Showing posts with label Fake AV. Show all posts
Showing posts with label Fake AV. Show all posts

Monday, September 9, 2013

Fake AV and PRISM warning on hijacked website

While many individuals are concerned about privacy in light of PRISM, some malicious actors are using the program to scare naive users into installing ransomware. Since August 23rd, we have seen about 20 domains that carry FakeAV and Ransomware. These websites seem to have been hijacked. They are all hosting the malicious content over port 972 and use similar URL patterns. Here are a couple examples:
  • kringpad.websiteanddomainauctions.com:972/lesser-assess_away-van.txt?e=20
  • miesurheilijaaantidiabetic.conferencesiq.com:972/realism_relinquish-umbrella-gasp.txt?e=21
  • squamipi.worldcupbasketball.net:972/duty_therefore.txt?e=21
The malicious files seem to be changing. It started with the classic FakeAV, then switched to a fake PRISM warning. In both cases, the goal is to scare the target into paying the attacker to "fix" their computer.

FakeAV

FakeAV remains a popular technique to lure targets into paying attackers. Most of the instances of FakeAV we have reported earlier were running a fake computer scan in the browser. This time it appeared as a Desktop application.


FakeAV scan of the computer
FakeAV claims to have found threats
The scan claims to have found 18 threats. Two have been cured, but the victim must pay to get the remaining 16 threats taken care of.

Some of the malicious behaviors of this FakeAV variant

PRISM warning

The other malware is interesting. The attacker uses the recent news about PRISM to claim that the victim's computer has been blocked because it accessed illegal pornographic content. The victim has to pay $300 through MoneyPak, a prepaid card service.

No less than 5 federal agencies are "blocking" your computer!

Victim needs to pay up $300 to get his computer back.

Both malware connect to the same couple of IP addresses over ports 80 and 443 that include:
  • 37.139.53.199
  • 64.120.167.162
  • 64.191.122.10
I expect attackers to take advantages of the upcoming UK laws on accessing adult content online to send new types of fake warnings to UK victims.

Friday, December 21, 2012

Fake AV 3 years later: still there, still not blocked

You may want to open the first blog post we did on Fake AV in December 2009, three years ago, side by side with this post. See if you can spot the differences... fake antivirus pages in 2012 are nearly the same as they were three years ago and most AV solutions still fail to block them.

Fake AV page

The pages we're seeing look exactly the same as they did three years ago. First, a popup alerts the user that their machine is likely infected. Then, an animated page fakes an antivirus engine scanning the user machine. Malware is of course 'found' and a download window opens, which prompts the user to download "free antivirus" to clean up the computer.

Warning popup
Fake scanning of the PC
Malicious executable disguised as an antivirus

The HTML source does not use any obfuscation technique, which was also true for the fake AV pages we saw three years ago (HTML and JavaScript obfuscation did show up for a time in 2010 and 2011). The only difference might be in the page title: Microsoft Antivirus 2013.

Antivirus failing again

Like three years ago, the detection rate remains very low. This time around, in the sample we investigated, only 12 AV out of 43 detect the executable as malicious. Windows Security Essentials, which I run on my PC, failed to block the download. It would appear that switching from AVG to Windows Security did not protect me against the new Fake AV executables...

On the bright side, both Internet Explorer (Smart Screen Filters) and Google Safe Browsing blocked this page.

Domains

We have seen a lot of fake AV domains lately. This particular fake AV campaign is very similar to a previous one we described in March 2011. Affiliates direct users toward the fake AV pages. The URLs contain an affiliate ID to track the referrals to ensure that the fake AV author can then compensate those forwarding victims. Here are a few of the fake AV URLs we have seen recently:
  • hxxp://googlenaimokimbles.info/?affid=00333&promo_type=4&promo_opt=1
  • hxxp://innersdomainsinser.net/?affid=00333&promo_type=4&promo_opt=1
  • hxxp://domainssinglsdoms.net/?affid=00333&promo_type=4&promo_opt=1
  • hxxp://moneushousessteam.net/?affid=00333&promo_type=4&promo_opt=1
  • hxxp://steamsinglemonthf.net/?affid=00333&promo_type=4&promo_opt=1
  • hxxp://domainddincowsrows.info/?affid=00333&promo_type=4&promo_opt=1
It appears that affiliate 00333 is very good at redirecting users, but we did see other IDs: 00401, 00399

Fake AV in action

Here are a couple of screenshots of the Fake AV executable in action. It does actually register itself as an antivirus solution on a Windows PC. You will notice that they have not bothered updating their software as it sill shows up as XP Anti-SPyware 2011.

