Original URL: http://www.channelregister.co.uk/2007/09/01/bank_of_india_website_takeover/
Bank of India IT staff are mopping up the mess left by attackers who rigged the firm's website to feed malware to customers trying to access online services.
The bank managed to pry loose the rogue iframe responsible for the malware sometime early Friday morning California time. At time of writing, though, Bank of India's website was effectively cordoned off, bearing a terse notification saying: "This site is under temporary maintenance and will be available after 09:00 IST on 1.09.07."
The shuttering came a day after employees for security provider Sunbelt Software discovered someone had planted an iframe in the site that caused unpatched Windows machines to be infected with some of the most destructive pieces of malware currently in circulation. Sunbelt counted 31 separate pieces in all, including Pinch, a powerful and easy-to-use Trojan (http://pandalabs.pandasecurity.com/PINCH_2C00_-THE-TROJAN-CREATOR.aspx) that siphons personal information from a user's PC. Other malware included Trojan.Netview, Trojan-Spy.Win32.Agent.ql, various rootkits and several spam bots.
Executives and IT administrators at US offices of Bank of India who were contacted Friday morning by IDG were initially unaware of the attack. A spokesman later told the news service (http://www.computerworld.com/action/article.do?command=viewArticleBasic&articleId=9033999) that officials were aware of the problem and were working to correct it, but had no information concerning its severity or duration.
Some of the servers used to install the malware belonged to the notorious Russian Business Network, a group Spamhaus says (http://www.spamhaus.org/Rokso/listing.lasso?-op=cn&spammer=Russian%20Business%20Network) is involved in child porn, phishing and other misdeeds. According to Verisign's iDefense unit, the RBN also played a hand in bringing us MPack, a powerful Trojan downloader that infect edmore than 10,000 websites (http://www.theregister.com/2007/06/18/hijacked_sites_install_malware/) in just three days.
In this case, the attackers appeared to use an exploit kit dubbed n404, according to this post (http://ddanchev.blogspot.com/2007/08/bank-of-india-serving-malware.html) by Dancho Danchev. It relies on a technique known as Fast Flux domain name service, which is proving to be resilient against bot hunters (http://www.theregister.com/2007/07/11/fast_flux_botnet/) because there is no single point of weakness to take down.
Roger Thompson, a researcher with Exploit Prevention Labs, said he spotted one piece of code that exploited a vulnerability patched by last year's Microsoft Security Bulletin MS06-042 (http://www.microsoft.com/technet/security/Bulletin/MS06-042.mspx).
"It's pretty much a cut-and-paste of the original proof-of-concept that was put out on Metasploit last July," Thompson said of the code.
A video showing the perspective of a unpatched user visiting the Bank of India site is here (http://wormradar.com/boi.wmv). ®
Hackers hijack hacking tools website (3 June 2008)
http://www.channelregister.co.uk/2008/06/03/metasploit_hijack/
Spam busters blacklist MessageLabs and chums (11 April 2008)
http://www.channelregister.co.uk/2008/04/11/cbl_blacklists_messagelabs_isps/
Trend Micro gets slashed in attack of the killer iframes (13 March 2008)
http://www.channelregister.co.uk/2008/03/13/trend_micro_website_infected/
Web browsers on the front line of exploitation (15 February 2008)
http://www.channelregister.co.uk/2008/02/15/browser_exploitation/
Hackers seed malware on Indian anti-virus site (8 February 2008)
http://www.channelregister.co.uk/2008/02/08/indian_av_site_compromise/
Forth Road Bridge hack redirects to smut bazaar (7 February 2008)
http://www.channelregister.co.uk/2008/02/07/forth_bridge_hack/
Russian Feds close in on Pinch Trojan authors (21 December 2007)
http://www.channelregister.co.uk/2007/12/21/pinch_authors_pinched/
Grisoft acquires LinkScanner (5 December 2007)
http://www.channelregister.co.uk/2007/12/05/grisoft_buys_epl/
Infamous RBN quits China (13 November 2007)
http://www.channelregister.co.uk/2007/11/13/rbn_quits_china/
IndiaTimes website 'attacks visitors' (10 November 2007)
http://www.channelregister.co.uk/2007/11/10/india_times_under_attack/
Controversial Russian Business Network drops offline (8 November 2007)
http://www.channelregister.co.uk/2007/11/08/rbn_offline/
US phishermen trawl UK waters (18 October 2007)
http://www.channelregister.co.uk/2007/10/18/phishing_trends/
US regional bank hacked (11 October 2007)
http://www.channelregister.co.uk/2007/10/11/commerce_bank_hack/
Government websites invaded by smut and spyware (8 October 2007)
http://www.channelregister.co.uk/2007/10/08/ca_smut_spyware/
Chinese internet security response team under attack (2 October 2007)
http://www.channelregister.co.uk/2007/10/02/chinese_internet_security_response_team_attacked/
Phishers bait hook with Verified by Visa scam (26 September 2007)
http://www.channelregister.co.uk/2007/09/26/verified_by_visa/
People are biggest threat to IT security (20 September 2007)
http://www.channelregister.co.uk/2007/09/20/it_security_survey/
Trojan planted on US Consulate website (13 September 2007)
http://www.channelregister.co.uk/2007/09/13/us_consulate_trojan/
A US CERT reminder: The net is an insecure place (8 September 2007)
http://www.channelregister.co.uk/2007/09/08/security_group_warns_of_web_vulnerabity/
Monster warns victims and pledges better defense (3 September 2007)
http://www.channelregister.co.uk/2007/09/03/monster_warns_victims/
MPack developer on automated infection kit (23 July 2007)
http://www.channelregister.co.uk/2007/07/23/mpack_developer_interview/
Fast flux foils botnet takedown (11 July 2007)
http://www.channelregister.co.uk/2007/07/11/fast_flux_botnet/
Psst - wanna buy a pirate MPack toolkit? (6 July 2007)
http://www.channelregister.co.uk/2007/07/06/pirate_mpack_toolkit/
MPack malware exposes cheapskate web hosts (3 July 2007)
http://www.channelregister.co.uk/2007/07/03/mpack_reloaded/
Banks want data pulled from US (3 July 2007)
http://www.theregister.co.uk/2007/07/03/swift_us_pull/
Rival malware gangs wage turf war (1 July 2007)
http://www.channelregister.co.uk/2007/07/01/malware_gang_war/
Europe's banks must inform customers of US snooping (27 June 2007)
http://www.theregister.co.uk/2007/06/27/swift-disclosure_rules_for-european_banks/
Cyber crooks hijack 10,000 websites (18 June 2007)
http://www.channelregister.co.uk/2007/06/18/hijacked_sites_install_malware/
Large-scale DOS attack menace continues to grow (11 June 2007)
http://www.channelregister.co.uk/2007/06/11/dos_security_cyberwarfare/
© Copyright 2008