Fake-CNN spam mutates as attacks continue

11 comments | 65I like it!
August 10, 2008, 03:16 PM —  Computerworld — 

The massive attack that has infected PCs by tricking users into clicking links in fake messages from CNN.com shows little sign of ending soon, security researchers said Friday.

According to MX Logic Inc., spam posing as CNN.com Top 10 lists peaked at close to 11 million messages per hour early Thursday, but remained at high volumes throughout the day Friday. The Colorado security vendor said it had been tracking an average of 8 million messages per hour since midnight.
MX Logic's vice president of information security, Sam Masiello , called the trend "a very slow, but steady decline" from the 11 a.m. Mountain Time peak the day before.

Masiello also said that the spam has changed since attacks were first launched on Tuesday. "We've also seen several morphs of this spam over the past couple of days," he said in an entry posted on the MX Logic blog Friday . Where the messages once trumpeted " CNN .com Daily Top 10" in the subject heading and linked to a single filename on malware-hosting sites, now the spam sports a subject reading "CNN Alerts: My Custom Alert" and uses a variety of filenames in the malicious URL.

"This is likely in response to all of the media attention and awareness that has been brought up over the past couple of days," Masiello speculated.

Also on Friday, Websense Inc. reported that its researchers had seen the attack mutating, with the spam subject heading not only touting "CNN Alerts: My Custom Alert," but also using legitimate news stories culled from CNN to make the messages more convincing.

Users who clicked on the "FULL STORY" link in the message were redirected to a fake CNN site, where they were told they needed to download an update to Flash Player, Adobe System Inc. 's popular Internet media player, to view a video clip from CNN.

Websense also said it had spotted traces of the campaign in blog spam.

If users agreed to download the bogus Flash update, they were trapped in an endless loop, where clicking "Cancel" in the initial dialog produced a second pop-up. Clicking "Cancel" there returned the user to the first pop-up. The only options at that point were for users to shut down the browser or give in and install the malware.

MX Logic added that it had seen the URLs in the spam lead to legitimate domains that had probably been compromised, and named a U.K.-based roofing company as an example.

Earlier this week, Bulgarian security researcher Dancho Danchev had found more than 1,000 compromised domains being used to serve up the fake Flash. In a follow-up e-mail, Danchev said that in most cases, he couldn't find any characteristics shared by the hacked sites, such as all being hosted by a single Internet service provider.

"My assumption is that they took the time and effort to do some reconnaissance of sites which are vulnerable to remote file inclusion, or other type of remotely exploitable flaw within their Web applications that would allow someone to locally host all the malicious files," Danchev said. "I wouldn't be surprised if I find out that someone has basically went through all keylogged Cpanel passwords he obtained through his botnet, or through the access to a botnet that he temporarily rented."

Cpanel, a popular server control panel program, has been targeted by password thieves in the past because of the access those passwords provide to sites.

» posted by ITworld staff

Computerworld

I like it!
Comments

I read of this a few days

I read of this a few days ago and had one in my junk mail folder. Today I received three that are from cnn.com and are cnn alerts: My Custom alert. I know I didn't sign up for them and hope others read about this before they click on them. I found this site from a google search on cnn and will ad to my bookmarks. I found your article interesting and this is my first time to this site. Hovering over the links shows before the cnn http://cineus.ru . I hope someone squashes this soon.
Jack
| reply

I saw this e-mail in my

I saw this e-mail in my Incredimail spam folder though I subscribe to CNN e-mails. I clicked on the link and tried installing the activex, although it didn't seem like an Abobe standard install. Eset Smart Security deleted the file immediately. This happened last week.
| reply

I am getting bombarded by

I am getting bombarded by these CNN Alerts. I have been marking them and their predecessors, Daily Top Ten as Junk but oddly Thunderbird for some reason doesn't recognise them as such so my Inbox is getting full of them.
| reply
Free books

Build your tech library with our book giveaways.

Hacking Exposed, Sixth Edition
By Stuart McClure, Joel Scambray, George Kurtz; Published by McGraw-Hill/Osborne

The original Hacking Exposed authors rejoin forces on this tenth anniversary edition to offer completely up-to-date coverage of today's most devastating hacks and how to prevent them. Using their proven methodology, the authors reveal how to locate and patch system vulnerabilities. The book includes new coverage of ISO images, wireless and RFID attacks, Web 2.0 vulnerabilities, anonymous hacking tools, Ubuntu, Windows Server 2008, mobile devices, and more. Enter now!

Featured Sponsor

AISO founders envisioned a Web hosting company that was environmentally friendly. While the company employed energy-efficient innovations like solar panels, its infrastructure produced unacceptable power and cooling requirements. Find out how AISO leveraged AMD technology to overcome their challenge in this case study white paper.

In this whitepaper, Scalar explores the opportunity to change the landscape with respect to mission critical databases built around Oracle. Leveraging technologies such as Linux, high-end commodity processing power and Oracle RAC technology to architect, design, build and maintain database infrastructure that delivers maximum availability, reliability and performance at a fraction of traditional cost.

On a typical day, weather.com, the Web site for The Weather Channel in Atlanta, serves up between 15 million and 20 million page views. But in September 2004, when back-to-back hurricanes ransacked Florida, the peak traffic on one day more than tripled: over 70 million page views by more than 7 million unique visitors. Read the full success story now.

Marketplace