<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: unicef]]></title>
    <link>http://securityratty.com/tag/unicef</link>
    <description></description>
    <pubDate>Tue, 01 Apr 2008 03:42:20 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[The United Nations Serving Malware]]></title>
      <link>http://securityratty.com/article/d1d822ed6374f6c7f294fed616ac7d76</link>
      <guid>http://securityratty.com/article/d1d822ed6374f6c7f294fed616ac7d76</guid>
      <description><![CDATA[Yet another massive SQL injection attack is making its rounds online, and this time without the SEO poisoning as an attack tactic , has managed to successfully infect the United Nations events page,...]]></description>
      <content:encoded><![CDATA[<div><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp1.blogger.com/_wICHhTiQmrA/SA5b7NDpi2I/AAAAAAAABm4/XilLYHXJoSs/s1600-h/united_nations_malicious_injection.JPG"><img id="BLOGGER_PHOTO_ID_5192188493080136546" style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" alt="" src="http://bp1.blogger.com/_wICHhTiQmrA/SA5b7NDpi2I/AAAAAAAABm4/XilLYHXJoSs/s200/united_nations_malicious_injection.JPG" border="0" /></a>Yet another massive SQL injection attack is making its rounds online, and this time without the <a href="http://ddanchev.blogspot.com/2008/03/massive-iframe-seo-poisoning-attack.html">SEO poisoning as an attack tactic</a>, has managed to successfully infect the United Nations events page, which is now also marked as malware infected page, and with a reason since both the malicious URl and the injection are still active. <a href="http://securitylabs.websense.com/content/Alerts/3070.aspx">According to WebSense</a> :<br /><br />"<span style="font-style: italic;">This mass injection is remarkably similar to the attack we saw earlier this month. When a </span><span style="font-style: italic;">user browses to a compromised site, the injected JavaScript loads a file named 1.js which is ho</span><span style="font-style: italic;">sted on http://www.nihao[removed].com The JavaScript code then redirects the user to 1.htm (also hosted on the same server). Once loaded, the file attempts 8 different exploits (the attack last April utilised 12). The exploits target Microsoft applications, specifically browsers not patched against the VML exploit MS07-004 as well as other applications. Ominously files named McAfee.htm and Yahoo.php are also called by 1.htm but are no longer active at the time of writing. There are further similarities too between the two mass attacks. Resident on the latest malici</span><span style="font-style: italic;">ous domain is a tool used in the execution of the attack. An analysis of that tool can be found in the ISC diary entry here. Mentioned in that diary entry is http://www.2117[removed].net. Our blog on that attack can be found here. It appears that same tool was used to orchestrate this attack too. </span>"<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp3.blogger.com/_wICHhTiQmrA/SA5rltDpi6I/AAAAAAAABnQ/73aOsN1uYy0/s1600-h/another_massive_injection.JPG"><img id="BLOGGER_PHOTO_ID_5192205715898993570" style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" alt="" src="http://bp3.blogger.com/_wICHhTiQmrA/SA5rltDpi6I/AAAAAAAABnQ/73aOsN1uYy0/s200/another_massive_injection.JPG" border="0" /></a>Let's assess the malicious injection. <span style="font-weight: bold;">nihaorr1.com/ 1.js</span> (219.153.46.28) is attempting to load <span style="font-weight: bold;">nihaorr1.com/ 1.htm</span>, where several other internal exploit serving URLs and javascript obfuscations load through IFRAMES, such as :<br /><br /><span style="font-weight: bold;">nihaorr1.com/ Real.gif</span> <span style="font-weight: bold;"><br />niha</span><span style="font-weight: bold;">orr1.com/ Yahoo.php</span> <span style="font-weight: bold;"><br />nihaorr1.com/ cuteqq.htm</span> <span style="font-weight: bold;"><br />nihaorr1.com/ Ms07055.htm</span> <span style="font-weight: bold;"><br />nihaorr1.com/ Ms07033.htm</span> <span style="font-weight: bold;"><br />nihaorr1.com/ Ms07018.htm</span> <span style="font-weight: bold;"><br />nihaorr1.com/ Ms07004.htm</span> <span style="font-weight: bold;"><br />nihaorr1.com/ Ajax.htm</span> <span style="font-weight: bold;"><br />nihaorr1</span><span style="font-weight: bold;">.com/ Ms06014.htm</span> <span style="font-weight: bold;"><br />nihaorr1.com/ Bfyy.htm</span> <span style="font-weight: bold;"><br />nihaorr1.com/ Lz.htm</span> <span style="font-weight: