Saturday, May 31, 2008
TrendLabs | Malware Blog - by Trend Micro - 2 new articles
"TrendLabs | Malware Blog - by Trend Micro" - 2 new articles
Total Recall: The Month of Mass CompromisesIt is that month of the year when flowers are in full bloom and people celebrate them in festive events. And it seems that same eventful—but darker—tone can be used to describe the month of May for the security industry. Trend Micro has so far documented several mass compromises of Web sites around the world for this month. Yes, you read it right—the world over. Here are the highlights of the notable Web site compromises we have seen in the past month: May 2 - One Year Later, Italian Job Still Working Overtime It's been a year since the infamous Italian Job attack of 2007. And in an apparent observance of its anniversary, a similar attack was seen compromising about 90 varied Italian Web sites, all hosted in Italy by a single hosting provider—the same one that hosted the thousands in last year's large-scale. TrendLabs discovered two forms of this compromise: one via an injected obfuscated script that redirects to a certain malicious URL, and the other via a readable iFrame and the same obfuscated script. May 7 - A Very Convoluted Chinese Gaming-Info-Stealing Campaign Web sites numbering approximately 9,000 were compromised via SQL injection with embedded malicious JavaScript redirecting users to two major malicious URLs. Among these Web sites were legitimate medical, educational, government, and entertainment sites from around the world. A survey of the site locations includes India, UK, Canada, France, and China. This observation suggests the attack as the work of an automated Chinese hacktool programmed to search through Web sites for vulnerabilities, creating the same .HTML file that has been used to launch various exploits. May 10 - More of The Same: Another Half Million Web Sites Compromised Meanwhile, a malicious script was injected into half a million Web sites believed to be either using poorly implemented or older exploitable versions of phpBB. This event was involved a ZLOB Trojan among others that changes an affected system's local DNS and Internet browser settings. May 19 - Chinese Weekend Compromise Also on the same date, Chinese-language Web sites were targeted in an attack that was meant specifically against China, Taiwan, Singapore, and Hong Kong. Google search results at the time of the attack showed 327,000 pages containing the malicious script tag. May 19 - Yet More Weekend Compromises Reach Other Shores Another string of Web site compromises was discovered the following week, involving at least four (4) Web sites of various affiliations and different countries. These were injected with a malicious JavaScript that redirects to two sites. Both eventually lead to their own series of redirections, and finally the download and execution of malware: a backdoor and Trojan, respectively. May 21 - It's Not Over: Asian Sites Injected with Nasty Code Two days later, hundreds of thousands of Web sites were again found compromised and inserted with malicious JavaScript code, some of which are sites from the APAC region. Hackers have apparently conducted another massive SQL injection attack. A Google search for the malicious URL turned up 197,000 results. May 22 - Malicious Domains Found in Compromised Japanese Sites The next day, several Web sites in Japan — including a popular music