<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://pandalabs.pandasecurity.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>PandaLabs : Targeted Attack</title><link>http://pandalabs.pandasecurity.com/archive/tags/Targeted+Attack/default.aspx</link><description>Tags: Targeted Attack</description><dc:language>en</dc:language><generator>CommunityServer 2.1 SP2 (Build: 61120.2)</generator><item><title>Targeted Blackhat SEO Attack against Ford Motor Co. (Updated)</title><link>http://pandalabs.pandasecurity.com/archive/Targeted-Blackhat-SEO-Attack-against-Ford-Motor-Co_2E00_.aspx</link><pubDate>Tue, 14 Apr 2009 08:29:00 GMT</pubDate><guid isPermaLink="false">b262f9bf-63e5-46e5-8a14-4069a6997bc7:991</guid><dc:creator>Sean-Paul Correll</dc:creator><slash:comments>0</slash:comments><comments>http://pandalabs.pandasecurity.com/comments/991.aspx</comments><wfw:commentRss>http://pandalabs.pandasecurity.com/commentrss.aspx?PostID=991</wfw:commentRss><description>&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;Recently, we have talked about&amp;nbsp;&lt;/font&gt;&lt;a href="http://pandalabs.pandasecurity.com/archive/Blackhat-SEO-Fueled-Rogue-Security-Campaign.aspx" target="_blank"&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;Blackhat SEO fueled Rogue Software Campaigns&lt;/font&gt;&lt;/a&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;.&amp;nbsp;Today, we have uncovered a similar campaign with over 1 Million links all targeting the&amp;nbsp;&lt;/font&gt;&lt;a href="http://www.ford.com" target="_blank"&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;Ford Motor Company&lt;/font&gt;&lt;/a&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;These attacks work by misleading search engines to falsely promote malicious pages to the top of the search results.&amp;nbsp;Once the user visits one of the malicious sites, they are prompted to download and install a malicious &amp;quot;codec&amp;quot;, which then installs the MS AntiSpyware 2009 (softwarefortubeview.40030.exe) Rogue Security Software, which we detect as&amp;nbsp;&lt;/font&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?lst=vis&amp;amp;idvirus=203719&amp;amp;sitepanda=particulares" title="Adware/MSAntiSpyware2009"&gt; &lt;font face="tahoma,arial,helvetica,sans-serif"&gt;&lt;strong&gt;Adware/MSAntiSpyware2009&lt;/strong&gt;&lt;/font&gt;&lt;/a&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;This case is especially interesting because it&amp;rsquo;s one of the few SEO attacks that we have seen targeting a single, specific brand.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;I have made a video demonstrating how the Blackhat SEO attacks work and you can see it below:&lt;/font&gt;&lt;/p&gt;&lt;blockquote&gt;&lt;blockquote&gt;&lt;p&gt;&lt;a href="http://vimeo.com/4143942" title="Vimeo" target="_blank"&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;&lt;img alt="Vimeo" height="379" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2009/04/14/Vimeo.png" style="width:505px;height:379px;" title="Vimeo" width="505" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;/p&gt;&lt;/blockquote&gt;&lt;/blockquote&gt;&lt;p&gt;&lt;strong&gt;Partial List of Hijacked Search Terms&lt;/strong&gt;:&lt;/p&gt;&lt;p&gt;&lt;strong&gt;*Update*&amp;nbsp; The SEO attack is starting to switch from Ford to Nissan Motor Co.&amp;nbsp;&amp;nbsp;&lt;/strong&gt; &lt;br /&gt;&lt;/p&gt;&lt;p&gt;Diagram Of A 1998 Nissan Pathfinder Blower Motor&lt;br /&gt;1989 Nissan Pickup Voltage Regulator&lt;br /&gt;2006 Nissan Skyline Gtr Vs 2005 Mustang Gt Cobra Youtube&lt;br /&gt;Where Is The Horn Relay On A 2002 Nissan Sentra&lt;br /&gt;1992 Rear Bumper Nissan Pickup Truck&lt;br /&gt;17 Gold Rims Wheels Nissan Honda Ford Toyota Hyundai&lt;br /&gt;Ford Dealership Car Dealership Beside Iee Nissan Wilson N.c.