Spear Phishing Emails Target U.S. Law and Public Relations Firms

November 18, 2009
Bookmark and Share
Spear Phishing  Emails Target  U.S. Law and  Public Relations Firms
Phishing emails

Washington, DC (RPRN) 11/18/09 — Investigative Programs Cyber Investigations

New E-Scams & Warnings

—The FBI assesses with high confidence that hackers are using spear phishing e-mails with malicious payloads to exploit U.S. law firms and public relations firms. During the course of ongoing investigations, the FBI identified noticeable increases in computer exploitation attempts against these entities. The specific intrusion vector used against the firms is a spear phishing or targeted socially engineered e-mail designed to compromise a network by bypassing technological network defenses and exploiting the person at the keyboard. Hackers exploit the ability of end users to launch the malicious payloads from within the network by attaching a file to the message or including a link to the domain housing the file and enticing users to click the attachment or link. Network defense against these attacks is difficult as the subject lines are spoofed, or crafted, in such a way to uniquely engage recipients with content appropriate to their specific business interests. In addition to appearing to originate from a trusted source based on the relevance of the subject line, the attachment name and message body are also crafted to associate with the same specific business interests. Opening a message will not directly compromise the system or network because the malicious payload lies in the attachment or linked domain. Infection occurs once someone opens the attachment or clicks the link, which launches a self-executing file and, through a variety of malicious processes, attempts to download another file.

Indicators are unreliable to flag in-bound messages; however, indicators are available to determine an existing compromise. Once executed, the malicious payload will attempt to download and execute the file ‘srhost.exe’ from the domain ‘http://d.ueopen.com’; e.g. http://d.ueopen.com/srhost.exe. Any traffic associated with ‘ueopen.com’ should be considered as an indication of an existing network compromise and addressed appropriately.

The malicious file does not necessarily appear as an ‘exe’ file in each incident. On occasion, the self-executing file has appeared as other file types, e.g., ‘.zip’, ‘.jpeg’, etc.

Please contact your local field office if you experience this network activity and direct incident response notifications to DHS and U.S. CERT.

How to Report E-Scams and Hoaxes to the FBI

 

Click here to see all news from this author/company
Bookmark and Share
Media Web Address: http://www.fbi.gov/cyberinvest/escams.htm
Main image credits: http://itsecurity.vermont.gov/threats/phishing

Filed Under: BUSINESS NEWS, Technology, Featured, MARKETING, ADVERTISING, PR, New Media - WEB 2.0, Social Media, PRESS RELEASE

RUSH PR NEWS newswire and press release services at rushprnews.com / Anne Howard annehowardpublicist.com

Content- Legal Responsibility - All material is copyrighted - You may repost but you MUST link back to the original post on your page and acknowledge Rush PR News as the news source. Rush PR News is not legally and/or morally responsible for content of press releases, opinions expressed or fact-checking.

Rush PR News cannot be held legally responsible for material published and distributed through its newswire service or published in its press-room and therefore cannot be sued for published material. Third-party must be contacted directly to dispute content.

Rush PR News is not the contact for material published.

Comments


Got something to say?

Name:

E-mail:

Website (optional):

Comments:

RSSFeed PRESS & SOCIAL MEDIA RELEASES

New Uno Motorcycle Concept - Street Legal?

Toronto, ON 03/20/10 · The Uno and its inventor, 18-year-old Ben J....

Polar Bear Trophy Hunt Ban Shot Down

CHICAGO, IL 03/19/10 · Polar Bear Trophy Hunt Ban Shot Down Most important...

Yahoo!(R) Named as the Exclusive Search Service on Telefonica's Mobile Portal in Spain

SUNNYVALE, Calif. & MADRID, 03/18/10 · Yahoo! Continues to Extend Mobile Presence by Providing...

Omni CEO to Present Advanced SugarCRM Integration at SugarCon 2010

EDMONTON, AB 03/18/10 · Omni Technology Solutions, Inc. (www.omni-ts.com), the first company...

Oil Addiction: Gas Price Spikes Threaten Americans' Wallets

WASHINGTON 03/17/10 · New Analysis Shows States Most Dependent Upon...

Yahoo! to Acquire Citizen Sports

SUNNYVALE, Calif., 03/17/10 · Strengthens Social Strategy by Combining the Power of...

Help Animals Imprisoned by SeaWorld

NEW YORK 03/17/10 · In aquariums, dolphins and other sea animals routinely...

New YouTube Video Looks at Many Ways Water Bottlers Actively Protect the Planet

Alexandria, VA 03/17/10 · To view the new video ‘Bottled Water’s Environmental...

Web Hosting Provider Super M Launches New Logo And Web site

SCOTTSDALE, AZ 03/17/10 · Leading domain name and web hosting provider,...

High Profile Speakers Announced for Coface Country Risk Conference in Manchester

Manchester, UK 03/17/10 · Chief Executive of the ICM and leading economists...

m62 Announces Plans to Release PowerPoint Slides for Every Occasion

Liverpool, UK 03/16/10 · m62 visualcommunications, the global leader in presentation effectiveness,...

IBM Extends Development and Test to the IBM Cloud

ARMONK, N.Y. 03/16/10 · Expands partner ecosystem; Unveils new software ...

Seth Firkins From Five by Five Media Group to Fight the Atlanta Beat Battle

Atlanta, GA 03/16/10 · The Year of the Placements continues with ATL...

Reebok EasyTone Marketing Sees Sales Soar at FitnessFootwear.com

LONDON, UK 03/15/10 · As the summer approaches and thoughts are on...