download site and a music company site — have been found injected with malicious code. These are the hard facts, and these developments tell us that there could indeed be a trend that cyber criminals seem to favor this type of attack over other methods. For what it’s worth, our engineers also think that mass compromises are common (or at least not as uncommon as we think), it's just that they are either found soon enough, or they remain unnoticed and consequently unreported. These documented compromises appear to be not distinct incidents unto themselves, but rather one big organized attack that just involved different domains. However, it is also very much possible that there are different groups using the same tool, or a big organized group outsourcing to small-time hackers. Until solid evidence is obtained, these scenarios are speculations as of the moment. We are keeping a close watch. National Bank of Kuwait PhishedBanks all over the world are fast taking on the challenge (and opportunity) of bringing part of their operations online. Sadly, being spoofed in a phishing attack is one of the risks financial services companies have to continually address via user education. Early this week we were able to catch a phishing attempt targeted at account holders of the National Bank of Kuwait (NBK). The phishing URL pretends to be a legitimate National Bank of Kuwait official login page: After entering the required information the next phishing page will ask for your ATM Pin and Civil ID. This may attempt to confuse the users into believing that the phishing Web site is directly related to the legitimate site: Here is a screenshot of the legitimate National Bank of Kuwait login page (a brilliant copy, yes?): Note that doing a WHOIS on the actual phishing URL reveals that the attempt seems to have originated from Chile. The attack is directed at users in the Middle East. Phishers typically commit border-crossing crimes to at least hold off immediate entrapment by the law. Trend Micro users need not worry as our URL filters already recognize and block this threat. More Recent Articles |
Click here to safely unsubscribe now from "TrendLabs | Malware Blog - by Trend Micro" or change subscription settings
Unsubscribe from all current and future newsletters powered by FeedBlitz
| Your requested content delivery powered by FeedBlitz, LLC, 9 Thoreau Way, Sudbury, MA 01776, USA. +1.978.776.9498 |
Friday, May 30, 2008
[Lockergnome] Computer Security ~ May 30, 2008
Blog Archive
-
►
2012
(71)
- 02/12 - 02/19 (8)
- 02/05 - 02/12 (11)
- 01/29 - 02/05 (10)
- 01/22 - 01/29 (12)
- 01/15 - 01/22 (9)
- 01/08 - 01/15 (12)
- 01/01 - 01/08 (9)
-
►
2011
(706)
- 12/25 - 01/01 (3)
- 12/18 - 12/25 (12)
- 12/11 - 12/18 (14)
- 12/04 - 12/11 (10)
- 11/27 - 12/04 (10)
- 11/20 - 11/27 (3)
- 11/13 - 11/20 (10)
- 11/06 - 11/13 (15)
- 10/30 - 11/06 (10)
- 10/23 - 10/30 (11)
- 10/16 - 10/23 (11)
- 10/09 - 10/16 (8)
- 10/02 - 10/09 (14)
- 09/25 - 10/02 (7)
- 09/18 - 09/25 (14)
- 09/11 - 09/18 (11)
- 09/04 - 09/11 (10)
- 08/28 - 09/04 (11)
- 08/21 - 08/28 (11)
- 08/14 - 08/21 (9)
- 08/07 - 08/14 (12)
- 07/31 - 08/07 (14)
- 07/24 - 07/31 (9)
- 07/17 - 07/24 (11)
- 07/10 - 07/17 (13)
- 07/03 - 07/10 (10)
- 06/26 - 07/03 (9)
- 06/19 - 06/26 (12)
- 06/12 - 06/19 (13)
- 06/05 - 06/12 (18)
- 05/29 - 06/05 (10)
- 05/22 - 05/29 (14)
- 05/15 - 05/22 (11)
- 05/08 - 05/15 (12)
- 05/01 - 05/08 (10)
- 04/24 - 05/01 (13)
