Showing posts with label Trends. Show all posts
Showing posts with label Trends. Show all posts

Friday, June 26, 2015

Potentially Painful Programs Promising Pirated Products

A major source of PC compromise doesn't come from targeted APT campaigns or Exploit Kits, but user's clicking things that they simply shouldn't. A common practice for adware and spyware writers is hosting large numbers of seemingly legitimate files that users might trust from an unknown source. Users know trusted download locations for common packages like Flash Player or Skype, but when searching for pirated software or media, any link that promises results becomes a trusted source. ThreatLabZ has been monitoring a large campaign of two well known adware/spyware packages, namely OutBrowse and MultiPlug.

ThreatLabZ has observed filenames purporting to be popular software applications, PC games, movies, TV series, car repair guides, etc. being used to trick users into downloading and running spyware packages. Below is a sample list of filenames from this month:
  • Colin McRae Rally 2.0 Full Version - FullRip   Download Low Spec PC Games   RataMap   Download Low End PC Games.exe
  • adobe acrobat 8 standard serial number generator.exe
  • dell bluetooth headset bh200 driver.exe
  • Wii dance revolution.exe
  • Besiege Free Download Game.exe
  • Tropico Reloaded   Free Download PC Game Full Version.exe
  • Minecraft 1.8 Crack Full Free Download.exe
  • Dragon Ball Complete Series Episode1.exe
  • Home.2015.720p._-DL.MaZiKa2daY.CoM.mkv.exe
  • visual studio 2012 crack torrent.exe
  • LEXUS LS 460 user guide provided through pdfretriever.com.exe
Once installed, the user is shown unsolicited advertisements and experiences a substantial increase in browser tracking activity. We noticed the cyber-criminals involved in these campaigns heavily leverage .info TLD domains as seen in the table below:



Domain
Adware Family
a.webboxwebs[.]info
MultiPlug Adware
get1.0111design[.]info
Outbrowse Adware
a.positionpublic[.]info
MultiPlug Adware
a.parser-case-croc[.]info
MultiPlug Adware
get.0136g[.]info
Outbrowse Adware
a.linuxcallring-north[.]info
MultiPlug Adware
a.northsinglemultiple[.]info
MultiPlug Adware
get.0136h[.]info
Outbrowse Adware
a.valuevilleville[.]info
MultiPlug Adware
a.cooledon[.]info
MultiPlug Adware
a.beeforcelevel[.]info
MultiPlug Adware
a.stickercenter[.]info
MultiPlug Adware
get.0136i[.]info
Outbrowse Adware

OutBrowse

The OutBrowse family authors leverage popular TV shows, software applications and trending news to deliver custom payloads that monitor the user's browsing activity. Their business model is to direct users to a pay site that provide various services.


Didn't I just download Tony Hawk Pro Skater2.Crack.CDKEY.exe?
The phone home communication for OutBrowse also provides excessive information to the advertisers. This data often includes the system's MAC address, IP address, different browser versions installed, and the machine GUID.


Data Collection from the victim's system.

OutBrowse beacons to several domains to share machine details and send aggressive advertisements. We have been monitoring this activity to the following domains for several months:
  • srv.dmdataserver[.]com
  • static.revenyou[.]com
  • srv.desk-top-app[.]info
Consistent traffic to known Outbrowse beacons

OutBrowse is normally found on the victim's machine by inspecting the user's C:\Documents And Settings\user\Local Settings\Temp\ directory for any suspicious files. It's common for OutBrowse to also install other bundled software packages as well. Users should check their autostart programs and Browser Helper Object (BHO) entries for software that is suspicious.

OutBrowse installed MiniGet as a BHO and Content Menu in Internet Explorer


MultiPlug

MutliPlug is another adware package that is installed as part of this campaign. The purpose of this package is to provide a custom executable to the victim that leads to additional bundleware. After a successful MultiPlug infection, we noticed applications like LightningDownloader, SeekerFoobar, WeatherBug, and EasyAutoRefresh getting dropped on the victim machine.


