Subscribe to RSS feeds


Jun18
by Carolyn Guevarra (Technical Communications)

Remember LINKOPTIM, which exploited a number of legitimate Italian Web sites to spread malicious JavaScripts? Since early Saturday morning (June 16, 2007), Trend Micro has been receiving several reports of a new batch of hacked Italian Web sites that trigger a series of malware downloads once a user visits them. These infection series begin with a malicious IFRAME tag. Trend Micro detects Web pages hosting the said malicious tag as HTML_IFRAME.CU. All the compromised sites are hosted in Italy and, to date, Trend Micro has identified more than 3,000 affected Web sites.

Here’s a sample screenshot of the IFRAME tag:

Compromised-site-srccode.gif

Most of the legitimate Web sites that were compromised by the malware authors are related to tourism, automotive industry, movies and music, tax and employment services, some Italian city councils, and hotels sites. Apparently, most of these sites are hosted on one of the largest Web hoster/provider in Italy.

Below is a sample screenshot of a compromised Web site:

Sample compromised Web site

Once the user visits any of the said Web sites, the affected computer is directed to another IP address that contains the malicious JavaScript detected by Trend Micro as JS_DLOADER.NTJ. This JavaScript then downloads a new member in the infection series detected as TROJ_SMALL.HCK. Trying to cause a buffer overflow on the user’s Internet browser, JS_DLOADER.NTJ exploits browser vulnerabilities. Through this, it is able to download TROJ_SMALL.HCK. On initial testing, TrendLabs researchers observed that this malicious JavaScript appears to be “browser-aware” in that it can choose which vulnerability to take advantage of depending on the browser.

TROJ_SMALL.HCK, in turn, downloads TROJ_AGENT.UHL and TROJ_PAKES.NC. TROJ_AGENT.UHL can act as a proxy server that allows a remote user to anonymously connect to the Internet via an infected computer. TROJ_PAKES.NC, on the other hand, is dumped in the user’s temporary folder and downloads the keylogging information thief TSPY_SINOWAL.BJ.

A diagram of the attack scenario is found below:

Attack scenario

Another important factor in this Italian attack is the involvement of the malware toolkit Mpack, specifically its version 0.86. On the IP page where the affected browser is initially redirected, an Mpack statistics page displays information on how users visiting legitimate Italian Web sites are getting redirected to the Mpack host where the download chain begins.

Multiple middlemen, in what looks like an attempt to steal information, is not new especially in this era of Web threats. Other threat incidents, some implicated in botnet investigations, have been known to use a slew of malware to deploy the entire plan of attack. However, what is especially interesting in this “Italian job” is how such a lot of the Web sites have been compromised in such a short period of time, possibly even at one go.

In terms of social engineering, it seems the authors behind this attack have come up with the perfect crime. Without the awareness gathered from security company reports, users will have no qualms accessing the said Web sites especially since most have been known to be relatively safe and legitimate prior to this incident. Among the top hacked sites are related to fashion, some have adult content, and several online communities with varied interests. It is possible that the malware authors are banking on an increase in user traffic due to the coming Italian holiday season, when users are expected to pursue more socially-inclined interests beyond work or school.

Further complications may amplify the impact of this attack, considering that the malicious server that hosts JS_DLOADER.NTJ may be updated at any given time by the malware authors, possibly giving the script new and improved capabilities, or other stealth mechanisms. Also, a newer version of MPack v.86 has been discovered, and may in fact be used in conjunction with the planted codes to perpetrate more nefarious activities.

As stated above, Trend Micro already detects all malicious codes and files, and blocks malicious URLs involved in this scheme.

Update : As of 8:22 PM (GMT +0800) June 19, 2007 we have received reports of about 3000++ compromised sites.




30 Responses to “Another malware pulls an Italian job”

  1. » Russian hackers hijack Italian sites to serve exploits | Zero Day | ZDNet.com Says:

    [...] Here’s a diagram of the attack scenario from Trend Micro’s Carolyn Guevarra: [...]

