• Visitors can check out the Forum FAQ by clicking this link. You have to register before you can post: click the REGISTER link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below. View our Forum Privacy Policy.
  • Want to receive the latest contracting news and advice straight to your inbox? Sign up to the ContractorUK newsletter here. Every sign up will also be entered into a draw to WIN £100 Amazon vouchers!

MPack Malware Plague

Collapse
X
  •  
  • Filter
  • Time
  • Show
Clear All
new posts

    MPack Malware Plague

    After cleaning several systems of micro bill over the past few weeks (including my own), it has become apparent that some systems are becoming infected not through the deliberate or accidental visitation of the porn sites that employ MBS as debt collectors,but through the deliberate infection of supposedly secure legitimate sites that many people use for reference, news and legitimate entertainment.
    MBS has denied that their software is being used in this way, but a carefull and comprehensive study of the search histories on the Systems that I have cleaned; reveal that Malware may have been responsible for the insertion of micro bills insidious software.
    Although MBS can be quickly and easily cleaned from the system, the cost for the uninitiated can be expensive, with systems locked untill cleaned.
    It has now been found that the Russian produced MPack is being used to infect these legitimate sites, with several thousand infections over the past few months.

    MPack has an integrated statistics function which informs its operator of the number of PCs attacked and the success rate of infections. Version 0.9 of MPack includes exploits for the ANI vulnerability and vulnerabilities in the MDAC function, Windows Media Player, Microsoft Management Console, XML functions, WebViewFolderIcon, QuickTime and WinZip.

    The starting point for some of the current attacks are websites located in Italy. The IFrames located on these web pages, which are needed for the attacks, were probably added during infiltration of the servers. The route is said to be a vulnerability in the hosting configuration application cPanel. Infiltration of a hosting server allows hundreds of websites to be compromised and manipulated simultaneously. In 2006 a vulnerability in cPanel was exploited for a mass hack at HostGator, as a result of which visitors were infected with a trojan via the VML vulnerability in Internet Explorer 6.

    As soon as a victim visits a prepared web page, his browser loads additional code from the MPack server via the integrated IFrame.
    After analysing the operating system and browser the attack module tries out multiple exploits until it scores a hit - or runs out of exploits.
    If it is successful, the server installs malware onto the PC.
    iDefense does not state whether or not MPack is able to infect non-Windows systems. The source code for MPack certainly includes switches for other browsers, such as Firefox and Opera.
    Currently MPack is only exploiting known vulnerabilities for which updates are available.
    Unfortunately when purchased the MPack comes with a 1 year subscription which includes updates that enable it to bypass new security patches almost as soon as they are released.
    One of the prime results of infection appears to be redirection, these redirections include porn sites, including child pornography.
    I would recommend that all surfers use great caution in allowing popups through, and take even greater caution when downloading Activex controls
    Even from legitimate websites.
    Three main servers in china are currently a source of infection.
    Much of the malware is dedicated to searching out financial/bank details on infected systems.
    Last edited by Diver; 24 June 2007, 08:09.
    Confusion is a natural state of being

    #2
    Bluddy hell..

    I knew it wasn't legal.

    On a really serious note, Diver - this has taken some serious time and investigative skills on your part. Well done that man.

    Have you sent your findings off the The Register? While we think CUK is the centre of the universe, I think that this article needs a wider audience.
    "I can put any old tat in my sig, put quotes around it and attribute to someone of whom I've heard, to make it sound true."
    - Voltaire/Benjamin Franklin/Anne Frank...

    Comment


      #3
      The info was already out there.
      One woman teacher in the US was facing 40 years in prison because nobody would believe that she hadn't deliberately allowed her class of kids to view porn.
      Nobody had pulled the bits of information/Evidence together to form a collective whole.
      Picked up the name MPack on Teletext the other day and recognized the signature from two systems I'd cleaned, and put 2 + 2 together and realized that some obnoxious tw@t was piggybacking MBS onto the systems.
      Confusion is a natural state of being

      Comment


        #4
        It's still worth passing the '=4' bit onto El Reg, I reckon. No one seems to have put it all together yet...
        "I can put any old tat in my sig, put quotes around it and attribute to someone of whom I've heard, to make it sound true."
        - Voltaire/Benjamin Franklin/Anne Frank...

        Comment


          #5
          http://www.theregister.co.uk/2007/06...stall_malware/

          Just googled this after your last post
          Confusion is a natural state of being

          Comment


            #6
            Nope - it's the link between MPack and MBS payment demand (thus rubbishing MBS's claim that porn punters have accepted their T&Cs) that's missing.

            Still - if you don't want to I can't force you...
            "I can put any old tat in my sig, put quotes around it and attribute to someone of whom I've heard, to make it sound true."
            - Voltaire/Benjamin Franklin/Anne Frank...

            Comment


              #7
              Passed it on to El REG but will have to wait until tomorrow to see if the allow it to be posted.
              (They have to check it for accuracy and legal ramifications apparently)

              You can buy MPack on line, $700, wanna go half?
              Confusion is a natural state of being

              Comment

              Working...
              X