Websense Security Labs(TM) ThreatSeeker(TM) Network has discovered that search engine results for information on how to download Microsoft's recently released Security Essentials tool are returning links to Web sites that serve rogue AV.
Threat Type: Malicious Web Site / Malicious Code
Malware authors have used Search Engine Optimization (SEO) techniques to mix rogue search results in with legitimate results. For example, one of the rogue links is directly under a MSDN blog entry discussing Microsoft Security Essentials. The rogue redirects are hosted on compromised Web sites, including a Canadian publisher's Web site and the British Travel Health Association.
When a user browses to the compromised Web sites, so long as they have been referred by a search engine, they are redirected to malicious Web sites with domain names such as computer-scanner21 and computervirusscanner31.
An example of one of the payload files shows that AV detection is low.
To view the details of this alert Click here
Security Alert: Microsoft Security Essentials SEO Poisoning
Posted on Wednesday, September 30, 2009 @ 10:10:22 CDT in Security: Websense
|
Security Alert: Ann Minch's YouTube Video SEO Poisoning
Posted on Thursday, September 24, 2009 @ 17:50:34 CDT in Security: Websense
|
Security Alert: Websense Security Labs report - State of Internet Security, Q1-Q
Posted on Tuesday, September 15, 2009 @ 16:01:05 CDT in Security: Websense
|
Security Alert: Labor Day Sale-Related SEO Poisoning Leads to Rogue Antivirus
Posted on Saturday, September 05, 2009 @ 01:05:55 CDT in Security: Websense
|
Torrentreactor Website Compromised
Posted on Wednesday, July 01, 2009 @ 15:23:37 CDT in Security: Websense
|
Michael Jackson Death Prompts Malicious Spam
Posted on Friday, June 26, 2009 @ 09:33:44 CDT in Security: Websense
|