  2. Trend Micro warns of widescale Trojan attack — Security Bytes Says:

    [...] antivirus firm Trend Micro is warning in its blog of a large Trojan attack that has proven especially troublesome for computers in Italy. The attack involved a blizzard of [...]

  3. Industry News Says:

    [...] antivirus firm Trend Micro is warning in its blog of a large Trojan attack that has proven especially troublesome for computers in Italy. The attack involved a blizzard of [...]

  4. A little bit about everything » Blog Archive » 'Italian job' Web attack hits more than 10,000 sites Says:

    [...] and by Monday morning, more than 10,000 Web sites had been compromised, according to security firms Trend Micro and [...]

  5. Techzi » Blog Archive » ‘Italian job’ Web attack hits more than 10,000 sites Says:

    [...] and by Monday morning, more than 10,000 Web sites had been compromised, according to security firms Trend Micro and [...]

  6. PCNiche » 'Italian job' Web attack hits more than 10,000 sites Says:

    [...] and by Monday morning, more than 10,000 Web sites had been compromised, according to security firms Trend Micro and [...]

  7. Filipino Programmer | Philippines | MPack - The Italian Job Says:

    [...] and by Monday morning, more than 10,000 Web sites had been compromised, according to security firms Trend Micro Inc. and Websense Inc. 80 percent of the infections are on Italian Web sites. Almost all of the Web [...]

  8. Italofile » Blog Archive » Web Site Attack Hits Italy Tourism Sites Says:

    [...] Be careful surfing for Italy travel information this summer. According to Reuters, the Italian Job has infected thousands of websites related to Italy travel and tourism. We are confident that the virus has not compromised our little blog, but we’ll remain ever vigilant. In the meantime, run your virus protection software and/or read more detailed information (mostly for techies) here. [...]

  9. Blitz - Stiri zilnice din IT, IT&C: tehnologie, internet, telecom, gadgets, jocuri » Stiri IT - Blitz RO » Atac de amploare asupra web-ului italian Says:

    [...] Conform cu Trend Micro, site-urile compromise sunt injectate cu un tag IFRAME, ce redirecteaza catre un server american cu malware, hub-ul acestui atac, care controleaza apoi download-ul de malware. [...]

  10. Europa y EEUU bajo un ataque de malware | Love4Tech Says:

    [...] puede obtener más información en la web de Panda Software y en la de TrendMicro. Por el momento, se recomienda a los usuarios no permitir descargas de sitios no conocidos y [...]

  11. New web threat takes advantage of iFrame vulnerability, making its way to the U.S. » D’ Technology Weblog: Technology News & Reviews Says:

    [...] firm Trend Micro said that it has discovered a new threat that is currently making the rounds on the Internet. The threat [...]

  12. Un IFRAME asesino ataca a más de 10.000 servidores Italianos : Says:

    [...] un reporte de la empresa de seguridad Trend Micro un IFRAME asesino está atacando a los servidores Italianos. [...]

  13. » The Italian Job: migliaia di siti italiani a rischio « Schininà.it - LogBook » Blog Archive Says:

    [...] con l’infezione di oltre 1000 siti web, quasi tutti italiani (oggi siamo a 10 volte tanto). Trendmicro e Websense hanno rilasciato qualche informazione [...]

  14. Se propaga código maligno desde páginas web - Blog de Dr. Max Glaser Says:

    [...] ha publicado un screenshot con el iframe y aconseja a los webmasters a controlar sus códigos fuentes, y en caso de que aparezca este iframe [...]

  15. Dragan’s Blog on Security » Tourism Sites Suffer 'Italian Job' Web Attacks Says:

    [...] This attack got a name HTML_IFRAME.CU and you can see more about it on TrendMicro Website (here and here). [...]

  16. Bloggitup » Blog Archive » ATTENZIONE! Migliaia di siti italiani contagiati da un pericoloso Trojan! Says:

    [...] Maggiori dettagli tecnici QUI [...]

