Sponsored by..

Showing posts with label Sinowal. Show all posts
Showing posts with label Sinowal. Show all posts

Wednesday 14 September 2011

Injection attack: malavasso.com, migraviro.com and montenegrorio.com

Three more domains being used in injection attacks today:

malavasso.com
migraviro.com
montenegrorio.com

The payload is the Sinowal trojan. Malicious software is hosted on 95.64.45.43 which is well-known very dark grey hat host Netserv Consult SRL of Romania. Blocking 95.64.0.0/17 (95.64.0.0 - 95.64.127.255) will probably do no harm.

The (possibly fake) registrant for these domains is:
Registrant Contact:
   Xicheng Co.
   Zhong Si Zhongguancun@yahoo.com
   01066569215 fax: 01066549216
   Huixindongjie 15  2
   Beijing Chaoyang 101402
   cn

Administrative Contact:
   Zhong Si Zhongguancun@yahoo.com
   01066569215 fax: 01066549216
   Huixindongjie 15  2
   Beijing Chaoyang 101402
   cn

Technical Contact:
   Zhong Si Zhongguancun@yahoo.com
   01066569215 fax: 01066549216
   Huixindongjie 15  2
   Beijing Chaoyang 101402
   cn

Billing Contact:
   Zhong Si Zhongguancun@yahoo.com
   01066569215 fax: 01066549216
   Huixindongjie 15  2
   Beijing Chaoyang 101402
   cn

Tuesday 13 September 2011

Injection attack: cbchhuacyus.com, ibccmsuiyus.com and wbccmquwyus.com

There is currently a Sinowal injection attack doing the rounds, redirecting traffic to the following domains on 46.165.192.97:

cbchhuacyus.com
ibccmsuiyus.com
wbccmquwyus.com

There may well be other domains on the same server, blocking traffic to 46.165.192.97 would probably be prudent. The payload is being analysed (I will post an update later), but detection rates are not good.