The Tech Herald

USPS website hit by Blackhole Exploit Kit

by Steve Ragan - Apr 8 2011, 06:05

Researchers at Zscaler have uncovered a Blackhole Kit attack carried out against the U.S. Postal Service’s Rapid Information Bulletin Board System (RIBBS). This is the second Blackhole Kit attack discovered this week, after another was spotted on the website for the Houston International Film Festival on Monday.

The Blackhole Kit, which was developed in Russia, cost about $1,500 USD annually for anyone who wants to deploy it, with discounts for six-month usage and quarterly usage. Described as being powerful, the kit includes payloads that target vulnerabilities in Java and Adobe PDF. Upgrades to the code make detection harder as the developers add more obfuscation and encryption to the packages.

The USPS attack focused on the RIBBS sub-domain that deals with Intelligent Mail services such as the use of barcodes for better tracking and logistics. Breaking down the attack, Zscaler noted that it followed patterns set previously by the Blackhole Kit by using staging to infect the victim’s machine.

Firstly, the attack starts with an Iframe injected into a legitimate site. This injected code then draws from another domain, which then redirects victims to the third stage. Here, the attack then scans the visitor's system and look for signs of Java or ActiveX before delivering appropriate payloads.

Again, this is the same process used during the attack on the Houston International Film Festival, and in both cases legitimate domains were used to initiate and propagate it each step of the way.

“Yet again, we have a legitimate website with a significant user base being used as a catalyst for attack. Combine that with an abysmal detection rate on the malicious payloads by desktop AV, the first and often only line of client side defense for many enterprises, and we have a potent attack that has no doubt affected many end users,” Zscaler’s Michael Sutton noted.

As this story was posted, the USPS had taken down the RIBBS domain while it works to clean out the infection.

Around the Web

Comment on this Story

comments powered by Disqus

From Autosaur.com

2014 Rolls-Royce Ghost Series 2 Pictures

Rolls-Royce have released a string of pictures of the Rolls-Royce Series II, unveiled at the 2014 ...

Gymkhana star Ken Block and Neymar’s Footkhana Video Teaser

Rally legend Ken Block, star of the famous Gymkhana video series, is releasing a new video to celb...

Aston Martin V8 Vantage GT Pictures

Here are some great pictures of the new V8 Vantage GT. The model, unveiled at the 2014 New York In...

Aston Martin V8 Vantage GT and DB9 Carbon Edition

British sportscar firm Aston Martin has released two new versions of its cars — a motorsport...

Ferrari 458 Speciale Pictures

We have added some pictures of the Ferrari 458 Speciale. Ferrari’s own team worked with Pini...