Yesterday, Monday, August 5, 2013, hundreds of websites began redirecting their visitors to pages hosting malware. One of them was the popular online electronics store Conrad.nl . The redirection was the result of a breach of the DNS servers of a Dutch web hosting company , Webstekker .
Researchers from security firm Fox-IT analyzed the attack and found that three web hostings had been hit by the unknown hackers.
The companies Digitalus, Virtual Dynamix (VDX) and Webstekker, as mentioned above, which host many websites, began sending all their visitors to certain websites that distributed malware.
In a statement from Digitalus, its representatives said that the attackers managed to modify the domain registration systems of SIDN, the Foundation for Internet Domain Registration in the Netherlands.
At present, there are no details on how the attackers managed to gain access to SIDN's domain registration systems.
Webstekker also released a brief statement, without providing much explanation. Its statement simply states that the company's DNS servers are redirecting visitors to its websites to malware-ridden sites.
Security firm Fox-IT published an analysis of the attack.
“The web pages had a simple message 'Under construction' but there was an iframe in them. The iframe was a window from a website running the Blackhole Exploit Kit. While we initially assumed that the company conrad.nl had been compromised, we discovered that the DNS servers responded to pings with the same IP every time: 178.33.22.5,” Fox-IT experts reported.
It is worth noting that, since July, this is the second time that SIDN has been breached.

