On CHOW: Why do onions make you cry?
BNET Business Network:
BNET
TechRepublic
ZDNet

April 8th, 2009

Paul McCartney's official site serving malware

Posted by Dancho Danchev @ 5:14 am

Categories: Anti Virus, Arbitrary Code Execution, Botnets, Browsers, Exploit code, Hackers, Malware, Passwords

Tags: Web, Malware, SQL, Web Site, Dancho Danchev, Security, Paul McCartney, Spyware, Adware & Malware, Cyberthreats, Web Site Development

All you (don’t) need is malware on Paul McCartney’s official web site.

According to Mary Landesman at ScanSafe, the official web site of Paul McCartney (paulmccartney.com) has been compromised, and is serving live exploits to its visitors. Landesman points out that the compromise might have occurred through stolen FTP accounting data, taking into consideration the fact that the campaign is also present at several different flat HTML only web sites.

The process of automatically injecting malicious code at hundreds of sites through compromised FTP accounts is nothing new, and continues being in a development phase with the most recent kit released earlier this year. What has changed through, is the typical proposition for bulk-orders of data mined FTP credentials from botnets which the sellers are now offering to bargain hunters of such tools.

Here’s a brief analysis of Paul McCartney’s site compromise. The attack is taking advantage of a newly distributed web malware exploitation kit which is already gaining popularity across the cybercrime ecosystem due to the several new features, among which is the use of RSA encryption of the javascript. Upon several redirections (84.244 .138.55 /google-analytics/ga.js -> 84.244 .138.55 /ts/in.cgi?sliframe -> 84.244 .138.55 /ase/?t=17), the visitor is exposed to the typical set of already patched client-side vulnerabilities which vary based on the administrator’s preferences.

The bottom line - would efficient exploitation of stolen FTP account data obtained through data mining an infected set of hosts re-emerge as a tactic of choice, or would massive SQL injection attacks through search engines reconnaissance targeting everyone, everywhere continue being the method of choice? In an increasingly multitasking cybercrime ecosystem, a combination of tactics is usually the method of choice.

Dancho DanchevDancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, malware and cybercrime incident response. He's been an active security blogger since 2007, and maintains a popular security blog. See his full profile and disclosure of his industry affiliations.

Email Dancho Danchev

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 23 Talkback(s)
lol
I get it! rotfl (Read the rest)
Posted by: iamagas Posted on: 04/09/09 You are currently: a Guest | | Terms of Use
No different to his songs then  Alan Smithie | 04/08/09
I think....  Erroneous | 04/08/09
+1  NStalnecker | 04/08/09
The frog song ?  Alan Smithie | 04/08/09
Come on now, it's not Paul's fault  Taz_z | 04/08/09
Paul McCartney did this on purpose  NonZealot | 04/08/09
My thought exactlly  GuidingLight | 04/08/09
I agree.  kozmcrae | 04/08/09
Big news?  NonZealot | 04/08/09
re: ... news?  n0neXn0ne | 04/08/09
Wait, wait, what??!!?  YammerSickle | 04/08/09
lol  iamagas | 04/09/09
Like most fanbois...  fairportfan | 04/08/09
RE: Paul McCartney's official site serving malware  richardalderson@... | 04/08/09
One can learn a lot...  kozmcrae | 04/08/09
RE: Paul McCartney's official site serving malware  gabrielbear@... | 04/08/09
....  n0neXn0ne | 04/08/09
RE: Paul McCartney's official site serving malware  QueenMama | 04/08/09
Do you run anti-virus?  NonZealot | 04/08/09
re:Do you run anti-virus?  n0neXn0ne | 04/08/09
No real discussion of the platform here  sdunn2000@... | 04/08/09
re: No real discussion of the platform here  n0neXn0ne | 04/09/09
ISPs get hacked too  pkatz | 04/08/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

  • Smart Tech Expert advice on innovations in healthcare and the green technologies that make it happen. Find out more
  • Smart Business Discussion and advice on management issues that revolve around making your world smarter and more useful. More Smart Advice
  • Smart People The best and worst moves in the management and strategy trenches. Learn More