Researchers Warn of Powerful New Data Theft "Cocktail"
Researchers with online security services provider ScanSafe are warning of a potent new blended attack that seeks to steal end users' personal data and is spreading rapidly across the Web. Mary Landesman, senior security researcher with ScanSafe, said in a brief blog post that the powerful "cocktail" of backdoor, password stealing malware and Trojan downloader attacks is being discovered on a growing number of Web sites, having tracked over 55,000 such infected URLs in only several days time since first discovering the nefarious package. The attack is being loaded onto sites via a malicious iframe, she said, infecting large numbers of otherwise legitimate URLs. The iframe itself is using an intermediary site which downloads the other threats from an assortment of other malware domains, Landesman said. It's not unusual for attackers to use such a layered distribution approach these days to thwart efforts to stop their campaigns by shutting down individual URLs that they've employed. A Google search on the intermediary site used in the blended attacks at the end of last week turned up masses of pages already owned by the sophisticated package, including www.feedzilla.com, latindiscover.com, and a number of charitable and nursing facilities, including howellcarecenter.com, sweetgrassvillagealf.com, www.foodsresourcebank.org, and morningsideassistedliving.com. According to ScanSafe, the domains involved in spreading the attack were registered only in early August and include ahthja.info, gaehh.info, htsrh.info, car741.info, game163.info, car963.info, and game158.info, with ahthja.info leading the way in terms of distribution. The involved attackers are using popular hosting providers including GoDaddy.com to register their domains, which remain online and volatile, the experts reported. Researchers have long been warning of the increasing use of such combined attacks as schemers seek new ways to distribute their work faster and more effectively. The newly discovered example appears to be particularly effective based on the fact that it has been able to find so many legitimate sites that it can load itself onto in a short period of time. End users should expect to see continued use of both the blended approach and the multi-tiered distribution model, as they continue to see increased adoption among attackers as they seek to keep their threats rolling even as researchers sniff them out.
|


Comments (3)
Compromising legitimate websites severely undermines the overly network-centric IT folk that try to curb the intrusion risks to enterprise endpoints via URL blacklisting. Mitigating these risks must be done at the respective endpoint, regardless of whether its an enterprise or consumer computer.
http://www.blueridgenetworks.com/securitynowblog/endpoint_security/beladen-websites-attack-pc-malware
Posted by Eirik Iverson | August 25, 2009 12:40 PM
Hello-
I work for GoDaddy.com and wanted to let you know that the domains listed in your article have been suspended by Go Daddy's 24/7 Abuse Department.
If anyone sees a suspicious site, they can always contact Abuse@GoDaddy.com and we will investigate.
Best,
Stephanie Bracken
GoDaddy.com
Posted by Stephanie Bracken - GoDaddy.com | August 26, 2009 8:27 PM
That's very nice, Stephanie. As of August 31st, 6PM, 4 sites of the "Sample of Dirtiest Web Sites" linked to in the above article are still up:
dfwdiesel.net
kingfamilyphotoalbum.com
sportsmansclub.net
texaswhitetailfever.com
You didn't bother to even check the list! Do you even care about the company you work for? [not] You stink at your job. What you said in your comment is hogwash! Get to work!
cc president@godaddy.com, sbracken@godaddy.com
Posted by Louise Timmons | August 31, 2009 9:10 PM