XP Antivirus 2011 installed as a legitimate AV
Fake AV finds viruses in files that do not exist
The malicious AV program seems to have been written by Russian hackers.

Upon installation, it disable the Firewall and existing AV solutions, disables AV updates, disables security warnings and sets itself as the default AV solution. It also deletes the installer (freescan_2013.exe).

It downloads and runs the file hxxp://googlesearchnaimokimbles.net/data.exe. This domain is blocked by Google Safe Browsing, but the executable is blocked by only 9 of 46 AV engines.

A malicious executable, bap.exe, is added to the file system and it is registered to execute any .exe file. The same file is also used to execute Internet Explorer: Instead of running C:\Program Files\Internet Explorer\iexplore.exe, it runs bap.exe -a "C:\Program Files\Internet Explorer\iexplore.exe". It wraps any executable run by the user.

The Fake AV program then connects back to 109.206.174.62. This IP hosts several suspicious domains including:
  • avit2013.com
  • str321.com
  • supporr2013.com
These Fake AV pages are also the same as they were three years ago. They probably don't need to change as long as very few antivirus vendors block them and as long as users keep trusting random warnings on the Internet. Once the user is infected, the Fake AV takes over the system and it is very hard to clean up.

Monday, April 30, 2012

Search Engine Security for Internet Explorer

Search Engine Security (SES), a browser extension designed to protect users against Blackhat SEO links in search engines, is now available for Internet Explorer. You can download it from our website. It is compatible with Internet Explorer 6.0 and above, on Windows XP thru Windows 7.

The features are the same as Search Engine Security for Google Chrome, released two weeks ago. The Referer and the User-Agent headers are modified when you follow a search result link on Google, Bing and Yahoo! This prevents the hijacked sites from redirecting users to a malicious page.

As with SES for Firefox and Google Chrome, you can turn the extension on and off for the three search engines.

Search Engine Security enabled on Bing

You can also whitelist specific pages. The only difference with the IE version as opposed to Firefox and Chrome is that the Referrer cannot be empty. This is why the default value is "-".

The options are available under Tools > Search Engine Security options.

Search Engine Security options

To test the features, search for "what is my user agent" or "what is my referrer" in Google, Bing or Yahoo! and follow a link. You will notice a different value when Search Engine Security is ON or OFF.

Modified User-Agent
There are very few browser extensions available for Internet Explorer, especially extensions helping to keep users safe. I will continue to port the Zscaler security extensions to Internet Explorer and will bring other security tools to this platform.

You can find a full list of all our browser extensions on the ThreatLabZ portal under Tools. Search Engine Security for Internet Explorer can be downloaded here.

Thursday, April 26, 2012

Multiple hijacking

Vulnerable websites are regularly hijacked to redirect users to malicious domains. The most popular type of of malicious page are Fake AV pages. Attackers commonly increase traffic to these hijacked websites using Blackhat SEO techniques.

Blackhat SEO requires that two different pages be delivered to different audiences:

  • A harmless spam page to the Googlebot and security scanners, in order to get references and be ranked well by Google, as well as evade blacklists
  • A redirection to a malicious domain to attack users
Existing pages on the hijacked sites are usually unchanged and instead, new pages are created. The newly created spam pages are completely harmless, with no obfuscated JavaScript. A 302/307 HTTP redirection is done mostly via a PHP file, or using an .htaccess file.

