Go Back   SZONE.US Forums > Computer & Web Realm > Web Tips > Web Findings

Web Findings Here you will find information about the internet.

Malicious Web Site / Malicious Code: Malicious Google Job Application Response

Views:241
Reply
 
LinkBack Thread Tools Search this Thread Rate Thread
  #1  
Old 02.01.10, 04:56 PM
Zachariah Boren's Avatar
Administrator
 
Join Date: 02.07
Location: Canoga Park, CA
Posts: 1,379
Blog Entries: 6
Images: 3539
Send a message via ICQ to Zachariah Boren Send a message via AIM to Zachariah Boren Send a message via MSN to Zachariah Boren Send a message via Yahoo to Zachariah Boren Send a message via twitter to Zachariah Boren
Malicious Web Site / Malicious Code: Malicious Google Job Application Response

Sat, 30 Dec 1899 12:00:00 AM GMT

Websense Security Labs? ThreatSeeker? Network has discovered a new malicious spam campaign that spoofs Google job application responses. The messages look very well written and are so believable that they are probably scrapes from actual Google job application responses. Typically, spam has grammatical errors or spelling mistakes that make the messages obviously unofficial and act as red flags. The text of these messages, however, has no such mistakes, making them much more believable--especially if the target really has applied for a job with Google.

The From: address is even spoofed to fool victims into believing the message was sent by Google. The messages have an attached file called CV-20100120-112.zip that contains a malicious payload. This is where the message gets suspicious, because the contents of the .zip file have a double extension ending with .exe. The attackers attempt to hide the .exe extension by preceding it with .html or .pdf, followed by a number of spaces and then the .exe extension. The .exe file (SHA1:80366cde71b84606ce8ecf62b5bd2e459c54942e) has little AV coverage at the moment.



Websense Messaging and Websense Web Security customers are protected against this attack.



http://securitylabs.websense.com/con...erts/3543.aspx
Reply With Quote
Reply

Tags
code, google, malicious, site, web

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Rate This Thread
Rate This Thread:




SZONE.US
| Share

» Stats
Members: 1,077
Threads: 32,090
Posts: 35,021
Top Poster: WhiteHouse (7,571)

Images: 23,767
Comment: 102
Categories: 292
Total Views: 1,255,345
Disk Space: 9.24 GB
Top Uploader: Steve Boren (19,316)
Welcome to our newest member, cinder123
Powered by vBadvanced CMPS v3.1.0

All times are GMT -8. The time now is 05:50 PM.


Powered by vBulletin® Version 3.8.5
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0
Copyright ©2007 - 20010 SZONE.US All rights reserved