Cybercriminals distribute malicious payloads and hide their tracks by planting code on “Account Suspended” pages that appear when accounts have been disabled.

Security researchers discovered that scammers turned to this trick to lead visitors to falsely believe that the website they visited is no longer active, making it more difficult to determine how their computer has been compromised.
Jerome Segura of Malwarebytes spotted this practice on websites managed through cPanel, one of the most widely used web hosting control panels.
The conclusion that the page with the message “Account Suspended” is transmitting something beyond the message consists of the fact that it was not available at the root of the domain, as it normally should be.
Segura found evidence that a legitimate website had been compromised and that a fake page titled “Account Suspended” contained a malicious iframe that led to the Fiesta exploit kit’s landing page.
The URL leading to the attack tool and the iframe’s size parameters are constantly changing as a tactic to avoid detection by various signature-based security tools for detecting malicious elements.
When a user accesses the malicious page, a verification is performed to determine the web browser and whether it contains vulnerable plug-in versions.
Segura noted on Thursday that the landing page leading to the Fiesta exploit kit calls out multiple exploits, for Flash Player (CVE-2015-0311), Silverlight (CVE-2013-0074), PDF (CVE-2010-0188) and Java (CVE-2013-2465). Only one of these is exploitable on each computer.
The general recommendation to users is to apply all the latest software patches released by developers, even more so in the case of browser plug-ins.
