Archive for May, 2007

Websense Security Labs has received reports of a new email campaign starting in Australia that attempts to lure users to connecting to a malicious website. The Australia CERT has reported emails that are spoofing the Dell online store. The emails claim that the user is being charged for a camera purchase and requests they connect to a site in order to view their profile. The site is encoding there code via Java Script which decodes to 8 different IFRAMES, all which attempt to load exploit code and download and install new malicious code. The site itself appears to be going up and down sporadically.

See: http://www.auscert.org.au/render.html?it=7595

Sample Email from original advisory:

        Subject: Your order #[number] has been accepted for the amount
                 865.00 AUD
        From:    Dell online Store <order_[number]@dell.co.uk>

        Thank you for shopping with us.

        Your order #[number] Canon DF-E037 8.0 MP Digital Camera has been
        accepted for the amount 865.00 AUD.

        Your card will be charged in that amount.

        Thank you for your purchase.

        You can check the order in your profile.
 
HTTP://URL Removed

        Thank you.
        Dell  Online Store.

Although this appears to be a new deception technique the website has been used in malicious code attacks in the past and Websense customers are protected from connecting to it already.

 

Screenshot of encode script:

Screenshot of decoded script:

 

Read The Article »

The Multiple Common Bond Expansion Report identifies the number of select group expansions approved, deferred and denied for federal credit unions. The report is presented in a year-to-date format and is updated monthly.

Read The Article »

The April 2007 Insurance Report of Activity is available

Read The Article »

National Credit Union Administration (NCUA) General Counsel Robert M. Fenner has sent a letter to Everest National Insurance Company expressing the agency's concern over pending litigation between Everest National and former officials of Centrix Financial, LLC (Centrix).

Read The Article »

The National Credit Union Administration (NCUA) liquidated Sharebuilders Federal Credit Union, of Northridge, Calif., April 25, 2007.

Read The Article »

The National Credit Union Administration (NCUA) has issued orders prohibiting the following individuals from participating in the affairs of any federally insured financial institution.

Read The Article »

National Credit Union Administration (NCUA) Vice Chairman Rodney E. Hood addressed the Municipal Credit Union's Annual Meeting in New York City as the first ever outside speaker invited to their Annual Meeting in over 90 years. This particular meeting marked a milestone for the credit union as they celebrated 90 years in service.

Read The Article »

National Credit Union Administration (NCUA) General Counsel Robert M. Fenner has sent a letter to Everest National Insurance Company expressing the agency's concern over pending litigation between Everest National and former officials of Centrix Financial, LLC (Centrix).

Read The Article »

The April Community Development Revolving Loan Funds reports are available

Read The Article »

The National Credit Union Administration (NCUA) liquidated Sharebuilders Federal Credit Union, of Northridge, Calif., April 25, 2007.

Read The Article »