madison

Zero Day

Ryan Naraine and Dancho Danchev

Malware Watch: Adobe zero day attack, malicious FIFA-themed spam, exploit serving Virus Alerts

By | June 11, 2010, 2:51pm PDT

Summary: Researchers from WebSense are reporting on three currently active malware campaigns, attempting to trick end users into opening malicious HTML files, or automatically exploiting vulnerable PCs relying on the recent Adobe zero day flaw (CVE-2010-1297).

Researchers from WebSense are reporting on three currently active malware campaigns, attempting to trick end users into opening malicious HTML files, or automatically exploiting vulnerable PCs relying on the recent Adobe zero day flaw (CVE-2010-1297).

The first campaign is using a FIFA World Cup scandal theme, whereas the second is relying on the well known (see Fake Conficker Infection Alerts) “Virus Infection” alert theme. The Adobe zero day flaw exploitation is taking place through a mass SQL injection attack currently affecting thousands of pages.

More details:

The ongoing mass SQL injection attack is closely related to another mass injection campaign that took place earlier this week:

The attack is closely related to the hxxp://ww.robint.us/[REMOVED].js  attack earlier this week that our friends at Sucuri blogged about, where the common theme was that all Web sites were running on Microsoft IIS and used ASP.NET. In fact, the majority of sites compromised by the new mass injection attack still have the robint.us code present.

The company published a video demonstrating what happens on an affected computer. A patch for the Flash flaw has already been released, with Acrobat’s patch set to be released by June, 29th. Users are always free to switch to an alternative PDF reader.

More details on the FIFA/Virus Alerts themed campaigns:

At the dawn of the eagerly anticipated World Cup tournament, we would expect to be inundated with suitably themed spam.  The sample we have encountered today is a little different from the usual, as the technique used may not raise suspicion.  We have seen over 80,000 email messages in this new campaign, which uses an HTML attachment with an embedded JavaScript.  Upon execution, this script leads to a malicious Web site, from which we are protecting our customers with our real-time analytics in our ACE engine.

Upon clicking on the malicious HTML file, an obfuscated JavaScript script loads a tiny iFrame refreshing the actual malicious link. Moreover, the cybercriminals behind the campaign are also optimizing the click through traffic by loading a second URL, this time serving a well known pharmaceutical scam theme - the Canadian Pharmacy. Both campaigns appear to be managed by the same individual/gang.

Related posts:

With FIFA-themed scams and drive-by downloads campaigns prone to escalate, consider going through the related “Protection tips for the upcoming FIFA World Cup themed cybercrime campaigns“, and “Ultimate guide to scareware protection” posts.

Kick off your day with ZDNet's daily e-mail newsletter. It's the freshest tech news and opinion, served hot. Get it.

Topics

Dancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, malware and cybercrime incident response.

Disclosure

Dancho Danchev

More details on Dancho Danchev's current and past professional affiliations, can be found in his LinkedIn profile.

Biography

Dancho Danchev

Dancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, and cybercrime incident response. He's been an active security blogger since 2007, and maintains a popular security blog sharing real-time threats intelligence data with the rest of the community on a daily basis. More details on Dancho Danchev's current and past professional affiliations, can be found in his LinkedIn profile. You can also follow him on Twitter

Talkback - Tell Us What You Think

Formatting +
BB Codes - Note: HTML is not supported in forums
  • [b] Bold [/b]
  • [i] Italic [/i]
  • [u] Underline [/u]
  • [s] Strikethrough [/s]
  • [q] "Quote" [/q]
  • [ol][*] 1. Ordered List [/ol]
  • [ul][*] · Unordered List [/ul]
  • [pre] Preformat [/pre]
  • [quote] "Blockquote" [/quote]
Click Here
Click Here

The best of ZDNet, delivered

ZDNet Newsletters

Get the best of ZDNet delivered straight to your inbox

Facebook Activity

White Papers, Webcasts, & Resources
Click Here