Archive for October, 2009

Blackhat SEO Aggressively Targets Halloween Related Keywords

October 28, 2009

Cyber criminals behind the Rogueware epidemic have been hard at work in poisoning search results to increase traffic to their campaign sites. Today, we identified a new Blackhat SEO campaign, which is currently targeting Halloween related keywords aggressively. While studying the campaign, I noticed that the most commonly targeted keywords were classic costume favorites, such as the Cat woman costume, vampire costume, and various adult costumes. In addition to costumes, the BHSEO campaign also targets Halloween related food recipes, haunted house directions, Halloween parties, and the movie Halloween.

Tainted search results:

Blackhat SEO - Search Results

Fake Antivirus site:

Rogueware Site

Tag cloud of targeted search terms:

BHSEO Tagcloud

As we have documented in prior blog posts, Blackhat SEO continues to be one of the most prevalent and pervasive attack vectors on the Internet today. As users, we tend to trust search engines to provide safe and accurate search results, but the reality is that today, search engines are becoming the most dangerous way to browse the Internet.

Blackhat SEO Campaign Targets 2009 Nobel Prize Winner

October 9, 2009

 We’ve identified a new Blackhat SEO campaign today which targets President Obama as the 2009 Nobel Peace Prize winner among a thousand or so other search terms.   Clicking on a malicious search result yields the typical Rogueware campaign. 

Search result:
Nobel Peace Prize Winner 2009 - Obama Blackhat SEO

Rogueware site:
Windows Performance Center Rogueware

The complete list of targeted search terms can be found here.   

Rogueware with new Ransomware Technology™

October 8, 2009

The criminals behind Rogueware attacks are becoming increasingly aggressive in their approach to make money. We recently stumbled across a sample (Adware/TotalSecurity2009) which uses a ransomware technique to improve its sales. Once the computer becomes infected, Total Security forces the victim to purchase it before it will allow any files from being accessed on the system.  When attempting to open a file, a message pops up in the notification area claiming that the application was blocked due to infection.  The pop up recommends activating the "antivirus" software, which costs $79.95. 

Notification Area - Notepad.exe blocked

This would be a devistating blow to any user and would likely force the victim to purchase it, so we went ahead and cracked the sample to reveal all of the valid serial numbers. We're hoping that  victims can find this blog post before shelling out any hard earned cash to these criminals.

Watch the video to see it in action: 

Valid serials for Adware/TotalSecurity2009:


You can download a free trial to completely remove the infection once the ransomware feature is removed.

Special thanks to Sherab Giovannini for extracting the serials. 

Rogueware distributors use Skype

October 5, 2009

Rogueware distributors are like the cockroaches of the Internet; they’re everywhere.   Malicious search results, online advertisements, and iframe hijacked sites are the typical distribution methods, but every once in a while we come across an interesting approach.

Recently, a colleague alerted me of a spam message coming through to his personal Skype account.  The message appeared out of nowhere from an account labeled “Online Notification” and made the typical claims of a found infection.  Once the victim navigates to the site, the usual fake antivirus trickery takes place.

Skype Spam

Skype isn’t the most reliable or innovative distribution method, but we’ll go ahead and give them an "A" for effort. 

Q3 report released

October 1, 2009

We've just published our latest quarterly report. We'll show the different figures about malware in Q3, and some interesting articles.  If you want to know what has happened in the last 3 months, which have been the most important Blakhat SEO attackes or the latest movements of the Koobface worm, just download it and enjoy!

