<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: Post mortem report on the sinowal/nu.nl incident</title>
	<atom:link href="http://blog.fox-it.com/2012/03/16/post-mortem-report-on-the-sinowallnu-nl-incident/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.fox-it.com/2012/03/16/post-mortem-report-on-the-sinowallnu-nl-incident/</link>
	<description>News and opinions from Fox-IT</description>
	<lastBuildDate>Sun, 19 May 2013 06:07:16 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
	<item>
		<title>By: Nuclear Pack Exploit Kit plays with smart redirection &#124; ESET ThreatBlog</title>
		<link>http://blog.fox-it.com/2012/03/16/post-mortem-report-on-the-sinowallnu-nl-incident/#comment-237</link>
		<dc:creator><![CDATA[Nuclear Pack Exploit Kit plays with smart redirection &#124; ESET ThreatBlog]]></dc:creator>
		<pubDate>Fri, 04 May 2012 13:45:57 +0000</pubDate>
		<guid isPermaLink="false">http://blog.fox-it.com/?p=136#comment-237</guid>
		<description><![CDATA[[...] update: there&#039;s a useful report of a major Nuclear Pack-related incident from Fox-IT at http://blog.fox-it.com/2012/03/16/post-mortem-report-on-the-sinowallnu-nl-incident/. However, in the case that Aleksandr has been looking at, there&#039;s an updated version that [...]]]></description>
		<content:encoded><![CDATA[<p>[...] update: there&#039;s a useful report of a major Nuclear Pack-related incident from Fox-IT at <a href="http://blog.fox-it.com/2012/03/16/post-mortem-report-on-the-sinowallnu-nl-incident/" rel="nofollow">http://blog.fox-it.com/2012/03/16/post-mortem-report-on-the-sinowallnu-nl-incident/</a>. However, in the case that Aleksandr has been looking at, there&#039;s an updated version that [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Умные редиректы на Nuclear Pack &#124; &#124; CopyBase.RU - Интересное из сетиCopyBase.RU &#8212; Интересное из сети</title>
		<link>http://blog.fox-it.com/2012/03/16/post-mortem-report-on-the-sinowallnu-nl-incident/#comment-145</link>
		<dc:creator><![CDATA[Умные редиректы на Nuclear Pack &#124; &#124; CopyBase.RU - Интересное из сетиCopyBase.RU &#8212; Интересное из сети]]></dc:creator>
		<pubDate>Mon, 09 Apr 2012 15:24:29 +0000</pubDate>
		<guid isPermaLink="false">http://blog.fox-it.com/?p=136#comment-145</guid>
		<description><![CDATA[[...] версии Blackhole и в последствии Nuclear Pack. Причем, похожая история уже произошла месяцем ранее в Нидерландах, но в ней [...]]]></description>
		<content:encoded><![CDATA[<p>[...] версии Blackhole и в последствии Nuclear Pack. Причем, похожая история уже произошла месяцем ранее в Нидерландах, но в ней [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: IT Secure Site &#187; Blog Archive &#187; Exploit Kit plays with smart redirection (amended)</title>
		<link>http://blog.fox-it.com/2012/03/16/post-mortem-report-on-the-sinowallnu-nl-incident/#comment-143</link>
		<dc:creator><![CDATA[IT Secure Site &#187; Blog Archive &#187; Exploit Kit plays with smart redirection (amended)]]></dc:creator>
		<pubDate>Sat, 07 Apr 2012 14:26:04 +0000</pubDate>
		<guid isPermaLink="false">http://blog.fox-it.com/?p=136#comment-143</guid>
		<description><![CDATA[[...] update: there&#039;s a useful news of a vital Nuclear Pack-related occurrence from Fox-IT during http://blog.fox-it.com/2012/03/16/post-mortem-report-on-the-sinowallnu-nl-incident/. However, in a box that Aleksandr has been looking at, there&#039;s an updated chronicle that includes [...]]]></description>
		<content:encoded><![CDATA[<p>[...] update: there&#039;s a useful news of a vital Nuclear Pack-related occurrence from Fox-IT during <a href="http://blog.fox-it.com/2012/03/16/post-mortem-report-on-the-sinowallnu-nl-incident/" rel="nofollow">http://blog.fox-it.com/2012/03/16/post-mortem-report-on-the-sinowallnu-nl-incident/</a>. However, in a box that Aleksandr has been looking at, there&#039;s an updated chronicle that includes [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Exploit Kit plays with smart redirection (amended) &#124; Security Antivirus Virus</title>
		<link>http://blog.fox-it.com/2012/03/16/post-mortem-report-on-the-sinowallnu-nl-incident/#comment-141</link>
		<dc:creator><![CDATA[Exploit Kit plays with smart redirection (amended) &#124; Security Antivirus Virus]]></dc:creator>
		<pubDate>Fri, 06 Apr 2012 02:45:33 +0000</pubDate>
		<guid isPermaLink="false">http://blog.fox-it.com/?p=136#comment-141</guid>
