Cyberattacks lay more 'stepping stones'

 

Summary

More intermediate domains are used to mask attack endpoints to extend longevity of malware families, new research from MessageLabs shows.

Events

IT Priorities 2010

Sydney, Australia - 27 Jul 2010
Melbourne, Australia - 28 Jul 2010
Mumbai, India - 4 Aug 2010
Delhi, India - 6 Aug 2010

IDC's Asia/Pacific Cloud Computing Conference 2010
31 Aug 2010

Marriott Hotel, Singapore

The number of compromised legitimate Web sites, as well as new malicious domains, continue to grow as cybercriminals employ more intermediate steps to mask their actual attacks, according to a new report.

Released Wednesday, the MessageLabs Intelligence report for August noted that when victims download malware from a legitimate Web site that has been compromised, they may be "led through a complex system of invisible redirects" to the attack endpoint. New domains are introduced over time to act as "stepping-stones" between the initial sites and final destinations.

"For the bad guys, it can be a costly exercise to produce new families of malware in order to maintain their criminal activity at sufficient levels," the Symantec-owned company said in the report. "Registering new domains is much more economical for them, and by spreading the malware across as many different Web sites and domains as possible, the longevity of each new malware is increased."

Of the 3,510 malicious Web sites blocked daily in August, 36.1 percent were thwarted for the first time, said MessageLabs. The majority of the new sites blocked for the first time are legitimate domains that have been compromised, while around 16 percent are newly-registered.

During the same period, around 12 percent of malware blocked daily were new to the company's monitoring systems.

In addition, the host country of new malicious Web sites are now more likely to differ from what the registered top-level or country-code domains suggest, said MessageLabs. For example, 46 percent of .cn sites blocked were found to be truly located in China, but the country also hosted 33.3 percent of blocked .in domains and 18.2 percent of .ru sites with malicious content. Ukraine was found to host 23 percent of .cn sites.

Older legitimate Web sites that have been compromised, are more likely to be hosted in a location that matches the top-level domain.

Asian markets lead in spam, virus infections
MessageLabs' latest report also shows that Hong Kong has regained its crown as the most spammed region globally. The Special Administrative Region recorded a spam rate of 93.4 percent, a slight drop from last month's 94.2 percent.

Denmark (92.6 percent) and China (92.5 percent) were ranked No. 2 and No. 3, respectively.

In August, one in every 296.6 e-mail messages contained a virus. China and Singapore took the lead--one in 196.9 messages was infected with malware. Switzerland, the United Kingdom and United Arab Emirates made up the top five.

Talkback

Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment
Access data anywhere in the private cloud & enable entirely new efficiencies with EMC VPLEX.
Tech Vendor: EMC

ZDNet Asia Live

RT @Droid_News: Motorola earnings beat expectations http://bit.ly/btsNAg | #Droid #Android

US court rejects class action status for Intel antitrust suit http://bit.ly/cWeSQZ

US court rejects class action status for Intel antitrust suit http://bit.ly/9mqiJR

http://bit.ly/8v7Ov3 US court rejects class action status for Intel antitrust suit - ZDNet Asia http://is.gd/dSz7R

20 minutes ago by easytweeting on topsy

US court rejects class action status for Intel antitrust suit http://bit.ly/9AbnMF

Non-green IT products 'marketing suicide': This 50-hectare eco-business park is described as a "living laboratory"... http://bit.ly/aCqko4

great! US court rejects class action status for Intel antitrust suit http://bit.ly/9acwER Good day!

Shocked! RT: @danielgoh: Oh really? RT @scoopsg: (zdnetasia) S'pore marketeers not chirping to Twitter's tune http://scoo.ps/dpkySs

Non-green IT products 'marketing suicide': By Munir Kotadia, ZDNet Australia on July 30, 2010 (8 minutes ago) Vend... http://bit.ly/aCqko4

Asian firms aware of IT snoops. http://bit.ly/9eGRxG

sg marketeers not chirping to twitter's tune http://bit.ly/aRAa1Y - baby steps baby steps

Non-green IT products 'marketing suicide': This 50-hectare eco-business park is described as a "living laboratory"... http://bit.ly/cEkDUD

Non-green IT products 'marketing suicide': At the same time, it seems vendors see green technology as a very high ... http://bit.ly/aCqko4

1 hour 20 minutes ago by greentreats on topsy

Oh really? RT @scoopsg: (zdnetasia) S'pore marketeers not chirping to Twitter's tune http://scoo.ps/dpkySs

@mrcolinlim but of course for more tech updates you can always visit zdnetasia.com

RT @zdnetasia: Searchable Facebook user data posted to Pirate Bay http://bit.ly/ciJQxY

2 hours 17 minutes ago by phyllis777loves on topsy

in the mean time, if you need to find PDF eBooks, you may use http://www.findpdf.us/

4 hours 56 minutes ago by findpdf on Researchers find workaround for Adobe PDF fix

Just want to say what a great blog you got here! My appreciation of your work, cause i am an IT student also. Try this one too, http://w...

5 hours 4 minutes ago by winsource on Making the case for Filipino IT entrepreneurship

Hi, We have ton of HP empty cartridges. Could you collect them in our office??
Thanks

1 day 57 minutes ago by Pacific Time Pte Ltd on Recycle your HP print cartridges and get rewards

Thanks Kenneth, for your insights. Good to know people out there can see the issue for what it is, and to do so impassively, that is. ...

2 days 2 minutes ago by yedwin on iPhone 4 shows prudence in procrastination

While I agree that the issues with the device have raised many an eyebrow, I think it's unwise to forget that many phone reviews have...

2 days 14 minutes ago by kennethkoh on iPhone 4 shows prudence in procrastination

The online apple store http://store.apple.com/ is not available now. Maybe it's updating the pricing ;)

2 days 12 minutes ago by mingnow on iPhone 4 to ring in Singapore on Friday

After an awful silence, finally the prices are out..

3 days 7 minutes ago by melvinchia on iPhone 4 to ring in Singapore on Friday

Glad you discovered the Xfce 4.6 magic. Its other endearing feature is its phenomenal configurability. You can make the desktop look and ...

3 days 14 minutes ago by gnome_refugee on Smitten with Xfce 4

yep, tried them all and xfce with compiz/emerald instead of fvwm is by far the best experience I've had. If you didn't know ther...

3 days 12 minutes ago by ggolemg on Smitten with Xfce 4

@mingnow: why do you think so? How do you think the FOSS community could tackle this issue? I'm involved in a lot of efforts to get t...

3 days 18 minutes ago by fredericmuller on Taobao initiates Chinese open source revolution

Geez. I would think giving free books and getting kids to school would be a better place to start.

3 days 26 minutes ago by mingnow on India's US$35 tablet--how low can it go?

I think it's great the that country with the biggest internet population is finally contributing back to the open-source world. I thi...

4 days 12 minutes ago by mingnow on Taobao initiates Chinese open source revolution

hey.there Im Wendy from a PR Agency.I find your blog interesting and well written.In days to come,we would hold an event. Therefore We ...

4 days 43 minutes ago by wendy on iPhone 4 shows prudence in procrastination

It could be done without all these. Just use the opacity addon of Compiz.

4 days 7 minutes ago by hariks0 on How to get RGBA support in Ubuntu