Expertsare from AlienVault currently analyzing an attack that took place website the US Department of Labor (dol.gov).
According to the security firm , when a user visits the Department of Labor website , a script begins to run. The script is designed to scan the victim's computer to determine what versions of Flash, Java, Microsoft Office and Acrobat Reader are installed on it. US Department of Labor hacked, page redirects to malware
It also checks for the presence of various antiviruses , including those from Avira , Bitdefender , AVG , ESET , Avira , Dr Web , Sophos , F -Secure , and Kaspersky .
Once the information is collected, it is sent to a remote website and a malicious payload begins to download to the victim's computer. It appears to be CVE - 2012-4792, an Internet Explorer vulnerability discovered by Microsoft in January .
The malware is detected by 13 of the 46 antiviruses listed on the VirusTotal.
Experts have found that the command and control communication protocol used by the malware is the same as that used by a well-known Chinese group called “DeepPanda. ” (PDF)