Other groups of attackers may want to use vulnerable websites for different purposes. So it is not rare to see the same vulnerable sites being abused by different groups. Recently, there was an increase in hijacked websites sending users to Fake AV pages also being infected with malicious JavaScript. The obfuscated JavaScript code is added before the original HTML code on all pages, making it much more likely to be blacklisted by Google. Here are a few examples:

Found on dailygizmonews.com


Found on malaysianaspiration.com


A mix of the 2 previous JavaScript codes

All of these examples result in the same HTML code, an IFRAME injection pointing to a malicious domain:

  • hxxp://fbyvdtydyth.myfw.us/?go=2
  • hxxp://tds46.lookin.at/stds/go.php?sid=1
  • hxxp://qerhkbdimoitvd5t.lowestprices.at/?go=2


Deofuscated code

Ironically, this malicious code might actually keep user safer. Since it is present on all pages, regardless of the HTTP Referrer, the entire website is flagged as malicious much more quickly by search engines.



Wednesday, April 18, 2012

French Budget Minister website hijacked

We've seen an increase in hijacked websites in recent months, redirecting users to Fake AV pages, Blackhole exploit kits and other malware. While most websites hacked are personal sites, or University websites, some are more high profile.

http://www.performance-publique.budget.gouv.fr/ hijacked

The website of the French Minister of Budget (www.performance-publique.budget.gouv.fr) is an example of a high profile site that was recently hijacked. Obfuscated JavaScript was added at the top of the page. It is very similar to what we have seen on other websites. The obfuscation contains some tricks to break JavaScript scanning tools, such as making reference to browser objects, exceptions, etc.
Malicious JavaScript inserted on the hijacked site

The code creates an IFRAME to hxxp://nysbrtyjdjntytdrj7yn.rr.nu/?go=2. This address is not blocked by Google Safe Browsing at this time. I was not able to retrieve the content.
Deobfuscated JavaScript


The domain rr.nu has been widely abused. It has been linked to the Mac Flashback Trojan, previous Fake AV campaigns, etc.

budget.gouv.fr is not the only governmental website that has been hijacked recently. In the last three months, we have seen many hijacked government sites including:
  • Australia: library.cgg.wa.gov.au, ofv.sa.gov.au
  • US: cityofhampton-ga.gov, sandy.utah.gov, governor.virginia.gov, letsread.cobbcountyga.gov, mississippi.gov, etc.
  • Philippines: car.dost.gov.ph
  • Colombia: acuavalle.gov.co, risaralda.gov.co
  • Malaysia: ipharm.gov.my
Unfortunately, no website can be fully trusted anymore.

Monday, April 16, 2012

Search Engine Security for Google Chrome

Google Chrome has recently added an API to modify HTTP headers. This in turns, made it possible to port Zscaler's Search Engine Security add-on from Firefox and Firefox Mobile to Google Chrome.

Search Engine Security on the Chrome Web Store

Most hijacked websites used for Blackhat SEO check the Referer header and the User-Agent, to decide whether to redirect the visitor to a harmless spam page or to a malicious domain (Fake AV page, Blackhole exploit kit, etc.). By modifying these 2 headers when the user leaves a Google, Bing or Yahoo! search, Search Engine Security fools the hijacked site into thinking that the visitor is not a real user and therefore avoids redirection to the malicious content.

Search Engine Security enabled for Google

All the work is done in the background, so it can be tricky to understand exactly what happens, or even if the add-on is working. We have therefore added a small note on the Google/Bing/Yahoo! search result pages to show you whether Search Engine Security is on (default settings) or off (disabled in the options):  Zscaler SES on or Zscaler SES off.

Search Engine Security disabled on Bing

To understand how the the headers are modified, look for "referer mobilefish" in Google after you have installed Search Engine Security. Click on the first link "Mobilefish.com - Show my IP". The page will display your User-Agent string and Referer header. With the default settings, the string "slurp" is appended to your User-Agent, and the Referer header is removed. These changes are done only when leaving a Google/Bing/Yahoo! search page.

You can also enable/disable the various settings on the Search Engine Security options page to see how the User-Agent and Referer strings are affected.

Search Engine Security options

You can install Search Engine Security for Google Chrome in the Chrome Web Store.

Friday, April 6, 2012

Blackhat SEO back in Google searches

In 2011, Blackhat SEO links were pretty much absent from the most popular searches in Google. Instead, Blackhat SEO was used to target more specific searches. The technique heavily used to poison the searches for buying software online with hundreds of fake online stores.

