<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: ccie]]></title>
    <link>http://securityratty.com/tag/ccie</link>
    <description></description>
    <pubDate>Wed, 12 Mar 2008 06:49:36 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[More High Profile Sites IFRAME Injected]]></title>
      <link>http://securityratty.com/article/97c88216eb87a2fbc044f1786b1d6ce8</link>
      <guid>http://securityratty.com/article/97c88216eb87a2fbc044f1786b1d6ce8</guid>
      <description><![CDATA[The ongoing monitoring of this campaign reveals that the group is continuing to expand the campaign, introducing over a hundred new bogus .info domains acting as traffic redirection points to the...]]></description>
      <content:encoded><![CDATA[<a href="http://bp1.blogger.com/_wICHhTiQmrA/R9fVaE-0GFI/AAAAAAAABdo/lBbPf6NfozM/s1600-h/iframe_injection_CSO.jpg"><img id="BLOGGER_PHOTO_ID_5176840940676192338" style="margin: 0px 10px 10px 0px; float: left;" alt="" src="http://bp1.blogger.com/_wICHhTiQmrA/R9fVaE-0GFI/AAAAAAAABdo/lBbPf6NfozM/s200/iframe_injection_CSO.jpg" border="0" /></a>The <a href="http://ddanchev.blogspot.com/2008/03/wiredcom-and-historycom-getting-rbn-ed.html">ongoing monitoring</a> of this <a href="http://ddanchev.blogspot.com/2008/03/more-cnet-sites-under-iframe-attack.html">campaign reveals</a> that <a href="http://ddanchev.blogspot.com/2008/03/zdnet-asia-and-torrentreactor-iframe-ed.html">the group</a> is continuing <a href="http://ddanchev.blogspot.com/2008/03/rogue-rbn-software-pushed-through.html">to expand</a> the campaign, <a href="http://ddanchev.blogspot.com/2008/03/injecting-iframes-by-abusing-input.html">introducing over</a> a hundred new bogus .info domains acting as traffic redirection points to the campaigns hardcoded within the secondary redirection point, in this case <strong>radt.info</strong> where a new malware variant of Zlob is attempting to install though an ActiveX object. These are the high profile sites targeted by the same group within the past 48 hours, with number of locally cached and IFRAME injected pages within their search engines :<br /><div><br />NCSU Libraries - <span style="font-weight: bold;">lib.ncsu.edu</span> - 372,000 pages<br />FullDownloads.us - <span style="font-weight: bold;">fulldownloads.us</span> - 13,000 pages<br />Central Statistics Office Ireland - <span style="font-weight: bold;">cso.ie</span> - 10,300 pages<br />DBLife Frontpage - <span style="font-weight: bold;">dblife.cs.wisc.edu</span> - 1,130 pages<br />School of Mathematics and Statistics - <span style="font-weight: bold;">www-history.mcs.st-andrews.ac.uk</span> - 1040 pages<br />eHawaii Portal - <span style="font-weight: bold;">ehawaii.gov</span> - 992 pages<br />The World Clock - <span style="font-weight: bold;">timeanddate.com</span> - 944 pages<br />Boise State University - <span style="font-weight: bold;">boisestate.edu</span> - 471 pages<br />The U.S. Administration on Aging (AoA) - <span style="font-weight: bold;">aoa.gov</span> - 425 pages<br />Gustavus Adolphus College - <span style="font-weight: bold;">gustavus.edu</span> - 312 pages<br />Internet Archive - <span style="font-weight: bold;">archive.org</span> - 261 pages<br />Stanford Business School Alumni Association - <span style="font-weight: bold;">gsbapps.stanford.edu</span> - 157 pages<br />BushTorrent -<span style="font-weight: bold;"> bushtorrent.com</span> - 147 pages<br />ChildCareExchange - <span style="font-weight: bold;">ccie.com</span> - 131 pages<br />The University of Vermont - <span style="font-weight: bold;">uvm.edu</span> - 120 pages<br />Hippodrome State Theatre - Gainesville, FL - <span style="font-weight: bold;">thehipp.org</span> - 112 pages<br />Minnesota State University Mankato - <span style="font-weight: bold;">mnsu.edu</span> - 94 pages<br />The California Majority Report - <span style="font-weight: bold;">camajorityreport.com</span> - 16 pages<br />Medicare.gov - <span