www.wackystone.com - Exploits
Just surfing a bit on Internet when suddenly I got a prompt about aig.scr ...
What .. Why .. How ... To keep it simple, this one comes through advertising (again) - ad.yieldmanager.com > count.exit0808.com > www.mytoursinfo.com - and from there an iframe to www.wackystone.com. That website has a huge amount of exploits running as seen below. This is the first time I did encounter the latest Windows Media Encoder 9 vulnerability - see Ms08053.htm
Details:
- Microsoft Data Access Components (MDAC)
http://www.microsoft.com/technet/security/...n/ms06-014.mspx - Microsoft Office Snapshot Viewer ActiveX Exploit
http://www.microsoft.com/technet/security/...n/ms08-041.mspx
Access.gif is only posing as a gif file, it contains a malicous script.
- Webex Meeting Manager - 32E26FD9-F435-4A20-A561-35D4B987CFDC
http://securitytracker.com/alerts/2008/Aug/1020641.html - Windows Media Encoder 9
http://www.microsoft.com/technet/security/...n/ms08-053.mspx - WkImgSrv.dll - 00E1DB59-6EFD-4CE7-8C0A-2DA3BCAAD9C6
http://www.avertlabs.com/research/blog/ind...0-day-surfaces/
http://blogs.technet.com/swi/archive/2008/...imgsrv-dll.aspx - RealPlayer IERPCtl.IERPCtl.1 - CVE-2007-5601
http://secunia.com/advisories/27248/
Different versions of RealPlayer are tested as seen in the snipit from real.js above.
- NCTAudioFile2.AudioFile2.2 - 77829F14-D911-40FF-A2F0-D11DB8D6D0BC
http://www.kb.cert.org/vuls/id/292713 - Vulnerability in Kodak Image Viewer Could Allow Remote Code Execution.
http://www.microsoft.com/technet/security/...n/ms07-055.mspx
The file will have the following loading point so that %windir%svchost.exe loads on startup.
%windir%\svchost.exe will prompt for internet access after few moments. It will request a page located at www.cpccpmlead.com and visit all the URL's contained in the response ... it's one of those "clicker trojans".QUOTEHKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows "load"
Old type: REG_SZ
New type: REG_SZ
Old data:
New data: C:\WINDOWS\svchost.exe
IP details
wackystone.com - 69.89.31.107
ICANN Registrar: FASTDOMAIN, INC.
Created: 2007-09-06
Expires: 2009-09-06
Updated: 2008-09-07
Name Server: NS1.BLUEHOST.COM (has 577,114 domains)
Name Server: NS2.BLUEHOST.COM
Whois Server: whois.fastdomain.com
www.golf1997.com 222.73.236.27
ICANN Registrar: ENOM, INC.
Created: 2007-09-05
Expires: 2009-09-05
Updated: 2008-08-08
Registrar Status: clientTransferProhibited
Name Server: DNS1.NAME-SERVICES.COM (has 4,702,489 domains)
Name Server: DNS2.NAME-SERVICES.COM
Name Server: DNS3.NAME-SERVICES.COM
Name Server: DNS4.NAME-SERVICES.COM
Name Server: DNS5.NAME-SERVICES.COM
Whois Server: whois.enom.com
www.cpccpmlead.com - 222.73.236.25
ICANN Registrar: ENOM, INC.
Created: 2007-09-05
Expires: 2009-09-05
Updated: 2008-08-08
Registrar Status: clientTransferProhibited
Name Server: DNS1.NAME-SERVICES.COM (has 4,702,489 domains)
Name Server: DNS2.NAME-SERVICES.COM
Name Server: DNS3.NAME-SERVICES.COM
Name Server: DNS4.NAME-SERVICES.COM
Name Server: DNS5.NAME-SERVICES.COM
Whois Server: whois.enom.com