Blackhat SEO

Things are starting to change in 2012. I ran some numbers on Google searches for the month of March 2012 and found:
  • 117 malicious domains, including 66 serving Fake AV pages and 35 fake online store domains
  • 1,142 spam/malicious links in Google searches, including 299 links leading to a Fake AV page
The number of new domains hosting fake online stores is slowly decreasing, I found only 6 new domains in March, but the number of Fake AV sites has increased significantly.

While Google search results leading to Fake AV pages used to be caused primarily by hijacked sites that were redirecting the entire site to a malicious domain, the current increase is due mostly to the targeted use of Blackhat SEO for popular searches, as it was in 2010. The big difference with current results compared to those in 2010 is that Google is doing a much better job at flagging these malicious links: 294 of the 299 search results leading to a Fake AV page were flagged by Google.

The spammers are still able to get their spam pages on hijacked sites to appear on the first result page for popular searches such as "puerile in a sentence" and "edhelper password".

Malicious link in first result page
The technique used is still the same. Websites are hijacked and new pages are added. Each new page is targeting a popular search term trending in Google Hot Trends. Pages from different hijacked sites are linked together to increase their rank.

As I mentioned in an earlier post, the Fake AV pages still look the same, but surprisingly, use new source code with no obfuscation in most cases.

Fake AV instead of Fake store

The second trend I see is the increase in Fake AV links in searches related to software sales, like "Buy Windows 7". This is something I noted last year. The increase in search results leading to malware (Fake AV pages and others) where you would usually find fake stores is alarming because Google has not yet cleaned up these results. None of the spam links sending users to fake stores are flagged by Google.

Search Engine Security

The best tool to protect yourself against Blackhat SEO is Search Engine Security, a free browser extension from Zscaler. It was available for Firefox only, but versions for Google Chrome (currently waiting for approval in the Google Chrome Store) and Internet Explorer will be available shortly.

Friday, March 30, 2012

On-Going Dynamic FakeAV Campaign

Looking back on traffic from this week, I noticed a large spike in the number of companies accessing free TLD / Dynamic DNS related sites.  Digging deeper it appears that a malware campaign tied to massive WordPress compromises was the culprit.  This is a very widespread malware campaign that remains live / on-going and is currently redirecting to FakeAV websites.  The campaign is making use of auto-domain generation and auto-updating of infected sites to change the embedded link with every visit.  Some major infected sites that remain live include: psoftsearch.com and sql-plus.com (careful if you visit these sites as they are currently infected).  We are in the process of reaching out to victim sites and assisting with handling the incident.  Here are the initial details:

There were over 100 of our customers attempting to access a large number of websites on a handful of IPs with domains matching the pattern:
[3-6 random letters][2 digits][3-6 random letters].rr.nu
Given the very, very large number of domains used, this has to be some auto-domain generation/registration algorithm used in this campaign.

The pages accessed in the campaign includes:
/n.php?h=1&s=mm
/mm.php?d=x1
/nl.php?p=d

Tracing referrer strings in our logs, here is one live example:
www.psoftsearch.com/peoplebooks/  (infected PeopleSoft search site)
-->
tank95ersfl.rr.nu/mm.php?d=x1
-->
tank95ersfl.rr.nu/n.php?h=1&s=mm
-->
protectcustodianmonitor.info/39f678a0d39279b6/3/
-->
protectcustodianmonitor.info/39f678a0d39279b6/3/setup.exe

FakeAV page that dropped setup.exe:
MD5: 153ae4d1813c6d29a7809a62ff23f84c
VirusTotal reports 2/42 A/V vendors detect (very, very poor detection)

I re-downloaded the malware sample a few seconds later and the MD5 was immediately different.
Also a few seconds later, I re-visited the above site and the embedded link had already changed:
I refreshed the page, and sure enough the embedded link changed again.  Aside from the hosting IPs, this appears to be a dynamic FakeAV campaign.

protectcustodianmonitor.info resolves to 64.120.207.106 (HostNOC)
Based on other domains on this IP, this will be an IP that you'll want to blacklist - there are numerous other FakeAV sites hosted here (see list below).

