<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://pandalabs.pandasecurity.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>PandaLabs : Blackhat SEO</title><link>http://pandalabs.pandasecurity.com/archive/tags/Blackhat+SEO/default.aspx</link><description>Tags: Blackhat SEO</description><dc:language>en</dc:language><generator>CommunityServer 2.1 SP2 (Build: 61120.2)</generator><item><title>Black(hat) Friday</title><link>http://pandalabs.pandasecurity.com/archive/Black_2800_hat_2900_-Friday.aspx</link><pubDate>Fri, 20 Nov 2009 21:01:00 GMT</pubDate><guid isPermaLink="false">b262f9bf-63e5-46e5-8a14-4069a6997bc7:1049</guid><dc:creator>Sean-Paul Correll</dc:creator><slash:comments>0</slash:comments><comments>http://pandalabs.pandasecurity.com/comments/1049.aspx</comments><wfw:commentRss>http://pandalabs.pandasecurity.com/commentrss.aspx?PostID=1049</wfw:commentRss><description>&lt;span&gt;&lt;p align="left" dir="ltr"&gt;If you plan on shopping online for &amp;quot;Black Friday&amp;quot;, or &amp;quot;Cyber Monday&amp;quot;, you might be in for more than you bargained for.　 Cyber criminals behind the Rogueware epidemic have their &lt;a href="http://pandalabs.pandasecurity.com/archive/tags/SEO/default.aspx"&gt;blackhat SEO&lt;/a&gt; campaigns optimized to take advantage of deal seekers looking for advertisements online.　 One misstep and you just might find yourself staring at a scareware site designed to trick you into believing that your computer is infected.&amp;nbsp; &lt;/p&gt;&lt;strong&gt;&lt;p align="left" dir="ltr"&gt;Google Search:&lt;/p&gt;&lt;/strong&gt;&lt;/span&gt;&lt;p align="left" dir="ltr"&gt;&lt;a href="http://www.flickr.com/photos/lithium-/4120742406/sizes/o/" title="Blackhat SEO - Black Friday Campaign"&gt;&lt;img border="0" src="http://farm3.static.flickr.com/2530/4120742406_09f89d01b8_d.jpg" /&gt;&lt;/a&gt;&lt;/p&gt;&lt;font face="Calibri" size="3"&gt;&lt;font face="Calibri" size="3"&gt;&lt;span&gt;&lt;p align="left" dir="ltr"&gt;&lt;strong&gt;Fake Antivirus Page:&lt;/strong&gt;&lt;/p&gt;&lt;p align="left" dir="ltr"&gt;&lt;strong&gt;&amp;nbsp;&lt;/strong&gt;&lt;a href="http://www.flickr.com/photos/lithium-/4120742422/sizes/o/" title="Fake Antivirus"&gt;&lt;strong&gt;&lt;img alt="Black Friday - Rogueware Page" border="0" src="http://farm3.static.flickr.com/2762/4120742422_753882db2d_d.jpg" title="Black Friday - Rogueware Page" /&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&lt;p align="left" dir="ltr"&gt;We are constantly monitoring this and other Blackhat SEO campaigns to protect our customers against the latest malware attacks on the Internet.&amp;nbsp; If you are not a customer yet,&amp;nbsp;we recommend at least&amp;nbsp;installing&amp;nbsp;our free&amp;nbsp;&lt;a href="http://download.cnet.com/Panda-Cloud-Antivirus-Free-Edition/3000-2239_4-10914099.html?tag=mncol" title="Cloud Antivirus Download" target="_blank"&gt;Cloud Antivirus&lt;/a&gt;&amp;nbsp;protection. We also recommend adding an extra layer of browsing protection&amp;nbsp;with safer browsing technology, such as the community driven system provided by our partner, &lt;a href="http://www.pandasecurity.com/homeusers/downloads/WOT/" title="Web of Trust" target="_blank"&gt;Web Of Trust&lt;/a&gt;. &lt;/p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=1049" width="1" height="1"&gt;</description><category domain="http://pandalabs.pandasecurity.com/archive/tags/Rogueware/default.aspx">Rogueware</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Blackhat+SEO/default.aspx">Blackhat SEO</category></item><item><title>Blackhat SEO Aggressively Targets Halloween Related Keywords</title><link>http://pandalabs.pandasecurity.com/archive/Blackhat-SEO-Aggressively-Targets-Halloween-Related-Keywords.aspx</link><pubDate>Wed, 28 Oct 2009 00:00:00 GMT</pubDate><guid isPermaLink="false">b262f9bf-63e5-46e5-8a14-4069a6997bc7:1047</guid><dc:creator>Sean-Paul Correll</dc:creator><slash:comments>0</slash:comments><comments>http://pandalabs.pandasecurity.com/comments/1047.aspx</comments><wfw:commentRss>http://pandalabs.pandasecurity.com/commentrss.aspx?PostID=1047</wfw:commentRss><description>&lt;p&gt;Cyber criminals behind the Rogueware epidemic have been hard at work in poisoning search results to increase traffic to their campaign sites. Today, we identified a new Blackhat SEO campaign, which is currently targeting Halloween related keywords aggressively. While studying the campaign, I noticed that the most commonly targeted keywords were classic costume favorites, such as the Cat woman costume, vampire costume, and various adult costumes. In addition to costumes, the BHSEO campaign also targets Halloween related food recipes, haunted house directions, Halloween parties, and the movie Halloween. &lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tainted search results:&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;img alt="Blackhat SEO - Search Results" src="http://farm3.static.flickr.com/2486/4051474252_b5e88bf078_o.png" /&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Fake Antivirus site:&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.flickr.com/photos/lithium-/4051474234/sizes/o/in/photostream/"&gt;&lt;img alt="Rogueware Site" border="0" height="362" src="http://farm3.static.flickr.com/2797/4051474234_a601e7762a.jpg" width="500" /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tag cloud of targeted search terms:&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;img alt="BHSEO Tagcloud" height="416" src="http://farm3.static.flickr.com/2638/4051474274_bf1bf97f33_o.png" width="574" /&gt;&lt;/p&gt;&lt;p&gt;As we have &lt;a href="http://pandalabs.pandasecurity.com/archive/Targeted-Blackhat-SEO-Attack-against-Ford-Motor-Co_2E00_.aspx"&gt;documented&lt;/a&gt; &lt;a href="http://pandalabs.pandasecurity.com/archive/New-Blackhat-SEO-attack-exploits-vulnerabilities-in-Wordpress-to-distribute-rogue-antivirus-software.aspx"&gt;in&lt;/a&gt; &lt;a href="http://pandalabs.pandasecurity.com/archive/Swin-flu-and-the-Blackhat-SEO-techniques.aspx"&gt;prior&lt;/a&gt; &lt;a href="http://pandalabs.pandasecurity.com/archive/Blackhat-SEO-continues-to-ravage-search-results.aspx"&gt;blog&lt;/a&gt; &lt;a href="http://pandalabs.pandasecurity.com/search.aspx?q=blackhat+seo&amp;amp;p=1"&gt;posts&lt;/a&gt;, Blackhat SEO continues to be one of the most prevalent and pervasive attack vectors on the Internet today. As users, we tend to trust search engines to provide safe and accurate search results, but the reality is that today, search engines are becoming the most dangerous way to browse the Internet. &lt;/p&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=1047" width="1" height="1"&gt;</description><category domain="http://pandalabs.pandasecurity.com/archive/tags/Rogueware/default.aspx">Rogueware</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Blackhat+SEO/default.aspx">Blackhat SEO</category></item><item><title>Blackhat SEO Campaign Targets 2009 Nobel Prize Winner</title><link>http://pandalabs.pandasecurity.com/archive/Blackhat-SEO-Campaign-Targets-2009-Nobel-Prize-Winner.aspx</link><pubDate>Fri, 09 Oct 2009 12:20:00 GMT</pubDate><guid isPermaLink="false">b262f9bf-63e5-46e5-8a14-4069a6997bc7:1046</guid><dc:creator>Sean-Paul Correll</dc:creator><slash:comments>0</slash:comments><comments>http://pandalabs.pandasecurity.com/comments/1046.aspx</comments><wfw:commentRss>http://pandalabs.pandasecurity.com/commentrss.aspx?PostID=1046</wfw:commentRss><description>&lt;p&gt;&amp;nbsp;We&amp;rsquo;ve identified a new Blackhat SEO campaign today which  targets President Obama as the 2009 Nobel Peace  Prize winner among a thousand or so other search terms.&amp;nbsp;&amp;nbsp; Clicking on a malicious search result yields  the typical Rogueware campaign.&amp;nbsp; 

