05
Aug
08

Sponsored Result != Safe

We have been monitoring several malware campaigns lately and we are noticing the distribution spread from just spam e-mails to social networking sites to search engine sponsored results.

A good example is the CNN Top 10 malspam campaign we exposed yesterday. The e-mail comes off as legit to the average user and leads to infection.

In a malware related google search we entered the search term “CNN Top 10 XP Antivirus” and found a sponsored result for a rogue anti-malware product, Antivirus XP 2008.

Google search with malicious results

Free online check! New Generation.

Search Results

If we click the link we are taken to a rogue anti-malware site, hxxp://antivirus-xp-2008.net. *Warning* Live malicious site! Proceed at your own risk** It’s appears legit, offers a free scan, and even sports badges from PC Magazine, Sun, Microsoft, Intel. ICSA, Checkmark, and VB100 to keep it looking like a credible site.

XP Antivirus

If we download the files we get a zip file with 2 files. The files are pretty much undetected across the board because they are so new. We have included the JoeBox Sandbox reports for you to look at.

Zip Contents

Antivirus-XP-2008.exe
-> VirusTotal: Result: 6/36 (16.67%) CDFAE03CA18BBAF307A77F9BA2BB7B38
->JoeBox Sandbox: JoeBox Sandbox Report

Update-July-2008.exe
-> VirusTotal: Result: 3/36 (8.34%) 2E3D63ED9BFF383926FBD34449513928
-> JoeBox Sandbox: JoeBox Sandbox Report

*UPDATED 835pm*

Found more sponsored links by simply searching “antivirus software” on Google. Same exact setup on a different domain name hxxp://2008antivirusxp.com.

avxp2k8ad

More results on other search engines (click image for Virustotal results)…

adwaredlad

*UPDATED 8-06-08*

Another sponsored link was found for rogue antivirus software on a different domain hxxp://xp-2008.com.  This was found by searching ‘antivirus’.  This has potential for misleading many people because also searching ‘norton antivirus’, ‘mcafee antivirus’, ‘panda antivirus’, or any other REAL software, will be presented with this advertisement.

xpav2k8ad


4 Responses to “Sponsored Result != Safe”


  1. 1 David Hammond Sep 1st, 2008 at 9:36 am

    Yes, but how the heck can I get rid of this thing?? I am not very computer literate and am therefore completely stuck!! Any help much appreciated!!!!!

  2. 2 djpnuemo Sep 1st, 2008 at 9:57 am

    You might want to try this. Although if it’s been on your computer for a while you may have more than just rogue software.

    http://malwaredatabase.net/blog/index.php/2008/08/30/rogue-software-removal-video/

  3. 3 Security tips Oct 16th, 2008 at 1:49 am

    Didnt even think its possible to catch a virus this way.

  1. 1 Antispyware 2008 Rogue Served Through Download.com Ads | Malware Database Pingback on Nov 6th, 2008 at 4:13 am



 

August 2008
M T W T F S S
« Jul   Sep »
 123
45678910
11121314151617
18192021222324
25262728293031