It looks like the primary hosting IP of the ".rr.nu" redirect changes each day, for example:
194.28.114.103 and 194.28.114.102 used in an earlier Sucuri post on this.
March 27 it was: 195.88.181.112
March 30 (today) it is: 91.230.147.204

A number of pages on sites have been compromised to drive this campaign.  For example:
www.psoftsearch.com
www.sql-plus.com
www.frozencodebase.com
www.megafuentes.com
www.sdamned.com
genaud.net
www.pumpkinpatchdaycare.in
indianmuslims.in

Infected websites have injected "eval(base64_decode(...));" statements in their wp-config.php and other WordPress .php files to communicate back to a command and control to retrieve a list of websites to inject these ".rr.nu" site inclusions into pages.

---

195.88.181.112 hosting information:

inetnum:  195.88.181.0 - 195.88.181.255
netname:  INET4YOU
descr:       PE Bogaturev Sergey Anatolievich
country:    RU

person:          Bogaturev Sergey
address:         RU, Gornuy Shit, Komsomolskiy str.
phone:           +7(495) 324-35-69

route:           195.88.181.0/24
descr:           Subnet for servers and VPS
origin:          AS57621
mnt-by:          INET4YOURU-MNT

route:           195.88.181.0/24
descr:           Client_TC_WIFI
origin:          AS57189
mnt-by:          COMCORNET-MNT

---

91.230.147.204 hosting information:

inetnum:         91.230.147.0 - 91.230.147.255
netname:         zuzu-net
descr:           OOO "Aldevir Invest"
country:         RU

person:          Krutko Evgeni Yurevich
address:         192012, St.-Petersburg, Chernova ul., 25, office 12
phone:           +7812850202
e-mail:          aldevirinvest@lenta.ru

route:           91.230.147.0/24
descr:           Route for DC
origin:          AS5508
mnt-by:          zuzu-mnt

---

protectcustodianmonitor.info domain information:

Registrant Name:Leah  Carandini
Registrant Street1:54 Ridge Road
Registrant City:Cordalba
Registrant State/Province:QLD
Registrant Postal Code:4660
Registrant Country:AU
Registrant Phone:+61.733106403
Registrant Phone: gapes@cutemail.org

---

Other related FakeAV sites that resolve / resolved to 64.120.207.106:

agentcleanerrescue.info
agentkeeprisks.info
agentonlineinspector.info
areon-linescan.info
avdefendqueerprocess.info
cleanavcenter.info
cleanerspywaresecurity.info
cleanprotectionspyware.info
computerinformationthreat.info
controlpcon-line.info
controlsafetystability.info
datasaverprotect.info
debuggerrisksfirewall.info
debugscannerhazard.info
debugvulnerabilityfirewall.info
defenderoptimizermonitor.info
defendtasksspyware.info
delivererdangerkeep.info
delivereron-linepc.info
delivererpreventionthreat.info
delivererworms.info
detectdeliverertrojans.info
detectionprotection.info
efficiencyprotectordefender.info
guarantorthreatcenter.info
guarantorwarderdata.info
highcleantasks.info
inspectionprotectprotection.info
keepcenteron-line.info
keeperdetectormonitor.info
lowhighworry.info
lowwormstesting.info
microsoftdatacenter.info
optimizerscanningpc.info
perilsthreatworry.info
preventiondebuggercenter.info
protectcustodianmonitor.info
protectionvulnerabilityantivirus.info
protectorsolutionav.info
protectsecurityanalysis.info
protectwarderav.info
queerprocesscentersolution.info
queerprocessdetectionon-line.info
queerprocesshazardmonitor.info
reliabilitydefenderon-line.info
remedyscannerprevention.info
risksbrittlenesssafety.info
scannerfirewallrescue.info
scansupervisionprotection.info
securityavdebugger.info
solverqueerprocessinformation.info
solverremedylow.info
spywareantivirusworry.info
stabilitydatadetection.info
systemminimizeranalysis.info
taskssafetyremedy.info
testersolutionperils.info
warderdetectionkeeper.info
warderinspectionantivirus.info
warderrescuescan.info
windowsservantdefend.info
windowssolutionprotect.info
wormsdefenderagent.info
wormsminimizerdanger.info
wreckminimizerprotection.info