&lt;/p&gt;&lt;p&gt;&lt;br /&gt;
  &lt;strong&gt;Search result&lt;/strong&gt;:&lt;br /&gt;
  &lt;img alt="Nobel Peace Prize Winner 2009 - Obama Blackhat SEO" height="107" src="http://farm3.static.flickr.com/2481/3994744083_33696b8a90_o.png" width="669" /&gt;&lt;br /&gt;
  &lt;br /&gt;
  &lt;strong&gt;Rogueware site&lt;/strong&gt;:&lt;br /&gt;
  &lt;img alt="Windows Performance Center Rogueware" height="439" src="http://farm4.static.flickr.com/3535/3995502608_1e92824bd1_o.png" width="603" /&gt;&lt;/p&gt;

&lt;p&gt;The complete list of targeted search terms can be found &lt;a href="http://dl.getdropbox.com/u/1301849/BlackhatSEO4.txt"&gt;here&lt;/a&gt;.&amp;nbsp; &amp;nbsp;&lt;/p&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=1046" width="1" height="1"&gt;</description><category domain="http://pandalabs.pandasecurity.com/archive/tags/Rogueware/default.aspx">Rogueware</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Blackhat+SEO/default.aspx">Blackhat SEO</category></item><item><title>Blackhat SEO continues to ravage search results</title><link>http://pandalabs.pandasecurity.com/archive/Blackhat-SEO-continues-to-ravage-search-results.aspx</link><pubDate>Tue, 22 Sep 2009 23:26:00 GMT</pubDate><guid isPermaLink="false">b262f9bf-63e5-46e5-8a14-4069a6997bc7:1041</guid><dc:creator>Sean-Paul Correll</dc:creator><slash:comments>0</slash:comments><comments>http://pandalabs.pandasecurity.com/comments/1041.aspx</comments><wfw:commentRss>http://pandalabs.pandasecurity.com/commentrss.aspx?PostID=1041</wfw:commentRss><description>&lt;p&gt;Every day cyber criminals are exploiting search engines to  display high ranking malicious search results. Targeting hot topics allows for  cyber criminals to improve infection rates for their money making &lt;a href="http://www.pandasecurity.com/img/enc/The%20Business%20of%20Rogueware.pdf"&gt;Rogueware&lt;/a&gt;  (pdf) schemes.&amp;nbsp;Below is an example of the attack we observed today. &amp;nbsp; &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;strong&gt;Most targeted search terms:&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Dallas Cowboys&lt;/li&gt;
&lt;li&gt;NFL&lt;/li&gt;
&lt;li&gt;School&lt;/li&gt;
&lt;li&gt;Emmy Awards&lt;/li&gt;
&lt;li&gt;Autumn Equinox (Mabon)&lt;/li&gt;
&lt;li&gt;Atlanta&lt;/li&gt;
&lt;li&gt;News&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;
..The full list of targeted keywords can be  downloaded here: &lt;a href="http://dl.getdropbox.com/u/1301849/BlackhatSEO3.txt"&gt;BlackhatSEO3.txt&lt;/a&gt; &lt;br /&gt;
&lt;/p&gt;

&lt;strong&gt;Sample search result:&lt;br /&gt;
&lt;/strong&gt;&lt;br /&gt;
  &lt;a href="http://www.flickr.com/photos/lithium-/3946167610/sizes/o/"&gt;&lt;img alt="BHSEO Search Result" border="0" height="68" src="http://farm4.static.flickr.com/3500/3946167610_9827cf3c0e.jpg" width="500" /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
  &lt;strong&gt;Redirection to fake  security (Rogueware) site:&lt;/strong&gt;&lt;br /&gt;
  &lt;br /&gt;
  &lt;a href="http://www.flickr.com/photos/lithium-/3945384803/sizes/o/"&gt;&lt;img alt="Rogueware Site" border="0" height="343" src="http://farm3.static.flickr.com/2494/3945384803_4ab52b828f.jpg" width="500" /&gt;&lt;/a&gt;

