Technologies that
Bring Peace of Mind
Online
technical Help
and Support
Status live support chat
Live support
Have a question?
Call us Toll-Free at:
1-877-ANTISPY
1-877-2684779
+44-207-099-2078
More contacts


Subscribe to our
RSS feed
Subscribe to our RSS feed
In focus
Fake Celebrity Video Sites Serving Malware
June 20, 2008 11:58

    With blackhat search engine optimization tactics clearly converging with social engineering, the result of which is the increasing supply of Zlob malware variants served as fake codecs, it's about time we spill some coffee on several campaigns in order to get a better understanding of the way the campaigns function.

These campaigns are also starting to get so sophisticated, that analyzing a single one will expose another massive SQL injection, reveal several blackhat SEO domain farms, let you obtain fresh Zlob malware variants, and point you to the very latest and undetected rogue software if you manage to expose the entire scammy ecosystem through all the redirections put in place to make it harder to get to the bottom of it.

What's important to keep in mind when assessing and shutting down such comprehensive campaigns is that on the majority of occassions the front end domains as well as the secondary ones are all attempting to download the codecs from hardcoded locations. Consequently, you have 50 front end domains and another 50 as secondary redirection points all attempting to download the codecs from 3 download locations. Once again, the malware authors efficiency centered mentality emphasising on the easy of management for the campaign is making it possible to.

Here's are some currently active fake celebrity video sites serving malware including the codec redirectors :

stillnaked.net
funkytube.net
starvid.info
yetmorefun.net
hotnudity.net
alreadynude.com
celebvids.info
sexystar.name
hotserved.net
thestars2008.com
nudde.net
gottabigfuick.com
moviecity.se
gossip-starz.com
tmz-video.com
js0.info
superfakamyvideo.com
hdavidz.com
blog-x.in
tmz-video.com
newhotpeople.com
dirty-gossips.com
flaxxvid.com
videoid.info
realvideofree.com
yetmorefun.net
popvids.info
ihavewetfuckpussy.com
virus-scanonline.com
adultx2008.com
lux-software2008.com

As well as some sample subdomains for traffic acquisition purposes, since all of these have already been crawled by search engines :

jodie.popvids.info
jessica.popvids.info
tila.popvids.info
paris.celebvids.info
vanessa.celebvids.info
britney.nudde.net
paris.nudde.net
kardashian.nudde.net
vanessahudgens.yetmorefun.net
lindsaylohan.yetmorefun.net
britneyspears.yetmorefun.net
parishilton.yetmorefun.net
kardashian.nudde.net

We also have embedded IFRAMEs and as well as injected ones into vulnerable sites, acting as redirectors to some of these fake video sites. For instance, at the pedophilesexstories.blog.com we have an injected redirector - js0.info/?s=16&k=pedophile+sex+stories&c=5 and js0.info itself is a blackhat SEO operation that's aggregating generic search traffic like this :

js0.info/16/5/ragnarok+hentai
js0.info/15/4/antivirus+characteristic
js0.info/16/5/msn+monkey
js0.info/15/4/airplus+internet+security

Once accessed, you get redirected to through two separate redirection campaigns at searchaw.info/sa/in.cgi?16; and hmel.info/stds13/go.php, until you finally get to the codecs.

With blackhat SEO-ers already well developed inventory of topical junk content, and experience in what's popular content and what's not, the entry barriers for malware authors into the traffic acquisition joys of blackhat SEO has never lower.

All news for October 10, 2008
  22:58  Schneier on Security: Friday Squid Blogging: Natural Squid Steganography
  22:45  Martin McKeay: Recording Notice: Security Roundtable - Blogger Ethics
  18:30  Schneier on Security: The More Things Change, the More They Stay the Same
  14:39  Martin McKeay: Brute force attacks against WPA/WPA2 using Nvidia cards
  12:35  Schneier on Security: Data Mining for Terrorists Doesn't Work
  00:02  Martin McKeay: Sequoia´s helping decide the election? God help us!

All news for October 9, 2008
  23:00  MSRC: Update 1: Microsoft Security Advisory 951306
  19:07  Schneier on Security: Nonviolent Activists Are Now Terrorists
  17:51  Martin McKeay: Cisco Ooops: drug runner music on VPN CD
  16:40  MSRC: October 2008 Advanced Notification
  12:44  Schneier on Security: "New Attack" Against Encrypted Images
  12:22  Martin McKeay: Step by step guide to the DNS vulnerability
  09:28  Dancho Danchev: Cybercriminals Abusing Lycos Spain To Serve Malware
  09:00  Dancho Danchev: Commoditization of Anti Debugging Features in RATs - Part Two

All news for October 8, 2008
  14:46  Martin McKeay: NoScript protects from ClickJacking
  14:14  Martin McKeay: Big Surprise: Data mining doesn´t catch terrorists
  12:55  Schneier on Security: Chinese Monitoring Skype Messages
  02:23  Martin McKeay: Network Security Podcast, Episode 123

All news for October 7, 2008
  21:51  Schneier on Security: Do-Not-Call Lists
  18:27  Martin McKeay: Recording notice: NSP 123
  15:54  Dancho Danchev: Summarizing Zero Day's Posts for September
  14:49  Martin McKeay: Now he´s done it! Security Mike sells out
  12:21  Dancho Danchev: A Diverse Portfolio of Fake Security Software - Part Eight
  11:48  Schneier on Security: The Seven Habits of Highly Ineffective Terrorists
  07:42  Dancho Danchev: Web Based Malware Emphasizes on Anti-Debugging Features
  00:01  Dancho Danchev: Fake Windows XP Activation Trojan Wants Your CVV2 Code
Keywords: fake, celebrity, video, sites, serving, malware

All news for October, 2008


All news for 2008