		<description><![CDATA[[...] update: there&#039;s a useful report of a major Nuclear Pack-related incident from Fox-IT at http://blog.fox-it.com/2012/03/16/post-mortem-report-on-the-sinowallnu-nl-incident/. However, in the case that Aleksandr has been looking at, there&#039;s an updated version that [...]]]></description>
		<content:encoded><![CDATA[<p>[...] update: there&#039;s a useful report of a major Nuclear Pack-related incident from Fox-IT at <a href="http://blog.fox-it.com/2012/03/16/post-mortem-report-on-the-sinowallnu-nl-incident/" rel="nofollow">http://blog.fox-it.com/2012/03/16/post-mortem-report-on-the-sinowallnu-nl-incident/</a>. However, in the case that Aleksandr has been looking at, there&#039;s an updated version that [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alex</title>
		<link>http://blog.fox-it.com/2012/03/16/post-mortem-report-on-the-sinowallnu-nl-incident/#comment-139</link>
		<dc:creator><![CDATA[Alex]]></dc:creator>
		<pubDate>Wed, 04 Apr 2012 18:52:04 +0000</pubDate>
		<guid isPermaLink="false">http://blog.fox-it.com/?p=136#comment-139</guid>
		<description><![CDATA[Did working without administrative permissions protect against this trojan?]]></description>
		<content:encoded><![CDATA[<p>Did working without administrative permissions protect against this trojan?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: 《漏洞攻擊》荷蘭新聞網 nu.nl 遭入侵,專挑午餐播報時段啟動病毒,蒐集系統資訊 &#124; 雲端防毒是趨勢</title>
		<link>http://blog.fox-it.com/2012/03/16/post-mortem-report-on-the-sinowallnu-nl-incident/#comment-131</link>
		<dc:creator><![CDATA[《漏洞攻擊》荷蘭新聞網 nu.nl 遭入侵,專挑午餐播報時段啟動病毒,蒐集系統資訊 &#124; 雲端防毒是趨勢]]></dc:creator>
		<pubDate>Fri, 30 Mar 2012 01:27:01 +0000</pubDate>
		<guid isPermaLink="false">http://blog.fox-it.com/?p=136#comment-131</guid>
		<description><![CDATA[[...] TROJ_SINOWAL.SMF也據稱會下載另一個組件去感染受影響電腦的MBR。 [...]]]></description>
		<content:encoded><![CDATA[<p>[...] TROJ_SINOWAL.SMF也據稱會下載另一個組件去感染受影響電腦的MBR。 [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ceptera Security Newswire &#187; Dutch Users Served SINOWAL for Lunch:</title>
		<link>http://blog.fox-it.com/2012/03/16/post-mortem-report-on-the-sinowallnu-nl-incident/#comment-118</link>
		<dc:creator><![CDATA[Ceptera Security Newswire &#187; Dutch Users Served SINOWAL for Lunch:]]></dc:creator>
		<pubDate>Tue, 20 Mar 2012 16:05:57 +0000</pubDate>
		<guid isPermaLink="false">http://blog.fox-it.com/?p=136#comment-118</guid>
		<description><![CDATA[[...] is also said to download another component that is capable of infecting the MBR of an affected [...]]]></description>
		<content:encoded><![CDATA[<p>[...] is also said to download another component that is capable of infecting the MBR of an affected [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dutch Users Served SINOWAL for Lunch &#124; Virus / malware / hacking / security news</title>
		<link>http://blog.fox-it.com/2012/03/16/post-mortem-report-on-the-sinowallnu-nl-incident/#comment-117</link>
		<dc:creator><![CDATA[Dutch Users Served SINOWAL for Lunch &#124; Virus / malware / hacking / security news]]></dc:creator>
		<pubDate>Tue, 20 Mar 2012 15:05:12 +0000</pubDate>
		<guid isPermaLink="false">http://blog.fox-it.com/?p=136#comment-117</guid>
		<description><![CDATA[[...] is also said to download another component that is capable of infecting the MBR of an affected [...]]]></description>
		<content:encoded><![CDATA[<p>[...] is also said to download another component that is capable of infecting the MBR of an affected [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Michael Sandee</title>
		<link>http://blog.fox-it.com/2012/03/16/post-mortem-report-on-the-sinowallnu-nl-incident/#comment-115</link>
		<dc:creator><![CDATA[Michael Sandee]]></dc:creator>
		<pubDate>Mon, 19 Mar 2012 13:03:51 +0000</pubDate>
		<guid isPermaLink="false">http://blog.fox-it.com/?p=136#comment-115</guid>
		<description><![CDATA[It is not a matter of time per se, there are many variables to verify, the reason we mentioned time will tell is because we cannot know everything but we do know that something was wrong in the cases we investigated. In time we will see the reports from other affected parties who might have additional information on this. A large number of systems was infected but did not get the real intended payload running for a number of reasons, some of those reasons we know and some of those we do not know. This makes it hard to apply this information to the total amount of infected systems, so while we can make a good estimate on how many systems are affected by the initial infection, we cannot say anything about the amount of real infections that is now active, but we are sure at least a percentage of the systems are active.
