Published: 2012-08-14 by Daniel B. Cid
Dennis (from unmask) posted about some iframe injections that he has been
seeing lately: RFI: Server-wide iframe injections
The post is interesting, so read that first. We are also seeing many variations
of this attack, always with the iframes being injected as domain.com/[randomnumbers].html and redirecting the user to Fake AV. This are some of the URLs we are seeing:
Note that all (or most) of these sites are compromised and being used by the attackers to spread malware "botnet" style. Dennis also questioned how are these sites being hacked.
Initially, all of them were running Plesk (at least I could access it as site.com:8443). However, as the infection is growing, I am seeing many sites not using Plesk with this type of malware, so we can't know for sure. We assume it is a mix of attacks (brute force FTP + outdated Plesk + anything they can find).