Go Back   SZONE.US Forums > Computer & Web Realm > Web Tips > Web Findings

Web Findings Here you will find information about the internet.

Malicious Web Site / Malicious Code: Targeted Email Examples Relating to Microsoft In

Views:177
Reply
 
LinkBack Thread Tools Search this Thread Rate Thread
  #1 (permalink)  
Old 01.21.10, 10:19 AM
Zachariah Boren's Avatar
Zachariah Boren Zachariah Boren is offline
Administrator
 
Join Date: 02.07
Location: Canoga Park, CA
Posts: 1,190
Blog Entries: 6
Images: 2052
Send a message via ICQ to Zachariah Boren Send a message via AIM to Zachariah Boren Send a message via MSN to Zachariah Boren Send a message via Yahoo to Zachariah Boren Send a message via Skype™ to Zachariah Boren Send a message via twitter to Zachariah Boren
Malicious Web Site / Malicious Code: Targeted Email Examples Relating to Microsoft In

01.20.10 04:00 PM


Websense® Security Labs? has reports that emails linking to malicious web-based exploit code that utilizes the vulnerability CVE-2010-0249 have been sent to organizations in a targeted manner since December 2009, and the attack is still on-going. This same vulnerability was used to target Google, Adobe, and approximately 30 other companies in mid-December 2009. This is a development of the attack we have blogged about previously here.

Investigation has so far lead to the conclusion that these targeted attacks appear to have started during the week of 20 December 2009, and are on-going to government, defence, energy sectors and other organizations in the United States and United Kingdom.

Within the malicious emails the sender's domain is spoofed to match the recipient's domain making the targeted emails more convincing to the recipient. The malicious executables that are delivered by the exploit code include hxxp://cnn[removed]/US/20100119/update.exe or hxxp://usnews[removed]/svchost.exe. These exhibit traits of an information-stealing Trojan with Backdoor capabilities. As of today only 25% of AV vendors protect against the payload according to this VT report.

Example email subjects include:
"Helping You Serve Your Customers"
"Obama Slips in Polls as Crises Dominate First Year as President"
"2010 DoD Commercial SATCOM"
"The Twelve Days of Christmas"


Microsoft has announced that they plan to release a patch to address the vulnerability on Thursday 21 January 10am PST. See MS10-002 summary for details.

Screenshots of targeted emails:









Websense® Messaging and Websense Web Security customers are protected against this attack.





http://securitylabs.websense.com/con...erts/3536.aspx
Reply With Quote
Reply

Bookmarks

Tags
code, malicious, site, targeted, web

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


SZONE.US
» Stats
Members: 859
Threads: 23,955
Posts: 26,857
Top Poster: WhiteHouse (6,224)

Images: 22,051
Comment: 102
Categories: 274
Total Views: 961,367
Disk Space: 8.67 GB
Top Uploader: Steve Boren (19,087)
Welcome to our newest member, MichealTracy
» Proud Member Of

chatsworth kiwanis

NRA
Powered by vBadvanced CMPS v3.1.0

All times are GMT -8. The time now is 10:51 PM.


Powered by vBulletin® Version 3.8.2
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0
Copyright ©2006 - 2009 SZONE.US All rights reserved