Tuesday, February 28, 2012

Fake AV: .ru sites used for redirections

This past month, I've seen an increase in hijacked sites redirecting to a Fake AV page. These attacks typically involves three separate phases:
  1. The hijacked website redirects users coming from a Google search to an external domain.
  2. A website redirects users to the Fake AV page or to a harmless site (mostly bing.com and google.com) depending upon the referer in step #1. This page adds a cookie using JavaScript, and reads it immediately, to make sure the page was accessed by a real browser that supports both JavaScript and cookies.
  3. The fake AV page is delivered.

Hijacked sites

I demonstrated last year that the Blackhat SEO attacks had migrated from the most popular searches to more specific searches like buying software online where up to 90% of the links returned are malicious. It comes as no surprise that about 95% of the hijacked sites were found for searches like "purchase microsoft word", "achat windows" ("buy Windows" in French), "precio office 2007" (Italian), etc.

There were 12 hijacked sites being used, with 3 domains representing 90% of the hijacked sites redirecting to a fake AV page:
  • politicalcampaignexpert.com (WordPress)
  • www.extralast.com (WordPress)
  • www.ukresistance.co.uk (blocked by Google Safe Browsing)
Redirection site

The domain used to redirect users from the hijacked sites to the fake AV pages are all .ru sites, with the same URL path:
  • bannortim-qimulta.ru/industry/index.php
  • daliachuuaroyalys.ru/industry/index.php
  • bannortim.ru/industry/index.php
  • uaroyalysdaliachu.ru/industry/index.php
  • uaroyalys.ru/industry/index.php
  • etc.
This page is used to differentiate between real browsers and bots or scanners. It uses JavaScript to write a cookie, and then reads it immediately thereafter. If the cookie is retrieved, the visitor is redirected to a malicious site, otherwise they are redirected to Bing or Google. Here is the snipped of the source code:

JavaScript and Cookie support test


Fake AV page

Fake AV page

Attackers are getting lazy! The fake AV page looks the same as it did two years ago and the source code of the page has barely changed. Fake AV pages used to change every 2-3 weeks when they were found all over the most popular searches, now they are remaining stagnant for six months. Here is the video that shows the Fake AV page in action:


As you can see in the video, the malicious executable is detected by 14 of 43 AV vendors.

Hopefully, one day Google will clean up the search results related to buying software as they did for the most popular searches. Until then, many users will end up on fake stores, fake AV pages or other malicious sites.  

Tuesday, December 6, 2011

Fake video codecs still going strong

Convincing users to download malicious software using fake AV pages is not a new attack vector, but has been a very successful one. Julien has previosuly blogged about how fake codecs are starting to replace fake AV pages. I recently encountered an interesting example employing both fake AV and fake codecs in a single attack. When a victim visits a page, they are presented with a warning message stating “You don’t have the correct Codec installed. Download should start automatically, if not, please click here to download”. Here is the screenshot of the page:

The page is loaded from “hxxp://onlinetubes24.com/go.html”. Let’s take a look at the HTML source of the page to identify the malicious code.


As you can see, it downloads an exe from “hxxp://privatetube.onlinetubes24.com/codec.exe". If the victim runs “codec.exe”, it starts a fake antivirus scan and delivers a report such as the following:


The above screenshot is typical of a fake AV attack and displays several fictitious threats being detected on the victim’s computer. Every time you run this exe file, different threats are allegedly detected . Once installed, the victim is asked to activate or buy the full version of this fake AV. This exe file downloads it’s content from a remote web server hosted at “94.23.39.156”. The ThreatExpert report for this IP address details the network activity performed by this malware.

The VirusTotal results for the fake security software in this example show that it is detected by only 20/42 popular AV vendors. You can find some tips to stay away from such attacks in a separate blog post.

Make sure you are downloading real codecs, not fake ones!

