<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://pandalabs.pandasecurity.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>PandaLabs : Malicious links</title><link>http://pandalabs.pandasecurity.com/archive/tags/Malicious+links/default.aspx</link><description>Tags: Malicious links</description><dc:language>en</dc:language><generator>CommunityServer 2.1 SP2 (Build: 61120.2)</generator><item><title>YouTube riddled with comments leading to Malware</title><link>http://pandalabs.pandasecurity.com/archive/YouTube-riddled-with-comments-leading-to-Malware.aspx</link><pubDate>Fri, 22 May 2009 06:10:00 GMT</pubDate><guid isPermaLink="false">b262f9bf-63e5-46e5-8a14-4069a6997bc7:999</guid><dc:creator>Sean-Paul Correll</dc:creator><slash:comments>0</slash:comments><comments>http://pandalabs.pandasecurity.com/comments/999.aspx</comments><wfw:commentRss>http://pandalabs.pandasecurity.com/commentrss.aspx?PostID=999</wfw:commentRss><description>&lt;p&gt;A few months ago, we talked about&lt;a href="http://pandalabs.pandasecurity.com/archive/Malware-in-Social-Media.aspx"&gt; YouTube&amp;#39;s Annotations feature&lt;/a&gt; being used as a tool for Cyber Criminals to help spread their malicious Rogueware campaigns.  Today, we have a similar case, but this time its automated comment Malspam (Malware spam).  My &lt;a href="http://www.flickr.com/photos/lithium-/3553092060/"&gt;initial&lt;/a&gt; &lt;a href="http://www.flickr.com/photos/lithium-/3552282729/"&gt;search&lt;/a&gt; &lt;a href="http://www.flickr.com/photos/lithium-/3553091998/"&gt;turned&lt;/a&gt; &lt;a href="http://www.flickr.com/photos/lithium-/3553091956/"&gt;up&lt;/a&gt; &lt;a href="http://www.flickr.com/photos/lithium-/3552282609/"&gt;about&lt;/a&gt; &lt;a href="http://www.flickr.com/photos/lithium-/3553091944/"&gt;30,000&lt;/a&gt; &lt;a href="http://www.flickr.com/photos/lithium-/3553091876/"&gt;malspam&lt;/a&gt; comments all pointing to a fake pornography website called &amp;quot;PornTube 2.0&amp;quot;.&lt;/p&gt;
&lt;p&gt;&lt;img src="http://farm4.static.flickr.com/3302/3553091944_aac4c0db2f.jpg" /&gt;&lt;/p&gt;
    
&lt;p&gt;Like the &lt;a href="http://pandalabs.pandasecurity.com/archive/Malware-in-Social-Media.aspx"&gt;last time&lt;/a&gt;, Cyber Criminals are targeting people who are searching YouTube for pornography.  In the comments each malicious link is accompanied by a few search terms.  Some common keywords we have seen are Adalt (sic), Tit s, Latina, Kinky, Girl, Porn, Sex, and the names of various pornography stars.&lt;br /&gt;
&lt;br /&gt;
By targeting these keywords the Cyber Criminals are able to optimize and improve their success rates by infecting those who are truly looking for pornographic material.&lt;/p&gt;
 
&lt;p&gt;
Note: It appears that all of the malicious links have brackets in between the &amp;quot; .com&amp;quot; portion of the comment.  It&amp;#39;s unclear if this is a temporary action done by the YouTube abuse team or if the criminals are just trying to evade detection.&lt;/p&gt;

