Thursday, April 8, 2010

Tiger Woods (Searches) Not to Be Trusted


Tiger Woods’ personal life and marital affairs have attracted constant attention from the press and has certainly damaged his public reputation.  With his return to the Masters only days away, Nike has released a new commercial in an effort to rebuild Woods’ image.  This compelling commercial is intended to spark a reaction, and may well be the next thing you talk about at the office water cooler.  Anyone who hasn’t seen it will go right back to their desk and search for the video. Blackhats have once again worked their way into these search results, leading users to malicious sites and Rogue Anti-Virus downloads. 

A user looking to see the commercial online would likely search “tiger woods commercial” – the search is heavily poisoned.  Out of the top 7 search results, six lead to Fake Anti-Virus pages begging the user to install malicious software.  The video results have also been poisoned to do the same.
























With low anti-virus detection rates, users tricked by this attack have little to prevent them from installing downloaded malware.  In fact, only 1 out of the 20 scanners on Jotti detected the payload as malicious.










Users should also be wary of any Masters’ related searches as these will also be a target of cyber criminals. eSoft’s proactive detection of these attacks protects any SiteFilter customers.  Any sites associated with these attacks are being flagged as malicious or compromised.

[Additional Note: In this particular attack, the referring site is also important.  If the user is not coming from Google, or presumably other search engines they will be redirected to cnn.com rather than the malicious site.  eSoft has noted the use of this technique in the past, but it is interesting the attackers have chosen CNN for use in this campaign.]

Monday, April 5, 2010

Affiliate Programs Rising Cause of Fraud and Abuse

What happens when you offer up money to anyone who can drive traffic to your website?  Hackers, scammers, spammers and fraudsters come to your aid.  That’s the case with online movie site zml.com, which offers 30% of each sale and 5% of rebills paid via anonymous means to anyone who refers paying customers to the site.  And zml.com is just one of many.

In general, it works like this: a person signs up as an affiliate and is given a code.  If someone goes to the website with the proper code embedded in the URL, then a cookie is set and if that person later buys something on the site, the affiliate gets a piece of the transaction.  Outside of the shadows this means others are encouraged to setup ads or to refer friends to the site.  But on bigger scales, this can be big money, so the established cyber criminal community gets in on the action – not always by breaking the law, but certainly using shady means to drive customers to these websites.

Among the techniques being used by these shadow affiliates are blackhat SEO, fake blogs, spam campaigns and more.  These will frequently redirect through servers managed by the shadow affiliate and, in eSoft’s investigations, frequently used for other purposes such as malware distribution and phishing campaigns.

Windows Live Spaces is again being abused with a slew of fake blog pages covering hundreds of popular movies available for download. The download links redirect the user to a number of different movie sites that offer high paying affiliate programs.

Example 1

















The blockbuster movie The Hangover is the sole blog post in the blog shown above and includes a promo image and full description of the movie with links to download. After a series of redirects to ensure the scammer gets paid, the user is brought to moviedownloads-pro.com. In order to download for free, the user must sign up for a yearly subscription with a credit card and our blog spammer gets a cut.


















After signing up, the user is emailed a link to download software which we suspect to be questionable although we did not give up our credit card info to find out.  The affiliate network in this case is Marketbay, which is also home to some other very shady software including 14 different bogus anti-virus products.

Example 2

















In another example, the eSoft Threat Prevention Team found the intermediary sites used by a shadow affiliate were hosted on the same site used in a ring of fraudulent "OEM Software" distribution sites we blogged about last year.  These links lead to zml.com, whose affiliate signup page contains the warning, "SEO or E-Mail spam is not tolerated!"  However, after sharing information of abuse with zml.com five days before the posting of this blog, we have yet to see the affiliate removed or to receive any response from zml.com.  In all likelihood, it is simply more profitable to turn a blind eye.

















Using Windows Live Blogs to disguise URLs can be an effective way to get around some Spam and Web filters. eSoft reported on a similar tactic used to push pharma-fraud sites just a few months back. While this is nothing new, it goes to show that cybercriminals will continue these types of campaigns so long as they continue to be effective and profitable.

eSoft currently categorizes a number of these affiliates’ sites as Phishing & Fraud due to their use in Blackhat SEO campaigns and others are categorized as Online Ads or Spammed URLs depending on the methods being used to drive users to the links.

Monday, March 22, 2010

Obfuscated URLs no match for eSoft SiteFilter

Researchers at Kaspersky labs have discovered a new banking malware campaign that uses an old trick to obfuscate malicious URLs. Rather than using a domain name or IP address for their malicious link the URL is converted to numerical bases such as octal or hexadecimal formats. These formats are supported by major browsers and serve the purpose of tricking users into following the link and infecting their machine.

The post goes on to speculate that URL filters would have difficulty detecting and blocking the obfuscated URLs, leaving users vulnerable to these attacks. While many web filtering vendors may be susceptible to this attack, eSoft customers are protected. eSoft SiteFilter provides full support for these obfuscated URLs, filtering sites in ALL categories.