bold;"><br />nihaorr1.com/ Pps.htm</span> <span style="font-weight: bold;"><br />nihaorr1.com/ XunLei.htm</span><br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp3.blogger.com/_wICHhTiQmrA/SA5rwtDpi7I/AAAAAAAABnY/BGvEieF0v0s/s1600-h/another_massive_injection_2.JPG"><img id="BLOGGER_PHOTO_ID_5192205904877554610" style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" alt="" src="http://bp3.blogger.com/_wICHhTiQmrA/SA5rwtDpi7I/AAAAAAAABnY/BGvEieF0v0s/s200/another_massive_injection_2.JPG" border="0" /></a>and finally serve the malware, by also taking us out of the point and loading another malicious IFRAME farm at <span style="font-weight: bold;">gg.haoliuliang.net/one/ hao8.htm?036</span> (222.73.44.162) :<br /><br />Scanners Result: 18/<span id="porcentaje"><span style="color:red;"></span>32 (56.25%) :<br />W32/PWStealer1!Generic; PWS:Win32/Lineage.WI.dr<br /></span>File size: 24667 bytes<br />MD5...: 4b913be127d648373e511974351ff04e<br />SHA1..: 0ab703c93e3ad7c03d1aae5ea394d7db3b89bfd2<br /><span id="porcentaje"><br />Another internal IFRAME serving exploits is also loading at </span><span style="font-weight: bold;">haoliuliang.net</span>, <span style="font-weight: bold;">gg.haoliuliang.net/wmwm/ new.htm</span> where a new piece of malware is served :<br /><br />Scanners Result: 26/32 (81.25%)<br />Trojan-PSW.Win32.OnLineGames.ppu; Trojan.PSW.Win32.OnlineGames.GEN<br />File size: 7205 bytes<br />MD5...: af05c777700b338f428463e56f316a05<br />SHA1..: bd68f621ec6c9796afa8b766c6cf4167afbd4703<br /><br />As it appears, everyone's a victim of web application vulnerabilities discovered automatically, and either filtered based on high-page rank, or trying to take advantage of the long-tail of SQL injected sites to compensate for the lack of vulnerable high profile sites.<br /><br /><strong>Related posts:</strong><br /><a href="http://ddanchev.blogspot.com/2008/04/unicef-too-iframe-injected-and-seo.html">UNICEF Too IFRAME Injected and SEO Poisoned</a><br /><a href="http://ddanchev.blogspot.com/2008/03/embedded-malware-at-bloggies-awards.html">Embedded Malware at Bloggies Awards Site</a><br /><a href="http://ddanchev.blogspot.com/2008/03/embedding-malicious-iframes-through.html">Embedding Malicious IFRAMEs Through Stolen FTP Accounts</a><br /><a href="http://ddanchev.blogspot.com/2008/02/yet-another-massive-embedded-malware.html">Yet Another Massive Embedded Malware Attack</a><br /><a href="http://ddanchev.blogspot.com/2007/12/mdac-activex-code-execution-exploit.html">MDAC ActiveX Code Execution Exploit Still in the Wild</a><br /><a href="http://ddanchev.blogspot.com/2008/01/malware-serving-exploits-embedded-sites.html">Malware Serving Exploits Embedded Sites as Usual</a><br /><a href="http://ddanchev.blogspot.com/2008/01/massive-realplayer-exploit-embedded.html">Massive RealPlayer Exploit Embedded Attack</a><br /><a href="http://ddanchev.blogspot.com/2007/09/syrian-embassy-in-london-serving.html">Syrian Embassy in London Serving Malware</a><br /><a href="http://ddanchev.blogspot.com/2007/08/bank-of-india-serving-malware.html">Bank of India Serving Malware</a><br /><a href="http://ddanchev.blogspot.com/2007/09/us-consulate-st-petersburg-serving.html">U.S Consulate St. Petersburg Serving Malware</a><br /><a href="http://ddanchev.blogspot.com/2008/01/dutch-embassy-in-moscow-serving-malware.html">The Dutch Embassy in Moscow Serving Malware</a><br /><a href="http://ddanchev.blogspot.com/2008/02/uks-feta-serving-malware.html">U.K's FETA Serving Malware</a><br /><a href="http://ddanchev.blogspot.com/2008/02/anti-malware-vendors-site-serving.html">Anti-Malware Vendor's Site Serving Malware</a><br /><a href="http://ddanchev.blogspot.com/2008/02/new-media-malware-gang-part-three.html">The New Media Malware Gang - Part Three</a><br /><a href="http://ddanchev.blogspot.com/2007/12/new-media-malware-gang-part-two.html">The New Media Malware Gang - Part Two</a><br /><a href="http://ddanchev.blogspot.com/2007/11/new-media-malware-gang.html">The New Media Malware Gang</a><br /><a href="http://ddanchev.blogspot.com/2007/10/portfolio-of-malware-embedded-magazines.html">A Portfolio of Malware Embedded Magazines</a><br /><a href="http://ddanchev.blogspot.com/2007/11/another-massive-embedded-malware-attack.html">Another Massive Embedded Malware Attack</a><br /><a href="http://ddanchev.blogspot.com/2007/11/i-see-alive-iframes-everywhere.html">I See Alive IFRAMEs Everywhere</a><br /><a href="http://ddanchev.blogspot.com/2007/11/i-see-alive-iframes-everywhere-part-two.html">I