Scob infection statistics, etc..

From: Hubbard, Dan (dhubbard_at_websense.com)
Date: 06/28/04

  • Next message: Sven Carstens: "Unknown Malware found csdiv.dll"
    Date: Mon, 28 Jun 2004 11:53:25 -0700
    To: <NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM>, <incidents@securityfocus.com>, <bugtraq@securityfocus.com>
    
    

    If anyone is interested we have some information on the Scob Trojan
    "released" last week.

    * we saw customers visiting the Russian URL's starting June 22. All the
    sites are down but here is a list of the sites visited with frequency
    counters.

            http://217.107.218.147:80/redir.php 2
            http://217.107.218.147/sht/shellscript.js 1
            http://217.107.218.147/thom.html 4
            http://217.107.218.147/smack.html? 1
            http://217.107.218.147/new.html 866
            http://217.107.218.147/fed.html 97
            http://217.107.218.147/msits.exe 208
            http://217.107.218.147/index.php 1193
            http://217.107.218.147/md.htm 169
            http://217.107.218.147/index1.htm 47
            http://217.107.218.147/dot.php 2665
            http://217.107.218.147/sht/its.html 4
            http://217.107.218.147/sht/msits.exe 9
            http://217.107.218.147/stat.php 205
            http://217.107.218.147/its.html 65
            http://217.107.218.147/shellscript_loader.js 1
            http://217.107.218.147:80/index.php 1
            http://217.107.218.147/sht/new.html 25
            http://217.107.218.147/sht/shellscript_loader.js 2
            http://217.107.218.147/redir.php 177
            http://217.107.218.147/shellscript.js 1
            http://217.107.218.147/sht/redir.php 24
            http://217.107.218.147:80/dot.php 34
            http://217.107.218.147:80/msits.exe 7
            http://217.107.218.147//main.chm 15
            http://217.107.218.147/sht/md.htm 11
            http://217.107.218.147/sht/md.html 13

    * as of Sunday we have identified more than 130 unique domains that are
    still infected.
    * all sites infected are running IIS 5.0 and SSL
    * all sites are infected on both HTTP and HTTPS URL's
    * sites IP addresses are located in USA (mostly web hosting ISP's),
    Australia, New Zealand, Canada, Japan, Spain, UK, and Norway). At least
    that is what arin, apnic, and ripe are reporting.
    * appears as though no sites certificates have been tampered
    * none of the sites still infected would be consider "top rated"
    websites
    * we have seen no unusual/increase in traffic in any of our honeypots

    Due to the number of sites infected, this leads me to believe that there
    is either a poorly written worm or that the source of the webserver
    exploit is out there. Does anyone have information on the exploit ? It
    would be interesting to see and then report on the number of webservers
    that are vulnerable to this type of attack. Also, has anyone seen any
    new versions yet ?

    Thanks


  • Next message: Sven Carstens: "Unknown Malware found csdiv.dll"

    Relevant Pages

    • Scob infection statistics, etc..
      ... * we saw customers visiting the Russian URL's starting June 22. ... all sites are infected on both HTTP and HTTPS URL's ... that is what arin, apnic, and ripe are reporting. ... is either a poorly written worm or that the source of the webserver ...
      (Bugtraq)
    • Scob infection statistics, etc..
      ... * we saw customers visiting the Russian URL's starting June 22. ... all sites are infected on both HTTP and HTTPS URL's ... that is what arin, apnic, and ripe are reporting. ... is either a poorly written worm or that the source of the webserver ...
      (NT-Bugtraq)
    • Re: Verarbeiten von *grossen* HTTP-uploads
      ... Bei HTTP GET funktioniert das auch einwandfrei, ... dass mein cgilaunch die Daten vom Client liest ... und sie via pipe an das cgi-script weiterreichen und nach CONTENT_LENGTH ... Der Client spricht mit dem Webserver HTTP, ...
      (de.comp.lang.perl.cgi)
    • Re: How to secure a webserver in a DMZ
      ... If your webserver gets comprised, your DB is open as well. ... How easy would it be for an "advanced agressor" to load evil code (for ssh-over-https-tunneling i.e.) from the internet, if the only connection to the webserver is encrypted http inbound and outbound traffic is not allowed? ... If anybody was able to compromise the Reverse proxy over https, than he could even go further and compromise the backand webserver through tricky-http stuff also? ...
      (Security-Basics)
    • RE: Web reports display HTTP 500 error with SMS 2003
      ... I was able to fix my own problem by turning off the "friendly http errors", ... "Rob" wrote: ... > In the reporting section of the management console, ... > Any thoughts on why I would be getting an HTTP 500 internal server error? ...
      (microsoft.public.sms.admin)