What the Tech logo
Welcome! Register for a free account (or login) > How does it work?
  1. Quickly register. It will only take 60 seconds.
  2. Start a new topic. Ask your question. Wait for an email reply.
  3. Is your system infected? Begin reading the malware removal guide.
register button
Reply to this topicStart new topic
> Search Engine poisoning...
AplusWebMaster
post Mar 12 2009, 02:58 AM
Post #1


AplusWebMaster
*****

Group: Authentic Member
Posts: 4,562
Joined: 30-December 03
From: USA
Member No.: 1,643
Operating System: XP/SP3



FYI...

Yahoo! sponsored search results lead to rogues
* http://preview.tinyurl.com/db25xj
03-10-2009 - Symantec Security Response Blog - "Search engines are often used by attackers as platforms from which to deliver malicious code. A while ago it was reported that Google was serving up advertisements that led to misleading applications (also known as rogue antispyware products). This time, the malicious code authors are using “Yahoo! Sponsored Search” listings as a means to promote a misleading product called ”Antivirus & Security.” Antivirus-2009-new .com and Antivirus-pro-download .com are returned in Yahoo!... The sponsored search result leads to antivirus-2009-new .com and antivirus-pro-download .com, where users are asked to make a payment to buy a membership in order to obtain the product.
>>> Instead of using techniques like search engine optimization (SEO) poisoning to get the opt listing in the search engine results, attackers are using Yahoo’s advertising services to display their advertisement on all websites that display Yahoo’s sponsored search results...
Fortunately, these sponsored listings have since been cleaned up and all websites that display sponsored search results from Yahoo, and no longer appear to be displaying these misleading advertisements. However, links to this website in forum comments and other website pages still can be found. A Yahoo search returned around 9,000 results and a Google search returned around 5,000 results when searching for “antivirus-2009-new .com.” For “antivirus-pro-download .com,” Yahoo returned around 10,000 results and Google returned around 1,650 results..."

(Screenshots available at the Symantec URL* above.)

ranting.gif ph34r.gif

This post has been edited by AplusWebMaster: Mar 12 2009, 03:08 AM
Go to the top of the page
 
+Quote Post
 
Start new topic
Replies
AplusWebMaster
post Nov 19 2009, 06:22 AM
Post #2


AplusWebMaster
*****

Group: Authentic Member
Posts: 4,562
Joined: 30-December 03
From: USA
Member No.: 1,643
Operating System: XP/SP3



FYI...

Redirects to scareware - Thousands of web sites compromised
- http://blogs.zdnet.com/security/?p=4947
November 17, 2009 - "Security researchers have detected a massive blackhat SEO (search engine optimization) campaign consisting of over 200,000 compromised web sites, all redirecting to fake security software (Inst_58s6.exe)*, commonly referred to as scareware. More details on the campaign: The compromised sites are using legitimately looking templates using automatically generated bogus content, with a tiny css.js** (Trojan-Downloader.JS.FraudLoad) uploaded on each of them which triggers the scareware campaign only if the visitor is coming a search engine listed as known http referrer by the gang - in this case Google, Yahoo, Live, Altavista, and Baidu... the massive blackat SEO campaign has been launched by the same people who operate/or manage the campaigns for the Koobface botnet..."
* http://www.virustotal.com/analisis/86c36d1...687e-1258481993
File nnovv_Inst_312s2.exe received on 2009.11.17 18:19:53 (UTC)
Result: 1/41 (2.44%)
** http://www.virustotal.com/analisis/7892e2b...63be-1258479383
File css.js received on 2009.11.17 17:36:23 (UTC)
Result: 7/41 (17.07%)

- http://blog.trendmicro.com/fake-blogs-lead-to-fakeav/
Nov. 19, 2009

- http://blogs.zdnet.com/security/?p=4297&page=2
"... the claims that “You’re Infected!; Windows has been infected; Warning: Malware Infections founds; Malware threat detected” should be considered as a fear mongering tactic..."

ph34r.gif dry.gif ph34r.gif

This post has been edited by AplusWebMaster: Nov 19 2009, 06:59 AM
Go to the top of the page
 