Silent Installers seen to download additional adware packages.
Once MultiPlug is installed, it starts downloading and installing additional packages in the background while displaying unsolicited advertisements.


A common location-targeted advertisement seen from a package installed by MultiPlug
Highly aggressive advertisements attempting to lead the victim to buying software.

The best way to remediate this attack is to review all installed programs through Windows Control Panel and odds are good that MultiPlug installed at least multiple unwanted software packages. Once this is done, users should review their autostart job files in the C:\WINDOWS\Tasks\ directory for anomalous entries. Installed Browser Helper Objects should also be checked using applications like HiJackThis or X-rayPC.

ThreatLabZ has been closely monitoring these campaigns for the past few months and the trend shows no sign of slowing down as seen in the time chart below:


Several sites are phishing users with the promise of illegally obtained content

The bulk of these attacks are hosted in the United States.




Conclusion
The moral of this story is to not trust seemingly legitimate content if you are attempting to obtain it illegally. Users show a distinct lapse in judgment when they believe the desired content is available for free. We recommend not attempting to pirate content and simply paying for the media desired.

Wednesday, October 31, 2012

Enterprise Traffic Decrease In Wake of Hurricane Sandy

We have received several requests inquiring as to the changes in enterprise Internet activity in the regions impacted by Hurricane Sandy.  There is no question that the hurricane impacted the US in a variety of ways.  Zscaler provides security and policy enforcement for web and email network traffic for Enterprise users, while in the office or working remotely.  Given the role that Zscaler plays, we are able to do regional traffic comparisons from enterprises from last Monday/Tuesday ("normal") with this Monday/Tuesday (impacted by hurricane).  Enterprise web traffic can be seen as one measure of economic productivity.

Region: Washington D.C.
Zscaler has regional nodes in and around the Washington D.C. area to service regional customers and road-warriors in the area.  The following details the transactions per hour from last week (in blue) compared with those from this week (in red):


The two blue spikes on the chart correspond to the workdays last Monday and Tuesday (beginning around 6AM and ending around 7PM local time).  The two small red humps correspond to the workday traffic observed this week during Hurricane Sandy.  It is immediately apparent that there was a significant decline in the transactions from Enterprise customers during the hurricane.  More specifically, we observed an average decline of 60.93% in transactions from the previous week.  Another view of this data can be seen in the following pie chart showing the percentage breakdown of transactions across the dates being compared.

Region: New York City / New York
As with Washington D.C., Zscaler has multiple nodes in the New York area to support regional customers and road-warriors in the area.  The following charts provide a similar comparison to that previously listed in the Washington D.C. region.  The blue line represents transactions serviced last Monday/Tuesday and the red lines from this week, impacted by Sandy.  To provide a little different illustration - we have selected two New York nodes to provide a more granular comparison of traffic across the two weeks.



The New York node 1 had an average decrease of 58.14% from the previous week, and node 2 had an average decrease of 52.31%.

In the wake of Hurricane Sandy we observed specific regional declines in traffic from our enterprise customers.  From the specific regions / nodes analyzed here, there was an average decline of 57.13% in web transaction from last week (normal customer activity) to this week (hurricane impact).  Enterprise traffic could be seen as one measure of economic productivity. 

Tuesday, August 7, 2012

Most common threats in top blacklisted sites

The vast majority of the most popular blacklisted websites contain a piece of malicious JavaScript inline. These sites were mostly hijacked by attackers and the malicious code can usually be linked to the Blackhole exploit kit.

Malicious code found on top blacklisted sites
I was surprised to find malicious Java applets in second place, having been found on 10% of the blocked sites. Malicious iFRAMEs were the third most prevalent infection and generally resulted from  mass SQL injection attacks. Only 2% of the sites are trying to foil users into downloading a malicious piece of code through a fake AV, Flash or codec page.

The scam and spam sites are mostly survey scams (the-rewardline.com, station-awardz-central.com, channelrewardscenter.org, etc.) and work-from-home scams (financereports.co). These sites have been blocked by Google Safe Browsing for months.

