Topics: Security & Insecurity,Malware, PHP, Fraud, Cybercrime
Panda Labs recently published an analysis "Mpack uncovered" [pdf]. It gives an interesting technical overview.
See also the Panda Lab blog entry
More Mpack information from Panda Labs:
F-Secure's blog has a brief explanation of what Mpack does:
---
MPack is a PHP based malware kit that's sold as if it were commercial software. It includes updates, support, and additional modules can be purchased. It's very successful at the moment. The kit uses compromised passwords to hack web servers and to insert an IFrame. If you visit a web page with such an IFrame, MPack's PHP script will be run and it will attempt to infect your computer. The PHP script is structured so that OS and browser versions are identified. The IFrame redirects to other PHP scripts depending on the details. These various scripts are easily updated by MPack's authors.
---
News.com has an overview of Mpack with a graphic of how it can be used to exploit systems. Meanwhile, Security Focus has an interview with Mpack's developers.
There was another Web reference for Mpack that gave some interesting details, but I can't find now. If I do, I'll post it.
J.D. Abolins