&lt;p&gt;&lt;strong&gt;Rogueware:  Adware/PCDefender&lt;/strong&gt;&lt;br /&gt;
&lt;br /&gt;
  &lt;a href="http://www.flickr.com/photos/lithium-/3946167632/sizes/o/in/photostream/"&gt;&lt;img alt="Adware/PC Defender" border="0" height="414" src="http://farm4.static.flickr.com/3498/3946167632_141197666d.jpg" width="500" /&gt;&lt;/a&gt;&lt;br /&gt;
  &lt;strong&gt;&lt;br /&gt;
Tag cloud of targeted terms:&lt;/strong&gt;&lt;br /&gt;
  &lt;a href="http://www.flickr.com/photos/lithium-/3946167600/sizes/o/"&gt;&lt;img alt="Blackhat SEO Tag Cloud" border="0" height="319" src="http://farm4.static.flickr.com/3459/3946167600_907938a5dd.jpg" width="500" /&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=1041" width="1" height="1"&gt;</description><category domain="http://pandalabs.pandasecurity.com/archive/tags/Rogueware/default.aspx">Rogueware</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Blackhat+SEO/default.aspx">Blackhat SEO</category></item><item><title>Blackhat SEO Attack Targets Obama's Speech</title><link>http://pandalabs.pandasecurity.com/archive/Blackhat-SEO-Attack-Targets-Obama_2700_s-Speech.aspx</link><pubDate>Wed, 09 Sep 2009 23:52:00 GMT</pubDate><guid isPermaLink="false">b262f9bf-63e5-46e5-8a14-4069a6997bc7:1038</guid><dc:creator>Sean-Paul Correll</dc:creator><slash:comments>0</slash:comments><comments>http://pandalabs.pandasecurity.com/comments/1038.aspx</comments><wfw:commentRss>http://pandalabs.pandasecurity.com/commentrss.aspx?PostID=1038</wfw:commentRss><description>&lt;p&gt;Using search engines to browse the Internet these days is a dangerous endeavor. Cyber criminals are keen on gaming search engine algorithms and are able to quickly divert innocent news seekers to malicious websites.&amp;nbsp; Today, &lt;a href="http://www.wired.com/threatlevel/2009/09/dan-brown/"&gt;&lt;em&gt;WIRED&lt;/em&gt; reported&lt;/a&gt; that cyber criminals were targeting a highly anticipated Dan Brown novel, but the target and scope is much deeper than that.&amp;nbsp; Literally every current relevant news topic is actively targeted each day, including highly publicized speeches given by President Obama this week. &lt;/p&gt;&lt;p&gt;Clicking the following link in a Google search result will point us to a malicious Rogueware campaign page:&amp;nbsp; &amp;nbsp; &lt;br /&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;img border="0" height="86" src="http://farm4.static.flickr.com/3455/3905344670_96c24804fd_o.png" width="526" /&gt;&lt;/p&gt;&lt;p&gt;&lt;img border="0" height="363" src="http://farm4.static.flickr.com/3457/3862323083_06c292d798.jpg" width="500" /&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Malware Info:&lt;/strong&gt; &lt;a href="http://www.pandasecurity.com/homeusers/security-info/212758/information/SmartVirusEliminator"&gt;Adware/SmartVirusEliminator&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;img border="0" height="415" src="http://farm3.static.flickr.com/2547/3875711839_282e6b7bc0.jpg" width="500" /&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&amp;nbsp;Investigating the attack shows us a bigger picture of the targeted keywords: &lt;/p&gt;&lt;p&gt;&lt;a href="http://farm3.static.flickr.com/2619/3905391770_7769fa48ee_o.png" target="_blank"&gt;&lt;img border="0" height="276" src="http://farm3.static.flickr.com/2619/3905391770_015412a26c.jpg" width="500" /&gt;&lt;/a&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Most commonly targeted keywords:&lt;/strong&gt; &lt;br /&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Obama Speech&lt;/li&gt;&lt;li&gt;GM group enterprises&lt;/li&gt;&lt;li&gt;Apple&lt;/li&gt;&lt;li&gt;Beatles&lt;/li&gt;&lt;li&gt;America&lt;/li&gt;&lt;li&gt;White House&lt;/li&gt;&lt;li&gt;Jon Gosselin&lt;/li&gt;&lt;li&gt;Live Interview&lt;/li&gt;&lt;li&gt;School Season&lt;br /&gt;The full list of targeted keywords can be downloaded here: &lt;a href="http://dl.getdropbox.com/u/1301849/BlackhatSEO2.txt"&gt;BlackhatSEO2.txt&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Over the past six months that PandaLabs has closely tracked the evolution of &lt;a href="http://pandalabs.pandasecurity.com/archive/tags/Blackhat/default.aspx"&gt;Blackhat SEO attacks&lt;/a&gt;, we&amp;rsquo;ve seen these targeted campaigns be executed by cybercriminals with increasing levels of speed and sophistication. &amp;nbsp;Today, Blackhat SEO is truly a mainstream tactic used by&amp;nbsp;cyber criminals.&amp;nbsp; Targeting real-time news events is a serious problem not only for search engines, but for all parties involved in malware mitigation.