Cyber criminals are taking the advantage of FIFA world cup and there have been origination of many targeted malware attacks intercepted by Symantec Hosted Services.
Brazil’s early world cup lead is also giving the distinction for being focused on the attacks targeted on the companies. There was also a malware attack on June 2, which was routed to many Brazilian companies. These emails attempted to draw the world cup fans by making spoof for a famous sports wear brand, which is manufacturing the sponsorship for FIFA world cup.
The company also noted that the interesting way of attack is that it makes use of 2 attack modes, i.e. PDF attachment and malicious link. This means that even if the malicious PDF attachment is eliminated by anti virus gateways, the code retains in the email body and may be delivered to recipient.
The intelligent unit of the company discovered the spam for pharma website by making use of the world cup as a decoy through an obfuscated JavaScript coding. It means that the spammer took considerable lengths for disguising the malicious JavaScript coding, which is an approach linked with malware issues.
It is different from normal JavaScript, which struggled to be very clear, the concealed the JavaScript and contains the coding for redirecting the browser of recipient to a different location. The location is given as hJt>t>p>:S/2/2aSd>v2aSnlcleldSwloloJd>tSe2c2hJ.2cSo>ml/2xJnSuJ4JeSjS/2z2. Shltlm” By removing certain characters, the destination URL is revealed as “http://redacted/xnu4ej/z.htm.
With the tournament getting into continuation, the experts of Symantec Hosted Services expect to get more World Cup related spam and malware threats to appear.
|