&lt;br /&gt;We Love rocky ford kansas!&lt;br /&gt;Mustang Gt Or Nissan 350z&lt;br /&gt;Dash Cover Nissan Pickup&lt;br /&gt;1992 Rear Bumper Nissan Pickup Truck&lt;br /&gt;Bumper For 1993 Nissan Pickup&lt;br /&gt;Relay Box On 1991 Nissan Pickup Truck&lt;br /&gt;1997 Nissan Maxima Trunk Emblem&lt;br /&gt;1993 Nissan Truck Door Panels&lt;br /&gt;2007 Nissan Versa Gauges Glow&lt;br /&gt;Nissan Sentra 2004 Horn Location&lt;br /&gt;1994 Nissan Extended Cab Truck Seat&lt;br /&gt;Pic Of 1983 Nissan Truck&lt;br /&gt;1989 Nissan Pickup Truck Engine Check Light Troubleshooting&lt;br /&gt;Fuel Tank Capacity On 1992 Sentra On 1992 Nissan Sentra&lt;br /&gt;How To Install A 1991 Nissan Pathfinder Windshield&lt;br /&gt;Auto Wheel Bearing Replace 1997 Nissan Sentra&lt;br /&gt;Nissan Micra 1.3 Metallic Green&lt;br /&gt;Dimensions And 1998 Nissan Pathfinder&lt;br /&gt;2005 Nissan Frontier Modesto&lt;br /&gt;87 Nissan Pathfinder Nuetral Starter Safety Switch&lt;br /&gt;1990 Nissan Pickup 2400 Motor Recalls&lt;br /&gt;Used Nissan Frontier 2006&lt;br /&gt;Frontier Titan 2006 &lt;br /&gt;Ford Ranger&lt;br /&gt;Parkway Ford&lt;br /&gt;Ford Uk&lt;br /&gt;Ford Finance&lt;br /&gt;Mustang Ford&lt;br /&gt;Evergreen Ford&lt;br /&gt;Kayser Ford&lt;br /&gt;Ford Anchorage&lt;br /&gt;Walker Ford&lt;br /&gt;2009 Ford&lt;br /&gt;Rochester Ford&lt;br /&gt;6 Ford Speed Transmission&lt;br /&gt;Ford Scamatic&lt;br /&gt;Sheehy Ford&lt;br /&gt;Ford Commercial&lt;br /&gt;Parr Ford&lt;br /&gt;Ford F8tz3504abrm&lt;br /&gt;1993 Ford Taurus&lt;br /&gt;1993 Ford Tauru&lt;br /&gt;Titan Ford&lt;br /&gt;Luther Ford Fargo&lt;br /&gt;Ford Freestar Problems&lt;br /&gt;Ford Crate Engine&lt;br /&gt;Ford Aftermarket Distributor&lt;br /&gt;Ford Ranger 2008&lt;br /&gt;Ford Falcon Sale&lt;br /&gt;1941 Ford Truck&lt;br /&gt;F150 Ford 2001&lt;br /&gt;Ford Window Guards&lt;br /&gt;1960 Ford Sunliner&lt;br /&gt;Ford Ironman Wisconsin&lt;br /&gt;Ford Window Guards&lt;br /&gt;1960 Ford Sunliner&lt;br /&gt;1960 Ford Sunline&lt;br /&gt;Ford Ironman Wisconsin&lt;br /&gt;2008 Ford Mustang&lt;br /&gt;New Orleans Ford&lt;br /&gt;Inventor Henry Ford&lt;br /&gt;Ford Van Seats&lt;br /&gt;1950s Ford Thunderbirds&lt;br /&gt;Don Vance Ford&lt;br /&gt;F150 Ford 2001&lt;br /&gt;Ford Taurus Repair&lt;br /&gt;Ford Window Guards&lt;br /&gt;1960 Ford Sunliner&lt;br /&gt;Ford Ironman Wisconsin&lt;br /&gt;2008 Ford Mustang&lt;br /&gt;New Orleans Ford&lt;br /&gt;Inventor Henry Ford&lt;br /&gt;Ford Van Seats&lt;br /&gt;1950s Ford Thunderbirds&lt;br /&gt;Don Vance Ford&lt;br /&gt;F150 Ford 2001&lt;br /&gt;Grappone Ford&lt;br /&gt;Ford Radio Removal&lt;br /&gt;Ford Expedition Diesel&lt;br /&gt;Ford Parts Catalog&lt;br /&gt;1940 Ford Coupe&lt;br /&gt;1966 Ford Mustangs&lt;br /&gt;Ford Door Lock&lt;br /&gt;Ford Escape Hybrid&lt;br /&gt;1930 Ford Coupe&lt;br /&gt;Ford Parts Look Up&lt;br /&gt;1968 Ford Trucks&lt;br /&gt;1995 Ford F150 Lightning&lt;br /&gt;Joe Machens Ford&lt;br /&gt;1956 Ford Panel&lt;br /&gt;Ford Global Terms&lt;br /&gt;2000 Ford Explorer Overheating&lt;br /&gt;1999 Ford F150 Engine&lt;br /&gt;Ford 6 Cyl&lt;br /&gt;Ford Ranger 4x4&lt;br /&gt;Door 2005 Ford F150&lt;br /&gt;Ford Falcon Futura Sprint&lt;br /&gt;Ford Ranger Engine&lt;br /&gt;Ford Escort Harrier&lt;br /&gt;Ford F150 Used 4x4&lt;br /&gt;1969 Custom Ford Ranger&lt;br /&gt;Ford Truck F150 Forum&lt;br /&gt;Only Ford Expedition Pics&lt;br /&gt;Diesel Ford