On June 24 , a visitor to the SANS Internet Storm Center reported …
Short Description
The HTML here attempts to exploit a known flaw in Internet Explorer to load and … Internet Explorer. When IE 4.x and higher starts, it reads the registry …
Website: isc.sans.org | Filesize: 41kb
Content
On June 24th, a visitor to the SANS Internet Storm Center reported that his company was
“. in the middle of a very disturbing. issue regarding the adware/spyware/IE exploit
genre.” He requested help analyzing an “encrypted or compressed” file that had been
downloaded to a machine at their site.
From packet capture logs provided by the compromised site, it appears that the initial
infection took place as a result of a pop-up advertisement. Unfortunately, the packet logs
do not capture the complete sequence of events. The first step in the sequence of events
leading to the compromise is a request to http://www4.yesadvertising.com:
GET
/loading.php?id=adpost&pop=exit&t=3&subid=9768&tid=1088092203&ref=http%3A//bannerser
ver4.adpost.com/%3Frotate HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; H010818)
Host: www4.yesadvertising.com
Connection: Keep-Alive
This HTTP GET request generates a response from what appears to be a standard rotating
banner ad server which creates a time-delayed “pop-under” ad:
<...
Get the file Download here
Related Books:Related Searches: sans internet storm center, initial infection, rotating banner, adware spyware, internet explorer
Comments
Leave a Reply