Here’s a quick update on CVE-2010-0249 , aka the Aurora exploit. A few days ago exploit code was made public . Since then malware authors have been customizing the exploits payload to install their own malicious creations. Much of the field telemetry we’ve been receiving has been coming from McAfee users in China visiting websites in China. Some users have been directed to malicious sites from blog and forum posts, while other cases involve compromised web pages that use multiple javascripts and iframes to pull in the malicious content. The exploits are often served from subdomains of 3322.org and 8866.org. A common filename is ie.html, which references what.jpg, which contains part of the exploit code (and not a JPEG image). Some payloads seen download files named down.css and log.css, which are malware executables. Those executables contain functionality to download other malware, including: Artemis!629E2332CFDA – Generic PWS.y!bsk Artemis!78043EBA321B – PWS-Mmorpg!la Artemis!911BCF95C022 – PWS-OnlineGames.gx Generic Downloader.x!coe Generic Dropper!byp Generic PWS.y!bsk PWS-Mmorpg!la Suspect-02!50CB7D4BB04E – Generic Dropper.hi Suspect-26!4EBF601DCBF6 – PWS-Mmorpg!la Suspect-26!6D89EB2792F7 – PWS-Mmorpg!hb Suspect-26!B01B63F88994 – PWS-Mmorpg!la Given that exploit code is readily available, this is likely the tip-of-the tip of the iceberg in terms of the domains and malware we are likely to see over the next few weeks (and we can expect to see new exploit and related malware variants for many months, if not years, to come)
Visit link:
Update on Recent Microsoft 0day (CVE-2010-0249)