Thursday, October 31, 2013
|
|
Tuesday, October 29, 2013
|
|
Thursday, October 24, 2013
|
|
Wednesday, October 23, 2013
|
|

The deobfuscated code shows the location from where the injected iframe URL will be gathered from, as well as the use of cookie to allow the redirection. It also shows that it only targets to infect those browsing from IE, Opera and Firefox.
And now for some good old snippet from the source site and infected site:

When an infected website successfully redirects, the user will end up with a Neutrino exploit kit that is serving some Java exploit:

We haven't fully analyzed the trojan payload yet, but initial checks showed that it makes HTTP posts to this IP:

Early this week, when it probably was not in full effect yet, the injected URLs were leading to google.com. However, it went in full operation starting yesterday evening when it began redirecting to Neutrino to serve Java exploits.

Based on that timeline, we plotted the location of all the IP addresses that visited the infected sites to a map. These IPs are potential victims of this threat. There were approximately 80,000 IPs.

We also plotted the location of the infected websites and so far, there were around 20,000+ domains affected by this threat. The infected sites appear to be using either WordPress or Joomla CMS.

You can also find other information about this threat in Kafeine's blog
post.
Samples related to this post are detected as Trojan:HTML/SORedir.A,
Exploit:Java/Majava.A, and Trojan:W32/Agent.DUOH.
Post by — Karmina and @
Daavid



It's as dramatic as a graph can get. From dominating the exploit kit charts, Paunch's brainchild, Blackhole, is slowly fading away with its master's arrest.
So what does the future look like? Will the numbers even out among the different exploit kits out there? Will one exploit kit arise to take over Blackhole's place? Will a new exploit kit come out and take over the market? We can only speculate. But one thing that we do hope though, is that other exploit kit authors will take the hint, that even if they may enjoy a few years of invincibility, they are not unreachable by the long arm of the law.
Wednesday, October 2, 2013
|
|