&amp;nbsp; In shifting to the &amp;quot;real-time web,&amp;quot; the entire IT security community must also recognize the need for real-time Malware protection and this is precisely why the move to cloud-based &lt;a href="http://www.pandasecurity.com/homeusers/solutions/collective-intelligence"&gt;antivirus technology&lt;/a&gt; is necessary. &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/p&gt;&lt;br /&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=1038" width="1" height="1"&gt;</description><category domain="http://pandalabs.pandasecurity.com/archive/tags/Rogueware/default.aspx">Rogueware</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Blackhat+SEO/default.aspx">Blackhat SEO</category></item><item><title>Be Careful With Your Search Results</title><link>http://pandalabs.pandasecurity.com/archive/Be-Careful-With-Your-Search-Results.aspx</link><pubDate>Tue, 01 Sep 2009 17:29:00 GMT</pubDate><guid isPermaLink="false">b262f9bf-63e5-46e5-8a14-4069a6997bc7:1034</guid><dc:creator>Sean-Paul Correll</dc:creator><slash:comments>0</slash:comments><comments>http://pandalabs.pandasecurity.com/comments/1034.aspx</comments><wfw:commentRss>http://pandalabs.pandasecurity.com/commentrss.aspx?PostID=1034</wfw:commentRss><description>&lt;p&gt;&amp;nbsp;&lt;strong&gt;Update:&amp;nbsp; &lt;a href="http://pandalabs.pandasecurity.com/archive/Blackhat-SEO-Attack-Targets-Obama_2700_s-Speech.aspx"&gt;Learn about the latest BHSEO attack here.&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;Blackhat SEO (BHSEO) is currently one of the most prevalent distribution methods for Malware on the Internet.&amp;nbsp; It&amp;rsquo;s also one of the most dangerous methods because of the user-implied trust in search results.&amp;nbsp; A Forrester &lt;a href="http://blogs.forrester.com/groundswell/2008/12/people-dont-tru.html"&gt;research study&lt;/a&gt; conducted in 2008 showed that 50 percent of Internet users trust content delivered by search engines. It&amp;rsquo;s no surprise that cyber criminals have been using malicious search results as a main monetization stream.&lt;br /&gt;&lt;br /&gt;The Rogueware campaign &lt;a href="http://pandalabs.pandasecurity.com/archive/Are-Cyber-Criminals-Targeting-Local-Events-In-Your-City_3F00_.aspx" target="_blank"&gt;we blogged about last week&lt;/a&gt; turned into a full blown BHSEO attack targeting relevant news topics such as, the California wildfires, Ted Kennedy&amp;rsquo;s death, DJ AM&amp;rsquo;s death, Mega Millions Lottery, Hurricane Danny, UFC 102, CNN and BBC breaking news among thousands of search terms and 123,000 links. &amp;nbsp;Upon clicking one of many malicious links in the top ranking search results, the victim is put through several redirections and finally taken to a fake scan website designed to infect and extort money. &amp;nbsp;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Fake scan site:&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.flickr.com/photos/lithium-/3862323083/sizes/o/" target="_blank"&gt;&lt;img alt="Adware/SmartVirusEliminator" border="0" height="363" src="http://farm4.static.flickr.com/3457/3862323083_06c292d798.jpg" width="500" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Installer: &lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;img alt="setup.exe" border="0" height="71" src="http://farm4.static.flickr.com/3439/3875737771_4e68859a8e.jpg" width="53" /&gt;&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;File&lt;/strong&gt;: setup.exe&lt;br /&gt;&lt;strong&gt;Size&lt;/strong&gt;: 72192&lt;br /&gt;&lt;strong&gt;MD5&lt;/strong&gt;: 2C0625D97A5BC7EC299D33CE8C9A299E&amp;nbsp;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;img alt="Installer" border="0" height="253" src="http://farm3.static.flickr.com/2576/3876528032_a56404095d.jpg" width="500" /&gt;&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Adware/SmartVirusEliminator&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.flickr.com/photos/lithium-/3875711839/sizes/o/" target="_blank"&gt;&lt;img alt="Adware/SmartVirusEliminator" border="0" height="415" src="http://farm3.static.flickr.com/2547/3875711839_282e6b7bc0.jpg" width="500" /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tag cloud of exploited keywords&lt;/strong&gt;:&lt;br /&gt;&lt;a href="http://www.flickr.com/photos/lithium-/3876510878/sizes/o/" target="_blank"&gt;&lt;img alt="4" border="0" height="338" src="http://farm3.static.flickr.com/2521/3876510878_01a39886c6.jpg" width="500" /&gt;&lt;/a&gt;&amp;nbsp;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Most