&lt;p&gt;Upon arriving at the website, we see a page that looks like a legitimate video website labeled &amp;quot;PornTube 2.0&amp;quot;, but it is actually the malware site.&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;Malware Site:&lt;/strong&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://www.flickr.com/photos/lithium-/3553091856/in/set-72157618509807695/"&gt;Click for the original uncensored image (Warning: NSFW)&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;img border="0" src="http://farm4.static.flickr.com/3626/3552282739_55bb7f24a5.jpg?v=0" /&gt; &lt;br /&gt;
 &lt;br /&gt;
If you click anything on the website it will prompt you to download a fake Adobe Flash plugin, which is the malware installer for &lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?lst=det&amp;amp;idvirus=207660&amp;amp;sitepanda=particulares"&gt;Adware/Privacy Center&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://www.flickr.com/photos/lithium-/3553092152/in/set-72157618509807695/"&gt;Click for the original uncensored image (Warning: NSFW)&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;img src="http://farm4.static.flickr.com/3330/3553092106_a4f2fb9189_o.png" /&gt; &lt;br /&gt;
&lt;strong&gt;&lt;br /&gt;
Adware/PrivacyCenter Rogue (fake) Antivirus&lt;br /&gt;
&lt;/strong&gt;&lt;/p&gt;
&lt;strong&gt;&lt;a href="http://www.flickr.com/photos/lithium-/3552354491/"&gt;&lt;img border="0" src="http://farm4.static.flickr.com/3320/3552354491_6a743eca68.jpg?v=0" /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;/strong&gt;
&lt;p&gt;Rogue Antivirus is one of the most prolific Malware in the threat landscape today. PandaLabs has received more Rogue Antivirus samples in Q1 of 2009 than in all of 2008 as demonstrated by the following illustration.&lt;br /&gt;
&lt;br /&gt;
&lt;img src="http://farm4.static.flickr.com/3396/3552483899_3a6e07bf01.jpg" /&gt;&lt;br /&gt;
&lt;br /&gt;
In this case, Cyber Criminals aim to profit from human vulnerabilities and inherent curiosities. &lt;/p&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=999" width="1" height="1"&gt;</description><category domain="http://pandalabs.pandasecurity.com/archive/tags/Rogueware/default.aspx">Rogueware</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Malicious+links/default.aspx">Malicious links</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/YouTube/default.aspx">YouTube</category></item><item><title>Malware in Social Media</title><link>http://pandalabs.pandasecurity.com/archive/Malware-in-Social-Media.aspx</link><pubDate>Thu, 26 Feb 2009 17:17:00 GMT</pubDate><guid isPermaLink="false">b262f9bf-63e5-46e5-8a14-4069a6997bc7:972</guid><dc:creator>Sean-Paul Correll</dc:creator><slash:comments>0</slash:comments><comments>http://pandalabs.pandasecurity.com/comments/972.aspx</comments><wfw:commentRss>http://pandalabs.pandasecurity.com/commentrss.aspx?PostID=972</wfw:commentRss><description>
&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;A few weeks ago we talked about &lt;/font&gt;&lt;a href="http://pandalabs.pandasecurity.com/archive/Have-you-ever-heard-the-term-_2200_Rickrolling_22003F00_-Malware-distributors-have_2E002E002E00_.aspx" target="_blank"&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;cyber-criminals using Digg.com to spread malware&lt;/font&gt;&lt;/a&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;. Today we see that the very same group responsible for the Digg.com incident was using the same tactic on YouTube through the use of YouTube&amp;#39;s Annotations feature. &lt;/font&gt;&lt;a href="http://www.youtube.com/t/annotations_about" target="_blank"&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;Video Annotations&lt;/font&gt;&lt;/a&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt; is a way to add interactive commentary to videos on YouTube. &lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;The following image displays a video using the annotations feature to guide users over to a malware ridden website:&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;img height="363" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2009/02/26/MWYoutube.png" style="width:700px;height:363px;" width="700" /&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;Although the YouTube description malware is not as prevalent as the Digg.com comment abuse, it does show that Social Media websites are increasingly being used to spread Malware. We expect to see plenty of new examples similar to this throughout 2009. &lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;Thanks to &lt;a href="http://ddanchev.blogspot.com/" target="_blank"&gt;Dancho Danchev&lt;/a&gt; for the information. &lt;br /&gt;
&lt;/font&gt;&lt;/p&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=972" width="1" height="1"&gt;</description><category domain="http://pandalabs.pandasecurity.com/archive/tags/Malware/default.aspx">Malware</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Malicious+links/default.aspx">Malicious links</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Social+Media/default.aspx">Social Media</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/YouTube/default.aspx">YouTube</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/PornTube/default.aspx">PornTube</category></item><item><title>Ever heard the term "Rickrolling"? Malware distributors have...</title><link>http://pandalabs.pandasecurity.com/archive/Have-you-ever-heard-the-term-_2200_Rickrolling_22003F00_-Malware-distributors-have_2E002E002E00_.aspx</link><pubDate>Mon, 09 Feb 2009 10:21:00 GMT</pubDate><guid isPermaLink="false">b262f9bf-63e5-46e5-8a14-4069a6997bc7:961</guid><dc:creator>Sean-Paul Correll</dc:creator><slash:comments>0</slash:comments><comments>http://pandalabs.pandasecurity.com/comments/961.aspx</comments><wfw:commentRss>http://pandalabs.pandasecurity.com/commentrss.aspx?PostID=961</wfw:commentRss><description>



&lt;p&gt;&lt;strong&gt;Rickrolling&lt;/strong&gt; is an Internet meme typically involving the music video for the 1987 Rick Astley song &amp;quot;Never Gonna Give You Up&amp;quot;. The meme is a bait and switch: a person provides a web link that he or she claims is relevant to the topic at hand, but the link actually takes the user to the Astley video.&lt;br /&gt;
&lt;/p&gt;

&lt;p&gt;Over the past few months we have noticed attacker efforts to maximize blackhat SEO tactics and increase infection rates at the same time by abusing the popular social news aggregate site &lt;a href="http://www.digg.com" title="Digg"&gt;Digg.com&lt;/a&gt;. Digg allows users to create, vote, and comment on news stories.&lt;/p&gt;

