Technologies that
Bring Peace of Mind
Online
technical Help
and Support
Status live support chat
Live support
Have a question?
Call us Toll-Free at:
1-877-ANTISPY
1-877-2684779
+44-207-099-2078
More contacts


Subscribe to our
RSS feed
Subscribe to our RSS feed
In focus
Fake Security Software Domains Serving Exploits
August 28, 2008 11:41

    
Psychological imagination, "think cybercriminals" mentality or scenario building intelligence, seem to always produce the results they are supposed to. On Monday, I pointed out that :

"Ironically, the participant in the affiliate program whose original objective was to drive traffic to the fake security software's site, may in fact start receiving so much traffic due to the combination of traffic acquisition tactics, that introducing client-side exploits courtesy of a third-party affiliate network, may in fact prove more profitable then the revenue sharing partnership with the rogue security software's vendor at the first place."

The next day, client-side exploits start getting introduced "in between" the fake security software sites :

"I've blogged before about the problem of Google Adwords pushing Antivirus XP Antivirus 2008. The situation is still ongoing.  However, it's taken a turn for the worse, as these XP Antivirus pages are pushing exploits to install malware on the users system. This will also affect the many syndicators of Google Adwords."

The domain in question bestantivirus2009.com - (68.180.151.21) is hosting the binary at bestantivirus2009 .com/setup_1096_MTYwM3wzNXww_.exe and has an IFRAME pointing to huytegygle .com/index.php (200.46.83.246).

Here's another example antivirus0003.net with an IFRAME pointing to a different location - 124.217.250.85 /~ave/etc/count.php?o=16.

Despite that these domains are part of the "International Virus Research Lab" fake domains portfolio, it remains to be seen whether others will start multitasking as well.

All news for November 20, 2008
  13:26  Schneier on Security: Secret German IP Addresses Leaked

All news for November 19, 2008
  19:33  Schneier on Security: RIAA Lawsuits May Be Unconstitutional
  16:00  Dancho Danchev: The DDoS Attack Against Bobbear.co.uk
  12:14  Schneier on Security: Skein and SHA-3 News
  10:15  Dancho Danchev: New Web Malware Exploitation Kit in the Wild
  04:19  Martin McKeay: Network Security Podcast, Episode 128

All news for November 18, 2008
  19:57  Dancho Danchev: Will Code Malware for Financial Incentives
  19:46  Schneier on Security: Schneier for TSA Administrator
  16:34  Jeff Jones Security Blog: SIRV5 Vulnerability Trends Webcast - 2 of 2 - Microsoft Trends
  12:32  Schneier on Security: The Neuroscience of Cons

All news for November 17, 2008
  11:11  Schneier on Security: Most Spam Came from a Single Web Hosting Firm
Keywords: fake, security, software, domains, serving, exploits

All news for November, 2008


All news for 2008