exploited keywords&lt;/strong&gt;:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;BBC News 2009&lt;/li&gt;&lt;li&gt;CNN News 2009&lt;/li&gt;&lt;li&gt;Ted Kennedy&lt;/li&gt;&lt;li&gt;Official Website&lt;/li&gt;&lt;li&gt;USA News&lt;/li&gt;&lt;li&gt;Hottest Info/News&lt;/li&gt;&lt;li&gt;CA/California Fire&lt;/li&gt;&lt;li&gt;Lottery&lt;/li&gt;&lt;li&gt;Hurricane&lt;/li&gt;&lt;li&gt;Halloween&lt;br /&gt;The full list can be downloaded here: &lt;a href="http://support.us.pandasecurity.com/blog/BlackhatSEO.txt" target="_blank"&gt;BlackhatSEO.txt&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;You can read more about Rogueware in our most recent report: &lt;a href="http://www.pandasecurity.com/img/enc/The%20Business%20of%20Rogueware.pdf" target="_blank"&gt;The Business of Rogueware&lt;/a&gt; [pdf]&lt;br /&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=1034" width="1" height="1"&gt;</description><category domain="http://pandalabs.pandasecurity.com/archive/tags/Rogueware/default.aspx">Rogueware</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Blackhat+SEO/default.aspx">Blackhat SEO</category></item><item><title>Are Cyber Criminals Targeting Local Events In Your City?</title><link>http://pandalabs.pandasecurity.com/archive/Are-Cyber-Criminals-Targeting-Local-Events-In-Your-City_3F00_.aspx</link><pubDate>Thu, 27 Aug 2009 21:36:00 GMT</pubDate><guid isPermaLink="false">b262f9bf-63e5-46e5-8a14-4069a6997bc7:1032</guid><dc:creator>Sean-Paul Correll</dc:creator><slash:comments>0</slash:comments><comments>http://pandalabs.pandasecurity.com/comments/1032.aspx</comments><wfw:commentRss>http://pandalabs.pandasecurity.com/commentrss.aspx?PostID=1032</wfw:commentRss><description>&lt;p&gt; Panda Security has a California based office in Los Angeles.&amp;nbsp; We are located in close proximity to two  ongoing wildfires in the Angeles Crest National Forrest that have now burned  through at least 30 acres, so naturally we have been keeping an eye on it.&amp;nbsp; To my surprise, I pulled up a Google search for &amp;ldquo;Angeles Crest Fire&amp;rdquo; and the result yielded a malicious link above most relevant sources.&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Update&lt;/strong&gt;: 9/01/08 - The Blackhat SEO attack has now grown significantly: &lt;a href="http://bit.ly/7jqGc" target="_blank"&gt;http://bit.ly/7jqGc&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;
  &lt;br /&gt;
&lt;a href="http://www.flickr.com/photos/lithium-/3863044314/sizes/o/"&gt;&lt;img alt="Angeles Crest Fire - Malicious Search Result" border="0" src="http://farm3.static.flickr.com/2651/3863044314_271113a1b2.jpg" /&gt;&lt;/a&gt;&amp;nbsp;&amp;nbsp;&lt;br /&gt;
&lt;br /&gt;
  Once clicked, the site loads and checks to make sure the  user came from Google.&amp;nbsp; If so, the following  script begins the redirection to the Rogueware site:&lt;br /&gt;
  &lt;br /&gt;
  &lt;img alt="Angeles Crest Fire - Malicious Script" border="0" height="25" src="http://farm3.static.flickr.com/2591/3863129480_b3e8db0044.jpg" width="500" /&gt;&lt;br /&gt;
  &lt;br /&gt;
The Rogueware site is designed to display a fake Antivirus  scan designed scare victims into thinking that their computer is infected.&amp;nbsp; If the Malware is downloaded and installed as  the site suggests, the user will see a fake Antivirus program pop up on their  computer.&amp;nbsp; At that point it becomes very  aggressive and difficult to remove.&amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://www.flickr.com/photos/lithium-/3862323083/sizes/o/"&gt;
  &lt;img alt="Adware/PersonalAntivirus" border="0" height="363" src="http://farm4.static.flickr.com/3457/3862323083_06c292d798.jpg" width="500" /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;strong&gt;&lt;br /&gt;
File:&lt;/strong&gt; Antivirus-x_x.exe&lt;br /&gt;
&lt;strong&gt;Size:&lt;/strong&gt; 172032&lt;br /&gt;
&lt;strong&gt;MD5:&lt;/strong&gt;  0E9BC3499560EEA9261F5883FAE2A10E
&lt;br /&gt;
&lt;strong&gt;Malware Info:&lt;/strong&gt; &lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?IdVirus=208332"&gt;Adware/PersonalAntivirus&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
  Rogueware attacks are among the most prevalent attacks on  the Internet today.&amp;nbsp; You can see our  latest report on them here: &lt;a href="http://www.pandasecurity.com/img/enc/The%20Business%20of%20Rogueware.pdf"&gt;The  Business of Rogueware&lt;/a&gt; (pdf)&lt;br /&gt;