style="font-weight: bold;">medicare.gov</span> - 12 pages<br />USAMRIID - <span style="font-weight: bold;">usamriid.army.mil</span> - 3 pages<br /><br /><a href="http://bp2.blogger.com/_wICHhTiQmrA/R9fZaU-0GGI/AAAAAAAABdw/gAd8mQtOdtM/s1600-h/iframe_injection_ncsu.jpg"><img id="BLOGGER_PHOTO_ID_5176845343017670754" style="margin: 0px 10px 10px 0px; float: left;" alt="" src="http://bp2.blogger.com/_wICHhTiQmrA/R9fZaU-0GGI/AAAAAAAABdw/gAd8mQtOdtM/s200/iframe_injection_ncsu.jpg" border="0" /></a>This sample of the newly introduced .info domains reside on the same netblock as the previous ones - <strong>75.125.181.0/255</strong> a KISS strategy making it easier to respond to this incident. Best of all, they further expand the campaign since they're injected in plain text, next to javascript obfuscated, this time embedded malware :<br /><br /><div> </div><strong>hickey.info</strong><br /><div><strong>kbst.info</strong></div><strong>sezejc.info</strong><br /><div><strong>mloqrd.info</strong></div><strong>mqghrd.info</strong><br /><div><strong>ymrxwd.info</strong></div><strong>fsqpsm.info</strong><br /><div><strong>haxkwd.info</strong></div><strong>aagpcw.info</strong><br /><div><strong>zdksgj.info</strong></div><strong>cgjttz.info</strong><br /><div><strong>hkedny.info</strong></div><strong>kbsxet.info</strong><br /><div><strong>wapdjw.info</strong></div><strong>kbsxet.info</strong><br /><div><strong>tdwham.info</strong></div><strong>mqghrd.info</strong><br /><div><strong>dhqjdz.info</strong></div><strong>bhrsaa.info</strong><br /><div><strong>jramae.info</strong></div><strong>wmtwes.info</strong><br /><div><strong>tacpmh.info</strong></div><strong>qwhhxq.info</strong><br /><div><strong>gmjett.info</strong></div><strong>hkedny.info</strong><br /><div><strong>rerkqz.info<br />bhrsaa.info</strong></div><strong>txmwxb.info</strong><br /><div><strong>psyckr.info</strong></div><strong>jramae.info</strong><br /><div><strong>nhwdrh.info</strong></div><span style="font-weight: bold;">cqqxkh.info</span><br /><div><strong>stysqf.info</strong></div><strong>tgzyqz.info</strong><br /><div><strong>kbsxet.info</strong></div><strong>cgjttz.info</strong><br /><div><strong>tazbhk.info</strong></div><strong>kbsxet.info</strong><br /><div> </div><br /><div>Each of the these is loading a secondary domain, which is then taking us to two more before finally reaching the Zlob variant. In this case it's <strong>radt.info </strong><strong style="font-weight: normal;">(75.125.208.243)</strong> with several campaigns currently up and running, pointing to the same fake codec. And the samples redirects upon visiting these as follows :<br /></div><div> </div><strong><br />seivomerutam.info/Free-Paris-Hilton-Nude-Pics/<br /></strong><strong>seivomerutam.info/spam/</strong><br /><div> </div><br />all of which ultimately redirect to :<br /><div> </div><strong><br />porn-popular.com</strong> (64.28.185.78) where the Zlob variant in the face of a fake codec, is downloaded from <strong>democodec.com/download/ democodec1292.exe</strong> (64.28.184.168) via an Active X object.<br /><br /><div> </div><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp0.blogger.com/_wICHhTiQmrA/R9fem0-0GHI/AAAAAAAABd4/HHD-sHBpx_k/s1600-h/iframe_input_validation_active_X.jpg"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp0.blogger.com/_wICHhTiQmrA/R9fem0-0GHI/AAAAAAAABd4/HHD-sHBpx_k/s200/iframe_input_validation_active_X.jpg" alt="" id="BLOGGER_PHOTO_ID_5176851055324174450" border="0" /></a><strong>Scanner results</strong> : 22% Scanner(8/36) found malware!