Popular Media Sites Involved In Mass Compromise
ID: eb8c3a47-6451-5238-b42b-4759bef773cd
STIX ID: report--eb8c3a47-6451-5238-b42b-4759bef773cd
Feed Name: Zscaler Security Research Blog
Zscaler identified a mass compromise of numerous legitimate websites (including WTOP and Federal News Radio) where attackers injected obfuscated JavaScript that conditionally (based on the browser User-Agent for Internet Explorer) loads iFrames from dynamic DNS hosts; victims are redirected to pages that deliver Fake AntiVirus scams and the ZeroAccess Trojan. The report includes example deobfuscated code, URL patterns hosted on DynDNS (e.g., myftp.biz, hopto.org), a list of compromised sites, and MD5 hashes for observed payloads.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
