News: Cexx forums, with volunteers dedicated to helping you remove malware and stay protected
 
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
May 19, 2013, 17:19:47
Pages: [1]   Go Down
  Print  
Topic: US Treasury sites compromised  (Read 685 times)
0 Members and 1 Guest are viewing this topic.
« on: May 04, 2010, 19:35:06 »
AplusWebMaster Offline
Global Moderator WWW

Karma: 501
Posts: 7314



FYI...

US Treasury websites compromised
- http://community.websense.com/blogs/securitylabs/archive/2010/05/04/treasury-websites-compromised.aspx
4 May 2010 - "A few of the US Treasury websites were compromised today and loaded a hidden iframe containing exploit code to anyone who visited the following three sites:
* bep .gov
* bep.treas .gov
* moneyfactory .gov ...
This iframe loads a page from gr[REMOVED]ad .com (hosted in Turkey) which in turn redirects to si[REMOVED]e-g .com/jobs/ (hosted in The Netherlands) which is where the exploits are hosted. In this case it's the Eleonore Exploit Kit that is used which has support for several vulnerabilities in Adobe Reader, Flash, Internet Explorer etc... the exploit kit pushes a malicious PDF to the user which exploits a vulnerability in Adobe Reader. At the time of writing only 20% of all AV vendors detected that file*..."

(Screenshots and video available at the Websense URL above.)

* http://www.virustotal.com/analisis/9a274b7d8f7eeadf33b98ebcc9b4c1493e3c3252c7be72b71e8cc08ca1601e63-1272930681
File mal.pdf received on 2010.05.03 23:51:21 (UTC)
Result: 8/40 (20.00%)

U.S. Treasury Site Compromise linked to NetworkSolutions Mass WordPress Blogs Compromise
- http://ddanchev.blogspot.com/2010/05/us-treasury-site-compromise-linked-to.html
May 04, 2010

- http://thompson.blog.avg.com/2010/05/treasury-website-hacked.html
May 03, 2010

- http://pandalabs.pandasecurity.com/usa-treasury-website-hacked-using-exploit-kit/
05/4/10

- http://boards.cexx.org/index.php?topic=18708.msg80824#msg80824
May 5, 2010

 Evil or Very Mad Evil or Very Mad
« Last Edit: May 05, 2010, 19:56:55 by AplusWebMaster » Logged

This machine has no brain.
....... Use your own.
Browser check for updates here.
.
 
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by SMF 1.1.18 | SMF © 2013, Simple Machines Page created in 0.125 seconds with 19 queries.