&lt;p&gt;  Malware distributors have been creating false stories with catchy subject lines as an attempt to bait users into clicking links which lead to Malware. In some cases the attackers do not create the news story themselves, rather linking to others relevant content. Below is an example of the attacker (in red) taking advantage of a valid digg submission. The malicious comment reads, &amp;quot;Heath Ledger naked in the shower, playing with herself.&amp;quot; and is posted to a relevant story about Heath Ledger. The &amp;quot;playing with herself&amp;quot; part is a bit confusing but my guess is that the attackers are using automation scripts to auto-generate content based on topic relevancy or that they are manually doing this and have no idea who Heath Ledger is.&lt;br /&gt;
&lt;/p&gt;

&lt;p&gt;&lt;img alt="Example on Digg" height="513" src="http://support.us.pandasecurity.com/blog/digg_example.png" width="679" /&gt;&lt;/p&gt;

&lt;p&gt;My initial search identified 52 accounts posting news stories or comments with malicious URI&amp;#39;s. The links all point to various fake codec sites, which lead to rogue anti-malware infections.  We detect and block the malware as &lt;strong&gt;Adware/VideoPlay&lt;/strong&gt;.&lt;br /&gt;&lt;/p&gt;&lt;strong&gt;Update:&lt;/strong&gt;  &lt;a href="http://ddanchev.blogspot.com/2009/02/fake-codec-serving-domains-from.html"&gt;Dancho Danchev&lt;/a&gt; reported that there has been over 500,000 malicious comments posted via Digg since last year.  

&lt;p&gt;&lt;strong&gt;Some of the titles include&lt;/strong&gt;: &lt;/p&gt;

&lt;blockquote&gt;
&lt;p class="style1"&gt;&lt;sub&gt;Christian Bale freak out dubbed with video!&lt;br /&gt;
  Christian Bale Terminator Salvation Takes it Up the Ass&lt;br /&gt;
  Hot and sexy model Mayuko Lwasa in bikini &lt;br /&gt;
  Pregnant Ujwala Raut in Bikini&lt;br /&gt;
  megan fox naked secret videos&lt;br /&gt;
  Sexy Megan Fox having sex Sex Tape, rally nice and hot video&lt;br /&gt;
  Megan Fox naked NEW SEX TAPE &lt;br /&gt;
  Robert Pattinson: fotos, v&amp;iacute;deos, hist&amp;oacute;ria&lt;br /&gt;
  Jessica Simpson Hotel Sex Tape&lt;br /&gt;
  Batman is Naked aka Christian Bale &lt;br /&gt;
  Watch Grey&amp;#39;s Anatomy Season 5 online here&lt;br /&gt;
  Breaks Season 4 Episode 9&lt;br /&gt;
  Emma Watson Nude Video&lt;br /&gt;
  Watch Emma Watson Sex Tape online here&lt;br /&gt;
  Paris Hilton Sex Tape Update&lt;br /&gt;
  VANESSA ANNE HUDGENS NUDE, NAKED GALLERY, EXCLUSIVE 2009&lt;br /&gt;
  Naked Truth on Celebrity News and Edison Chen Sex Scandal&lt;br /&gt;
  Paris Hilton sex tape! Paris Hilton nude, naked movie!&lt;br /&gt;
  Celebrity and Angelina Jolie nude, naked, in bikini, gallery&lt;br /&gt;
  Tila Tequila topless nude and naked sex-porn gallery&lt;br /&gt;
  Alyssa Milano nude, naked, sex tape - free gallery!&lt;br /&gt;
  BRITNEY SPEARS NUDE, BRITNEY SPEARS NAKED &amp;amp; SEX TAPE (CLICK HERE)&lt;br /&gt;
  Lindsay Lohan&amp;#39;s nude Marilyn shoot&lt;br /&gt;
  Heath Ledger naked in shower, playing with herself!!&lt;/sub&gt;&lt;/p&gt;
&lt;sub&gt;&lt;/sub&gt;
&lt;/blockquote&gt;

&lt;p class="style1"&gt;&lt;strong&gt;Fake Codec Sites:&amp;nbsp;&lt;/strong&gt; &lt;br /&gt;
&lt;/p&gt;

&lt;p&gt;&lt;img alt="Types of Fake Media Codec Pages" height="291" src="http://support.us.pandasecurity.com/blog/media_codecs.png" width="679" /&gt;&lt;/p&gt;

&lt;p&gt;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;New Version of MS Antispyware 2009&lt;/strong&gt; &lt;br /&gt;
&lt;/p&gt;

&lt;p&gt;&lt;img alt="Rogue Infections" height="427" src="http://support.us.pandasecurity.com/blog/rogue_infections.png" width="679" /&gt;&lt;/p&gt;

&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=961" width="1" height="1"&gt;</description><category domain="http://pandalabs.pandasecurity.com/archive/tags/Social+Networks/default.aspx">Social Networks</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Malicious+links/default.aspx">Malicious links</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Rickroll/default.aspx">Rickroll</category></item></channel></rss>