America's Favorite News Feed

THE NEWS COMMENTER

VOTE  (0)  (0)

Equifax website hacked again, this time to redirect to fake Flash update



Screenshot Arstechnica.com

Image via arstechnica.com screen capture

Added 10-12-17 03:10:01am EST - “Malware researcher encounters bogus download links during multiple visits.” - Arstechnica.com

CLICK TO SHARE

Posted By TheNewsCommenter: From Arstechnica.com: “Equifax website hacked again, this time to redirect to fake Flash update”. Below is an excerpt from the article.

In May credit reporting service Equifax's website was breached by attackers who eventually made off with social security numbers, names, and a dizzying amount of other details for some 145.5 million US consumers. For several hours on Wednesday the site was compromised again, this time to deliver fraudulent Adobe Flash updates, which when clicked, infected visitors' computers with adware that was detected by only three of 65 antivirus providers.

Randy Abrams, an independent security analyst by day, happened to visit the site Wednesday evening to contest what he said was false information he had just found on his credit report. Eventually, his browser opened up a page on the domain hxxp:centerbluray.info that looked like this:

Further ReadingWhy the Equifax breach is very possibly the worst leak of personal info everHe was understandably incredulous. The site that previously gave up personal data for virtually every US person with a credit history was once again under the control of attackers, this time trying to trick Equifax visitors into installing crapware Symantec calls Adware.Eorezo. Knowing a thing or two about drive-by campaigns, Abrams figured the chances were slim he'd see the download on follow-on visits. To fly under the radar, attackers frequently serve the downloads to only a select number of visitors, and then only once.

Abrams tried anyway, and to his amazement, he encountered the bogus Flash download links on at least three subsequent visits. The picture above this post is the higher-resolution screen shot he captured during one visit. He also provided the video below. It shows an Equifax page redirecting the browser to at least four domains before finally opening the Flash download at the same centerbluray.info page.

The file that got delivered when Abrams clicked through is called MediaDownloaderIron.exe. This VirusTotal entry shows only Panda, Symantec, and Webroot detecting the file as adware. This separate malware analysis from Packet Security shows the code is highly obfuscated and takes pains to conceal itself from reverse engineering. Malwarebytes flagged the centerbluray.info site as one that pushes malware, while both Eset and Avira provided similar malware warnings for one of the intermediate domains, newcyclevaults.com

Read more...

Watch the video:

Post a comment.

CLICK TO SHARE

COMMENTS VIA TWITTER






BACK TO THE HOME-PAGE