Wednesday, March 18, 2009

New Fake AntiVirus warning screen

With looking at this screen closely you might not recognize this is a web page rendered in Firefox. Once gain the bad guys have upped the ante in the high stakes poker game of malware. This particular trick attempts to make the end user believe they are looking at a Windows Explorer screen with warning messages of a large number of trojans and virus infections. It next presents a popup box to entice the user to download the fake antivirus, probably our old friend Antivirus2009.



Click on the picture of a better view.

This is another example of how malware writers continue to excelerate the arms race in the battle of keeping users from clicking on things.

If you see a screen like this kill it from the process viewer. There has been reports clicking anywhere on this screen will cause infection. In this case the user was looking for NCAA brackets using a Google search. Thankfully he called to report the incident before taking any other action.

Related Story: NCAA March Madness Malicious Blog Links

Labels: , ,

Friday, February 27, 2009

Update on compromised adservers serving malware (eWeek/other Ziff Davis Enterprise sites)

Websense reports the recent eWeek PDF attack via adservers took no user interaction.
eWeek.com is the online version of the popular business computing magazine.

When users browse to the home page of eWeek, a malvertisement hosted on the DoubleClick advertisement network performs a redirect to a malicious Web site through a series of iframes. This causes a redirect to one of two files on hxxp://[removed]inside.com/

Either a pdf document containing exploit code is served, or index.php redirects to the rogue ad-server.

With no user interaction, a file named "winratit.exe" (MD5: A12DA1D62B7335CBE6D6EA270247BBC1) is installed in the user's temporary files folder. Two additional files are dropped onto the user's machine and are bound to startup. The host file is also modified so that if the user tries to browse to popular software download sites to remedy the infected machine, s/he is instead directed to a malicious Web site offering further rogue AV downloads.

The name of the rogue AV application is Anti-Virus-1. If the user chooses to register the rogue AV, a connection is made to hxxp://[removed]-site.info/ which has been setup to collect payment details.

Security4all says this isn't the recent 0-day Adobe Reader PDF exploit also served by compromised adservers, but a previous one reported last November. This attack hit eWeek and other Ziff Davis Enterprise site ad servers this week. The goal of this attack is to install fake antivirus software.

Labels: , , ,