wICHhTiQmrA/R4VbBT8-MtI/AAAAAAAABTg/x9ErgYXAvEc/s200/ms07-004.jpg" border="0" /></a>The combination of the recent <a href="http://ddanchev.blogspot.com/2008/01/massive-realplayer-exploit-embedded.html">RealPlayer exploit</a> and <a href="http://ddanchev.blogspot.com/2007/12/mdac-activex-code-execution-exploit.html">MDAC</a> is a fad, but the very same is getting embraced in the short-term by malicious parties in China that have also started combining the Internet Explorer VML Download and Execute Exploit (MS07-004), thanks to recent localized forum postings on modifying the third exploit. Let's assess several sample domains.<br /><br /><strong>8v8.biz/ms07004.htm</strong> (58.53.128.98) is such a domain that's serving a combination of these starting with Exploit-MS07-004 :<br /><br /><strong>Result</strong>: 12/32 (37.5%)<br /><strong>File size</strong>: 3432 bytes<br /><strong>MD5</strong>: bafab9b8e38527e9830047fd66b39532<br /><strong>SHA1</strong>: b81abcf63a2c4bcf43526f28aec20fca2f58d67c<br /><br /><strong>8v8.biz/1.htm</strong> - MDAC also loads <strong>8v8.biz/06014.html</strong> in between <strong>8v8.biz/r.htm</strong> - real player unobfuscated, wheere all of these attempt to load <strong>8v8.biz/v.exe</strong> - Worm.Win32.AutoRun.bkx; Win32/Cekar!generic<br /><br /><strong>Result:</strong> 27/31 (87.10%)<br /><strong>File size</strong>: 19501 bytes<br /><strong>MD5</strong>: 7b101f7baeae0ebab9ecc06fdb9542dc<br /><strong>SHA1</strong>: 36ffa50ce3873fb04c13c80421c205a7760f47ca<br /><br />The binary is using a default set of known executables of anti malware products, and is installing a default debugger injected upon execution of any of these, and is therefore successfully killing many of the applications.<br /><br />Another exploit serving domain with a very diverse set of exploits used, but again serving the faddish RealPlayer plus MDAC combination is <strong>uc147.com</strong> (218.107.216.85) :<br /><br /><strong>uc147.com/test/MS07004.htm</strong><br /><strong>uc147.com/test/PPs.htm</strong><br /><strong>uc147.com/test/biaxing06014.Htm</strong><br /><strong>uc147.com/test/index.htm</strong><br /><strong>uc147.com/test/Click_here.html</strong><br /><strong>uc147.com/test/PPLIVE.htm</strong><br /><strong>uc147.com/test/Thunder.html</strong><br /><strong>uc147.com/test/bf.htm</strong><br /><strong>uc147.com/test/Open.htm</strong><br /><strong>uc147.com/test/ms06014.htm</strong><br /><strong>uc147.com/test/jetAudio%207.x.htm</strong><br /><br />where all are trying to load <strong>uc147.com/zy.exe</strong> :<br /><br /><strong>Result</strong>: 24/32 (75%)<br /><strong>File size</strong>: 15456 bytes<br /><strong>MD5</strong>: 3a0804d8e12706e97cdda6aa4f50ef5f<br /><strong>SHA1</strong>: cfd2f158a658dc0d8618c35806b94008b4fb1c0f<br /><br />The third domain is great example of what's an emerging trend rather than a fad, namely the use of comprehensive multiple IFRAMES loading campaigns. <strong>qx13.cn/3.htm</strong> (61.174.61.94) (IE COM CreateObject Code Execution (MS06-042) which loads sp.<strong>070808.net/23.htm</strong>, (75.126.3.218) where the following try to load as well :<br /><br /><strong>sp.070808.net/in.htm</strong><br /><strong>wc.070808.net/37.htm</strong><br /><strong>az.sbb22.com/hh.htm</strong><br /><strong>um.uuzzvv.com/uu.htm</strong><br /><strong>fa.55189.net</strong><br /><strong>acc.jqxx.org/40.htm</strong><br /><strong>ktv.mm5208.com/25.htm</strong><br /><br />Two other IFRAMES within within <strong>qx13.cn/3.htm</strong>,<strong> w.aeaer.com/ae.htm</strong> (75.126.3.216) loads the same IFRAMES, and <strong>qi.ccbtv.net/btv.htm</strong> (66.90.79.138) again loads the same IFRAMEs. It gets even more complicated and the ecosystem more comprehensive as the secondary IFRAMEs logically load many others such as :<br /><br /><strong>68yu.cn/s29.htm</strong><br /><strong>ermei.loveyoushipin.com/pic/9041.htm</strong><br /><strong>yun.yun878.com/web/6619038.htm</strong><br /><strong>ppp.749571.com/ww/new82.htm</strong><br /><strong>2.xks08.com/dm1.htm?60</strong><br /><strong>ad.2365.us/110</strong><br /><br />The more complicated and dynamic these IFRAME-ing attacks get, the higher the campaign's lifecycle becomes, making it harder the determine where's the weakest link, and making it easier for the malicious parties to evaluate which node needs a boost by including new domains spread across different netblocks like this case.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=w2zMTzD"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=w2zMTzD" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=41CiaPD"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=41CiaPD" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=qUx21Md"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=qUx21Md" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=1nBOgLd"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=1nBOgLd" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=o9eVooD"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=o9eVooD" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=l2sWXKD"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=l2sWXKD" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=dF5Oyod"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=dF5Oyod" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/214080496" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 09 Jan 2008 15:04:58 +0000</pubDate>
      <category domain="http://securityratty.com/tag/htm">htm</category>
      <category domain="http://securityratty.com/tag/load uc147">load uc147</category>
      <category domain="http://securityratty.com/tag/uc147">uc147</category>
      <category domain="http://securityratty.com/tag/loads 8v8">loads 8v8</category>
      <category domain="http://securityratty.com/tag/8v8">8v8</category>
      <category domain="http://securityratty.com/tag/load 8v8">load 8v8</category>
      <category domain="http://securityratty.com/tag/iframes">iframes</category>
      <category domain="http://securityratty.com/tag/recent realplayer exploit">recent realplayer exploit</category>
      <category domain="http://securityratty.com/tag/secondary iframes">secondary iframes</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/214080496/malware-serving-exploits-embedded-sites.html">Malware Serving Exploits Embedded Sites as Usual</source>
    </item>
  </channel>
</rss>