+Quote Post

Posts in this topic
- AplusWebMaster   Search Engine poisoning...   Mar 12 2009, 02:58 AM
- - AplusWebMaster   FYI... March Madness-related SEO poisoning leads ...   Mar 16 2009, 12:56 PM
- - AplusWebMaster   FYI... SEO campaign serving scareware - http://dd...   Apr 22 2009, 05:42 PM
- - AplusWebMaster   FYI... Swine Flu SEO... - http://www.f-secure.com...   Apr 27 2009, 08:11 AM
- - AplusWebMaster   Warning: We strongly suggest that readers NOT visi...   May 3 2009, 03:20 PM
- - AplusWebMaster   FYI... Swine Flu SEO spreads malware - http://sec...   May 8 2009, 05:04 AM
- - AplusWebMaster   FYI... Most Dangerous Search... - http://preview....   May 27 2009, 04:01 PM
- - AplusWebMaster   FYI... Blackhat SEO - http://preview.tinyurl.com/...   Jun 5 2009, 07:17 PM
- - AplusWebMaster   FYI... Google search abused - again - http://blog...   Jun 16 2009, 10:59 AM
- - AplusWebMaster   FYI... Blackhat SEO quick to abuse death of celeb...   Jun 26 2009, 05:42 AM
- - AplusWebMaster   FYI... Rumors of Emma Watson's death leading ...   Jul 27 2009, 02:29 PM
- - AplusWebMaster   FYI... Free Online Movie Blogs... Trojan for Wind...   Aug 21 2009, 06:13 AM
- - AplusWebMaster   FYI... Labor Day - SEO Poisoning leads to Rogue A...   Sep 5 2009, 04:14 AM
- - AplusWebMaster   FYI... SEO poisoning - Ann Minch's YouTube vi...   Sep 25 2009, 06:28 AM
- - AplusWebMaster   FYI... iPhone Blackhat SEO Poisoning Leads to Tot...   Sep 28 2009, 03:34 PM
- - AplusWebMaster   FYI... SEO Poisoning - MS Security Essentials ......   Sep 30 2009, 08:53 AM
- - AplusWebMaster   FYI... SEO Poisoning - Google Wave - http://secur...   Sep 30 2009, 02:00 PM
- - AplusWebMaster   FYI... SEO poisoning - Samoa Earthquake News lead...   Oct 1 2009, 05:45 AM
- - AplusWebMaster   FYI... Halloween rogue AV - http://www.eset.com/t...   Oct 29 2009, 01:56 PM
- - AplusWebMaster   FYI... More FAKE AV - SEO poisoning - http://blog...   Nov 18 2009, 07:13 AM
- - AplusWebMaster   FYI... Redirects to scareware - Thousands of web ...   Nov 19 2009, 06:22 AM
- - AplusWebMaster   FYI... Office.Microsoft.Com search results can le...   Jan 8 2010, 07:16 AM
- - AplusWebMaster   FYI... Black Hat SEO Ice Skating Car Video - http...   Jan 11 2010, 07:46 PM
- - AplusWebMaster   FYI... Black Hat SEO - Haiti Earthquake - http://...   Jan 13 2010, 05:37 PM
- - AplusWebMaster   FYI... Searches for free printable items lead to ...   Jan 26 2010, 11:19 AM
- - AplusWebMaster   FYI... More SEO poisoning attacks... - http://isc...   Jan 28 2010, 08:16 AM
- - AplusWebMaster   FYI... Kneber = Zeus... - http://www.symantec.com...   Feb 19 2010, 01:55 PM
- - AplusWebMaster   FYI... Bloombox - Blackhat SEO poisoning - http:/...   Feb 22 2010, 12:51 PM
- - AplusWebMaster   FYI... SEO poisoning galore - leads to rogue AV.....   Feb 26 2010, 06:21 PM
- - AplusWebMaster   FYI... SEO Poisoning sites use Flash for redirect...   Mar 4 2010, 10:14 AM
- - AplusWebMaster   FYI... SEO poisoning on TV show - http://isc.sans...   Mar 8 2010, 06:18 AM


Reply to this topicStart new topic

 


RSS Time is now: 14th March 2010 - 10:47 PM
Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk.
Member site: Alliance of Security Analysis Professionals | UNITE Against Malware
Memory Forums | Auto Repair Forum
© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy