Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security

April 8th, 2011, 10:40 GMT · By

Drive-By Download Attack Launched from USPS.gov Website

SHARE:

Adjust text size:


USPS website infected by Blackhole exploit kit
Enlarge picture
Malicious code that led to a powerful exploit kit was injected into a compromised USPS.gov website in order to infect visitors with malware.

The infection was spotted by cloud security provider Zscaler on the United States Postal Service's Rapid Information Bulletin Board System (RIBBS) website, ribbs.usps.gov.

The RIBBS website provides information for Intelligent Mail package barcode (IMpb), a new system designed to provide price-level intelligence.

The injected code consisted of obfuscated JavaScript which, when parsed, generated a rogue iframe that loaded a script from an external domain.

Like in most drive-by download attacks, the script in question was used for redirection and led users to another page designed to look as a 404 error.

That page was part of a Blackhole exploit kit installation which checked visitors' browser and operating system in order to launch one of several Java and PDF exploits.

Blackhole is a popular commercial drive-by attack toolkit sold on the underground market and as Virus Total scans show, it comes with well obfuscated exploits that evade the detection of many antivirus products.

"Yet again, we have a legitimate website with a significant user base being used as a catalyst for attack. Combine that with an abysmal detection rate on the malicious payloads by desktop AV, the first and often only line of client side defense for many enterprises, and we have a potent attack that has no doubt affected many end users," writes Michael Sutton, Zscaler's vice president of security research.

The ribbs.usps.gov website was taken offline by USPS and remains down at the time of writing this article. The URL was also blacklisted by Google's Safe Browsing service.

Users are advised to keep their software and operating systems up to date and always run with an antivirus capable of scanning Web traffic.

TELL US WHAT YOU THINK:

1,591 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


LizaMoon Mass Injection Attack Spreads Rapidly

New Mass SQL Injection Attack Infects Thousands of Pages

Trojan Distributed in New Mass Injection Attack via Java Downloader

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM