According to a public notice of Trend Micro, many Web pages of Trend Micro Japan’s Web site, which providing PC Viruses information, were inserted Viruses named "JS_DLOADER.TZE", around 21:00 pm, March 9, 2008. At 11:30am, March 12, 2008, the infected pages were found, and the Web site was closed to prepare. The Web site run again At 8:30am, March 13.
http://jp.trendmicro.com/jp/about/notice/0312/index.html
Related News Links from USA
PC World: [Hackers Attack Trend Micro, and CA]
http://www.pcworld.com/article/id,143445-c,hackers/article.html
abc NEWS: [SANS Solves Mystery of Mass Web Site Infections]
http://abcnews.go.com/Technology/PCWorld/story?id=4674207
Information Week: [Trend Micro Details Its Recent Failed Web Attack]
http://www.informationweek.com/news/internet/browsers/showArticle.jhtml?articleID=206903807
At least the following Viruses information pages have been infected:
[Japanese site]
- ADW_BRUNME.A
- ADW_ZANGO.A
- ADWARE_ADBLASTER
- ADWARE_EXACTADVERTISING
- ADWARE_EZULA.ILOOKUP
- TSPY_AGENT.HS
- TSPY_ANICMOO
- TSPY_GOLDUN.GEN
- TSPY_HUPIGON.ZY
- TSPY_Lmir
- TSPY_Tiny
【English site】
- ADWARE_BHO_WEBDIR
- ADWARE_BHO_WSTART
- HKTL_MDBEXP.A
- POSSIBLE_OTORUN3
- SPYWARE_TRAK_RADMIN
- TROJ_ARTIEF-1
- TROJ_CLAGGER.D
- TSPY_BANKER-2.002
- TSPY_BANKRYPT.N
- TSPY_GAMANIA.CI
- TSPY_GOLDUN.GEN
- TSPY_LINEAGE
- TSPY_ONLINEG.DAU
- TSPY_ONLINEG.OAX
- TSPY_QQPASS
- TSPY_SDBOT.BTI
- W97M_DLOADER.BKV
- WORM_IRCBOT.JK
- WORM_NYXEM.E
- WORM_SOBER.AG
http://itpro.nikkeibp.co.jp/article/NEWS/20080312/296060/?ST=security
The current solution of "Perimeter security products + Web " never gives us a secured Web infrastructure! The only way to win the battle against 21st Century Web attacks, whether Known or Unknown, is with the next generation Web server --- 3Gweb Self-Defending Web server!