Is Philippine Bureau of Immigration website compromised, hosting malware?

According to Websense Security Labs™ and the Websense ThreatSeeker® Network, they have detected malicious emails disguised as HSBC Notifications.  A closer look at these emails, like the one you can see below, reveals that the link provided in the emails is a compromised URL belonging to the Philippine Bureau of Immigration.

Clicking the link prompts the user to download a malicious file called "atualizar.exe".

The Philippine Bureau of Immigration is using Joomla as their CMS and there is a file named “atualizar.php” which is a Portuguese word and translate to “update.php”. 

The file was probably replaced or inserted maliciously. This link “” if you hit it, the HTTP response status code is 302 which is the most common way of performing a redirection. It redirect to “” which probably contain the actual payload…


   2: [kramfs@viasvr temp]$ wget

   3: --2011-08-10 

   4: 17:15:03--

   5: Resolving 


   7: Connecting to 

   8:||:80... connected.

   9: HTTP request sent, 

  10: awaiting response... 302 Found

  11: Location: 

  12: [following]

  13: --2011-08-10 17:15:04--

  14: Reusing 

  15: existing connection to

  16: HTTP request sent, awaiting 

  17: response... No data received.

  18: Retrying.

  19: --2011-08-10 17:15:05-- (try: 2)

  20: Connecting 

  21: to||:80... connected.

  22: HTTP request sent, 

  23: awaiting response... 200 OK

  24: Length: 699460 (683K) 

  25: [application/x-msdos-program]

  26: Saving to: âatualizar.exeâ

  27: 100%[============================================================================>] 

  28: 699,460 63.4K/s in 12s

  29: 2011-08-10 17:15:17 (57.2 KB/s) - âatualizar.exeâ


Trend Micro flag this file as malicious….


You can find the VirusTotal analysis results for this .exe as it is detected by different AV solutions.

Source Reference: Websense Security Labs


  1. Pingback: massage sensuel paris

  2. Pingback: ipads

  3. Pingback: Real Estate Commercial News

  4. Pingback: Fashion Styling Solution

  5. Pingback: how to get free money online

  6. Pingback: Sport Center

  7. Pingback: Newark Limo

  8. Pingback: home interior design

  9. Pingback: cash money loans

  10. Pingback: Personal Styling Service

  11. Pingback: action figures

  12. Pingback: Automotive News

  13. Pingback: improve your English pronunciation

  14. Pingback: American Football

  15. Pingback: Business Counseling

  16. Pingback: Regnbuetetra

  17. Pingback: tattoos for girls

  18. Pingback: diet program

  19. Pingback: cape town hotels

  20. Pingback: Dry Cleaning Naples

  21. Pingback: marc grimaldi medford

  22. Pingback: Real Estate Commersial News

  23. Pingback: Automotive Supplies and Products

  24. Pingback: Environmental Technology

  25. Pingback: garage door

  26. Pingback: aluminum awnings

  27. Pingback: how to grow taller during puberty

  28. Pingback: oil and gas careers

  29. Pingback: halloween history

  30. Pingback: Clothing Design Expert Tips

  31. Pingback: Home Investment Partnerships

  32. Pingback: Bed & Breakfast in Johannesburg

  33. Pingback: joanna shields ceo of tech city

  34. Pingback: France

  35. Pingback: armoir

  36. Pingback: premium wordpress themes

  37. Pingback: Pirater un compte facebook

  38. Pingback: cocaine addiction treatment

  39. Pingback: pest control hertfordshire

  40. Pingback: Entrepreneuer Best Advice

  41. Pingback: Business and Careers Resource

  42. Pingback: redesign website

  43. Pingback: buy zynga poker chips

  44. Pingback: rent a apartment

  45. Pingback: Indiana boulders

  46. Pingback: clash of clans hack download

  47. Pingback: Basslager Trap Music

  48. Pingback: iptv xbmc channel list

  49. Pingback: runescape classic

  50. Pingback: best student homestay in singapore

Leave a Comment

Your email address will not be published. Required fields are marked *