Showing posts with label affiliates. Show all posts
Showing posts with label affiliates. Show all posts
Friday, June 22, 2012
Fake Flash update with a twist
This summary is not available. Please
click here to view the post.
Wednesday, January 25, 2012
Fake missing plugin warnings used for spam/spyware
A key element for a successful spam/malicious page is to establish trust with the visitor so that he will perform the requested actions. Users trust their browser, but not necessarily the content (i.e. web page) that it displays. A trick that I've blogged about earlier, is to fool the user into thinking that certain elements on the page are actually from the browser.
Recently, I've seen several websites showing a fake warning for a missing plugin. The fake warning is designed to look the same as the real warning shown by Firefox when the page requires a plugin that is not installed: a yellow bar at the top of the page with a link to install the plugin on the right, and a blue icon on the left.
On allostreaming.biz (French language), the fake warning is for a "missing" VLC plugin. You can tell that the warning is part of the page, and not part of the browser, because the scroll bar goes to the top of the warning, whereas the real warning is above the scroll bar (see the image above).
A look at the source code shows that the warning is indeed HTML from the page:
The "VLC plugin" is the classic pay-per-install bundle, where the spammer gets paid for tricking the users into installing spyware/adware.
The spammers are using the same fake warning on all browsers, which is also a giveaway as browsers other than Firefox don't actually have the same warning for missing plugins. Anyway, the attack will likely fool users of other browsers into installing this adware/spyware.
Recently, I've seen several websites showing a fake warning for a missing plugin. The fake warning is designed to look the same as the real warning shown by Firefox when the page requires a plugin that is not installed: a yellow bar at the top of the page with a link to install the plugin on the right, and a blue icon on the left.
| Legitimate Firefox warning for a missing Adobe Shockwave plugin |
On allostreaming.biz (French language), the fake warning is for a "missing" VLC plugin. You can tell that the warning is part of the page, and not part of the browser, because the scroll bar goes to the top of the warning, whereas the real warning is above the scroll bar (see the image above).
| Fake warning for missing plugin |
| HTML code for the fake warning |
The spammers are using the same fake warning on all browsers, which is also a giveaway as browsers other than Firefox don't actually have the same warning for missing plugins. Anyway, the attack will likely fool users of other browsers into installing this adware/spyware.
Labels:
affiliates,
analysis,
Fake codec,
plugins,
Rogue software,
social,
spam
Tuesday, January 3, 2012
Google serves ad for Adware/Spyware
Last year, we wrote about Bing and Yahoo! serving ads leading to malicious websites. This week, it was Google who inserted ads for adware/spyware.
I found a suspicious ad in my Google Reader for a free FLV player. I've recently shown that this type of free software is regularly repackaged with adware/spyware for profit.
The ad leads to a download page for FoxTab FLV Player. There is a disclosure statement at the end of the page discussing the content of the bundle: "This product is totally free and offers the user additional bundle products that may include advertisement."
The adware/spyware is flagged by only 4 antivirus vendors out of 43. A behavioral analysis of the executable provided much more information about packages that were downloaded and ports open on the machine, etc.
The ad was found on the RSS feed of a security company specialized in cleaning up infected websites. This highlights the fact that even reading content from otherwise legitimate resources can inadvertently lead users to unwanted applications when sites include third-party elements (JavaScript driven ads in this case, but also IFRAMES, widgets, etc.) that they do not not have control over. Even trusted third-parties like Google are apparently not succeeding in delivering 100% adware/spyware free content to users.
Happy New Year 2012!
I found a suspicious ad in my Google Reader for a free FLV player. I've recently shown that this type of free software is regularly repackaged with adware/spyware for profit.
The ad leads to a download page for FoxTab FLV Player. There is a disclosure statement at the end of the page discussing the content of the bundle: "This product is totally free and offers the user additional bundle products that may include advertisement."
| FLV Player download page |
The adware/spyware is flagged by only 4 antivirus vendors out of 43. A behavioral analysis of the executable provided much more information about packages that were downloaded and ports open on the machine, etc.
