Results 1 to 3 of 3

Thread: MySpace Flux malware

  1. #1
    Adviser Team AplusWebMaster's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    6,881

    Exclamation MySpace Flux malware

    FYI...

    - http://isc.sans.org/diary.html?storyid=3060
    Last Updated: 2007-06-26 22:44:49 UTC ...(Version: 2)
    "...A number of MySpace profiles include drive by exploits. The exploits will install a version of "flux bot", a very popular proxy network bot.
    FluxBot (aka "Fast-Flux") is typically used to hide phishing and malware delivery sites behind complex ever changing networks of proxy servers... The actual exploit/malware is served via an existing flux network... once its all set and done, you will be a proud new member of the flux net and soon you
    will find your system to participate in phishing and similar endevours.
    Couple IPs that may be worthwhile to block:
    AS13767 | 72.232.254.218
    AS15083 | 65.111.176.176
    AS25761 | 72.20.18.86
    AS25761 | 72.20.6.10 ..."

    The machine has no brain.
    ......... Use your own.
    Browser check for updates here.
    YOU need to defend against -all- vulnerabilities.
    Hacks only need to find -1- to get in...
    .

  2. #2
    Adviser Team AplusWebMaster's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    6,881

    Exclamation

    FYI...

    MySpace Phish/Drive-by attack vector propagating Fast Flux network growth
    - http://isc.sans.org/diary.html?storyid=3060
    Last Updated: 2007-06-29 01:13:26 UTC ~ "Two primary infection vectors have been observed providing us with unique insight into the life cycle involved in propagating a fast flux service network. The attack vectors include:
    * Compromised MySpace Member profiles redirecting to phishing sites...
    * SWF Flash image malicious redirection to Phishing and drive-by browser exploit attempt.
    All Flash redirects were observed redirecting browsers... The successful compromise of a windows host via this exploit content results in the download of a malicious downloader stub executable (session.exe) that is then responsible for attempting to download additional malicious components necessary for integration of new compromised hosts into a fast flux service network..."
    (More detail at the URL above.)

    - http://preview.tinyurl.com/yvq6bv
    June 28, 2007 (InfoWorld) - "..."Two components comprise the attack. It attempts to install malicious botnet software on victims' computers, and it uses these infected computers to try to steal MySpace credentials in a phishing attack. Computers that are compromised by the attack become infected with malicious botnet software known as "flux bot," which makes them unwitting participants in the phishing scam. After the malicious Web site attempts to install the flux bot code, it then presents victims with a fake MySpace.com login page, which tries to extract their MySpace.com user name and password... Because MySpace.com allows users to install their own HTML code and is visited by such a large number of technically unsophisticated users, it has become an attractive target for these types of attacks..."

    Last edited by AplusWebMaster; 2007-06-29 at 15:01.
    The machine has no brain.
    ......... Use your own.
    Browser check for updates here.
    YOU need to defend against -all- vulnerabilities.
    Hacks only need to find -1- to get in...
    .

  3. #3
    Adviser Team AplusWebMaster's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    6,881

    Exclamation

    FYI...

    - http://www.theregister.com/2007/07/1...net/page2.html
    11 July 2007 - "...By design, fast-flux bot nets last much longer and, just by their ability to outlive IRC-based bot nets, will likely soon make up the majority of attack networks on the Internet..."

    > http://en.wikipedia.org/wiki/Fast_flux

    Last edited by AplusWebMaster; 2007-11-07 at 12:18.
    The machine has no brain.
    ......... Use your own.
    Browser check for updates here.
    YOU need to defend against -all- vulnerabilities.
    Hacks only need to find -1- to get in...
    .

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •