Hacked Go Daddy sites infecting users with ransomware

Status
Not open for further replies.

Jack

Administrator
Thread author
Verified
Staff Member
Well-known
Jan 24, 2011
9,378
Sophos said:
Users are getting infected with ransomware thanks to criminals managing to hack the DNS records of Go Daddy hosted websites.

That's not welcome news for the world's largest domain name registrar, especially so soon after the recent denial of service attack.

To understand how these attacks work, a short primer on DNS is required.

In a nutshell, DNS provides a system where computers on a network (the internet) can be referenced by a user-friendly name. These names are known as hostnames, and DNS translates them into what is known as an IP address.

A key feature of DNS is that changes can be made and applied very rapidly, allowing resources to be moved between machines/networks/locations without affecting end users. The hostnames remain constant, and DNS handles any changes in the IP address as the resources move.

In this current spate of attacks, criminals are exploiting DNS by hacking the DNS records of sites, adding one or more additional subdomains with corresponding DNS entries (A records) referencing malicious IP addresses. The legitimate hostname resolves to the legitimate IP address, but the added sub-domains resolve to rogue servers.

This enables the attackers to use legitimate-looking URLs in their attacks, which can help to evade security filtering and trick users into thinking the content must be safe.

godaddy_dns_hacks2.png


Read more: http://nakedsecurity.sophos.com/2012/11/23/hacked-go-daddy-ransomware/
 

imsoadude

Level 3
Verified
Feb 21, 2011
838
Seems like if your gonna go with a web hosting company to avoid GoDaddy since they seem to always be getting targeted by hackers and the customers end up suffering
 

Exterminator

Level 85
Verified
Top Poster
Well-known
Oct 23, 2012
12,527
I have never experienced any problems with GoDaddy.Problems and issues were always resolved fast and satisfactorily.I found them to be very good compared to others.Maybe they get targeted because their marketing makes them more known then others.I would recommend them to someone looking for a cost effective way to run a site using vbulletin ect.Obviously now security is an issue and a very big issue and one GoDaddy needs to address
 

Malware1

Level 76
Sep 28, 2011
6,545
This Ransomware is Reveton, posted already here: http://malwaretips.com/Thread-Ransomware-Reveton-new-version
but this is from Cool Exploit Kit, not Blackhole, they are similar. Sorry for mistake.
Post modified.
 

madyrocksin

New Member
Jul 30, 2012
510
sorry if i couldn't understand it,
but won't it require the user to install something before getting infected???
 

Malware1

Level 76
Sep 28, 2011
6,545
Java is needed, but of course some Exploits needs for example Adobe Reader for downloading payload and running it. Just go to Exploit page and your computer will be infected. Let me know if you need links.

madyrocksin said:
sorry if i couldn't understand it,
but won't it require the user to install something before getting infected???
 

madyrocksin

New Member
Jul 30, 2012
510
MalwareCenter said:
Java is needed, but of course some Exploits needs for example Adobe Reader for downloading payload and running it. Just go to Exploit page and your computer will be infected. Let me know if you need links.

madyrocksin said:
sorry if i couldn't understand it,
but won't it require the user to install something before getting infected???

Thanks for the explanation :D
ScriptNo is sure useful :p
 

zorror

New Member
Verified
Nov 25, 2012
22
Recently got infected by FBI Computer Locked Moneypak Virus but the troublesome part wasn't removing it as I just restored using a backup the troublesome part was why couldn't my AVIRA stop it
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top