What the Tech logo
Welcome! Register for a free account (or login) > How does it work?
  1. Quickly register. It will only take 60 seconds.
  2. Start a new topic. Ask your question. Wait for an email reply.
  3. Is your system infected? Begin reading the malware removal guide.
register button
Reply to this topicStart new topic
> Search Engine poisoning...
AplusWebMaster
post Mar 12 2009, 02:58 AM
Post #1


AplusWebMaster
*****

Group: Authentic Member
Posts: 4,577
Joined: 30-December 03
From: USA
Member No.: 1,643
Operating System: XP/SP3



FYI...

Yahoo! sponsored search results lead to rogues
* http://preview.tinyurl.com/db25xj
03-10-2009 - Symantec Security Response Blog - "Search engines are often used by attackers as platforms from which to deliver malicious code. A while ago it was reported that Google was serving up advertisements that led to misleading applications (also known as rogue antispyware products). This time, the malicious code authors are using “Yahoo! Sponsored Search” listings as a means to promote a misleading product called ”Antivirus & Security.” Antivirus-2009-new .com and Antivirus-pro-download .com are returned in Yahoo!... The sponsored search result leads to antivirus-2009-new .com and antivirus-pro-download .com, where users are asked to make a payment to buy a membership in order to obtain the product.
>>> Instead of using techniques like search engine optimization (SEO) poisoning to get the opt listing in the search engine results, attackers are using Yahoo’s advertising services to display their advertisement on all websites that display Yahoo’s sponsored search results...
Fortunately, these sponsored listings have since been cleaned up and all websites that display sponsored search results from Yahoo, and no longer appear to be displaying these misleading advertisements. However, links to this website in forum comments and other website pages still can be found. A Yahoo search returned around 9,000 results and a Google search returned around 5,000 results when searching for “antivirus-2009-new .com.” For “antivirus-pro-download .com,” Yahoo returned around 10,000 results and Google returned around 1,650 results..."

(Screenshots available at the Symantec URL* above.)

ranting.gif ph34r.gif

This post has been edited by AplusWebMaster: Mar 12 2009, 03:08 AM
Go to the top of the page
 
+Quote Post
 
Start new topic
Replies
AplusWebMaster
post Sep 30 2009, 08:53 AM
Post #2


AplusWebMaster
*****

Group: Authentic Member
Posts: 4,577
Joined: 30-December 03
From: USA
Member No.: 1,643
Operating System: XP/SP3



FYI...

SEO Poisoning - MS Security Essentials ...
- http://securitylabs.websense.com/content/Alerts/3485.aspx
09.30.2009 - " Websense... has discovered that search engine results for information on how to download Microsoft's recently released Security Essentials tool are returning links to Web sites that serve rogue AV. Malware authors have used Search Engine Optimization (SEO) techniques to mix rogue search results in with legitimate results. For example, one of the rogue links is directly under a MSDN blog entry discussing Microsoft Security Essentials. The rogue redirects are hosted on compromised Web sites, including a Canadian publisher's Web site and the British Travel Health Association. When a user browses to the compromised Web sites, so long as they have been referred by a search engine, they are redirected to malicious Web sites with domain names such as computer-scanner21 and computervirusscanner31. An example of one of the payload files shows that AV detection is low. One such file is named Soft_71.exe (SHA1: 4e58a12a9f722be0712517a0475fda60a8e94fdc). If the user downloads the application, a file with extension .tif is downloaded in the "program files\TS" directory as TSC.exe and system.dat (the .tif file is decrypted/decompressed and split). The payload then executes "tsc.exe -dltest" apparently connects to a NASA Web site to check internet connectivity. Finally, "tsc.exe" is executed with no parameters, and the rogue AV starts. (In the background the original file is deleted). Since yesterday the Websense ThreatSeeker Network has been monitoring SEO poisoning of search terms related to Microsoft Security Essentials. It appears that the malware authors set up a trial run of SEO poisoning techniques, before converting the redirects to deliver rogue applications today..."

(Screenshots available at the Websense URL above.)

ph34r.gif ph34r.gif ph34r.gif
Go to the top of the page
 
+Quote Post

Posts in this topic
- AplusWebMaster   Search Engine poisoning...   Mar 12 2009, 02:58 AM
- - AplusWebMaster   FYI... SEO Poisoning - MS Security Essentials ......   Sep 30 2009, 08:53 AM
- - AplusWebMaster   FYI... SEO Poisoning - Google Wave - http://secur...   Sep 30 2009, 02:00 PM
- - AplusWebMaster   FYI... SEO poisoning - Samoa Earthquake News lead...   Oct 1 2009, 05:45 AM
- - AplusWebMaster   FYI... Halloween rogue AV - http://www.eset.com/t...   Oct 29 2009, 01:56 PM
- - AplusWebMaster   FYI... More FAKE AV - SEO poisoning - http://blog...   Nov 18 2009, 07:13 AM
- - AplusWebMaster   FYI... Redirects to scareware - Thousands of web ...   Nov 19 2009, 06:22 AM
- - AplusWebMaster   FYI... Office.Microsoft.Com search results can le...   Jan 8 2010, 07:16 AM
- - AplusWebMaster   FYI... Black Hat SEO Ice Skating Car Video - http...   Jan 11 2010, 07:46 PM
- - AplusWebMaster   FYI... Black Hat SEO - Haiti Earthquake - http://...   Jan 13 2010, 05:37 PM
- - AplusWebMaster   FYI... Searches for free printable items lead to ...   Jan 26 2010, 11:19 AM
- - AplusWebMaster   FYI... More SEO poisoning attacks... - http://isc...   Jan 28 2010, 08:16 AM
- - AplusWebMaster   FYI... Kneber = Zeus... - http://www.symantec.com...   Feb 19 2010, 01:55 PM
- - AplusWebMaster   FYI... Bloombox - Blackhat SEO poisoning - http:/...   Feb 22 2010, 12:51 PM
- - AplusWebMaster   FYI... SEO poisoning galore - leads to rogue AV.....   Feb 26 2010, 06:21 PM
- - AplusWebMaster   FYI... SEO Poisoning sites use Flash for redirect...   Mar 4 2010, 10:14 AM
- - AplusWebMaster   FYI... SEO poisoning on TV show - http://isc.sans...   Mar 8 2010, 06:18 AM


Reply to this topicStart new topic

 


RSS Time is now: 22nd March 2010 - 04:48 AM
Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk.
Member site: Alliance of Security Analysis Professionals | UNITE Against Malware
Memory Forums | Auto Repair Forum
© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy