Tuesday, June 18, 2013

openxadvertising.com Mass Malvertising Campaign

-->
On Monday, Government Security News (GSN), reported that their website had been compromised during a mass infection. While in the case of the GSN infection, the injected content was delivered from googlecodehosting.com, we have determined that the same content was also delivered from googlecodehosting.org and googlecodehosting.net, all of which resolve to 89.45.14.87 and are now offline.

In reviewing our logs for sites with the aforementioned referrers, indicating that they too were/are compromised, we have thus far identified 65 different sites (see list below), with the earliest referrers appearing on Thursday June 13 at 6:32:28 2013 GMT. Referers for the GSN site appeared as early as Jun 14th, suggesting that the site was likely compromised for a couple of days before they became aware of the situation and took steps to clean the site.

The attack leveraged the following chain of events:

1.     Malvertising – The injected code appears to have occurred in malicious advertisements used by the impacted sites, as opposed to the sites themselves. The malicious advertisements were delivered from openxadvertising.com, which is currently blocked by Google SafeBrowsing.
2.     Redirect – The content hosted at the googlecodehosting pages (now offline) has been archived on Pastebin.  As can be seen, the actual malware is being pulled from compromised WordPress sites.
3.     Infection – A malicious .jar file is delivered. At least two separate Java vulnerabilities have been observed in the attacks (CVE-2013-1493 and CVE-2013-2423), which are used to install the ZeroAccess Trojan.

The following infected domains have been identified in this attack from reviewing referer headers referencing googlecodehosting.com/net/org:

·      2475-lsxtv.voxcdn.com
·      ads.rahesabz.net
·      ads.thehiveworks.com
·      delaware.newszap.com
·      disabilitynow.org.uk
·      dj1067fm.com
·      greenhomeguide.com
·      insanescouter.org
·      lamega.com
·      marinefuel.com
·      mess.troutcave.net
·      omahanightlife.com
·      openx.multimediajamaica.com
·      pacificweddings.com
·      supernormalstep.com
·      test.theeagle.com
·      traveloregon.com
·      truthdig.com
·      vmblog.com
·      www.adrants.com
·      www.artshound.com
·      www.beginnertriathlete.com
·      www.birmingham365.org
·      www.brambletonian.net
·      www.charlestongolfguide.com
·      www.clashmusic.com
·      www.cobizmag.com
·      www.controleng.com
·      www.dragzine.com
·      www.ediblemanhattan.com
·      www.empirepage.com
·      www.environmentalleader.com
·      www.first30days.com
·      www.girlswithslingshots.com
·      www.guideposts.org
·      www.hospitalmedicine.org
·      www.hot-dinners.com
·      www.jeepsunlimited.com
·      www.jewishjournal.com
·      www.knittinghelp.com
·      www.lakestclair.net
·      www.lethbridgeherald.com
·      www.lsxtv.com
·      www.menuclub.com
·      www.nowplayingaustin.com
·      www.onedirt.com
·      www.phillyfunguide.com
·      www.popco.net
·      www.pro-touring.com
·      www.questionablecontent.net
·      www.radiohitz92fm.com
·      www.rtbookreviews.com
·      www.sayfiereview.com
·      www.sermonspice.com
·      www.spearfishingplanet.com
·      www.sportscollectorsdaily.com
·      www.stangtv.com
·      www.success.com
·      www.talentzoo.com
·      www.thejc.com
·      www.ventura-usa.com
·      www.wannabebig.com
·      www.whichbudget.com
·      www.workerscompensation.com
·      www.worthgoing.com

For those wishing to implement IDS based signatures to prevent the attacks, the following unique strings have been identified in URL paths seen to be delivering the malicious .jar files:

"/.cache/?f=site.jar&k=" OR
"/.cache/?f=atom.jar&k="
followed by:
"&h="

This attack is very similar to one that we blogged about in May. That attack was also a mass infection, which impacted media sites and also leveraged the ZeroAccess Trojan. As a courtesy, communication has been sent to the webmasters of all impacted domains informing them of the potential infection.

- michael

1 comment:

Anonymous said...

Looks like there's another round of malvertising for July. The URLs being used are now containing ?f=s&k= such as hxxp://www.kalliskallis.com/images/site/staff/2268e6d961/?f=s&k=5949089125084813 and hxxp://www.patinsproject.com/images/stories/simpleslideshow1/d6adc84c52/?f=a&k=1937445198084834. You can only view the file if you modify the user agent to spoof Java as the requester.