  17. Sotto l’ombra degli olmi » Blog Archive » In qualcosa siamo primi... Says:

    [...] se magari la quantità di attacchi potrebbe dipendere solo dal fatto che l’infezione è stata diretta principalmente a siti [...]

  18. Siti web di nuovo sotto attacco | rubriche Says:

    [...] Direttamente da sito Trend-Micro [...]

  19. Kaizenlog » Blog Archive » [Slashdot] Stories for 2007-06-20 Says:

    [...] 0. http://www.websense.com/securitylabs/alerts/alert.php?AlertID=782 1. http://blog.trendmicro.com/another-malware-pulls-an-italian-job/ 2. [...]

  20. pressemeldungen.at » Blog Archive » Trend Micro warnt vor neuem Web Threat Says:

    [...] Informationen stehen unter http://www.trendmicro.de bereit sowie im Trend Micro Malware Blog unter http://blog.trendmicro.com/another-malware-pulls-an-italian-job/. Weitere Informationen zum Thema Web Threats finden Sie unter [...]

  21. krybabyblogbox 360 » attaque massive de virus sur l’italie Says:

    [...] la rapidité avec laquelle un grand nombre de sites ont été corrompus”, précise Trend Micro.La plupart des pages touchées s’adresse à un large public. Les principaux sites corrompus [...]

  22. Infinito.Alfa » Ataques desde páginas WEB Says:

    [...] ha publicado un screenshot con el iframe y aconseja a los webmasters a controlar sus códigos fuentes, y en caso de que aparezca este iframe [...]

  23. Boris Blog » Archives » Propagación de codigo maligno desde paginas Web Says:

    [...] informacion aqui Posted in Programación | Trackback | del.icio.us | Top Of [...]

  24. Kataweb.it - Blog - Cablogrammi di Massimo Russo » Blog Archive » Siti italiani sotto attacco dalla Russia Says:

    [...] 1.100 siti italiani sotto attacco dalla Russia. E chi li visita rischia di infettare il proprio pc. Secondo Html.it molti sarebbero gestiti da [...]

  25. Alanat News » Massive Web Exploit Emerges Says:

    [...] Trend Micro’s ongoing effort to track the exploits can be found on its http://blog.trendmicro.com/another-malware-pulls-an-italian-job/. [...]

  26. Cossacks Breaking News » Multi-Middleman ‘Mpack’ Attacks Use Google AdWords to Lure Victims Says:

    [...] http://blog.trendmicro.com/another-malware-pulls-an-italian-job/ states this morning, the target of choice for Mpack in recent days has been Italy. Many of its higher-profile sites have been targeted in recent days, including media publishers, tourism services, and auto sales sites. [...]

  27. Alanat Coop News » Multi-Middleman ‘Mpack’ Attacks Use Google AdWords to Lure Victims Says:

    [...] http://blog.trendmicro.com/another-malware-pulls-an-italian-job/ states this morning, the target of choice for Mpack in recent days has been Italy. Many of its higher-profile sites have been targeted in recent days, including media publishers, tourism services, and auto sales sites. [...]

  28. Futures News » Massive Web Exploit Emerges Says:

    [...] Trend Micro’s ongoing effort to track the exploits can be found on its http://blog.trendmicro.com/another-malware-pulls-an-italian-job/. [...]

  29. Technology latest news » Blog Archive » MPack Trojan Attack Claims 10,000 Web Sites (PC Magazine) Says:

    [...] the “Italian Job” by Trend Micro, the attack was first uncovered June 15. Legitimate sites were hacked to include a malicious iFrames [...]

  30. Simple kind of life… » Blog Archive » The geek in me… Says:

    [...] was once again recognized worldwide after a local team discovered the rapidly spreading infection Italian Job “malware” (malicious software) and became one of the first to provide [...]



© Copyright 2008 Trend Micro IncAll rights reserved. Legal Notice