Patrick Walsh

Job title:
CTO, eSoft

Areas of expertise:
Web threats, email threats, social networking, web filtering

Biography:
Patrick has over 10 years of experience in computer security and software development and holds a Bachelor of Science degree in Information and Computer Science from the University of California, Irvine. In addition to his entrepreneurial past, other past roles include software engineer, engineering manager, product manager, marketing manager.

Tag Cloud

Bloggers

Blog

135 000 Fake YouTube Pages Delivering Malware

The eSoft Threat Prevention Team has uncovered thousands compromised web servers hosting fake YouTube pages. Attempting to play the video on these fake pages prompts the user to install a ‘media codec’ which then infects the machine with malware.

The fake YouTube pages are well crafted and look almost identical to the real site.  By using websites like YouTube, cyber criminals are taking advantage of a users’ inherent trust in the site and are able to infect more machines.

Each page claims to have a “Hot Video” associated with anything from the Gulf Oil Spill to the NBA Playoffs.  Google search results show 135,000 of these infected pages at the time of writing. 

By clicking ‘OK’ to install the codec the user is redirected through intermediary sites to a final destination where the malware is downloaded.  After opening the file, the malware runs silently in the background giving unsuspecting users no sign that their computer is now infected and their data and computing resources are under the control of hackers.

Presently, this fake codec is actually a downloader Trojan with very low anti-virus detection.  Virus Total shows that only 8 of 41 anti-virus scanners currently detect the threat.  Without capable, secure web filtering to block access to these malicious sites these threats will have a high percentage chance of infecting users.

eSoft is flagging any sites hosting the fake YouTube pages as compromised until the pages are removed.  Intermediary sites and distribution points will also be blocked as compromised or malicious distribution points, protecting SiteFilter customers from infection.

Posted 07/06/2010 by Patrick Walsh

Tagged under: compromised websites , youtube , malware , virus

Comment on this blog

You must be registered and logged in to leave a comment about this blog.