Ranger&lt;br /&gt;Ford F150 Throttle Body&lt;br /&gt;2001 Ford Escort Reviews&lt;br /&gt;1998 Ford F150 Bumper&lt;br /&gt;1989 Ford Mustang Wallpaper&lt;br /&gt;1939 Ford For Sale&lt;br /&gt;Ford Ranger Directional Rims&lt;br /&gt;2009 Ford Mustang Reviews&lt;br /&gt;Rowe Ford Hyundai&lt;br /&gt;Remanufactured Ford V8 Engines&lt;br /&gt;Ford Ranger 4x4 Automatic&lt;/p&gt;&lt;h3&gt;Rogue Information:&lt;br /&gt;&lt;/h3&gt;&lt;p&gt;&lt;strong&gt;File&lt;/strong&gt;: softwarefortubeview.40030.exe&lt;br /&gt;&lt;strong&gt;MD5&lt;/strong&gt;: 3C146F57FE65BF03CAB8289F31B57618&lt;br /&gt;&lt;strong&gt;Detected as&lt;/strong&gt;:&lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?lst=vis&amp;amp;idvirus=203719&amp;amp;sitepanda=particulares" title="Adware/MSAntiSpyware2009"&gt; &lt;font face="tahoma,arial,helvetica,sans-serif"&gt;&lt;strong&gt;Adware/MSAntiSpyware2009&lt;/strong&gt;&lt;/font&gt;&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;&lt;h3&gt;Registrar and Host Information:&lt;/h3&gt;&lt;div id="registryDataContainer"&gt;&lt;div class="4 ajax" style="width:auto;text-align:left;"&gt;&lt;table cellspacing="1" class="whois"&gt;&lt;tr class="odd"&gt;&lt;td class="t"&gt;ICANN Registrar: &lt;/td&gt;&lt;td&gt;REGTIME LTD.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="t"&gt;Created: &lt;/td&gt;&lt;td&gt;2009-03-17&lt;/td&gt;&lt;/tr&gt;&lt;tr class="odd"&gt;&lt;td class="t"&gt;Expires: &lt;/td&gt;&lt;td&gt;2010-03-17&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="t"&gt;Updated: &lt;/td&gt;&lt;td&gt;2009-03-31&lt;/td&gt;&lt;/tr&gt;&lt;tr class="odd"&gt;&lt;td class="t"&gt;Registrar Status: &lt;/td&gt;&lt;td&gt;ok&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="t"&gt;Name Server: &lt;/td&gt;&lt;td&gt;NS1.GLOBEXTUBES.COM&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr class="odd"&gt;&lt;td class="t"&gt;Name Server: &lt;/td&gt;&lt;td&gt;NS2.GLOBEXTUBES.COM&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="t"&gt;Whois Server: &lt;/td&gt;&lt;td&gt;whois.regtime.net&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;/div&gt;&lt;/div&gt;&lt;h3&gt;Server Data&lt;/h3&gt;&lt;table cellspacing="1" class="whois"&gt;&lt;tr class="odd"&gt;&lt;td class="t"&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="t"&gt;Server Type:&lt;/td&gt;&lt;td&gt;&amp;nbsp;Apache/1.3.39 (Unix) PHP/5.2.5 &lt;/td&gt;&lt;/tr&gt;&lt;tr class="odd"&gt;&lt;td class="t"&gt;IP Location &lt;/td&gt;&lt;td&gt;&lt;img alt="United States" height="12" src="http://img.domaintools.com/flags/us.gif" width="18" /&gt; - California - Los Angeles - Coreexpress &lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="t"&gt;Domain Status: &lt;/td&gt;&lt;td&gt;Registered And Active Website&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;p&gt;If you have any questions about the attack, you could always reach me on Twitter (&lt;a href="http://twitter.com/lithium"&gt;@lithium&lt;/a&gt;) &lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;Special thanks to &lt;a href="http://securityblahblah.blogspot.com/"&gt;Greg Feezel&lt;/a&gt; for the heads up on this one!&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=991" width="1" height="1"&gt;</description><category domain="http://pandalabs.pandasecurity.com/archive/tags/Targeted+Attack/default.aspx">Targeted Attack</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/SEO/default.aspx">SEO</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Blackhat/default.aspx">Blackhat</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Rogue+Antimalware/default.aspx">Rogue Antimalware</category></item></channel></rss>