Go Back   SZONE.US Forums > Computer & Web Realm > Web Tips > Web Findings

Web Findings Here you will find information about the internet.

Malicious Web Site / Malicious Code: Zeus Campaign Targeted Government Departments

Views:99
Reply
 
LinkBack Thread Tools Search this Thread Rate Thread
  #1 (permalink)  
Old 02.08.10, 12:28 PM
Zachariah Boren's Avatar
Zachariah Boren Zachariah Boren is offline
Administrator
 
Join Date: 02.07
Location: Canoga Park, CA
Posts: 1,190
Blog Entries: 6
Images: 2052
Send a message via ICQ to Zachariah Boren Send a message via AIM to Zachariah Boren Send a message via MSN to Zachariah Boren Send a message via Yahoo to Zachariah Boren Send a message via Skype™ to Zachariah Boren Send a message via twitter to Zachariah Boren
Malicious Web Site / Malicious Code: Zeus Campaign Targeted Government Departments

02.07.10 04:00 PM

Websense Security Labs? ThreatSeeker? Network has discovered a new Zeus campaign (a banking data stealing Trojan) which is now targeting government departments. Our research shows that the campaign has especially targeted workers from government and military departments in the UK and US: we found most victims' email addresses end with .gov.



Figure 1 - Zeus Campaign:

Our ThreatSeeker? Network has seen thousands of emails which pretend to be from the National Intelligence Council (see Figure 2). The email subjects include: "National Intelligence Council"
"RE: National Intelligence Council"
"Report of the National Intelligence Council"

Figure 2 - Content of the email:

The spoofed emails lure victims to download a document about the "2020 project"; this is actually a Zeus bot. The Web sites which host the bot look very trustworthy: one of them is a compromised organization Web site and the other is located on a popular file hosting service. The bot has rootkit capabilities and connects to C&C servers at update*snip*.com and pack*snip*.com to report back on a successful infection and to download some archives with DLLs, it also modifies the hosts file to prevent updates from popular anti-virus vendors.

Websense® Messaging and Websense Web Security customers are protected against this attack, however the anti-virus detection rate for this bot is currently at 26/40.



http://securitylabs.websense.com/con...erts/3546.aspx
Reply With Quote
Reply

Bookmarks

Tags
code, malicious, site, web, zeus

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


SZONE.US
» Stats
Members: 859
Threads: 23,934
Posts: 26,836
Top Poster: WhiteHouse (6,224)

Images: 22,051
Comment: 102
Categories: 274
Total Views: 960,874
Disk Space: 8.67 GB
Top Uploader: Steve Boren (19,087)
Welcome to our newest member, MichealTracy
» Proud Member Of

chatsworth kiwanis

NRA
Powered by vBadvanced CMPS v3.1.0

All times are GMT -8. The time now is 02:55 PM.


Powered by vBulletin® Version 3.8.2
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0
Copyright ©2006 - 2009 SZONE.US All rights reserved