&lt;p&gt;&lt;strong&gt;5 Steps to Avoid Infection&lt;/strong&gt;:&lt;/p&gt;

&lt;blockquote&gt;&lt;ol&gt;&lt;li&gt;Always have up-to-date Anti-Malware software  installed.&amp;nbsp; If you don&amp;rsquo;t have one or if  your current solution is not removing the Malware, you could download a free trial from us here: &lt;a href="http://www.pandasecurity.com/usa/homeusers/downloads/evaluation/"&gt;http://www.pandasecurity.com/usa/homeusers/downloads/evaluation/&lt;br /&gt;&lt;br /&gt;&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Don&amp;rsquo;t rely on search engines to provide valid or  safe search results.&amp;nbsp; You can improve  your chances of safe browsing by downloading our free Web of Trust browser  plugin: &lt;a href="http://www.pandasecurity.com/homeusers/downloads/wot/"&gt;http://www.pandasecurity.com/homeusers/downloads/wot/&lt;br /&gt;&lt;br /&gt;&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Pay close attention to what links you are  clicking on.&amp;nbsp; If you don&amp;rsquo;t recognize the  source you may want to research the domain in a separate search or avoid the  link all together.&amp;nbsp; &lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Rogueware attacks rely on Social Engineering (I.e.  making you believe you are infected when you are not).&amp;nbsp; Don&amp;rsquo;t believe it!  Simply close the browser window if you see a scan appear all of the sudden.&amp;nbsp; If you cannot close the window with your mouse you can try ALT+F4 to force close it.&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Don&amp;rsquo;t be afraid to ask for help.&amp;nbsp; Call your Antivirus Company or a tech savvy  friend if you feel that you are in over your head.&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/li&gt;&lt;/ol&gt;&lt;/blockquote&gt; 