Since most the blocked sites are legitimate sites with high traffic, they quickly get cleaned up and removed from the Google blacklist. While the average number of days a top-site is blocked by Google is 7 days, the graph below shows that the vast majority are blocked for only a few days:


The number of top-domains blacklisted, can vary considerably on a daily basis, but the trend is upward - from an average of 400 sites in May to more than 1,000 in July.

Number of top-websites blacklisted daily by Google

Here are the top-ranked websites blacklisted by Google since May 2012:

Domain Alexa rank Country
blog.com 681 PT
fatakat.com 699 US
ziddu.com 878 GB
warez-bb.org 1,029 RU
vanguardngr.com 1,528 US
prlog.org 1,555 US
damnlol.com 1,949 US
arabseed.com 2,002 US
h33t.com 2,213 CA
geo.tv 2,606 GB

Small or big, popular or not, all websites are under attack. No domain can be fully trusted and you never know if attackers managed to breach the protections of the website that you're currently on.

Friday, April 6, 2012

Blackhat SEO back in Google searches

In 2011, Blackhat SEO links were pretty much absent from the most popular searches in Google. Instead, Blackhat SEO was used to target more specific searches. The technique heavily used to poison the searches for buying software online with hundreds of fake online stores.

Blackhat SEO

Things are starting to change in 2012. I ran some numbers on Google searches for the month of March 2012 and found:
  • 117 malicious domains, including 66 serving Fake AV pages and 35 fake online store domains
  • 1,142 spam/malicious links in Google searches, including 299 links leading to a Fake AV page
The number of new domains hosting fake online stores is slowly decreasing, I found only 6 new domains in March, but the number of Fake AV sites has increased significantly.

While Google search results leading to Fake AV pages used to be caused primarily by hijacked sites that were redirecting the entire site to a malicious domain, the current increase is due mostly to the targeted use of Blackhat SEO for popular searches, as it was in 2010. The big difference with current results compared to those in 2010 is that Google is doing a much better job at flagging these malicious links: 294 of the 299 search results leading to a Fake AV page were flagged by Google.

The spammers are still able to get their spam pages on hijacked sites to appear on the first result page for popular searches such as "puerile in a sentence" and "edhelper password".

Malicious link in first result page
The technique used is still the same. Websites are hijacked and new pages are added. Each new page is targeting a popular search term trending in Google Hot Trends. Pages from different hijacked sites are linked together to increase their rank.

As I mentioned in an earlier post, the Fake AV pages still look the same, but surprisingly, use new source code with no obfuscation in most cases.

Fake AV instead of Fake store

The second trend I see is the increase in Fake AV links in searches related to software sales, like "Buy Windows 7". This is something I noted last year. The increase in search results leading to malware (Fake AV pages and others) where you would usually find fake stores is alarming because Google has not yet cleaned up these results. None of the spam links sending users to fake stores are flagged by Google.

Search Engine Security

The best tool to protect yourself against Blackhat SEO is Search Engine Security, a free browser extension from Zscaler. It was available for Firefox only, but versions for Google Chrome (currently waiting for approval in the Google Chrome Store) and Internet Explorer will be available shortly.

Tuesday, March 20, 2012

"Super Bowl" and "March Madness" in the Enterprise

3/26 Update: I was approached and asked to run stats to do a bit of comparison and contrast with Sports traffic from last year - with the goal in mind to identify if there was a noticeable percentage increase in Sports (March Madness) this year compared to last year. There was a two day difference from March 2011 to 2012 for the tournament dates - these are noticeable in the tracked stats. The data shows only a slight increase (<1%) in March Madness traffic this year compared to last year - in general this appears to be a fairly static and expected event within Enterprise traffic.




