Spear Phishing Emails Target U.S. Law and Public Relations Firms

November 18, 2009

Bookmark and Share
Spear Phishing  Emails Target  U.S. Law and  Public Relations Firms
Phishing emails

Washington, DC (RPRN) 11/18/09 — Investigative Programs Cyber Investigations

New E-Scams & Warnings

—The FBI assesses with high confidence that hackers are using spear phishing e-mails with malicious payloads to exploit U.S. law firms and public relations firms. During the course of ongoing investigations, the FBI identified noticeable increases in computer exploitation attempts against these entities. The specific intrusion vector used against the firms is a spear phishing or targeted socially engineered e-mail designed to compromise a network by bypassing technological network defenses and exploiting the person at the keyboard. Hackers exploit the ability of end users to launch the malicious payloads from within the network by attaching a file to the message or including a link to the domain housing the file and enticing users to click the attachment or link. Network defense against these attacks is difficult as the subject lines are spoofed, or crafted, in such a way to uniquely engage recipients with content appropriate to their specific business interests. In addition to appearing to originate from a trusted source based on the relevance of the subject line, the attachment name and message body are also crafted to associate with the same specific business interests. Opening a message will not directly compromise the system or network because the malicious payload lies in the attachment or linked domain. Infection occurs once someone opens the attachment or clicks the link, which launches a self-executing file and, through a variety of malicious processes, attempts to download another file.

Indicators are unreliable to flag in-bound messages; however, indicators are available to determine an existing compromise. Once executed, the malicious payload will attempt to download and execute the file ‘srhost.exe’ from the domain ‘http://d.ueopen.com’; e.g. http://d.ueopen.com/srhost.exe. Any traffic associated with ‘ueopen.com’ should be considered as an indication of an existing network compromise and addressed appropriately.

The malicious file does not necessarily appear as an ‘exe’ file in each incident. On occasion, the self-executing file has appeared as other file types, e.g., ‘.zip’, ‘.jpeg’, etc.

Please contact your local field office if you experience this network activity and direct incident response notifications to DHS and U.S. CERT.

How to Report E-Scams and Hoaxes to the FBI

 

Click here to see all news from this author/company
Bookmark and Share
Media Web Address: http://www.fbi.gov/cyberinvest/escams.htm
Main image credits: http://itsecurity.vermont.gov/threats/phishing

Filed Under: BUSINESS NEWS, Technology, Featured, MARKETING, ADVERTISING, PR, New Media - WEB 2.0, Social Media, PRESS RELEASE

RUSH PR NEWS newswire and press release services at rushprnews.com / Anne Howard annehowardpublicist.com

Content- Legal Responsibility - All material is copyrighted - You may repost but you MUST link back to the original post on your page and acknowledge Rush PR News as the news source. Rush PR News is not legally and/or morally responsible for content of press releases, opinions expressed or fact-checking.

Rush PR News cannot be held legally responsible for material published and distributed through its newswire service or published in its press-room and therefore cannot be sued for published material. Third-party must be contacted directly to dispute content.

Rush PR News is not the contact for material published.

Please leave your comments here

RSSFeed PRESS & SOCIAL MEDIA RELEASES

Speech Remedy Launches Speech Therapy App Adult-focused iOS App to Rebuild Language Skills

Belmont, CA 05/23/12 · --- Speech Remedy, a leading provider of adult-focused...

Longer Apprenticeships Will Mean More Highly Skilled Workers, Says Perspective

London, UK 05/22/12 · The recent announcement from the Government that the...

Corporate Gifts Specialist Leighmans Aims for £1m Revenues

London, UK 05/22/12 · --- Leighmans.com, the specialist corporate incentive and gift...

Stratford Managers Corporation Launches Operations and Engineering Practices

Ottawa, ON 05/22/12 · Growing Ottawa-Based Management Consulting Firm Expands Services for...

Leasing Sector Capitalising on Recession Opportunities finds Business Leader

London, UK 05/16/12 · As the economic downturn continues to bite, business...

Your Highest Investment Return on Property in Asia is Best at JL Antara Raya, Jakarta Pusat

Jakarta Pusat, Indonesia 05/16/12 · Asia property hub, govt; highest return investment in...

Aysling Digital Media Solutions achieves ISO 9001:2008 re-certification

Ann Arbor, Michigan 05/16/12 · ---Aysling Digital Media Solutions completed an external ISO...

elicit Investors Include Greycroft Partners, First Round Capital, ff Ventures, and L3

Chicago, IL 05/15/12 · elicit Secures $1.5 Million Series A Funding For...

Money Off Famous Brands This May and Summer with New DiscountVouchers.co.uk Deals

London, UK 05/15/12 · Retail deals specialist helps consumers save with latest...

Change Your Brain, Change Your Wealth

Dallas / Fort Worth, TX 05/15/12 · Many of the world's most successfully driven business...

Cheap Rentals in Corfu and Malaga with New 121carhire.com Summer Prices

London, UK 05/14/12 · Leading rental site offers up bargain hire deals...