Pradeep

Tuesday, November 22, 2011

More software-related searches lead to malware

Spammers have done a very good job a hijacking web searches related to buying software online. More than 90% of search results for "buy Microsoft Windows" and similar searches, lead to fake stores on major search engines. Not much has been done by the search engines to clean up these search results.

Since the beginning of 2011, the number of search results for popular queries leading to fake AV pages and malware has dramatically decreased, especially on Google.

I've wondered when attackers would switch from the poisoning popular search phrases, to more targeted searches. In the past few weeks, I've seen more and more spam redirected to malware, where similar searches would previously have led to a fake online store.

For example, the website www.saloncti.com contains multiple spam pages around "buy microsoft office" (be careful if you decide to follow the search results). These spam pages are very similar to the spam pages leading to fake stores.

Spam page on http://www.saloncti.com/?p=1523
Instead of a fake store, the visitor is redirected to at least three types of malware.

Fake AV

One of the malicious redirections is to 31.44.184.89. It hosts a Fake AV page. Although the page looks visually the same as the Fake AV pages I've seen so far, the source code is very different.

Here is a video of the Fake AV page. I quickly got blacklisted (see details below in the post), so I had to reconstruct the page on my local machine. On the real website, I would have been prompted to download an executable, which was malware disguised as an antivirus solution.



Naked Emma Watson video

I've described this malicious page in a previous blog post. Basically, the page looks like YouTube, with a purported video of Emma Waston naked. The "Play" button warns users that they don't have the latest version of Flash and tricks users into installing malware.

Fake Flash installation



Top 10 Famous Celebrity Scandals

This is a variation of the naked Emma Watson video. The page shows a picture of a scantily clad Paris Hilton. Again, the goal is to trick users into installing malware disguised as a Flash update.


The page was hosted on firstuzsoft.rr.nu and was not blocked by Google Safe Browsing. The malicious executable was detected by only 6 AV out of 43. Zscaler's free Search Engine Security add-on for Firefox, does protect against these types of sites.

IP checks

There are multiple redirections between the spam page on the initial site (www.saloncti.com) and the final malicious page (31.44.184.89 or firstuzsoft.rr.nu). The referrer and the IP address are checked along the way. Here is a sample of a redirection from a Yahoo! search, to the malicious domain:

  1. http://search.yahoo.com/ra/click?.bcrumb=tfNYWE9Y1t1&p=site%3Asaloncti.com%20software&cq=[...]
  2. http://www.saloncti.com/?p=1870 (302 redirection)
  3. http://74.63.193.178/tra1/change.php?sid=8 (302 redirection)
  4. http://74.63.193.178/tra1/got.php?sid=8 (302 redirection)
  5. http://www.communitysupportottawa.ca/cutenews/ip.php (302 redirection)
  6. http://www.skibec.ca/castor-kanik/cutenews/ss/2.php (302 redirection)
  7.  http://www3.bestiiarmy.rr.nu/?nlqqufcc=kuHa1bKbmpOZi%2BPdzaaUmNnsq56lopva18%2Bfl6Sqnp%2BU1Z3cntKV
After following a couple of search results, my IP address got blacklisted and I was redirected to ask.com instead of the malicious domain.

It is scary, but predictable, to see attackers switching their targets. I hope the search engines will take the threat of malicious executables more seriously than fake stores and clean up their search results. It will be interesting to see who has the best Blackhat SEO skills: people behind fake stores, or people behind fake AV/Flash pages.

Friday, November 18, 2011

When scammers call you at home

UPDATE: I've updated the post with a second Skype call I received on 1/17.

Scammers are always trying new ways to reach their targets to foil them into buying free software, sending credit card information, etc. Yesterday, they called me directly at home!

I was working on my computer when I got a Skype call from an unknown caller with a Skype ID of "NOTIFICATION® URGENT - WWW.SWNOW.COM - UPGRADE INSTRUCTIONS". The automated call explained that my "software protections" were disabled and I had to urgently go to www.swnow.com (spelled out in the call). I could not record the call, but it was very similar to what you hear when you visit hxxp://www.swnow.com/.

Skype call from a scammer

The call does not give any information about who is calling or what this "software protection" is supposed to be. It lasted 1 min. 50 secs. and basically just urged me to visit www.swnow.com.

