USPS.gov Website Infected with Blackhole EK
ID: ec1156fc-0568-51a1-af68-37c3296100fa
STIX ID: report--ec1156fc-0568-51a1-af68-37c3296100fa
Feed Name: Zscaler Security Research Blog
**Executive Summary:** A United States Postal Service RIBBS site (ribbs.usps.gov) was compromised and used to deliver the Blackhole exploit kit via an encoded JavaScript iframe and a staged redirect to a malicious page disguised as a 404 error. The attack performs browser and OS fingerprinting to select appropriate exploits and served multiple payloads (EXE, JAR, PDF, PHP) with low antivirus detection rates; the intermediate malicious redirect domain was later taken offline.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