See Alive IFRAMEs Everywhere - Part Two</a></div><br /><div> </div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=h2szloG"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=h2szloG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Jh8d9YG"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Jh8d9YG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=TZyIhPg"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=TZyIhPg" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=DQqL6Mg"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=DQqL6Mg" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=tPC4aNG"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=tPC4aNG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=nWuC8GG"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=nWuC8GG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=3djJeCg"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=3djJeCg" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/276225903" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 23 Apr 2008 06:13:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/attack">attack</category>
      <category domain="http://securityratty.com/tag/malware attack">malware attack</category>
      <category domain="http://securityratty.com/tag/anti-malware vendor">anti-malware vendor</category>
      <category domain="http://securityratty.com/tag/media malware gang">media malware gang</category>
      <category domain="http://securityratty.com/tag/htm">htm</category>
      <category domain="http://securityratty.com/tag/nihaorr1">nihaorr1</category>
      <category domain="http://securityratty.com/tag/load nihaorr1">load nihaorr1</category>
      <category domain="http://securityratty.com/tag/attack tactic">attack tactic</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/276225903/united-nations-serving-malware.html">The United Nations Serving Malware</source>
    </item>
    <item>
      <title><![CDATA[UNICEF Too IFRAME Injected and SEO Poisoned]]></title>
      <link>http://securityratty.com/article/452a90ccfc35d6ad6a998c60113508e2</link>
      <guid>http://securityratty.com/article/452a90ccfc35d6ad6a998c60113508e2</guid>
      <description><![CDATA[The very latest, and hopefully very last, high profile site to successfully participate in the recently exposed massive SEO poisoning , is UNICEF's official site. In fact the campaign is so...]]></description>
      <content:encoded><![CDATA[<a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp0.blogger.com/_wICHhTiQmrA/R_IhMF281II/AAAAAAAABhQ/ZQqcx7ujQQ0/s1600-h/UNICEF_iframe_SEO1.jpg"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp0.blogger.com/_wICHhTiQmrA/R_IhMF281II/AAAAAAAABhQ/ZQqcx7ujQQ0/s200/UNICEF_iframe_SEO1.jpg" alt="" id="BLOGGER_PHOTO_ID_5184242612671665282" border="0" /></a>The very latest, and hopefully very last, high profile site to successfully participate in the recently exposed <a href="http://ddanchev.blogspot.com/2008/03/%20massive-iframe-seo-poisoning-attack.html">massive SEO poisoning</a>, is UNICEF's official site. In fact the campaign is so successful, where successful means that each and every poisoned result loads the injected IFRAME using UNICEF.org as a doorway to pharmaceutical spam and scams, that one of the most prolific domains within the IFRAMES (<span style="font-weight: bold;">highjar.info</span>) is already returning "<span style="font-style: italic;">Bandwidth Limit Exceeded. The server is temporarily unable to service your request due </span><span style="font-style: italic;">to the site owner reaching his/her bandwidth limit. Please try again later</span>" messages.<br /><br /><span style="font-weight: bold;">This is the perfect moment to point out that as of yesterday's afternoon the search engines that were indexing the SEO poisoned pages have implemented filters so that the malicious pages no longer appear in their indexes, thereby undermining the critical success factor for this campaign - hijacking search traffic</span>. Case closed? At least for now, and even though the black hat SEO is taken care of the last time I checked, some of the sites originally mentioned, and many others still need to take care of the web application vulnerabilities.