<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://pandalabs.pandasecurity.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>PandaLabs : E3</title><link>http://pandalabs.pandasecurity.com/archive/tags/E3/default.aspx</link><description>Tags: E3</description><dc:language>en</dc:language><generator>CommunityServer 2.1 SP2 (Build: 61120.2)</generator><item><title>Cyber Criminals Target Air France, YouTube, E3, Microsoft, Project Natal, and more…</title><link>http://pandalabs.pandasecurity.com/archive/Cyber-Criminals-Target-Air-France_2C00_-YouTube_2C00_-E3_2C00_-Microsoft_2C00_-Project-Natal_2C00_-and-more_2620_.aspx</link><pubDate>Wed, 03 Jun 2009 11:53:00 GMT</pubDate><guid isPermaLink="false">b262f9bf-63e5-46e5-8a14-4069a6997bc7:1002</guid><dc:creator>Sean-Paul Correll</dc:creator><slash:comments>0</slash:comments><comments>http://pandalabs.pandasecurity.com/comments/1002.aspx</comments><wfw:commentRss>http://pandalabs.pandasecurity.com/commentrss.aspx?PostID=1002</wfw:commentRss><description>
&lt;p&gt;It seems like these days every other news breaking story is paralleled with a similar Blackhat SEO fueled Rogueware campaign. Today, Luis Corrons and I were talking about Microsoft&amp;rsquo;s recently announced Project Natal when his Google search for a video of the technology in action turned out to place a malicious link in the very top of the search results.&lt;/p&gt;
&lt;p&gt;
&lt;br /&gt;
&lt;img src="http://farm3.static.flickr.com/2472/3592212684_181d587477_o.jpg" /&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;Connection&lt;/strong&gt;: (Google to Rogue) &lt;br /&gt;
&lt;img height="103" src="http://farm4.static.flickr.com/3416/3591405941_9a70a41caa_o.jpg" width="630" /&gt;&lt;br /&gt;
&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;**UPDATE** 6/04/09 -&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt; 16,000 new malicious links have appeared in Google over the last 24 hours targeting the phrase &amp;quot;TV Online&amp;quot;. The malicious site appears to be a video viewing website.&amp;nbsp; It will prompt to you to downoad and install a codec.exe file, which of course is a malicious file.&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.flickr.com/photos/lithium-/3596363688/sizes/o/"&gt;&lt;img src="http://farm3.static.flickr.com/2465/3596363688_4aba7edb27.jpg" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;
&lt;img height="419" src="http://farm4.static.flickr.com/3398/3592212756_a1fa44bee4_o.jpg" width="599" /&gt;&lt;br /&gt;
&lt;/p&gt;
&lt;p&gt;Knowing that this link wouldn&amp;rsquo;t be the only one, we started researching the domains and keywords being targeted and here is what we found:&lt;/p&gt;

&lt;br /&gt;
&lt;strong&gt;Keywords:&lt;/strong&gt;&lt;br /&gt;
&lt;strong&gt;16,000 &lt;/strong&gt;links targeting &amp;quot;&lt;strong&gt;TV Online&lt;/strong&gt;&amp;quot;&lt;br /&gt;
&lt;strong&gt;16,000 &lt;/strong&gt;links targeting &amp;ldquo;&lt;strong&gt;YouTube&lt;/strong&gt;&amp;rdquo;&lt;br /&gt;
&lt;strong&gt;10,500&lt;/strong&gt; links targeting &amp;quot;&lt;strong&gt;France&lt;/strong&gt;&amp;quot; (Airline Crash)&lt;br /&gt;
&amp;nbsp; &lt;strong&gt;8,930&lt;/strong&gt; links targeting &amp;quot;&lt;strong&gt;Microsoft&lt;/strong&gt;&amp;quot; (Project Natal)&lt;br /&gt;
&amp;nbsp; &lt;strong&gt;3,380&lt;/strong&gt; links targeting &amp;quot;&lt;strong&gt;E3&lt;/strong&gt;&amp;quot; &lt;br /&gt;
&amp;nbsp; &lt;strong&gt;2,900&lt;/strong&gt; links targeting &amp;quot;&lt;strong&gt;Eminem&lt;/strong&gt;&amp;quot; (MTV Awards/Bruno Incident)&lt;br /&gt;
&amp;nbsp; &lt;strong&gt;2,850&lt;/strong&gt; links targeting &amp;ldquo;&lt;strong&gt;Sony&lt;/strong&gt;&amp;rdquo;&lt;br /&gt;
&lt;br /&gt;

&lt;p&gt;The sites are all hosted via Lycos Tripod, which is a free web host. This allows the cyber criminals to create thousands of free sites to take advantage of the Blackhat SEO and then simply redirect the free sites to just a handful of their own servers.&lt;/p&gt;

&lt;p&gt;Blackhat SEO is definitely one of the most prevalent threat distribution methods today. We expect to see several more examples of this type of attack throughout the year, so be especially careful when searching for news breaking stories.&lt;/p&gt;
All of the links associated in this attack have already been blocked for Panda users. &lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=1002" width="1" height="1"&gt;</description><category domain="http://pandalabs.pandasecurity.com/archive/tags/Rogueware/default.aspx">Rogueware</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Microsoft/default.aspx">Microsoft</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/YouTube/default.aspx">YouTube</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Blackhat+SEO/default.aspx">Blackhat SEO</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/E3/default.aspx">E3</category></item></channel></rss>