WinZipIces.cn - Several thousand websites have been hacked by a MySQL exploit that redirects visitors to WinZipIces.cn where a phishing trojan is downloaded onto your PC.

Prominent sites affected by the WinZipIces.cn hack are WiredSeniors.com, CGSI.org, MoviesUnlimited, SeniorsTravelGuide.com, CancerIssues.com, USSC.edu, UCLA.edu, telluride-co.gov, and thousands more hacked websites which are similarly infected worldwide.
The WinZipIces phishing exploit launched by Chinese hackers using an automated script that searches for an unpatched SQL vulnerability on web servers downloads two files onto visitors computers, JS_DLOADER.AEHM and TROJ_REALPLAY.BR.
Both these initial files in turn download TROJ_AGENT.AKVP onto the infected system of visitors to these hacked websites.
Users should make sure their own personal computers are not infected by the WinZipIces hack by having current antivirus software and firewalls installed and active on their PCs.
You can go to download.com (a site run by PC Week & CNET) to get free versions of AVG antivirus and Zone Labs personal firewall there, so there’s no excuse for letting your own PC get hacked.
Website hosting providers should check their servers to be sure all patches have been applied to vulnerable servers. Experts expect the wave of infected sites to continue for the next week to ten days.
And that’s the latest news on WinZipIces.cn
Tags: chinese hackers, jueduizuan, phishing, WinZipIces, WinZipIces.cn
May 8th, 2008 at 12:03 pm
[...] the original post: WinZipIces.cn freebsd securityfreebsd securityRelated Posts Hosting Website Template Flash [...]
May 9th, 2008 at 11:33 pm
So, I’ve visited all the above mentioned sites, and the sites in the google search, and the winzipices site itself, executed the .js files, created a local html and manually added the scripts, visited the infecteting site itself, and I see nothing happening. I did this on a windows 2003 machine on an admin account on IE 6 with the security and privacy settings resetted to the lowest level, without any antivirus or firewall.
Scanned my PC but no trojans were found, confirmed this with procmon, procexp, autoruns and rootkitrevealer.
So is there a bug in this bug or am I missing something?
May 10th, 2008 at 8:33 am
[...] where trojan files are downloaded to infect their PCs in an identity theft phishing scheme. http://a11news.com/95/winzipices-cn/ HACKERS CATALOG-computer hacking, phone phreaking, software …Huge on-line catalog dedicated to [...]
May 13th, 2008 at 6:08 pm
[...] where trojan files are downloaded to infect their PCs in an identity theft phishing scheme. http://a11news.com/95/winzipices-cn/ [...]