Botnet Installs SQL Injection Tool

執筆者
Brian Prince
Brian Prince
Published: May 14, 2008
Updated: Feb 2, 2021
2 minute read
eWeek のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る

A botnet is outfitting its army of compromised computers with a SQL injection attack tool to hack Web sites, researchers at SecureWorks have discovered.

According to SecureWorks, the Asprox botnet, once used solely to send out phishing e-mails, is pushing the tool out to systems in its network via a binary with the file name msscntr32.exe. The executable is installed as a system service with the name “Microsoft Security Center Extension.”

Despite the name, the file is in fact a SQL injection attack tool that when launched searches Google for .asp pages that contain certain terms. It then launches SQL injection attacks against the Web sites returned by the search. According to SecureWorks, the attack is designed to inject an IFrame into the Web site that tricks visitors into downloading a JavaScript file from the domain direct84.com.

This file in turn redirects computers to a site where additional malicious JavaScripts are stored, although the secondary site appeared to be down when SecureWorks first reported the attacks May 14. When successful, however, the site installs additional copies of Asprox, the password-stealing Trojan Danmec or the SQL attack tool.

When researchers have the power to seize control of botnets, should they? A recent discovery triggers ethical debate. Click here to read more.

According to a list from VirusTotal, only a handful of the major anti-virus vendors are detecting the attack tool at this time.

“This is the first time I’ve seen a SQL injection tool, but certainly other botnets have tried to spread in a similar manner, infecting Web sites with IFrames,” said Joe Stewart, director of malware research at SecureWorks. “For instance, Storm tries to get your password if you log in to a Web site with FTP, and will put an IFrame into the page for you.”

So far, SecureWorks has found 1,000 Web sites infected by this wave of SQL attacks. Visitors to these infected Web sites are infected with the Asprox malware-turning them into bots-and also download some scareware.

“We’ve estimated [the Asprox botnet] at around 15,000 hosts, but that was before the wave of SQL attacks,” Stewart said in an interview with eWEEK.

Researchers are still investigating exactly what vulnerability on the Web sites is being exploited, Stewart said. The Web sites are English-language and their owners include law firms and midsize businesses.

Advertisement

A similar attack technique is currently being seen spreading game-password-stealing Trojans from China. Whether the tool is related or only the attack syntax is shared, it is clear that SQL injection attack activity is on the rise from multiple sources, Stewart wrote in his blog.

Brian Prince

Brian Prince

Content Writer
eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。