<br /><div>File Name : democodec1292.exe</div><strong>File Size</strong> : 74823 byte<br /><div><strong>MD5</strong> : 30965fdbd893990dd24abda2285d9edc</div><strong>SHA1</strong> : 53eacbb9cdf42394bd455d9bd2275f05730332f7<br /><div>Downloader.Zlob.ZV; Trojan-Downloader.Win32.Zlob.eie; TrojanDownloader.Zlob.epx</div><br /><div> </div>It gets even more interesting as according to <a href="http://ca.com/us/securityadvisor/pest/pest.aspx?id=453119651">Computer Associates</a> :<br /><div> </div><br /><div>"<em>This fake codec is actually a hijacker that will change your DNS settings whether you are aquire your IP settings through DHCP or set your IP information manually. <span style="font-weight: bold;">This hijacker will attempt to re-route all your DNS queries through 85.255.x.29 or 85.255.x.121.</span> If you use a static IP address, CA AntiSpyware will set your DNS server to 198.6.1.1 to prevent your DNS queries from continuing to go through the rogue DNS servers. Please change your DNS server to the DNS server provided by your IP or Network Administrator.</em>"</div><div> </div><br /><div><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp2.blogger.com/_wICHhTiQmrA/R9ffVU-0GII/AAAAAAAABeA/Ghf8PbhPtqI/s1600-h/zlob_variant_codec_IFRAME.jpg"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp2.blogger.com/_wICHhTiQmrA/R9ffVU-0GII/AAAAAAAABeA/Ghf8PbhPtqI/s200/zlob_variant_codec_IFRAME.jpg" alt="" id="BLOGGER_PHOTO_ID_5176851854188091522" border="0" /></a>What this means is that <a href="http://ddanchev.blogspot.com/2008/02/geolocating-malicious-isps.html">known Russian Business Network netblocks</a> are receiving all the re-routed DNS queries from infected hosts, thereby setting up the foundations for a large scale pharming attack by infecting the weakest link, the end user from the perspective of using rogue DNS servers, a much more effective but noisy approach.</div><br /><div> </div>To sum up - it's a mess that I'll continue trying to structure, and it's a single group exploiting input validation capability within the sites' search engines we're talking about. With this segmented targeting of sites with high page ranks, and their persistance, is already positioning hundreds of thousands of keywords within the top search results, with the targeted sites are acting as the redirectors to the malware locations.</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=HfotYvF"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=HfotYvF" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=UFAs33F"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=UFAs33F" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=jrG9vvf"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=jrG9vvf" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=dDM9F6f"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=dDM9F6f" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=isZ3yzF"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=isZ3yzF" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=f8lRmjF"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=f8lRmjF" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=h8KWZCf"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=h8KWZCf" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/250167533" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 12 Mar 2008 06:49:36 +0000</pubDate>
      <category domain="http://securityratty.com/tag/info">info</category>
      <category domain="http://securityratty.com/tag/info txmwxb">info txmwxb</category>
      <category domain="http://securityratty.com/tag/info kbsxet">info kbsxet</category>
      <category domain="http://securityratty.com/tag/info bhrsaa">info bhrsaa</category>
      <category domain="http://securityratty.com/tag/info sezejc">info sezejc</category>
      <category domain="http://securityratty.com/tag/info cgjttz">info cgjttz</category>
      <category domain="http://securityratty.com/tag/info wmtwes">info wmtwes</category>
      <category domain="http://securityratty.com/tag/info cqqxkh">info cqqxkh</category>
      <category domain="http://securityratty.com/tag/info qwhhxq">info qwhhxq</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/250167533/more-high-profile-sites-iframe-injected.html">More High Profile Sites IFRAME Injected</source>
    </item>
  </channel>
</rss>