With the Super Bowl in early February and the NCAA basketball tournament ("March Madness") sports are a major focus of attention in Quarter 1. That means a lot of bandwidth consumed by the enterprise and time spent by employees on this subject. One report calculated that an estimated $1.7B is to be lost in productivity at the office during this March Madness. Even if sports are not your thing, you may find yourself participating in an office pool surrounding the Super Bowl or March Madness. When I was filling out my bracket this year, I found myself on some "gambling" web-sites to do some quick research on team odds in the tournament (not that it helped my bracket any). I was curious how much bandwidth we saw across our enterprise customers related to sports and gambling for these major Q1 sporting events and to also see if there was any correlation. For those interested in tracking this subject, here are my findings from our large, diverse, enterprise customers:

The above blue line represents gambling traffic as a percentage of its total seen thus far for the quarter, and the red line is sports traffic as a percentage of its total seen thus far for the quarter. The cyclic nature of our data-set is because this is from our enterprise customers -many of which have less employees working on weekends. (Date periods are related to PST time)

There were not large noticeable spikes in sports or gambling traffic observed in the enterprise during the NFL playoffs or Super Bowl - likely due to the fact that the NFL games are on the weekend and toward the end of the season may have a more regional versus global fan base.

However, there was a very noticeable increase in traffic surrounding March Madness - particularly during the 2nd round of games, several of which are televised during US work hours. Specifically the start of March Madness had about a 74% increase in sports related traffic from the Super Bowl.

Throughout our Q1 data-set we see that gambling closely follows the traffic patterns related to sports. In the case of the noticeable spike in sports traffic, we see a similar related pattern increases in gambling traffic. One major exception related to gambling was the period of Feb 20 -22. While most of the baseline gambling traffic are online casinos and gambling affiliates -- looking more closely at the website paths visited related to gambling within this period determined that this anomaly was caused due to the ICC Cricket World Cup in which many of our Australian and Indian customers were following the games.

Chances are that traffic from your enterprise participated in one or more of these events during this Q1.

Thursday, January 19, 2012

SOPA Protest: Wikipedia Traffic Trend (updated)

Updated 1/19: we have updated charts and the narrative to reflect all of 1/18 (protest timeframe) data and the first 10 hours of today. The last graph shows about a 365% increase in visits to their SOPA Initiative page and >77% increase across SOPA related page visits during the protest - this visually shows the success of Wikipedia's protest in which it is successfully spreading their message and educating visitors on SOPA. The middle graphs visually show an increase in unique visitors, while the number of transactions per visitor decreases throughout the protest - a phenomena that we have called "online rubber necking," in which visitors are there to see the protest page and perhaps inform themselves about the issue but are not accessing the site in the "normal" manner in which many more pages/media files are accessed.


If you want a quick way of increasing traffic to your website - change or take down portions of your website in protest ... at least that is what we have gleaned from today's (1/18) Wikipedia protest against SOPA. There will likely be other blog posts and stats released on the results of this and other cyber protests - here is what we have seen from traffic thus far that has passed through one of Zscaler's clouds.

We observed a noticeable percentage increase in the unique visits (by client IP address) to Wikipedia comparing the protest timeframe to the surrounding dates:


However, these additional visitors are not incurring that much more bandwidth for Wikipedia - we have noticed only a slight percentage increase in Wikipedia web transactions today. See the chart below to see the slight increase in number of transactions per hour:

We can combine the two above graphs into a graph of transactions per unique visitor, and we see that this is much smaller today. This suggests that more people are flocking to Wikipedia today, but just to see the protest page and some details on SOPA. This behavior could be described as "online rubber necking".


We observed significantly more visits to Wikipedia's main page and SOPA Initiative page than the surrounding dates - further corroborating our above statements:

From the above stats we are able to visually represent the Wikipedia protest and the Internet community's "rubber necking" behavior in which the number of visitors increase but the transactions per vistor decreases. While not the goal of Wikipedia's protest, from a media and public relations standpoint these types of Internet events can stand to be beneficial or even lucrative. This last graph shows a large volume of people checking out the protest page. However, there too was about a 365% increase (going from about 16% to 75% of the visits) in visits to their SOPA Initiative page and >77% increase (going from about 9% to 16% of the visits) across SOPA related page visits during the protest - this visually shows the success of Wikipedia's protest in which it is successfully spreading their message and educating visitors on SOPA. I would expect that this may be a sign of the times to come given the successful results of the protest on the Internet and that the message was received on Capitol Hill (reference on which Senators dropped support for SOPA).

