Block ueopen .com ASAP
Block the domain ueopen .com ASAP.
From http://www.fbi.gov/cyberinvest/escams.htm (spaces added to malicious domain):
The FBI assesses with high confidence that hackers are using spear phishing e-mails with malicious payloads to exploit U.S. law firms and public relations firms…. The specific intrusion vector used against the firms is a spear phishing or targeted socially engineered e-mail designed to compromise a network by bypassing technological network defenses and exploiting the person at the keyboard. Hackers exploit the ability of end users to launch the malicious payloads from within the network by attaching a file to the message or including a link to the domain housing the file and enticing users to click the attachment or link….
Once executed, the malicious payload will attempt to download and execute the file ‘srhost.exe’ from the domain ‘hxxp://d. ueopen.com’; e.g. hxxp://d. ueopen.com/srhost.exe. Any traffic associated with ‘ueopen.com’ should be considered as an indication of an existing network compromise and addressed appropriately.
Domain will be added on the next update but you should not wait….
