Thursday, 18 April 2013

ANON_0x03 invade Argentina military website


The hacker group "ANON_0x03" affiliated with Anonymous hacktivists has invaded the website belong to Infantry branch of Argentina Army (infanteria.mil.ar).

The website has been defaced and notified in the zone-h mirror page by a hacker with the handle "voldem0rt".

Unlike other hackers, they didn't left any messages in the defacement.  They leaked the compromised database in the defacement instead.

The data leaked by Anon 0x03 includes email addresses, usernames, hashed passwords and other information.

We are still able to see the defacement page at the time of writing.  But the security breach was done 24 hours ago.

Mirror:
http://www.zone-h.org/mirror/id/19658987

They also leaked login credentials belong to few Peru government websites along with the link to login panel.

Cyber Criminals take advantage of Boston attack for spreading malware

[Spam alert] While everyone horrified by the Boston Marathon bombings, the heartless cyber criminals ready to take advantage of this tragic incident and started to spread spam mails.

Earlier Today i received two mails with subject related to Explosions at Boston Marathon. The mail had nothing other than a link to external page [IP_address/boston.html]

When i tried to visit the "85.198.81.**/boston.html" page, the page with title "Hot News::Videos of Explosions at the Boston Marathon 2013" displayed some legitimate youtube videos .




But, in background, the page load an iframe to a malicious page where the java exploit is being hosted.  Anyway, i am not able to download the .jar file because it is unavailable when i try to download.

It seems like the same link is being used in the spam mail received by Kaspersky Lab.  Kaspersky analyzed and found that malware tries to connect to several IP addresses in Ukraine, Argentina and Taiwan.