<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://pandalabs.pandasecurity.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>PandaLabs : Adware</title><link>http://pandalabs.pandasecurity.com/archive/tags/Adware/default.aspx</link><description>Tags: Adware</description><dc:language>en</dc:language><generator>CommunityServer 2.1 SP2 (Build: 61120.2)</generator><item><title>Metatags in malware websites: II part</title><link>http://pandalabs.pandasecurity.com/archive/Metatags-in-malware-websites_3A00_-II-part.aspx</link><pubDate>Thu, 05 Mar 2009 08:15:00 GMT</pubDate><guid isPermaLink="false">b262f9bf-63e5-46e5-8a14-4069a6997bc7:976</guid><dc:creator>Asier Martínez</dc:creator><slash:comments>0</slash:comments><comments>http://pandalabs.pandasecurity.com/comments/976.aspx</comments><wfw:commentRss>http://pandalabs.pandasecurity.com/commentrss.aspx?PostID=976</wfw:commentRss><description>&lt;p&gt;A couple of days ago we mentioned how some creators of websites that host malware add metatags to them, so that they are not indexed by the search robots.&lt;/p&gt;&lt;p&gt;Today, we are going to mention the opposite case. Let&amp;rsquo;s take the following URL as an example: &lt;u&gt;http://malwa&amp;lt;blocked&amp;gt;.com&lt;/u&gt; &lt;/p&gt;&lt;p&gt;The following tag can be found in the source code of the website:&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;img align="middle" alt="Adware/MalwareDoctor" height="96" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2009/03/05/metatag.jpg" style="width:544px;height:96px;" title="Adware/MalwareDoctor" width="544" /&gt;&lt;/p&gt;&lt;p&gt;The FOLLOW attribute allows the links included in the website to be scanned.&lt;/p&gt;&lt;p&gt;The ALL attribute allows all the files to be indexed completely.&lt;/p&gt;&lt;p&gt;The INDEX attribute allows the search engines to index the website.&lt;/p&gt;&lt;p&gt;Generally the creators of this type of websites want the malware to spread widely and asap. That&amp;rsquo;s why they decide not to add metatags or to add them, so that the indexing robots could index and scan the links easily. This way, when users make queries in the search engines, they are likely to access a malicious website, causing their computers to get infected with the malware hosted in them.&lt;/p&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=976" width="1" height="1"&gt;</description><category domain="http://pandalabs.pandasecurity.com/archive/tags/Rogueware/default.aspx">Rogueware</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Adware/default.aspx">Adware</category></item><item><title>Metatags in malware websites</title><link>http://pandalabs.pandasecurity.com/archive/Metatags-in-malware-websites.aspx</link><pubDate>Tue, 03 Mar 2009 16:20:00 GMT</pubDate><guid isPermaLink="false">b262f9bf-63e5-46e5-8a14-4069a6997bc7:975</guid><dc:creator>Asier Martínez</dc:creator><slash:comments>0</slash:comments><comments>http://pandalabs.pandasecurity.com/comments/975.aspx</comments><wfw:commentRss>http://pandalabs.pandasecurity.com/commentrss.aspx?PostID=975</wfw:commentRss><description>&lt;p&gt;An indexing robot is a program which tracks websites, storing their content in databases and following the links which point to other websites.&lt;/p&gt;&lt;p&gt;Rogue antimalware creators don&amp;rsquo;t usually add tags to the code of their websites or they add them so that the websites are indexed by the robots of the searchers. This way, they are more accessible and malware can be widely spread. &lt;/p&gt;&lt;p&gt;Lately we have found several cases that prove quite the opposite: tags are added to go unnoticed.