Skype call information

When visited, hxxp://www.swnow.com/ displays a fake antivirus page. It looks different than the Fake AV sites that use Blackhat spam SEO to reach users. Of course, the site purports that numerous viruses are found on your computer...

Fake AV claim to have found viruses
The website is trying to sell the antivirus solution, rather than trying to get user's to install malware disguised as a free AV program. The website is well designed. The button "Activate Computer Protections" shows an "activation" form..

Check out form
Then, the website gathers some personal information (name, e-mail address, etc.) via the "activation" form.

Information gathering

Finally, the user is sent to a different website, securecheckouts.org, to process the payment.


Payment processing form

Looking at the HTML code, the page only contains an iframe, pointing to hxxp://www.liveadmin.com/affiliates.php?affil104, where the payment form is actually hosted.

HTML source of securecheckouts.org
There have been a steady rise of websites trying to resell free software (AVG and other antivirus, OpenOffice, P2P clients, etc.) or deliver fake stores that claim to offer software at deep discounts, etc. However, this was the first time that I've encountered a Skype call being used to push users to visit a fake store.


Second call

I received a similar Skype call on 11/17. I was urged to visit www.msgmf.com to protect my computer. Te website is similar to www.swnow.com. It tricks users into paying $19.95 through click2sell.eu for an antivirus.

Second Skype call spam
Fake antivirus on www.msgmf.com
Antivirus "activation" page
Payment form on click2sell.eu

-- Julien

Friday, August 26, 2011

Blackhat spam SEO trends in 2011

My last post on Blackhat SEO spam trends was posted in December 2010. Things have changed quite a bit in 2011.

Cleaner results in popular searches

The main target of search engine poisoning used to be popular searches found in the Google Hot Trends list. In several instances, popular searches contained up to 90% malicious links in the first ten pages. Currently, the number is between only one and three total malicious results in the first ten pages.

Still, in July 2011, we identified 60 popular searches which contained at least one malicious spam link. They led to 35 different fake AV domains and three other domains serving different types of malware.

Better protection

One of the big changes in 2011 is that various players appear to be taking action much more quickly in stoping hijacked sites from infecting users. Google has cleaner results and hosting companies are in general, much faster at taking down malicious domains. Antivirus vendors also seem to have better protection for fake AV pages (the fact that these pages are changing very slowly must help).

Webmasters seem to clean up their sites much faster as well. I believe that this is at least in part driven by better education as the threat of hijacked sites is now better known. Google has also helped to make webmasters aware of issues in their websites with warnings in Google Webmaster Tools, new warnings to users in search results and even direct e-mails to the owners of hijacked sites.

As a result, the number of spam pages redirecting to a malicious sites that are either down or have been cleaned up has increased significantly.

New targets

While the most popular searches are cleaner, a broader range of Google searches are now being poisoned. We recently demonstrated how Google News was redirecting users to malicious Java applets and Google Image search was poisoned for 6 months as well.

Searches for buying software online remains 90% malicious, redirecting users to fake stores. There has been no significant improvement on that front, with 60 different fake store domains observed in July 2011. This is a problem that pretty much all search engines are facing.

In total, I've found over 1,000 spam search results leading to 150 different domains, most of them were malicious. This is a conservative number as I did not include malicious sites that were down (but were likely infecting users in the past) and malicious domains which prevented me from accessing their content.

Distribution of malicious domains per category


Fake AV is still there

As you can see in the chart above, Fake AV sites are still present. They continue to look similar, both visually and in their source code. I've spotted 35 different Fake AV domains in July 2011. The usual suspects were there: 10 co.cc sites (xyfybir.co.cc, wydrjim.co.cc, ttvzxiw.co.cc, etc.), 6 co.be (vrtwyqz.co.be, urtty.co.be, etc.), etc.

Fake AV page seen on 08/22/2011

Google has definitely made progress cleaning their search results and hosting companies have been doing their part as well. It has been some time since I have seen a mass Google Web search poisoning like the millions of  "Hot Video" pages that we observed last year. The only exception would be for searches related to malicious online software stores.

I hope Google and other search engines vendors will continue to combat this threat.

-- Julien