 
Everybody who worries, do not read our blogpost in a way that it is an excuse to not do anything (you might conclude otherwise from some information in the press), if you were affected your systems are using outdated software, additionally they might have been infected with one or more pieces of malware causing a possible information leak. See it as a wake-up call. A number of URLs have been mentioned, if your proxy logs contain the the url which fetches the payload (executable) from the exploit kit, or if your logs contain references to the two urls we mentioned of the SmokeLoader command and control server, you should know that the system has been compromised. Verifying the additional Sinowal infection requires some more information that we cannot explain in a few words.
 
A significant amount of Anti-Virus product vendors now recognizes it, but some remain that do not detect the SmokeLoader infections:
https://www.virustotal.com/file/e625fdb49695886ee2781d6e2c3755f7fc8c9c56ca208bdd14e51f11466abe10/analysis/1332150024/
https://www.virustotal.com/file/c667f39573b4bbd10aa26e841a9dda3ab0407de12606e9a58e16fc9427ce7dc1/analysis/1332150155/]]></description>
		<content:encoded><![CDATA[<p>It is not a matter of time per se, there are many variables to verify, the reason we mentioned time will tell is because we cannot know everything but we do know that something was wrong in the cases we investigated. In time we will see the reports from other affected parties who might have additional information on this. A large number of systems was infected but did not get the real intended payload running for a number of reasons, some of those reasons we know and some of those we do not know. This makes it hard to apply this information to the total amount of infected systems, so while we can make a good estimate on how many systems are affected by the initial infection, we cannot say anything about the amount of real infections that is now active, but we are sure at least a percentage of the systems are active.</p>
<p>Everybody who worries, do not read our blogpost in a way that it is an excuse to not do anything (you might conclude otherwise from some information in the press), if you were affected your systems are using outdated software, additionally they might have been infected with one or more pieces of malware causing a possible information leak. See it as a wake-up call. A number of URLs have been mentioned, if your proxy logs contain the the url which fetches the payload (executable) from the exploit kit, or if your logs contain references to the two urls we mentioned of the SmokeLoader command and control server, you should know that the system has been compromised. Verifying the additional Sinowal infection requires some more information that we cannot explain in a few words.</p>
<p>A significant amount of Anti-Virus product vendors now recognizes it, but some remain that do not detect the SmokeLoader infections:<br />
<a href="https://www.virustotal.com/file/e625fdb49695886ee2781d6e2c3755f7fc8c9c56ca208bdd14e51f11466abe10/analysis/1332150024/" rel="nofollow">https://www.virustotal.com/file/e625fdb49695886ee2781d6e2c3755f7fc8c9c56ca208bdd14e51f11466abe10/analysis/1332150024/</a><br />
<a href="https://www.virustotal.com/file/c667f39573b4bbd10aa26e841a9dda3ab0407de12606e9a58e16fc9427ce7dc1/analysis/1332150155/" rel="nofollow">https://www.virustotal.com/file/c667f39573b4bbd10aa26e841a9dda3ab0407de12606e9a58e16fc9427ce7dc1/analysis/1332150155/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jan</title>
		<link>http://blog.fox-it.com/2012/03/16/post-mortem-report-on-the-sinowallnu-nl-incident/#comment-114</link>
		<dc:creator><![CDATA[Jan]]></dc:creator>
		<pubDate>Sun, 18 Mar 2012 22:18:54 +0000</pubDate>
		<guid isPermaLink="false">http://blog.fox-it.com/?p=136#comment-114</guid>
		<description><![CDATA[You end with your report with the text &quot;Time will tell&quot;.

Do you have any idee how much time it will take te be sure this is harmless? We really would like to reassure our customers en move on to the &#039;business as usual&#039;]]></description>
		<content:encoded><![CDATA[<p>You end with your report with the text &#8220;Time will tell&#8221;.</p>
<p>Do you have any idee how much time it will take te be sure this is harmless? We really would like to reassure our customers en move on to the &#8216;business as usual&#8217;</p>
]]></content:encoded>
	</item>
</channel>
</rss>