&lt;ol&gt;
  

  

  

  

  

&lt;/ol&gt;

&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=1032" width="1" height="1"&gt;</description><category domain="http://pandalabs.pandasecurity.com/archive/tags/Rogueware/default.aspx">Rogueware</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Tips/default.aspx">Tips</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Blackhat+SEO/default.aspx">Blackhat SEO</category></item><item><title>Cyber Criminals Target Air France, YouTube, E3, Microsoft, Project Natal, and more…</title><link>http://pandalabs.pandasecurity.com/archive/Cyber-Criminals-Target-Air-France_2C00_-YouTube_2C00_-E3_2C00_-Microsoft_2C00_-Project-Natal_2C00_-and-more_2620_.aspx</link><pubDate>Wed, 03 Jun 2009 11:53:00 GMT</pubDate><guid isPermaLink="false">b262f9bf-63e5-46e5-8a14-4069a6997bc7:1002</guid><dc:creator>Sean-Paul Correll</dc:creator><slash:comments>0</slash:comments><comments>http://pandalabs.pandasecurity.com/comments/1002.aspx</comments><wfw:commentRss>http://pandalabs.pandasecurity.com/commentrss.aspx?PostID=1002</wfw:commentRss><description>
&lt;p&gt;It seems like these days every other news breaking story is paralleled with a similar Blackhat SEO fueled Rogueware campaign. Today, Luis Corrons and I were talking about Microsoft&amp;rsquo;s recently announced Project Natal when his Google search for a video of the technology in action turned out to place a malicious link in the very top of the search results.&lt;/p&gt;
&lt;p&gt;
&lt;br /&gt;
&lt;img src="http://farm3.static.flickr.com/2472/3592212684_181d587477_o.jpg" /&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;Connection&lt;/strong&gt;: (Google to Rogue) &lt;br /&gt;
&lt;img height="103" src="http://farm4.static.flickr.com/3416/3591405941_9a70a41caa_o.jpg" width="630" /&gt;&lt;br /&gt;
&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;**UPDATE** 6/04/09 -&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt; 16,000 new malicious links have appeared in Google over the last 24 hours targeting the phrase &amp;quot;TV Online&amp;quot;. The malicious site appears to be a video viewing website.&amp;nbsp; It will prompt to you to downoad and install a codec.exe file, which of course is a malicious file.&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.flickr.com/photos/lithium-/3596363688/sizes/o/"&gt;&lt;img src="http://farm3.static.flickr.com/2465/3596363688_4aba7edb27.jpg" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;
&lt;img height="419" src="http://farm4.static.flickr.com/3398/3592212756_a1fa44bee4_o.jpg" width="599" /&gt;&lt;br /&gt;
&lt;/p&gt;
&lt;p&gt;Knowing that this link wouldn&amp;rsquo;t be the only one, we started researching the domains and keywords being targeted and here is what we found:&lt;/p&gt;

&lt;br /&gt;
&lt;strong&gt;Keywords:&lt;/strong&gt;&lt;br /&gt;
&lt;strong&gt;16,000 &lt;/strong&gt;links targeting &amp;quot;&lt;strong&gt;TV Online&lt;/strong&gt;&amp;quot;&lt;br /&gt;
&lt;strong&gt;16,000 &lt;/strong&gt;links targeting &amp;ldquo;&lt;strong&gt;YouTube&lt;/strong&gt;&amp;rdquo;&lt;br /&gt;
&lt;strong&gt;10,500&lt;/strong&gt; links targeting &amp;quot;&lt;strong&gt;France&lt;/strong&gt;&amp;quot; (Airline Crash)&lt;br /&gt;
&amp;nbsp; &lt;strong&gt;8,930&lt;/strong&gt; links targeting &amp;quot;&lt;strong&gt;Microsoft&lt;/strong&gt;&amp;quot; (Project Natal)&lt;br /&gt;
&amp;nbsp; &lt;strong&gt;3,380&lt;/strong&gt; links targeting &amp;quot;&lt;strong&gt;E3&lt;/strong&gt;&amp;quot; &lt;br /&gt;
&amp;nbsp; &lt;strong&gt;2,900&lt;/strong&gt; links targeting &amp;quot;&lt;strong&gt;Eminem&lt;/strong&gt;&amp;quot; (MTV Awards/Bruno Incident)&lt;br /&gt;
&amp;nbsp; &lt;strong&gt;2,850&lt;/strong&gt; links targeting &amp;ldquo;&lt;strong&gt;Sony&lt;/strong&gt;&amp;rdquo;&lt;br /&gt;
&lt;br /&gt;

