<?xml version="1.0" encoding="UTF-8"?>
<blog-post>
  <author-id type="integer">7526</author-id>
  <blog-comments-count type="integer">11</blog-comments-count>
  <blog-post-status-id type="integer">3</blog-post-status-id>
  <body-format>econsultancy_xml</body-format>
  <body-formatted>
  &lt;p&gt;Some 80% of affected sites were Italian, and many of them part of the country's vital tourist trade.&lt;/p&gt;
  &lt;p&gt;The malicious software installed a &lt;a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=HTML%5FIFRAME%2ECU"&gt;HTML iFrame&lt;/a&gt; on web pages that opened a tool called MPack on users' machines that exploits known bugs via Internet Explorer.&lt;/p&gt;
  &lt;p&gt;It then sought to install a keylogger and a download channel so that authors can monitor users' activity and install further software. Data captured from users is reportedly sent to a server in Chicago.&lt;/p&gt;
  &lt;p&gt;Japan-based Trend Micro, which &lt;a href="http://itw.trendmicro.com/index.php?id=26&amp;amp;blogid=1212"&gt;discovered&lt;/a&gt; the first attacks, said it found over 4,500 travel sites in Italy had been infected, including http://www.adriahotel.it, http://wwww.bestoftuscany.it and &lt;a href="http://www.mothertheesacause.info"&gt;http://www.mothertheesacause.info&lt;/a&gt;.&lt;/p&gt;
  &lt;p&gt;The firm's David Perry said the &lt;a href="http://us.trendmicro.com/us/about/threat-level/"&gt;perpetrators&lt;/a&gt; had used software to carry out the attack that was originally bought in Russia.&lt;/p&gt;
</body-formatted>
  <body-unformatted>&lt;FormattedContent xmlns="http://www.e-consultancy.com/schema/formattedContent/"&gt;
  &lt;Paragraph&gt;Some 80% of affected sites were Italian, and many of them part of the country's vital tourist trade.&lt;/Paragraph&gt;
  &lt;Paragraph&gt;The malicious software installed a &lt;Link URL="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=HTML%5FIFRAME%2ECU" Window="New"&gt;HTML iFrame&lt;/Link&gt; on web pages that opened a tool called MPack on users' machines that exploits known bugs via Internet Explorer.&lt;/Paragraph&gt;
  &lt;Paragraph&gt;It then sought to install a keylogger and a download channel so that authors can monitor users' activity and install further software. Data captured from users is reportedly sent to a server in Chicago.&lt;/Paragraph&gt;
  &lt;Paragraph&gt;Japan-based Trend Micro, which &lt;Link URL="http://itw.trendmicro.com/index.php?id=26&amp;amp;blogid=1212" Window="New"&gt;discovered&lt;/Link&gt; the first attacks, said it found over 4,500 travel sites in Italy had been infected, including http://www.adriahotel.it, http://wwww.bestoftuscany.it and &lt;Link URL="http://www.mothertheesacause.info" Window="New"&gt;http://www.mothertheesacause.info&lt;/Link&gt;.&lt;/Paragraph&gt;
  &lt;Paragraph&gt;The firm's David Perry said the &lt;Link URL="http://us.trendmicro.com/us/about/threat-level/" Window="New"&gt;perpetrators&lt;/Link&gt; had used software to carry out the attack that was originally bought in Russia.&lt;/Paragraph&gt;
&lt;/FormattedContent&gt;</body-unformatted>
  <created-at type="datetime">2007-06-19T09:16:00+01:00</created-at>
  <enabled-blog-comments-count type="integer">1</enabled-blog-comments-count>
  <expertise-level-id type="integer">1</expertise-level-id>
  <extract-format>econsultancy_xml</extract-format>
  <extract-formatted>
  &lt;p&gt;
    &lt;strong&gt;Italy's online tourism industry was thrown into chaos when thousands of tourism websites were shut down by a software infection that takes over users' computers.&lt;/strong&gt;
  &lt;/p&gt;
  &lt;p&gt;Nicknamed 'The Italian Job' by security experts, the attack began last week and claimed around 10,000 sites by Monday morning.&lt;/p&gt;
</extract-formatted>
  <extract-unformatted>&lt;FormattedContent xmlns="http://www.e-consultancy.com/schema/formattedContent/"&gt;
  &lt;Paragraph&gt;
    &lt;Emphasis&gt;Italy's online tourism industry was thrown into chaos when thousands of tourism websites were shut down by a software infection that takes over users' computers.&lt;/Emphasis&gt;
  &lt;/Paragraph&gt;
  &lt;Paragraph&gt;Nicknamed 'The Italian Job' by security experts, the attack began last week and claimed around 10,000 sites by Monday morning.&lt;/Paragraph&gt;
&lt;/FormattedContent&gt;</extract-unformatted>
  <featured type="boolean">false</featured>
  <id type="integer">1376</id>
  <learn-more-formatted nil="true"></learn-more-formatted>
  <learn-more-unformatted nil="true"></learn-more-unformatted>
  <legacy-article-id type="integer">363601</legacy-article-id>
  <name>Italian tourism crippled by malicious web bug</name>
  <private type="boolean">false</private>
  <published-at type="datetime">2007-06-19T09:58:00+01:00</published-at>
  <slug>italian-tourism-crippled-by-malicious-web-bug</slug>
  <tweetbacks-updated-at type="datetime">2009-04-28T22:52:01+01:00</tweetbacks-updated-at>
  <unpublished-at type="datetime" nil="true"></unpublished-at>
  <updated-at type="datetime">2009-04-28T22:52:01+01:00</updated-at>
  <views-count type="integer">304</views-count>
</blog-post>
