MPack packs a nasty punch

Network Security · 2007

Over 10,000 sites have been compromised and used to direct visiting browsers to a web-based attack using commercially sold PHP code and blended threat techniques. The sophisticated attack, which the industry has dubbed MPack, uses an iFrame embedded in the HTML of a compromised site. The iFrame points the browser to the index.php file on an intermediate server, which then directs it to the server hosting the MPack code. The server analyses the browser's HTTP header to determine the attributes of the browser and the underlying operating system before sending the relevant exploits. The server then uses a MySQL database to log which exploits worked, in addition to the target PC's country of origin, enabling its operators to gather broad statistics about their base of compromised machines. When a machine is infected, it downloads a trojan that then downloads further malware.

Read the paper · More papers on PaperTik