<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp1.blogger.com/_wICHhTiQmrA/R_Il4V281JI/AAAAAAAABhY/X04F34wws-A/s1600-h/UNICEF_iframe_SEO_poison.jpg"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp1.blogger.com/_wICHhTiQmrA/R_Il4V281JI/AAAAAAAABhY/X04F34wws-A/s200/UNICEF_iframe_SEO_poison.jpg" alt="" id="BLOGGER_PHOTO_ID_5184247770927387794" border="0" /></a>Tracking this campaign in a detailed manner inevitably results in a quality actionable intelligence data, in between the added value out of the historical preservation of evidence. The malicious parties behind this know what they're doing, they've been doing it in the past, and will continue doing it, therefore it's extremely important to document what was going on at a particular moment in time. It's all a matter of perspective, some care about the type of vulnerability exploited, others care who's hosting the rogue security applications and the malware, others want to establish the RBN connection, and others want to know who's behind this. <a href="http://ddanchev.blogspot.com/2006/09/cyber-intelligence-cyberint.html">Virtual situational awareness through CYBERINT</a> is what I care about.<br /><br />Let's close the case by assessing UNICEF.org's IFRAME injection state as of yesterday's afternoon. What is <span style="font-weight: bold;">highjar.info/error</span> (75.127.104.26) anyway? Before it felt the "UNICEF effect" in terms of traffic, it used to be a "<span style="font-style: italic;">Easy SEO | A Coaching Site For BEGINNING webmasters</span>". And the last time it was active, the injected redirect was forwarding to <span style="font-weight: bold;">ravepills.com/?TOPQUALITY</span> (69.50.196.63) and RavePills is what looks like a "legal alternative to Ecstasy" :<br /><br />"<span style="font-style: italic;">On the other hand, Rave is the safest option available to you without the fear of nasty side-effects or a long time in jail. Rave gives you the same buzz that the illegal ones do but without any proven side-effects. It's absolutely non-addictive &amp; is legal to possess in every country. Rave gives you the freedom to carry it anywhere you go as it also comes in a mini-pack of 10 capsules.</span>"<br /><br />IFRAMES injected within UNICEF.org :<br /><br /><span style="font-weight: bold;">highjar.info</span> (<span class="ipaddr">75.127.104.26)</span><br /><span style="font-weight: bold;">viagrabest.info</span> (<span class="ipaddr">81.222.139.184)</span><br /><span style="font-weight: bold;">pharmacytop.net</span> (<span class="ipaddr">216.98.148.6)</span><br /><span style="font-weight: bold;">grabest.info</span><br /><br />Now that the entire campaign received the necessary attention and raised awareness on its impact, let's move onto the next one(s), shall we?<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=sOaGdMG"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=sOaGdMG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=jWtKlrG"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=jWtKlrG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Bg8sI4g"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Bg8sI4g" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=DKhNQLg"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=DKhNQLg" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ikmbV4G"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ikmbV4G" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=9j24zkG"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=9j24zkG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=X99fvfg"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=X99fvfg" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/261944315" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 01 Apr 2008 03:42:20 +0000</pubDate>
      <category domain="http://securityratty.com/tag/seo">seo</category>
      <category domain="http://securityratty.com/tag/unicef">unicef</category>
      <category domain="http://securityratty.com/tag/easy seo">easy seo</category>
      <category domain="http://securityratty.com/tag/site">site</category>
      <category domain="http://securityratty.com/tag/site owner">site owner</category>
      <category domain="http://securityratty.com/tag/iframe">iframe</category>
      <category domain="http://securityratty.com/tag/unicef effect">unicef effect</category>
      <category domain="http://securityratty.com/tag/massive seo">massive seo</category>
      <category domain="http://securityratty.com/tag/campaign">campaign</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/261944315/unicef-too-iframe-injected-and-seo.html">UNICEF Too IFRAME Injected and SEO Poisoned</source>
    </item>
  </channel>
</rss>