Wednesday, December 28, 2011

Web threats: trends and statistics

One of the question I often get asked is "What is the most prevalent threat on the Internet for the enterprises?". In terms of the total number of transactions, botnets are the biggest security risk. Once a host gets infected, the botnet usually spreads quickly within an enterprise. It also generates a significant amount of traffic to the command and control server, to download additional malware or perform other actions. For the last 30 days, botnets account for almost 80% of the security blocks at Zscaler.

Security blocks for the last 30 days


When it comes to individual variants of malware, botnets, or other threats, there is no single piece of malware that dominates. Some threats appear one day, and disappear just as quickly. Others are seen daily for months, with random peaks. For example, Blackhole exploits and Zeus have been active for months.
One of the Blackhole exploits
Zeus traffic
Mass infections of legitimate sites can still be seen months after the infection initially occurred and the vulnerable application has been patched. For example, our customers are still hitting websites infected with Lizamoon which was first reported in May 2011 and reached it's peak in September.
Legitimate sites infected by mass LizaMoon SQL Injection attacks
The security landscape is very wide. Although botnets, as a category, represent the majority of overall malicious web traffic, there are a huge number of different threats seen daily by enterprise users. This means that security solutions must be able to detect and block a wide variety of traffic by looking at all components: URLs, HTTP header and content on both the client and server side.

Tuesday, November 29, 2011

Cyber Monday Transactions - Indication of Economy?

Last year I did a post on the transactions that we saw related to online shopping on Cyber Monday - as I indicated in the past, yes there is a spike. And looking at the transactions this year, again we notice a spike:
You can see the cyclic nature of the work week given that we handle enterprise traffic. The Y-axis values are is the monthly percentage of online shopping/auction transactions. So Cyber Monday made up 7.51% of the November 2011 shopping transactions and Black Friday made up 3.82%. The average for the month was 3.57%, excluding weekends the average for the month was 4.53%. These stats look at web transactions from a "micro" level - looking at a a longer-term trend across Black Friday and Cyber Monday online shopping transactions:

We notice a downward trend in online shopping transactions from 2009-2011 Black Fridays and that online shopping transactions have remained fairly static from 2009-2011. In this case the Y-axis is the percentage of online shopping transactions for the day - for example, 4.63% of this Cyber Monday's transactions were online shopping. The precise numbers for the other Cyber Mondays were 4.68% in 2009 and 4.61% in 2010. So there was a 0.05% decrease from 2009 to 2010 and a 0.02% increase in 2011. Given the general increase in online shopping vendors, general awareness of "Cyber Monday", and people being more comfortable making online purchases I would expect Cyber Monday online shopping to noticeably trend upward. Black Friday online shopping trended downward year over year, and we see the Cyber Monday downturn in 2010 and the slightest increase / stagnation in 2011 -- these online shopping stats may provide an indication as to the health of the economy.

Wednesday, October 26, 2011

IPAbuseCheck Stats

Last week, we announced our IPAbuseCheck lookup tool. We see lots of infected/abusive hosts on the Internet attempting to proxy abusive web transactions through our proxies. Rather than just ignoring these transactions, we’ve decided to provide this lookup utility for security professionals and organizations to query and identify abusive/infected hosts within their networks – based on some feedback, the service has been well received. This follow-up post provides a brief summary of the top offenders that we see in our database to date (July 1 – October 25, 2011).

Top Abuse Breakdown by Geography
The top 15 countries account for over 75% of the abusive clients that we have seen- with the US, China, Russia, Germany, Venezuela, and India accounting for half of the abusive clients that we have seen to date.