&lt;/p&gt;&lt;p&gt;Let&amp;rsquo;s take the following URL as an example:&lt;br /&gt;&lt;u&gt;http://&amp;lt;blocked&amp;gt;akedpics.blogspot.com&lt;/u&gt;&lt;/p&gt;&lt;p&gt;When clicking the video to view it, we are redirected to the following URL &lt;u&gt;http://&amp;lt;blocked&amp;gt;pomp.com/index.php?q=Adrienne-Bailon-Naked-Pics&lt;/u&gt;, which in turn redirect us to &lt;u&gt;http://crack-&amp;lt;blocked&amp;gt;.com&lt;/u&gt; (*) and finally to &lt;u&gt;http://fast&amp;lt;blocked&amp;gt;.com/xplays.php?id=40004&lt;/u&gt; from which we will download the file viewtubesoftware.40004.exe, detected as Adware/MSAntiSpyware2009&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;img align="middle" alt="Adware/MSAntispyware2009" height="487" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2009/03/02/msantispyware.PNG" style="width:500px;height:487px;" title="Adware/MSAntispyware2009" width="500" /&gt;&lt;/p&gt;&lt;p&gt;(*) This URL redirects us to different malware hosting websites randomly, depending on the time.&lt;/p&gt;&lt;p&gt;If we look at the source code of the URL &lt;u&gt;http://fast&amp;lt;blocked&amp;gt;.com/xplays.php?id=40004&lt;/u&gt;, we can find the following tag: &amp;lt;META content=noindex,nofollow,noarchive name=robots&amp;gt;&lt;/p&gt;&lt;p&gt;1.&amp;nbsp;The noindex tag doesn&amp;rsquo;t allow the search engines to index a website.&lt;br /&gt;2.&amp;nbsp;The nofollow tag doesn&amp;rsquo;t allow the search engines to scan the links of the document.&lt;br /&gt;3.&amp;nbsp;The noarchive tag prevents the website from being cached.&lt;/p&gt;&lt;p&gt;It seems that these techniques are aimed at making malware analysts&amp;rsquo; and antivirus companies&amp;rsquo; job more difficult. They are also used to prevent the proactivity, in the sense of preventing the infection with techniques such as URL blocking, which consists in making queries of specific parameters in the search engines.&lt;/p&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=975" width="1" height="1"&gt;</description><category domain="http://pandalabs.pandasecurity.com/archive/tags/Rogueware/default.aspx">Rogueware</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Adware/default.aspx">Adware</category></item><item><title>Rogue ScanVirus site impersonates SaaS Anti-Virus</title><link>http://pandalabs.pandasecurity.com/archive/ScanVirus-infection-site-impersonates-SaaS-Anti_2D00_Virus.aspx</link><pubDate>Tue, 03 Feb 2009 13:23:00 GMT</pubDate><guid isPermaLink="false">b262f9bf-63e5-46e5-8a14-4069a6997bc7:958</guid><dc:creator>Sean-Paul Correll</dc:creator><slash:comments>0</slash:comments><comments>http://pandalabs.pandasecurity.com/comments/958.aspx</comments><wfw:commentRss>http://pandalabs.pandasecurity.com/commentrss.aspx?PostID=958</wfw:commentRss><description>
&lt;p&gt;Today we discovered a new site using an interesting tactic  to trick users into infecting themselves with malware. This time the  cyber-criminals opted to pretend to be a Software as a Service (SaaS)  Anti-Virus solution. &lt;/p&gt;

&lt;p&gt;The &amp;quot;Scan Virus&amp;quot; website uses several legitimate  Anti-Malware logos and badges in order to gain the victims confidence.&amp;nbsp; Immediately upon loading the site a fake scan will begin and shortly
after that the site will prompt the user to download a file called
AntiVir.exe, which we detect as &lt;strong&gt;Adware/Antivirus2009&lt;/strong&gt;. The site attempts to scare users by displaying images such as,  &amp;quot;&lt;strong&gt;Your PC is infected! Sorry, standard programs cannot disinfect your PC  now&lt;/strong&gt;&amp;quot;, and &amp;quot;&lt;strong&gt;DO&lt;/strong&gt;&lt;strong&gt;WNLOAD PATCH to fix this problem&lt;/strong&gt;&amp;quot;&lt;/p&gt;

&lt;p&gt;&lt;a href="http://support.us.pandasecurity.com/blog/ScanVirus.jpg"&gt;&lt;img alt="scanvirusonline.net" border="0" height="390" src="http://support.us.pandasecurity.com/blog/ScanVirus.jpg" width="705" /&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=958" width="1" height="1"&gt;</description><category domain="http://pandalabs.pandasecurity.com/archive/tags/Malware/default.aspx">Malware</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/SaaS/default.aspx">SaaS</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Trojan/default.aspx">Trojan</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Adware/default.aspx">Adware</category></item></channel></rss>