&lt;p&gt;The sites are all hosted via Lycos Tripod, which is a free web host. This allows the cyber criminals to create thousands of free sites to take advantage of the Blackhat SEO and then simply redirect the free sites to just a handful of their own servers.&lt;/p&gt;

&lt;p&gt;Blackhat SEO is definitely one of the most prevalent threat distribution methods today. We expect to see several more examples of this type of attack throughout the year, so be especially careful when searching for news breaking stories.&lt;/p&gt;
All of the links associated in this attack have already been blocked for Panda users. &lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=1002" width="1" height="1"&gt;</description><category domain="http://pandalabs.pandasecurity.com/archive/tags/Rogueware/default.aspx">Rogueware</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Microsoft/default.aspx">Microsoft</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/YouTube/default.aspx">YouTube</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Blackhat+SEO/default.aspx">Blackhat SEO</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/E3/default.aspx">E3</category></item><item><title>Rogueware Campaigns blending in with Twitter Trends</title><link>http://pandalabs.pandasecurity.com/archive/Rogueware-Campaigns-now-blending-into-Twitter-Trends.aspx</link><pubDate>Wed, 03 Jun 2009 08:23:00 GMT</pubDate><guid isPermaLink="false">b262f9bf-63e5-46e5-8a14-4069a6997bc7:1001</guid><dc:creator>Sean-Paul Correll</dc:creator><slash:comments>0</slash:comments><comments>http://pandalabs.pandasecurity.com/comments/1001.aspx</comments><wfw:commentRss>http://pandalabs.pandasecurity.com/commentrss.aspx?PostID=1001</wfw:commentRss><description>
&lt;p&gt;&amp;nbsp;&lt;strong&gt;Update: 6/4/09 - &lt;a href="http://bit.ly/lFde3"&gt;Rogueware campaign on Twitter continues...&lt;/a&gt;&lt;br /&gt;
&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&amp;quot;PhishTube Broadcast&amp;quot; became a trending topic on &lt;a href="http://www.twitter.com"&gt;Twitter&lt;/a&gt; today.  The word &amp;ldquo;tube&amp;rdquo; is a big red flag to any Threat Researcher these days, so naturally I had to investigate it. &lt;/p&gt;
&lt;a href="http://www.flickr.com/photos/lithium-/3590917121/sizes/o/"&gt;
&lt;img border="0" height="670" src="http://farm4.static.flickr.com/3401/3590917121_ce957f0097_o.jpg" width="643" /&gt;&lt;/a&gt;
&lt;p&gt;
I clicked on the section inside of the trending topics group and ironically the links in the tweets looked fishy.&lt;br /&gt;
&lt;br /&gt;
&lt;img src="http://farm4.static.flickr.com/3591/3590917143_6dd61607d5_o.jpg" /&gt;&lt;br /&gt;
&lt;br /&gt;
I started to investigate further and found that while there was definitely legitimate tweet traffic for the band Phish, several zombie accounts were posting hundreds of strange and highly suspicious messages. Eventually the links led me through several redirections and finally to PornTube malware websites.&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://www.flickr.com/photos/lithium-/3591725374/sizes/o/"&gt;&lt;img border="0" src="http://farm3.static.flickr.com/2100/3591725374_844bf2c398.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Connections/Redirects leaving Twitter:&lt;/strong&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;&lt;/strong&gt; &lt;img src="http://farm3.static.flickr.com/2039/3591725400_124dd0c381_o.jpg" /&gt;&lt;/p&gt;

&lt;p&gt;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Clicking on any element inside of the PornTube page resulted in a run of the mill &lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?lst=det&amp;amp;idvirus=207660"&gt;Adware/PrivacyCenter&lt;/a&gt; infection, but the interesting part of it all is that cyber criminals are starting
to target social networking sites more than ever. In this case they
took advantage of the open dialog on Twitter and essentially blended in
with the trending topics in order to effectively trick unsuspecting
users into clicking malicious links. This technique is strikingly
similar to the Blackhat SEO tricks criminals use on search engines to
place their malicious links at the top of search results. &lt;br /&gt;
&lt;/p&gt;

&lt;p&gt;
&lt;img src="http://farm4.static.flickr.com/3638/3591938300_a44886881f.jpg" /&gt;
&lt;/p&gt;

&lt;p&gt;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=1001" width="1" height="1"&gt;</description><category domain="http://pandalabs.pandasecurity.com/archive/tags/Rogueware/default.aspx">Rogueware</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Twitter/default.aspx">Twitter</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Blackhat+SEO/default.aspx">Blackhat SEO</category></item></channel></rss>