Top Abuse Breakdown by Organization (ASN)

ASN by Abusive ClientsASN by Abusive Transactions
ASN% of Clients
AS4812 China Telecom6.32%
AS4134 Chinanet5.16%
AS8048 Servicios, Venezuela3.82%
AS4837 CNCGROUP 2.54%
AS15857 Telefonia Dialog S.A.2.53%
ASN% of Transactions
AS14618 Amazon.com, Inc.25.16%
AS8069 Microsoft Corp10.23%
AS8075 Microsoft Corp9.92%
AS4134 Chinanet5.02%
AS28753 Leaseweb Germany4.28%

It was interesting to see some well known organizations like Amazon and Microsoft near the top for organizations that have sent us the most abusive transactions. Rather than these being infected corporate systems, it appears to be a handful of hosting service systems that are being abused either directly from the customer or from an infection. Here is a snapshot of a report from our database of a Microsoft IP that we reported to their Abuse Dept. once we started digging into this data:

70.37.48.163
OriginAS: AS8075
NetName: MICROSOFT-DYNAMIC-HOSTING

Screenshot of 70.37.48.163 Abuse Report

The transactions observed were hundreds of thousands of brute-force attempts against file sharing sites like Megaupload, Hotfile, Filesonic, and Rapidshare.

Top Abuse Breakdown by Client
Clients in our database that have the longest time range of abuse seen tend to be those clients that are scanning the Internet looking for open web proxies. These were the top 5 clients that we have seen with the longest date range from:

Top 5 Abusive Hosts by Date Range
HostFirst SeenLast SeenBehavior
193.17.253.707/01/11 07:0010/25/11 06:54Proxy Scanning
207.226.163.14607/01/11 07:0010/25/11 06:51Proxy Scanning
174.34.168.11407/01/11 07:0610/25/11 06:57Proxy Scanning
221.187.4.2807/01/11 07:0710/25/11 06:56Proxy Scanning
69.164.211.21207/01/11 07:0810/25/11 06:54Proxy Scanning

The following table lists the top 5 abusive hosts by transaction count - these tend to be hosts that attempt to forward bulk transactions through proxies, like forum spam and brute-force attempts. Related to the previous section of organizations with the top abusive transactions - you can see that two Amazon EC2 systems (75.101.225.168, 248) are at the top of the list.

Top 5 Abusive Hosts by Transactions
HostTransaction %Behavior
75.101.225.16819.94%Forum Spam
111.221.81.706.31%Forum Spam
75.101.225.2485.17%Forum Spam
117.41.235.1333.06%Brute-Forcing
84.16.224.622.13%Brute-Forcing

Top Web Services Targeted in Abuse
The following lists the top 5 most targeted web sites/services abused by number of transactions and number of unique abusing clients.

Top 5 Abused Web Services by:
Abusive Transactions:
  1. forum.zing.vn
  2. dbol.vn/forum/
  3. forum.sonlaol.vn
  4. api.rapidshare.com
  5. vdrz.vn/f/
Abusive Clients:
  1. chek.zennolab.com
  2. login.sina.com.cn
  3. clickingagent.com
  4. p24.easybitsgo.net
  5. checker.samair.ru
The bulk of the top sites by transaction are forum spam sites - in the top instances, the forums being abused are in Vietnam. One brute-forcing target is in the top 5, which is the Rapidshare file host. The bulk of the top services being used/abused by number of clients are proxy checkers - the Chinese service sina.com.cn was also listed in the top as a spam bot / brute-forcing target.

The above post provides some insight into the types of information that can be extracted from this service, and we'll continue to update the database regularly with the latest abusing clients.

Thursday, September 15, 2011

Thousands/Millions of .tk sites created for fake online stores

While I was monitoring hijacked sites leading to fake online stores, I noticed a significant increase in .tk sites redirecting to searchdiscovered.com via domain.dot.tk. There are a number of interesting things going on with these .tk sites. First, the spammers have decided to create their own sites rather than hijacking existing sites with good reputation rankings. Doing a Google search, I found thousands of these sites: fidymarch.tk, isaftaho.tk, isaftaho.tk, jedkyosculit.tk, flicreuci.tk, meicatec.tk, etc. There may be up to 6 million sites like this.  Most of the domains are registered by two entities: DOT TK and Malo Ni Advertising Limited (Isle of Man).

