On June 24 , a visitor to the SANS Internet Storm Center reported …

On June 24 , a visitor to the SANS Internet Storm Center reported ...Short Description
The HTML here attempts to exploit a known flaw in Internet Explorer to load and … Internet Explorer. When IE 4.x and higher starts, it reads the registry …

Website: isc.sans.org | Filesize: 41kb

Content
On June 24th, a visitor to the SANS Internet Storm Center reported that his company was
“. in the middle of a very disturbing. issue regarding the adware/spyware/IE exploit
genre.” He requested help analyzing an “encrypted or compressed” file that had been
downloaded to a machine at their site.
From packet capture logs provided by the compromised site, it appears that the initial
infection took place as a result of a pop-up advertisement. Unfortunately, the packet logs
do not capture the complete sequence of events. The first step in the sequence of events
leading to the compromise is a request to http://www4.yesadvertising.com:
GET
/loading.php?id=adpost&pop=exit&t=3&subid=9768&tid=1088092203&ref=http%3A//bannerser
ver4.adpost.com/%3Frotate HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; H010818)
Host: www4.yesadvertising.com
Connection: Keep-Alive
This HTTP GET request generates a response from what appears to be a standard rotating
banner ad server which creates a time-delayed “pop-under” ad:


Advertising_Loading_Window…
<...

Get the file Download here

AddThis Social Bookmark Button
Related Books:
  • The Visitor design pattern
  • Frog Quiz & Internet Explorer 7
  • Virtual Private Network (VPN) Policy
  • General Health Status
  • Introduction to Windows 2000 Professional
  • Installing Internet Explorer 7
  • WO/GA/31/2 Matters Concerning Internet Domain Names (annex 312)
  • Internet Explorer 7

  • Related Searches: , , , ,



    Comments

    Leave a Reply