The ad was found on the RSS feed of a security company specialized in cleaning up infected websites. This highlights the fact that even reading content from otherwise legitimate resources can inadvertently lead users to unwanted applications when sites include third-party elements (JavaScript driven ads in this case, but also IFRAMES, widgets, etc.) that they do not not have control over. Even trusted third-parties like Google are apparently not succeeding in delivering 100% adware/spyware free content to users.
Happy New Year 2012!
Labels:
affiliates,
analysis,
Compromised,
google,
Rogue software
Monday, March 14, 2011
Facebook Likejacking, phishing and spam
Last Thursday, I wrote about Facebook Likejacking. Today, similar pages were brought to my attention. They use Likejacking to spread through user profiles using much more aggressive spam techniques.
The pages looks like they come from Facebook. The teaser is a video that should be watched "only if you are 16 or older". The play button hides a Facebook Like widget.
Before the user can play the video, he must either verify that he is at least 18, or that he is a human ... by filling out surveys, trying games, etc.! The spammers are paid for each action taken by the user (PTC campaign).
If you stay on these pages long enough, they will attempt to send a form on your behalf. Fortunately, Firefox throws a warning.
acidattacker.com shows a Facebook page and a Youtube page with the same content.
These spam pages can be found at:
-- Julien
The pages looks like they come from Facebook. The teaser is a video that should be watched "only if you are 16 or older". The play button hides a Facebook Like widget.
| Spam page looking like Facebook |
Before the user can play the video, he must either verify that he is at least 18, or that he is a human ... by filling out surveys, trying games, etc.! The spammers are paid for each action taken by the user (PTC campaign).
| "Security check": the user must fill out a survey |
If you stay on these pages long enough, they will attempt to send a form on your behalf. Fortunately, Firefox throws a warning.
| Firefox prevent the automatic POST |
acidattacker.com shows a Facebook page and a Youtube page with the same content.
| Fake Youtube page from spammers |
These spam pages can be found at:
- hxxp://bnltwo.info/video2/
- hxxp://acidattacker.com/
-- Julien
Labels:
affiliates,
phishing,
privacy
Tuesday, October 19, 2010
Who else is benefiting from the spam SEO?
Blackhat SEO spam is used mainly to redirect users to pages serving malware, often disguised as an antivirus. However, other players are using the same Blackhat spam SEO techniques (they use hijacked sites) more and more to increase traffic to their site.
Fake search engines
These sites look like a search engine. But all links are actually paid advertising. To trick the advertising networks, the user is redirected to different IP addresses when he clicks on these links, so that the advertising networks see a small amount of traffic coming from multiple addresses instead of massive amounts of traffic coming from one location.
I've described how these fake search engines work in detail in the post about Mother's day scam.
These fake search engines include xaras.net, p3p0.com, yeasbear.com, xsearcher.net, smartbuzz.biz (currently blocked by Google Safe Browsing), etc.
Download sites
In the past few months, I've seen more and more hijacked pages redirecting users to (illegal) download sites. These sites make money by selling subscriptions to users.
They redirect users to a page that claims the file they are looking for is available for download. The file name is obtained by appending .rar to the search term. In the screenshot above, a search for "deadliest catch" on Google lead to sapm page redirecting to http://express-downloads.com/download.php?file=deadliest%20catch.rar where the the file deadliest catch.rar is available for download.
But the user needs to be "to be logged in to download" the file. After entering his e-mail address and a password, he must also make a payment to access this file.
Of course, the file does not exist. You can change the file name to any string, the site always claims the corresponding file is available: http://express-downloads.com/download.php?file=[string].rar
Most of these sites have very similar domain names: fast-downloads.biz, turbo-speed-downloads.com, express-downloads.com, thedownloadfiles.com, etc.
Conclusion
There are more and more shady sites using Blackhat SEO in order to make money. And there is no shortage of vulnerable Wordpress installations to take advantage of. This type of spam will very likely exist for a long time.
Botnets are already available for rent, I think it won't take long before hijacked sites are up for rent to increase traffic to shady websites.
-- Julien
Fake search engines
These sites look like a search engine. But all links are actually paid advertising. To trick the advertising networks, the user is redirected to different IP addresses when he clicks on these links, so that the advertising networks see a small amount of traffic coming from multiple addresses instead of massive amounts of traffic coming from one location.
