<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: russiannews]]></title>
    <link>http://securityratty.com/tag/russiannews</link>
    <description></description>
    <pubDate>Sun, 23 Dec 2007 18:01:52 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Pinch Variant Embedded Within RussianNews.ru]]></title>
      <link>http://securityratty.com/article/5c1543c93dcbfb2efe5750392b281e1c</link>
      <guid>http://securityratty.com/article/5c1543c93dcbfb2efe5750392b281e1c</guid>
      <description><![CDATA[This is a perfect and currently live example demonstrating how a once compromised site can also be used as a web dropper compared to the default infection vector mentality we've been witnessing on...]]></description>
      <content:encoded><![CDATA[<a href="http://bp3.blogger.com/_wICHhTiQmrA/R28cqD8-MeI/AAAAAAAABRo/W7ILodhY7Rk/s1600-h/mdac_obfuscation.jpg"><img id="BLOGGER_PHOTO_ID_5147364408048890338" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="" src="http://bp3.blogger.com/_wICHhTiQmrA/R28cqD8-MeI/AAAAAAAABRo/W7ILodhY7Rk/s200/mdac_obfuscation.jpg" border="0" /></a>This is a perfect and currently live example demonstrating how a once compromised site can also be used as a web dropper compared to the default infection vector mentality we've been witnessing on pretty much each and every related case of malware embedded sites during 2007. The URL at a popular news portal for Russian/Iranian related news at : <strong>russiannews.ru/arabic/data/news/upload/exp</strong> is serving a Pinch variant thought an <a href="http://ddanchev.blogspot.com/2007/12/mdac-activex-code-execution-exploit.html">MDAC ActiveX code execution exploit</a> - CVE-2006-0003, the type of virtual Keep it Simple Stupid <a href="http://ddanchev.blogspot.com/2007/09/popular-web-malware-exploitation.html">strategy of using outdated vulnerabilities</a> I discussed before. Deobfuscation leads us to : <strong>russiannews.ru/arabic/data/news/upload/exp/exe.php</strong><br /><br />Trojan-PSW.Win32.LdPinch.dzr<br /><strong>File Size</strong>: 22016 bytes<br /><strong>MD5</strong> : cb0a480fd845632b9c4df0400f512bb3<br /><strong>SHA1</strong> : 83bb4132d1df8a42603977bd2b1f9c4de07463ab<br /><br />What's important to point out in this case, is that the main index and the pages within the site are clean, so instead of trying to infect the visitors, the malicious parties are basically using it as a web dropper. Moreover, in the wake of <a href="http://ddanchev.blogspot.com/2007/12/russias-fsb-vs-cybercrime.html">Pinch-ing the Pinch authors</a>, this variant generated on the fly courtesy of their tool fully confirms the simple logic that once released in the wild, DIY malware builders and <a href="http://ddanchev.blogspot.com/2007/09/localizing-open-source-malware.html">open source malware</a> greatly <a href="http://ddanchev.blogspot.com/2007/10/mpack-and-icepack-localized-to-chinese.html">extend their lifecycles</a> and possibility for added innovation on behalf of the community behind them.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Q8UzXfC"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Q8UzXfC" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=hsSPuVC"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=hsSPuVC" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=dAgmepc"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=dAgmepc" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=zmDPVBc"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=zmDPVBc" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=QZkS41C"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=QZkS41C" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=BTk0zcC"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=BTk0zcC" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ybUOiFc"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ybUOiFc" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/205412393" height="1" width="1"/>]]></content:encoded>
      <pubDate>Sun, 23 Dec 2007 18:01:52 +0000</pubDate>
      <category domain="http://securityratty.com/tag/variant">variant</category>
      <category domain="http://securityratty.com/tag/pinch variant">pinch variant</category>
      <category domain="http://securityratty.com/tag/diy malware builders">diy malware builders</category>
      <category domain="http://securityratty.com/tag/russiannews">russiannews</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/popular news portal">popular news portal</category>
      <category domain="http://securityratty.com/tag/web dropper">web dropper</category>
      <category domain="http://securityratty.com/tag/news">news</category>
      <category domain="http://securityratty.com/tag/simple stupid strategy">simple stupid strategy</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/205412393/pinch-variant-embedded-within.html">Pinch Variant Embedded Within RussianNews.ru</source>
    </item>
  </channel>
</rss>
