Sep28
6:01 am (UTC-7)   |   by Bernadette Irinco (Technical Communications)

Trend Micro researchers discovered another wave of mass compromised websites involving several Thai government agencies’ sites. One of the compromised sites, the Thai Police site, was injected with malicious codes to redirect users to several malicious sites. One of the landing pages, http://{BLOCKED}t.ru/ip/bchqu1.exe served a downloader detected by Trend Micro as TROJ_DLOADER.DNG. This Trojan downloader is responsible for downloading several malware (detected as TROJ_FAKEREAN.BW, TROJ_CUTWAIL.GQ, and TSPY_ZBOT.ACH).

Click for larger view

Figure 1. Screenshot of compromised police site

Click for larger view

Figure 2. Screenshot of fake Antivirus Pro 2010

Click for larger view

Figure 3. Screenshot of compromised site

 
According to Senior Threat Analyst Joseph Pacamara who found out about the mass compromise, cybercriminals are now entertaining the idea of employing compromised legitimate sites as an avenue to proliferate FAKEAVs.

As of this writing, Trend Micro has contacted and informed all entities concerned to clean up the said websites. They have also been informed of the user risks brought about by such attacks. We have also notified ThaiCERT regarding the compromised sites. Users of Trend Micro Smart Protection Network are protected from this attack.

If you're new here, you may want to subscribe to our RSS feed. Thanks for visiting!




3 Responses to “Several Compromised Thai Sites Serve Malware”

Trackbacks

  1. TrendMicro (TrendMicro)
  2. jespinhara (joaquim espinhara)
  3. Arvutikaitse » Blog Archive » Tai politsei veebileht on rünnaku all

Leave a Reply



© Copyright 2009 Trend Micro Inc. All rights reserved. Legal Notice