NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security > Incidents

Incidents


Over 62,000 New URLs Serving Exploit Cocktail

Vulnerable visitors get infected with backdoors and info stealing trojans

By Lucian Constantin, Web News Editor

25th of August 2009, 09:52 GMT

Adjust text size:


New mass SQL injection attack infects over 62,000 Web pages
Enlarge picture
Security researchers advise that a new mass compromise attack is underway and has affected over 62,000 URLs to date. A rogue IFrame injected into the compromised Web pages loads a cocktail of exploits and malware from other domains.

Web security company ScanSafe has been monitoring this new threat and advises that the infection pattern is a hidden IFrame loading JavaScript content from a domain called a0v.org. A Google search for "script src=http://a0v.org/x.js" reveals 62,100 results.

Mary Landesman, a senior security researcher at ScanSafe, has told The Register that the infections are the result of SQL injection attacks. The x.js called from a0v.org has the role of loading exploits from a number of seven other domain names. At the moment of writing this article, Google's Safe Browsing was tagging a0v.org as malicious.

"The malware hosting domains were registered on or after August 3, 2009 and include: ahthja.info, gaehh.info, htsrh.info, car741.info, game163.info, car963.info, and game158.info. The most prolific observed by ScanSafe thus far has been ahthja.info," Mary Landesman writes on the company's blog.

If exploitation is successful, several malware installers are dropped and executed onto the victim's computer as drive-by downloads. The security researcher warns that "post infection, additional malware may also be downloaded" from a different host. The exploits target vulnerabilities in popular software, including Internet Explorer, Mozilla Firefox, Adobe Flash Player, Adobe Reader and Acrobat or avast! Antivirus. AV detection rates for the malicious executables downloaded during the attack range from poor to moderate on Virustotal.

This sort of malware distribution attacks, which involve exploit cocktails, are popular with cybercrooks because end users have historically proven a failure to deploy security patches for software installed on their computers. Just recently, we reported on a similar mass web compromise campaign discovered by network security company eSoft. The point of entry for those attacks seems to be a buffer overflow vulnerability in Webalizer, a popular program for generating web statistics.

TAGS:

IFrame injection | drive-by download | website compromise | mass infection | malware distribution
Read by 1,627 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
NOT RATED 0 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2010 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Webalizer Bug Possibly Leading to Mass Web Compromise

Infected Website Hosting 56,371 Threats

Gumblar, the Most Widespread Virus on the Internet in Q2

Web Exploit Kit Targets 0-Day Microsoft DirectShow Vulnerability

Nine-Ball Distributes Complex Click Fraud Trojan

Nine-Ball Mass Injection Attack Makes over 40,000 Victims

New Mass Web Attack Makes 40,000 Victims

Gumblar Morphs, Becomes Martuz

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM