<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://pandalabs.pandasecurity.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>PandaLabs : YouTube</title><link>http://pandalabs.pandasecurity.com/archive/tags/YouTube/default.aspx</link><description>Tags: YouTube</description><dc:language>en</dc:language><generator>CommunityServer 2.1 SP2 (Build: 61120.2)</generator><item><title>Cyber Criminals Target Air France, YouTube, E3, Microsoft, Project Natal, and more…</title><link>http://pandalabs.pandasecurity.com/archive/Cyber-Criminals-Target-Air-France_2C00_-YouTube_2C00_-E3_2C00_-Microsoft_2C00_-Project-Natal_2C00_-and-more_2620_.aspx</link><pubDate>Wed, 03 Jun 2009 11:53:00 GMT</pubDate><guid isPermaLink="false">b262f9bf-63e5-46e5-8a14-4069a6997bc7:1002</guid><dc:creator>Sean-Paul Correll</dc:creator><slash:comments>0</slash:comments><comments>http://pandalabs.pandasecurity.com/comments/1002.aspx</comments><wfw:commentRss>http://pandalabs.pandasecurity.com/commentrss.aspx?PostID=1002</wfw:commentRss><description>
&lt;p&gt;It seems like these days every other news breaking story is paralleled with a similar Blackhat SEO fueled Rogueware campaign. Today, Luis Corrons and I were talking about Microsoft&amp;rsquo;s recently announced Project Natal when his Google search for a video of the technology in action turned out to place a malicious link in the very top of the search results.&lt;/p&gt;
&lt;p&gt;
&lt;br /&gt;
&lt;img src="http://farm3.static.flickr.com/2472/3592212684_181d587477_o.jpg" /&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;Connection&lt;/strong&gt;: (Google to Rogue) &lt;br /&gt;
&lt;img height="103" src="http://farm4.static.flickr.com/3416/3591405941_9a70a41caa_o.jpg" width="630" /&gt;&lt;br /&gt;
&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;**UPDATE** 6/04/09 -&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt; 16,000 new malicious links have appeared in Google over the last 24 hours targeting the phrase &amp;quot;TV Online&amp;quot;. The malicious site appears to be a video viewing website.&amp;nbsp; It will prompt to you to downoad and install a codec.exe file, which of course is a malicious file.&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.flickr.com/photos/lithium-/3596363688/sizes/o/"&gt;&lt;img src="http://farm3.static.flickr.com/2465/3596363688_4aba7edb27.jpg" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;
&lt;img height="419" src="http://farm4.static.flickr.com/3398/3592212756_a1fa44bee4_o.jpg" width="599" /&gt;&lt;br /&gt;
&lt;/p&gt;
&lt;p&gt;Knowing that this link wouldn&amp;rsquo;t be the only one, we started researching the domains and keywords being targeted and here is what we found:&lt;/p&gt;

&lt;br /&gt;
&lt;strong&gt;Keywords:&lt;/strong&gt;&lt;br /&gt;
&lt;strong&gt;16,000 &lt;/strong&gt;links targeting &amp;quot;&lt;strong&gt;TV Online&lt;/strong&gt;&amp;quot;&lt;br /&gt;
&lt;strong&gt;16,000 &lt;/strong&gt;links targeting &amp;ldquo;&lt;strong&gt;YouTube&lt;/strong&gt;&amp;rdquo;&lt;br /&gt;
&lt;strong&gt;10,500&lt;/strong&gt; links targeting &amp;quot;&lt;strong&gt;France&lt;/strong&gt;&amp;quot; (Airline Crash)&lt;br /&gt;
&amp;nbsp; &lt;strong&gt;8,930&lt;/strong&gt; links targeting &amp;quot;&lt;strong&gt;Microsoft&lt;/strong&gt;&amp;quot; (Project Natal)&lt;br /&gt;
&amp;nbsp; &lt;strong&gt;3,380&lt;/strong&gt; links targeting &amp;quot;&lt;strong&gt;E3&lt;/strong&gt;&amp;quot; &lt;br /&gt;
&amp;nbsp; &lt;strong&gt;2,900&lt;/strong&gt; links targeting &amp;quot;&lt;strong&gt;Eminem&lt;/strong&gt;&amp;quot; (MTV Awards/Bruno Incident)&lt;br /&gt;
&amp;nbsp; &lt;strong&gt;2,850&lt;/strong&gt; links targeting &amp;ldquo;&lt;strong&gt;Sony&lt;/strong&gt;&amp;rdquo;&lt;br /&gt;
&lt;br /&gt;

&lt;p&gt;The sites are all hosted via Lycos Tripod, which is a free web host. This allows the cyber criminals to create thousands of free sites to take advantage of the Blackhat SEO and then simply redirect the free sites to just a handful of their own servers.&lt;/p&gt;

&lt;p&gt;Blackhat SEO is definitely one of the most prevalent threat distribution methods today. We expect to see several more examples of this type of attack throughout the year, so be especially careful when searching for news breaking stories.&lt;/p&gt;
All of the links associated in this attack have already been blocked for Panda users. &lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=1002" width="1" height="1"&gt;</description><category domain="http://pandalabs.pandasecurity.com/archive/tags/Rogueware/default.aspx">Rogueware</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Microsoft/default.aspx">Microsoft</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/YouTube/default.aspx">YouTube</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Blackhat+SEO/default.aspx">Blackhat SEO</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/E3/default.aspx">E3</category></item><item><title>YouTube riddled with comments leading to Malware</title><link>http://pandalabs.pandasecurity.com/archive/YouTube-riddled-with-comments-leading-to-Malware.aspx</link><pubDate>Fri, 22 May 2009 06:10:00 GMT</pubDate><guid isPermaLink="false">b262f9bf-63e5-46e5-8a14-4069a6997bc7:999</guid><dc:creator>Sean-Paul Correll</dc:creator><slash:comments>0</slash:comments><comments>http://pandalabs.pandasecurity.com/comments/999.aspx</comments><wfw:commentRss>http://pandalabs.pandasecurity.com/commentrss.aspx?PostID=999</wfw:commentRss><description>&lt;p&gt;A few months ago, we talked about&lt;a href="http://pandalabs.pandasecurity.com/archive/Malware-in-Social-Media.aspx"&gt; YouTube&amp;#39;s Annotations feature&lt;/a&gt; being used as a tool for Cyber Criminals to help spread their malicious Rogueware campaigns.  Today, we have a similar case, but this time its automated comment Malspam (Malware spam).  My &lt;a href="http://www.flickr.com/photos/lithium-/3553092060/"&gt;initial&lt;/a&gt; &lt;a href="http://www.flickr.com/photos/lithium-/3552282729/"&gt;search&lt;/a&gt; &lt;a href="http://www.flickr.com/photos/lithium-/3553091998/"&gt;turned&lt;/a&gt; &lt;a href="http://www.flickr.com/photos/lithium-/3553091956/"&gt;up&lt;/a&gt; &lt;a href="http://www.flickr.com/photos/lithium-/3552282609/"&gt;about&lt;/a&gt; &lt;a href="http://www.flickr.com/photos/lithium-/3553091944/"&gt;30,000&lt;/a&gt; &lt;a href="http://www.flickr.com/photos/lithium-/3553091876/"&gt;malspam&lt;/a&gt; comments all pointing to a fake pornography website called &amp;quot;PornTube 2.0&amp;quot;.&lt;/p&gt;
&lt;p&gt;&lt;img src="http://farm4.static.flickr.com/3302/3553091944_aac4c0db2f.jpg" /&gt;&lt;/p&gt;
    
&lt;p&gt;Like the &lt;a href="http://pandalabs.pandasecurity.com/archive/Malware-in-Social-Media.aspx"&gt;last time&lt;/a&gt;, Cyber Criminals are targeting people who are searching YouTube for pornography.  In the comments each malicious link is accompanied by a few search terms.  Some common keywords we have seen are Adalt (sic), Tit s, Latina, Kinky, Girl, Porn, Sex, and the names of various pornography stars.&lt;br /&gt;
&lt;br /&gt;
By targeting these keywords the Cyber Criminals are able to optimize and improve their success rates by infecting those who are truly looking for pornographic material.&lt;/p&gt;
 
&lt;p&gt;
Note: It appears that all of the malicious links have brackets in between the &amp;quot; .com&amp;quot; portion of the comment.  It&amp;#39;s unclear if this is a temporary action done by the YouTube abuse team or if the criminals are just trying to evade detection.&lt;/p&gt;

&lt;p&gt;Upon arriving at the website, we see a page that looks like a legitimate video website labeled &amp;quot;PornTube 2.0&amp;quot;, but it is actually the malware site.&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;Malware Site:&lt;/strong&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://www.flickr.com/photos/lithium-/3553091856/in/set-72157618509807695/"&gt;Click for the original uncensored image (Warning: NSFW)&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;img border="0" src="http://farm4.static.flickr.com/3626/3552282739_55bb7f24a5.jpg?v=0" /&gt; &lt;br /&gt;
 &lt;br /&gt;
If you click anything on the website it will prompt you to download a fake Adobe Flash plugin, which is the malware installer for &lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?lst=det&amp;amp;idvirus=207660&amp;amp;sitepanda=particulares"&gt;Adware/Privacy Center&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://www.flickr.com/photos/lithium-/3553092152/in/set-72157618509807695/"&gt;Click for the original uncensored image (Warning: NSFW)&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;img src="http://farm4.static.flickr.com/3330/3553092106_a4f2fb9189_o.png" /&gt; &lt;br /&gt;
&lt;strong&gt;&lt;br /&gt;
Adware/PrivacyCenter Rogue (fake) Antivirus&lt;br /&gt;
&lt;/strong&gt;&lt;/p&gt;
&lt;strong&gt;&lt;a href="http://www.flickr.com/photos/lithium-/3552354491/"&gt;&lt;img border="0" src="http://farm4.static.flickr.com/3320/3552354491_6a743eca68.jpg?v=0" /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;/strong&gt;
&lt;p&gt;Rogue Antivirus is one of the most prolific Malware in the threat landscape today. PandaLabs has received more Rogue Antivirus samples in Q1 of 2009 than in all of 2008 as demonstrated by the following illustration.&lt;br /&gt;
&lt;br /&gt;
&lt;img src="http://farm4.static.flickr.com/3396/3552483899_3a6e07bf01.jpg" /&gt;&lt;br /&gt;
&lt;br /&gt;
In this case, Cyber Criminals aim to profit from human vulnerabilities and inherent curiosities. &lt;/p&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=999" width="1" height="1"&gt;</description><category domain="http://pandalabs.pandasecurity.com/archive/tags/Rogueware/default.aspx">Rogueware</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Malicious+links/default.aspx">Malicious links</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/YouTube/default.aspx">YouTube</category></item><item><title>How To: Infect yourself with Malware</title><link>http://pandalabs.pandasecurity.com/archive/How-To_3A00_-Infect-yourself-with-Malware.aspx</link><pubDate>Wed, 25 Mar 2009 22:20:00 GMT</pubDate><guid isPermaLink="false">b262f9bf-63e5-46e5-8a14-4069a6997bc7:986</guid><dc:creator>Sean-Paul Correll</dc:creator><slash:comments>0</slash:comments><comments>http://pandalabs.pandasecurity.com/comments/986.aspx</comments><wfw:commentRss>http://pandalabs.pandasecurity.com/commentrss.aspx?PostID=986</wfw:commentRss><description>&lt;p&gt;&lt;font face="Times New Roman" size="3"&gt;Last time we talked about cyber 
criminals using YouTube&amp;#39;s &lt;/font&gt;&lt;a href="http://pandalabs.pandasecurity.com/archive/Malware-in-Social-Media.aspx" target="_blank"&gt;&lt;font color="#0000ff" face="Tahoma" size="3"&gt;&lt;u&gt;Video 
Annotations&lt;/u&gt;&lt;/font&gt;&lt;/a&gt;&lt;font face="Times New Roman" size="3"&gt; feature 
to guide victims to Malware ridden websites.&amp;nbsp; Today we&amp;#39;ll talk about 
yet another method being used within YouTube and other social media 
websites.&amp;nbsp;&amp;nbsp; &lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="Times New Roman" size="3"&gt;Malware distributors have been 
creating instructional &amp;quot;How to&amp;quot; videos to get victims to willingly 
visit malicious websites and infect their own computers.&lt;/font&gt;&lt;br /&gt;
  &lt;br /&gt;
  &lt;img alt="How to infect yourself with Malware" border="0" height="487" src="http://support.us.pandasecurity.com/blog/youtube_malware_instruction.jpg" width="624" /&gt;&lt;br /&gt;
  &lt;br /&gt;
  Once on the site the victim is lured to install &lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?idvirus=203966"&gt;Adware/SystemSecurity&lt;/a&gt; rogue software.&amp;nbsp;&lt;/p&gt;&lt;p&gt;The best way to avoid these types of scams is by researching the product prior to installing it on your computer.&amp;nbsp; Sometimes a simple Google search can literally save you hundreds of dollars in repair costs.&amp;nbsp; &lt;br /&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=986" width="1" height="1"&gt;</description><category domain="http://pandalabs.pandasecurity.com/archive/tags/YouTube/default.aspx">YouTube</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Malware+in+Social+Media/default.aspx">Malware in Social Media</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/How+To/default.aspx">How To</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Tutorial/default.aspx">Tutorial</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/SystemSecurity/default.aspx">SystemSecurity</category></item><item><title>Malware in Social Media</title><link>http://pandalabs.pandasecurity.com/archive/Malware-in-Social-Media.aspx</link><pubDate>Thu, 26 Feb 2009 17:17:00 GMT</pubDate><guid isPermaLink="false">b262f9bf-63e5-46e5-8a14-4069a6997bc7:972</guid><dc:creator>Sean-Paul Correll</dc:creator><slash:comments>0</slash:comments><comments>http://pandalabs.pandasecurity.com/comments/972.aspx</comments><wfw:commentRss>http://pandalabs.pandasecurity.com/commentrss.aspx?PostID=972</wfw:commentRss><description>
&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;A few weeks ago we talked about &lt;/font&gt;&lt;a href="http://pandalabs.pandasecurity.com/archive/Have-you-ever-heard-the-term-_2200_Rickrolling_22003F00_-Malware-distributors-have_2E002E002E00_.aspx" target="_blank"&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;cyber-criminals using Digg.com to spread malware&lt;/font&gt;&lt;/a&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;. Today we see that the very same group responsible for the Digg.com incident was using the same tactic on YouTube through the use of YouTube&amp;#39;s Annotations feature. &lt;/font&gt;&lt;a href="http://www.youtube.com/t/annotations_about" target="_blank"&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;Video Annotations&lt;/font&gt;&lt;/a&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt; is a way to add interactive commentary to videos on YouTube. &lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;The following image displays a video using the annotations feature to guide users over to a malware ridden website:&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;img height="363" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2009/02/26/MWYoutube.png" style="width:700px;height:363px;" width="700" /&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;Although the YouTube description malware is not as prevalent as the Digg.com comment abuse, it does show that Social Media websites are increasingly being used to spread Malware. We expect to see plenty of new examples similar to this throughout 2009. &lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;Thanks to &lt;a href="http://ddanchev.blogspot.com/" target="_blank"&gt;Dancho Danchev&lt;/a&gt; for the information. &lt;br /&gt;
&lt;/font&gt;&lt;/p&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=972" width="1" height="1"&gt;</description><category domain="http://pandalabs.pandasecurity.com/archive/tags/Malware/default.aspx">Malware</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Malicious+links/default.aspx">Malicious links</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Social+Media/default.aspx">Social Media</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/YouTube/default.aspx">YouTube</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/PornTube/default.aspx">PornTube</category></item></channel></rss>