Patrick Walsh

Job title:
CTO, eSoft

Areas of expertise:
Web threats, email threats, social networking, web filtering

Biography:
Patrick has over 10 years of experience in computer security and software development and holds a Bachelor of Science degree in Information and Computer Science from the University of California, Irvine. In addition to his entrepreneurial past, other past roles include software engineer, engineering manager, product manager, marketing manager.

Tag Cloud

Bloggers

Blog

Blackhats Unleash Fake Blog Campaign Spreading Rogue AV

In September, eSoft reported as many as 720,000 compromised sites hosting fake blog pages and being used to distribute rogue anti-virus programmes. Many of these sites are still active and continue to plague searches with malicious results.

Earlier today, Cyveillance issued this report of a nearly identical attack with over 260 000 dangerous URLs prompting the Threat Prevention Team to revisit this threat.

Between the newly reported Cyveillance URLs and additional URLs discovered by eSoft, there are now well over 800 000 active URLs matching this pattern. Surprisingly, Google only detects a small portion of these sites as malicious.

The key to this scheme is javascript uploaded to the compromised server and used in the fake blog pages. Using this technique allows the attackers to quickly and easily change distribution points and payloads. The current payloads have low detection rates among AV scanners.

The eSoft Threat Prevention Team is tracking this threat, flagging associated domains into their appropriate security categories. More information on this threat can be obtained on the eSoft ThreatCenter Blog.

Posted 18/11/2009 by Patrick Walsh

Tagged under: web security , compromised sites , rogue AV , malware

Comment on this blog

You must be registered and logged in to leave a comment about this blog.