I've described how these fake search engines work in detail in the post about Mother's day scam.
| p3p0.com fake search engine |
Download sites
In the past few months, I've seen more and more hijacked pages redirecting users to (illegal) download sites. These sites make money by selling subscriptions to users.
| Site claims to have deadliest catch.rar available for download... |
| but the user must sign up first ... |
| and pay to access a file which does not exist! |
Most of these sites have very similar domain names: fast-downloads.biz, turbo-speed-downloads.com, express-downloads.com, thedownloadfiles.com, etc.
Conclusion
There are more and more shady sites using Blackhat SEO in order to make money. And there is no shortage of vulnerable Wordpress installations to take advantage of. This type of spam will very likely exist for a long time.
Botnets are already available for rent, I think it won't take long before hijacked sites are up for rent to increase traffic to shady websites.
-- Julien
Labels:
affiliates,
Compromised,
SEO
Monday, July 19, 2010
placeblogger and others lead to imgwebsearch spam
Over the weekend I was playing around with the iPad application SkyGrid to read the latest news stories on particular subjects. In one of my feeds that I setup for mobile security I saw a story with the title "GvHpMqAVt." From the title I immediately suspected the story as spam (can't seem to go anywhere these days without running into some type of spam on the web). The page has nothing on Blackberry or mobile security which was my topic on SkyGrid - but there was one link on the page for "streaming porn on blackberry pearl" - not really the subject I was looking for. The page is a spam advertisement page to multiple affiliate pages advertising various porn and dating sites. Figured I'd write a brief blog post to detail this campaign:
Placeblogger spam page:

Clicking any of the links takes you to the affiliate page (this one is setup on Quogger but there are a large number of social media sites used for this):

It didn't take long from here to start to unravel the web of spam and affiliate pages setup to monetize porn and dating service pay-per-clicks / pay-per-purchase.
Some Placeblogger spam pages:
hxxp://placeblogger.com/content/gvhpmqavt
hxxp://placeblogger.com/content/rrvlxrrhjpnt
hxxp://www.placeblogger.com/content/tvkbzvxrmydrdmtlit
hxxp://placeblogger.com/content/hnuxlavx
hxxp://placeblogger.com/content/efvwiokczlmffeeugnt
hxxp://placeblogger.com/content/tipsgyxr
hxxp://placeblogger.com/content/lxyyfrohukysmzev
hxxp://placeblogger.com/content/frbonuntjf
hxxp://placeblogger.com/content/dnlnfbbkmfvcxga
hxxp://placeblogger.com/content/hsgsqurgd
The list goes on...
This Google search identifies about 300 or so for example.
Some Affiliate / Advertisement pages:
hxxp://www.quogger.com/pg/profile/AassidyWood49
hxxp://silentzow.com/elgg/pg/profile/AaydaThompson01
hxxp://www.yappey.com/pg/profile/AharlizeMiller59
hxxp://jivebook.co.uk/main/pg/profile/AreannCook29
hxxp://www.quogger.com/pg/profile/ArynnJames38
hxxp://www.swakiya.com/pg/profile/AaylaHayes00
hxxp://socialcommerce.in/pg/profile/AryannaDoyle28
~ snip ~
Note: there are a lot more affiliate pages - about 10 per Placeblogger spam page. Most of these are profile pages on a variety of social media sites.
Most of the affiliate links direct the visitor through imgwebsearch.com. A search for this site uncovers a large number of spam links to a variety of campaigns including: porn/dating, pharma, casinos, loans, replicas, etc., etc. Imgwebsearch spam shows up everywhere - yes, including Facebook. An example of imgwebsearch pharma spam on Facebook:
hxxp://www.facebook.com/pages/Com-Program-ahdth-bramj-alkmbywtr/277890114062
Actually, this Google search shows over 600 some related spam pages on Facebook.
How does this work?
