An advertisement for car insurance served up by the “FOX Audience Network” (domain fimserve.com) is redirecting visitors to a couple different scareware/rogue security software websites. These scareware websites perform a fake virus scan and then tell the victim they are infected (when in reality they aren’t) and to download their “security” application to clean them up. Their security application does not perform as advertised. Typical method-of-operation for the scareware purveyers.
Leads to ==>
WARNING: Stay away from this badness!
Malvert link:
hxxp://cache.fimservecdn.com/contents/377/311/311377/CR_autopolicyweb_728×90_V6.swf?clickTag=http%3A//delb.opt.fimserve.com/lnk/%3Fk%3DMzY5N
Scareware/rogue website links:
hxxp://windows-helpcenter.com/?id=198760222
hxxp://uniqviruscleaner.com/index.php?affid=08043
windows-helpcenter.com – 83.229.250.27
uniqviruscleaner.com – 209.44.126.241 (Registered today 5/20/2009)
VirusTotal scan of rogue application file shows 6/40 detections:
http://www.virustotal.com/analisis/c4bd7049e54a00b21e978c6227849bd7
–mwdisector
