Recent Posts

Community

Email Notifications

Personal Links

Archives

Harry Waldron - IT Security

Security Developments, Software Updates and Best Practices

Asprox Botnet Installs SQL Injection Tool

A small botnet known as Asprox has been used in password stealing, spam, and phishing attacks.  This week Asprox was modified to include a new SQL Injection tool.  As recently shared, SQL injection attacks are more reflective of poorly programmed Internet web pages, rather than vendor product vulnerabilities. 

This new botnet based attack is innovative.  It interfaces with Google's search engine to locate vulnerable web pages. When a weakness is found, Asprox injects an iFrame based redirectional link on the vulnerable website.  Later folks who visit the newly seeded web page, may download and install malicious code automatically on their PC and join the Asprox botnot.

It's always important to stay up-to-date on security patches and AV protection, as this could help prevent an infection if folks accidently visit a malicious website.        

Asprox Botnet Installs SQL Injection Tool
http://www.secureworks.com/research/threats/danmecasprox/
http://vil.mcafeesecurity.com/vil/content/v_137684.htm
http://www.eweek.com/c/a/Security/Botnet-Installs-SQL-Injection-Tool/
http://www.scmagazineus.com/Asprox-botnet-malware-morphs/article/110169/
http://news.idg.no/cw/art.cfm?id=E9210D49-17A4-0F78-31AA26FE725B1F22

QUOTE: Danmec is a password-stealing trojan which has been around for a couple of years, but in the last year new components have been introduced by the author, turning it into a more complete crimeware family. One of these components (developed last year) is the Asprox trojan, which is designed to create a spam botnet which appears to be solely dedicated to sending phishing emails. As of yesterday, we observed the Asprox botnet pushing an update to the infected systems, a binary with the filename msscntr32.exe. The executable is installed as a system service with the name "Microsoft Security Center Extension", but in reality it is a SQL-injection attack tool.

After the Asprox botnet seeds its bots with the msscntr32.exe file, the attack tool launches and uses Google 's search engine to find potentially-vulnerable pages. It then hits those pages with a SQL-injection attack and, if successful, plants a malicious IFRAME on the site.

Visitors are redirected through a series of malware-hosting servers that try one or more exploits to crack the PC. If that works, a Trojan horse is downloaded and installed on the PC, adding it to the Asprox botnet; those compromised PCs are then used to spew more phishing spam.

Stewart has counted 1,000 sites that have been hacked by the SQL-injection attack tool since Monday night. The sites include small business sites, domains for several small colleges and universities and some hosted by law firms. Most are in the U.S.

Comments

Yossarian said:

We recently had a bunch of sites hit by the SQL injection. It is a nightmare. It looks like we had one vulnerable querystring that we had overlooked. It took 3 days to find it as well. As it is all automated even if your site gets hacked and you clean the data you either need to take the site completely down or monitor it 24/7 until the vulnerabilities are discovered.

We found the attacks would be occur hourly in some cases.

I guess it is a lesson learned to triple check every querystring & sql statement.

# July 3, 2008 6:56 AM

Beanie said:

This virus took my site offline for 3 weeks and I had to seek an internet security company to fix my site.

It cost me £50 but well worth it after the hastle I have had!!

Hope this helps others:

www.firestorm-online.com/.../asprox

# July 30, 2008 5:25 PM

lo; said:

l;l

# September 18, 2008 6:59 AM

Kamal said:

Researching Asprox and Beanie seems to turn up everywhere, spammer....

# October 1, 2008 10:05 AM

Raviv Raz said:

More details on ASPROX, SQL Injections at:

chaptersinwebsecurity.blogspot.com/.../asprox-silent-defacement.html

You can find download links for:

- Injector: tests for ASPROX vulnerability on websites

- dotDefender: protects web sites against ASPROX

Raviv

# October 13, 2008 11:59 AM

Jerry Mollany said:

Our website was under attack with some kind of an injection.

We tried to deal with it for 2 weeks with no success.

We tested a few products and eventually, we found a tool name dotDefender that actually stop all those attacks and more of them that appeared in the log files.

The main site where you can download dotdefender for 30 days is at: http://www.applicure.com

Jerry M.

# October 17, 2008 4:13 AM

Applicure Technologies said:

Here is the correct download link:

www.applicure.com/.../idevaffiliate.php

# October 30, 2008 9:53 PM