- 04/17 - 04/24 (17)
- 04/10 - 04/17 (25)
- 04/03 - 04/10 (18)
- 03/27 - 04/03 (18)
- 03/20 - 03/27 (21)
- 03/13 - 03/20 (21)
- 03/06 - 03/13 (23)
- 02/27 - 03/06 (20)
- 02/20 - 02/27 (15)
- 02/13 - 02/20 (15)
- 02/06 - 02/13 (25)
- 01/30 - 02/06 (23)
- 01/23 - 01/30 (19)
- 01/16 - 01/23 (15)
- 01/09 - 01/16 (18)
- 01/02 - 01/09 (18)
-
►
2010
(1039)
- 12/26 - 01/02 (10)
- 12/19 - 12/26 (16)
- 12/12 - 12/19 (19)
- 12/05 - 12/12 (18)
- 11/28 - 12/05 (23)
- 11/21 - 11/28 (13)
- 11/14 - 11/21 (20)
- 11/07 - 11/14 (19)
- 10/31 - 11/07 (22)
- 10/24 - 10/31 (22)
- 10/17 - 10/24 (20)
- 10/10 - 10/17 (16)
- 10/03 - 10/10 (14)
- 09/26 - 10/03 (13)
- 09/19 - 09/26 (15)
- 09/12 - 09/19 (24)
- 09/05 - 09/12 (20)
- 08/29 - 09/05 (20)
- 08/22 - 08/29 (22)
- 08/15 - 08/22 (16)
- 08/08 - 08/15 (24)
- 08/01 - 08/08 (21)
- 07/25 - 08/01 (20)
- 07/18 - 07/25 (21)
- 07/11 - 07/18 (19)
- 07/04 - 07/11 (18)
- 06/27 - 07/04 (17)
- 06/20 - 06/27 (17)
- 06/13 - 06/20 (19)
- 06/06 - 06/13 (26)
- 05/30 - 06/06 (17)
- 05/23 - 05/30 (18)
- 05/16 - 05/23 (16)
- 05/09 - 05/16 (24)
- 05/02 - 05/09 (18)
- 04/25 - 05/02 (21)
- 04/18 - 04/25 (21)
- 04/11 - 04/18 (27)
- 04/04 - 04/11 (19)
- 03/28 - 04/04 (24)
- 03/21 - 03/28 (23)
- 03/14 - 03/21 (17)
- 03/07 - 03/14 (28)
- 02/28 - 03/07 (26)
- 02/21 - 02/28 (18)
- 02/14 - 02/21 (18)
- 02/07 - 02/14 (30)
- 01/31 - 02/07 (24)
- 01/24 - 01/31 (19)
- 01/17 - 01/24 (20)
- 01/10 - 01/17 (28)
- 01/03 - 01/10 (19)
-
►
2009
(1033)
- 12/27 - 01/03 (10)
- 12/20 - 12/27 (18)
- 12/13 - 12/20 (20)
- 12/06 - 12/13 (24)
- 11/29 - 12/06 (19)
- 11/22 - 11/29 (15)
- 11/15 - 11/22 (19)
- 11/08 - 11/15 (23)
- 11/01 - 11/08 (23)
- 10/25 - 11/01 (22)
- 10/18 - 10/25 (20)
- 10/11 - 10/18 (23)
- 10/04 - 10/11 (21)
- 09/27 - 10/04 (23)
- 09/20 - 09/27 (21)
- 09/13 - 09/20 (18)
- 09/06 - 09/13 (23)
- 08/30 - 09/06 (18)
- 08/23 - 08/30 (21)
- 08/16 - 08/23 (23)
- 08/09 - 08/16 (20)
- 08/02 - 08/09 (28)
- 07/26 - 08/02 (30)
- 07/19 - 07/26 (25)
- 07/12 - 07/19 (27)
- 07/05 - 07/12 (26)
- 06/28 - 07/05 (17)
- 06/21 - 06/28 (26)
- 06/14 - 06/21 (20)
- 06/07 - 06/14 (30)
- 05/31 - 06/07 (19)
- 05/24 - 05/31 (9)
- 04/12 - 04/19 (7)
- 04/05 - 04/12 (25)
- 03/29 - 04/05 (25)
- 03/22 - 03/29 (27)
- 03/15 - 03/22 (25)
- 03/08 - 03/15 (29)
- 03/01 - 03/08 (22)
- 02/22 - 03/01 (23)
- 02/15 - 02/22 (24)
- 02/08 - 02/15 (22)
- 02/01 - 02/08 (26)
- 01/25 - 02/01 (20)
- 01/18 - 01/25 (19)
- 01/11 - 01/18 (34)
- 01/04 - 01/11 (24)
-
▼
2008
(1133)
- 12/28 - 01/04 (19)
- 12/21 - 12/28 (19)
- 12/14 - 12/21 (27)
- 12/07 - 12/14 (39)
- 11/30 - 12/07 (25)
- 11/23 - 11/30 (16)
- 11/16 - 11/23 (20)
- 11/09 - 11/16 (27)
- 11/02 - 11/09 (37)
- 10/26 - 11/02 (29)
- 10/19 - 10/26 (29)
- 10/12 - 10/19 (29)
- 10/05 - 10/12 (25)
- 09/28 - 10/05 (18)
- 09/21 - 09/28 (28)
- 09/14 - 09/21 (23)
- 09/07 - 09/14 (29)
- 08/31 - 09/07 (22)
- 08/24 - 08/31 (18)
- 08/17 - 08/24 (23)
- 08/10 - 08/17 (33)
- 08/03 - 08/10 (23)
- 07/27 - 08/03 (33)
- 07/20 - 07/27 (25)
- 07/13 - 07/20 (27)
- 07/06 - 07/13 (30)
- 06/29 - 07/06 (23)
- 06/22 - 06/29 (21)
- 06/15 - 06/22 (25)
- 06/08 - 06/15 (30)
- 06/01 - 06/08 (36)
- 05/25 - 06/01 (24)
- 05/18 - 05/25 (21)
- 05/11 - 05/18 (25)
- 05/04 - 05/11 (25)
- 04/27 - 05/04 (20)
- 04/20 - 04/27 (22)
- 04/13 - 04/20 (38)
- 04/06 - 04/13 (35)
- 03/30 - 04/06 (28)
- 03/23 - 03/30 (16)
- 03/16 - 03/23 (17)
- 03/09 - 03/16 (23)
- 03/02 - 03/09 (14)
- 02/24 - 03/02 (10)
- 02/17 - 02/24 (7)