WHOIS information for isaftaho.tk

http://dot.tk/ offers free .tk domains and redirections, like co.cc, so it is is not surprising to see this service being abused.

Free .tk domain names

These .tk sites contain only spam, unlike hijacked sites, which contain both legitimate content and spam. They look all pretty much the same. The previous spam pages I saw were using only text, with no images. These sites look more like online stores, with images, and links to the actual fake stores

Spam page from cetescawin.tk

The fake online stores linked from these spam sites are the same as the fake stores that I saw earlier: same template, same translations into 5 languages, same discounts, etc: cheapoem.com.ua, discountsoftware.com.ua, etc.

Fake store discountsoftware.com.ua
Down .... but still there

About half of the .tk domains I've tried seem to be down. They redirect to domain.dot.tk, then to searchdiscovered.com which seems to be a parking domain.

Domain parked on searchdiscovered.com
It is very likely that the .tk domains were suspended by the registrar Dot.tk, and now redirect to to a parking domain where the registrar can make some money for it's free service with the advertising.

These domains are not harming users anymore, since they redirect to a harmless advertising page instead of a fake store. But it is disappointing that they are still in Google's index, and show up for queries related to buying software online. For example, Google displays more than 600 spam pages for the domain cetescawin.tk.

The second take away is that these dead domains illustrate why it is more effective for the spammers to hijack existing sites rather than create their own. With their own spam sites, it is very easy for both the registrar and Google to take down the entire domain, but is is not likely that Google, or any other search engine, or for example that the registrar Educause is going take down harvard.edu because some sub-domains of their sites contain spam.

Protect yourself

Users can be warned when they visit a fake online store by installing the free Zscaler Safe Shopping add-on for Firefox, Safari, Chrome, Opera and Firefox Mobile.

-- Julien

Wednesday, August 31, 2011

Fake stores on other search engines

A few weeks ago, I showed that even search engines focused on eliminating spam from their search results fail to remove spam pages leading to fake online stores. I was curious to get a broader pictures of how different search engines deal with this issue. Since the fake stores exist in several languages (English, French, German, etc.), this issue affects web users in many countries.

I decided to check how spam pages for "Buy Windows 7 key" (or its translation) are displayed in the first two pages (20 results) for various search engines. For reference, the numbers for the 3 main search engines in the US are:

Russia
Yandex contains a lot of blackhat spam in general, much more than Google and not just for fake stores. While Google has cleaned up search results for popular queries, especially spam leading to fake AV pages, I have seen no progress on Yandex.

Yandex shows only spam pages leading to fake stores in the first 2 pages

China
A lot of the spam pages are hosted on Chinese websites (for example):
  • hxxp://nimende.com/notcjjff83/2011/08/29/ubuntu-10-04-lts-debut/
  • hxxp://bbs.52pk.com/thread-4913231-1-1.html
  • etc.

Spam pages and fake stores on Baidu

Germany
Yahoo.de and Bing.de show very similar search results. The first result page shows mostly spam pages hosted on German sites, while the second pages contain spam in German languages on US .edu sites.


Yahoo.de gives worse results than the US site
Italy

Italian spam pages on Google.it

France
Voila.fr and Google.fr give priority to web sites located in France. Most of the hijacked sites hosting spam are US University sites, hence they get a lower ranking.

DuckDuckGo

DuckDuckGo is a a one-man search engine that is gaining a lot of attention in the start up community. All results appear on the same page. Out of the first 20 results, 12 are spam pages.

The first 3 results on DuckDuckGo, all spam

As can be seen from the results, blackhat SEO spam is a global problem, not just one affecting the popular US based search engines. In fact, overall, the US seems to be in slightly better shape than some countries
such as Russia, China and Germany that may not yet have suffered the same battle scars in this fight.

-- Julien