Using the example of playboy.com, the URL can be expressed in many different ways including the few examples below.

http://216.163.137.68
http://3634596164
http://0xd8.0xa3.0x89.0x44
http://0xd8.0xa3.0x89.68
http://0330.0243.0211.0104
http://000000330.0xa3.137.0104
http://0xD8A38944
http://033050704504

As shown on the Test a Site portal, eSoft correctly interprets these encoded addresses and detects each of these URLs as Pornography/Sex, the same as the domain playboy.com.












 
With the example found by Kaspersky, vendors that do not accurately filter these URLs leave users vulnerable to dangerous banking Trojans and end-user evasions. Malicious campaigns using this technique have been seen in the past and due to their effectiveness will be used in the future.

eSoft’s web filtering technology and focus on security provides users with unsurpassed protection against the latest web threats, including these obfuscation techniques.

Sunday, March 21, 2010

Cinderella Story Leads to March Madness Malware

The first week of March Madness has brought about many compelling stories, with a good deal of upsets and bracket busters. The most newsworthy of these has been the University of Northern Iowa’s ousting of #1 overall seed Kansas. This ‘Cinderella’ story has deservedly gotten a great deal of press coverage. However, those looking for information on the web may get infected with malware rather than a great story.

The eSoft Threat Prevention Team has been tracking search results on the story, and the NCAA Basketball Tournament in general, uncovering a great number of poisoned search terms. Searches for UNI Basketball or star player Ali Farokhmanesh return dangerous results leading to malware.



7 out of the top 10 results for UNI Basketball link to malware including the second result. The rogue anti-virus payload has very low detection among anti-virus vendors.

eSoft proactively detects and blocks blackhat SEO and search attacks similar to these using its automated systems and in-depth web site analysis. Any sites found are flagged as Compromised or Malicious, protecting eSoft SiteFilter customers.

Thursday, March 4, 2010

Virus Alert! Twitter, Google, Hallmark and Others Subject To Attack

The eSoft Threat Prevention Team is warning customers today of a new email scam circulating very quickly.  These fraudulent emails claim to be from Google Staffing, Hallmark, Twitter as well as other social networks and legitimate businesses.

The email persuades the user to open the attached zip file to find out more information. Users that follow through and open the file infect their own system and become part of the threat.

The very legitimate looking email below is just one example of the scam.  The email uses the actual Google logo downloaded directly from their website and easily hooks you into opening the attached file to find out more.


In this case, the downloader infected the system with a bot which immediately begins spewing thousands more of infected emails including fake e-cards from Hallmark, and invitations from social networks like Twitter and Hi5. 

The Twitter email is also very well crafted to make the user believe they were invited by a friend and is legitimately from Twitter.  The from address is spoofed to invitations@twitter.com with a subject “Your friend invited you to Twitter!”.  The body of the message begs the user to open the attached file - “To join or see who invited you check the attachment”.  Using this clever social engineering tactic the scammers are able to peak interest in finding out who may have sent them the message.  The user is tricked into opening the attachment and infecting their system.

As always, be very cautious opening any attachments and especially cautious when they are unexpected.  When in doubt verify with the sender or do not open them. 

Tuesday, February 16, 2010

Hotmail Users Look for Answers in Dangerous Places

An outage of the Windows Live ID service affected a large number of MSN users today including users of the popular Hotmail email service. Hotmail is one of the largest web based email outlets and not surprisingly news of the outage spread quickly as users were not able to access their email.

Those hoping to find more information on Google may have ended up with more than they bargained for. Blackhats have once again worked their magic to infect users looking for news related to the outage. In fact, 8 out of the top 10 results for “hotmail service unavailable” returned dangerous URLs.


At the time of writing Google Trends shows this as one of the top searches of the day. Other dangerous searches include “hotmail down” and “hotmail not working” both of which also returned malicious URLs that can cause a visitor’s computer to become infected with malware.


As an added twist, some results direct users that revisit the same page to a fake download site. The user is asked to download hotmail_down.rar, but not before entering their credit card information.



eSoft has detection for many of these sites and is flagging any new sites into their appropriate security category to protect SiteFilter users.

Saturday, February 6, 2010

IRS Tax Avoidance Scam

Today, eSoft is alerting customers to a new targeted email scam.  This newest twist to the common IRS email scam seems to be targeted to organizations, notifying the recipient of a tax evasion complaint being filed against the company.  Opening the file infects the user's machine with dangerous trojans that monitor the infected machine, report back to the attacker and download other malicious payloads.

An example of the fraudulent email is below, which prompts the user to open "balance report" attachment.  Because the attachment appears to be a Word file, most users will readily trust the file and proceed to open the file to find out more.


The file is actually in Rich Text Format (RTF) and contains a hidden executable.  Upon opening the file, an error is reported and the user is asked to double click to restart Word.  Doing so will open the executable as shown below, with most unsuspecting users allowing the malicious file to run.

 

Two processes are started and added to Windows startup to run on subsequent boots, microsoft.exe and wks.exe.  These processes send data back to the attacker using HTTP connections to their call home destination.  eSoft is flagging these sites as Malicious to protect any victims of this attack.