Here is an example of one such related spammer detected via Project HoneyPot. In this case the spammer / spam group seems to have one or more netblocks (94.142.131.0/24 in Latvia for example) with the hosts setup to spider the web and post comment spam to sites (infected machines / bots may be used or rented out for this purpose as well). In this case all of the spammer's links were through imgwebsearch. The pool of source IP addresses for spidering / spamming and the changing of the user-agent is used to evade detection. This relatively simple spam operation could be home grown by the spammer(s), or there are relatively inexpensive tools such as XRumer for purchase to facilitate this type of spam (also used for SEO). This and other tools provide account creation / CAPTCHA bypass to be able to spam to sites that require account / login. Affiliate programs (aka Partnerka in Russian slang) -- in this case it appears to be imgwebsearch -- pay these spammers from anywhere from a few cents per click, a few dollars per sign-up/purchase, or in some cases tens of dollars per install (for example, the FakeAV campaigns). There is a good paper from Dmitry Samosseiko from last year's Virus Bulletin that details the Partnerka.
Placeblogger spam page:

Clicking any of the links takes you to the affiliate page (this one is setup on Quogger but there are a large number of social media sites used for this):

It didn't take long from here to start to unravel the web of spam and affiliate pages setup to monetize porn and dating service pay-per-clicks / pay-per-purchase.
Some Placeblogger spam pages:
hxxp://placeblogger.com/content/gvhpmqavt
hxxp://placeblogger.com/content/rrvlxrrhjpnt
hxxp://www.placeblogger.com/content/tvkbzvxrmydrdmtlit
hxxp://placeblogger.com/content/hnuxlavx
hxxp://placeblogger.com/content/efvwiokczlmffeeugnt
hxxp://placeblogger.com/content/tipsgyxr
hxxp://placeblogger.com/content/lxyyfrohukysmzev
hxxp://placeblogger.com/content/frbonuntjf
hxxp://placeblogger.com/content/dnlnfbbkmfvcxga
hxxp://placeblogger.com/content/hsgsqurgd
The list goes on...
This Google search identifies about 300 or so for example.
Some Affiliate / Advertisement pages:
hxxp://www.quogger.com/pg/profile/AassidyWood49
hxxp://silentzow.com/elgg/pg/profile/AaydaThompson01
hxxp://www.yappey.com/pg/profile/AharlizeMiller59
hxxp://jivebook.co.uk/main/pg/profile/AreannCook29
hxxp://www.quogger.com/pg/profile/ArynnJames38
hxxp://www.swakiya.com/pg/profile/AaylaHayes00
hxxp://socialcommerce.in/pg/profile/AryannaDoyle28
~ snip ~
Note: there are a lot more affiliate pages - about 10 per Placeblogger spam page. Most of these are profile pages on a variety of social media sites.
Most of the affiliate links direct the visitor through imgwebsearch.com. A search for this site uncovers a large number of spam links to a variety of campaigns including: porn/dating, pharma, casinos, loans, replicas, etc., etc. Imgwebsearch spam shows up everywhere - yes, including Facebook. An example of imgwebsearch pharma spam on Facebook:
hxxp://www.facebook.com/pages/Com-Program-ahdth-bramj-alkmbywtr/277890114062
Actually, this Google search shows over 600 some related spam pages on Facebook.
How does this work?
Here is an example of one such related spammer detected via Project HoneyPot. In this case the spammer / spam group seems to have one or more netblocks (94.142.131.0/24 in Latvia for example) with the hosts setup to spider the web and post comment spam to sites (infected machines / bots may be used or rented out for this purpose as well). In this case all of the spammer's links were through imgwebsearch. The pool of source IP addresses for spidering / spamming and the changing of the user-agent is used to evade detection. This relatively simple spam operation could be home grown by the spammer(s), or there are relatively inexpensive tools such as XRumer for purchase to facilitate this type of spam (also used for SEO). This and other tools provide account creation / CAPTCHA bypass to be able to spam to sites that require account / login. Affiliate programs (aka Partnerka in Russian slang) -- in this case it appears to be imgwebsearch -- pay these spammers from anywhere from a few cents per click, a few dollars per sign-up/purchase, or in some cases tens of dollars per install (for example, the FakeAV campaigns). There is a good paper from Dmitry Samosseiko from last year's Virus Bulletin that details the Partnerka.
Labels:
affiliates,
spam
Subscribe to:
Posts (Atom)