Security Labs

Alerts

BOOKMARK THIS ALERT
  digg   |     del.icio.us   |     reddit
  newsvine   |     furl   |     technorati

Compromised Site: Embassy of Ethiopia in Washington D.C.

Date:06.22.2009

Threat Type: Malicious Web Site / Malicious Code

Websense® Security Labs™ ThreatSeeker™ Network has discovered that the official Web site of the Ethiopian Embassy in Washington, D.C., has been compromised with malicious code. The Web site has been injected with obfuscated JavaScript (the code is in an Iframe). The code redirects users to sites that deliver malicious software that is installed without needing any explicit user interaction. The domains hosting these links are being monitored by Websense Security Labs. They currently host malicious files, such as Trojan Downloaders.

Ethiopian Embassy services include: issuing passports, immigrant and non-immigrant visas; notarization and attestation; cultural exchange; consultant services for commercial ventures; representation of Ethiopian citizens in dealings with local authorities; assistance in emergencies; and providing necessary tourist and local information for the needy. The Embassy carries out government-to-government and people-to-people diplomacy, and serves as a vital resource for Ethiopians in the United States and the Ethiopian-American community.

Screenshot of infected site:

Screenshot of infected source: 
 

We have notified the site owners about the malicious content. The hub site that is hosting the malicious JavaScript is currently down.

Websense Messaging and Websense Web Security customers are protected against these threats.