These call home destinations are even disguised as a Google search page to evade detection by web filtering companies and automated systems which may detect the site as a search engine.

 

At the time of writing, Virus Total reports only a 25% detection rate on the most recent samples.

Users should be very cautious with any unsolicited emails, particularly those containing an attachment.  The IRS will never email you if they need to contact you, and any emails appearing to come from them are very likely malicous scams.  As noted on the IRS website, "The IRS does not initiate taxpayer communications through email."

Tuesday, February 2, 2010

Fake Firefox Update Pages Push Adware

Since its’ release on January 21st, the newest version of the Firefox web browser has received a great deal of attention. In just a short time it has achieved over 30 million downloads. Adware pushers are capitalizing on the success of Firefox, packing ad serving software in with the program in an effort to increase their reach.

Purveyors of spyware and adware will try to take advantage of well known programs, illegitimately bundling their software into the install of the popular software. These programs are also commonly referred to as Potentially Unwanted Programs (PUPs) whose content is not necessarily malicious, but is almost never wanted by the user. These types of software are often used to collect information about the user without the users’ knowledge or consent.

The latest example is found on the fake Firefox download site below.  The page is cleverly disguised with the appearance of a legitimate Firefox download site and could easily fool many users hoping to upgrade. 


Taking a closer look reveals clues to the fraudulent page. While the page advertises version 3.5 the newest version is actually 3.6.  There are also misspellings such as “Anti-Pishing” in the title of the security section.

Victims of this scam install the “Hotbar” toolbar by Pinball Corp, formerly Zango.  Not only are users subject to the annoying toolbar, they're also barraged with pop-up ads and host to a new Hotbar weather application running in the system tray.


It should be noted that the owner of the fake Firefox site above is most likely not associated with Pinball Corp and only using its pay-per-install ad network for fast cash. Pay-per-install affiliate programs reward referring sites that generate installs of their programs, with Pinball paying as high as $1.45 per install. 

Always take caution installing any software and ensure the software is downloaded directly from the publisher whenever possible.  Users looking to upgrade Firefox should go to the real download site at http://getfirefox.com.

Blocking the Spyware and Malicious Sites category protects eSoft SiteFilter customers from this site and others like it.

Tuesday, January 19, 2010

Super Bowl Associations: football, nachos, big screens and … malware?

The Super Bowl is the one of the biggest and most watched television events of the year in the United States. People everywhere scour the internet looking for predictions, gambling spreads and news before the event and scores, stories and clips after the event.  In anticipation of the increased search traffic for Super Bowl related terms, cybercriminals have shown themselves to be well-organized and planning ahead.  Search results for Super Bowl related search terms are already turning up top-ten results linked to malicious websites.

Among the poisoned search terms detected by eSoft are: 
Super bowl 2010 score
Super bowl 44 MVP
Super bowl 2010 entertainment
Super bowl champions 2010

For some of these searches, the top result is malicious.  It seems that this round of poisoning is, so far, being done by the Rogue AV outfits as these links lead to sites with fake antivirus software and low detection rates from legitimate anti-virus software:



Background

Poisoned search results are becoming commonplace.  Most recently searching for information on the earthquake in Haiti returned large numbers of poisoned results.  Getting bogus search results to the top of the rankings is commonly achieved by linking to the site from compromised sites or fake blogs and thereby boosting the apparent popularity of the bogus site.  The bogus site is then used to compromise the machine of visiting users through social engineering tricks and browser or browser-plugin exploits.

eSoft’s automated systems quickly identify these risky websites and block them for customers and partners.

eSoft recommends confining Super Bowl searches to news search engines such as Google News.  These results tend to be safer since the sources have gone through an approval process.

Monday, January 18, 2010

Lack of Egress Filtering Spurs Success of Injected IFrame Attack

The security community at large and the eSoft Threat Prevention Team have recently noticed an uptick in sites compromised by a new injection attack that results in an injected iframe.  This attack can be recognized by its attempts to masquerade the malicious script as GNU GPL or LGPL.  GPL and LGPL refer to public licenses for open source software and add a veneer of legitimacy to the malicious files.

The attacks in themselves are not new or novel, but their success seems to be in part because the iframes point to websites on non-standard ports.  In particular, the attackers are hosting browser exploits and social engineering tricks on servers running on port 8080. Such as this one shown below:




(note also the trusted domains that have been added to the URL to get the casual user to trust the link)

As secure web filtering is added to anti-virus products and makes inroads in gateway security products, attackers are trying to circumvent the web filters with this age-old technique.  Frequently these secure web filters only operate on common ports such as port 80.  By hosting a web server on an alternate port, the security may be bypassed.

For this reason, it is essential that administrators who deploy secure web filtering lock down any ports not expressly being scanned.  In other words, egress firewall rules that block outbound traffic on ports that don't have some security and content filtering, will save networks from this attack and ones like it.

At present, eSoft is detecting dozens to hundreds of newly compromised websites that have fallen victim to this attack and become conduits for attacks against their site's visitors.  More detailed information on how the attack is spreading and its links to gumblar can be found on the Unmask Parasites blog.