Welcome to the Proxy Update, your source of news and information on Proxies and their role in network security.

Friday, June 26, 2009

Recent Events Trigger New Malware Sites

As Sophos reported this week, the death of Michael Jackson and Farah Fawcett triggered new fake reporting websites on those stories complete with malware.

Sophos ran a test and here's what they came up with:

Looking at the Google Trends data we can see that nearly a dozen of the top 100 searched terms today have involved the words “Farrah Fawcett”. What this translates to in the eyes of scammers is a better opportunity to have you click one of their sites which redirects you to their own FakeAV site in an attempt to get your money.

Doing a quick Google search for the words “Farrah Fawcett Dead” turns up the following link on the first page of results.




Visiting the link with a FireFox addon such as NoScript allows us to prevent the immediate redirection to the FakeAV site, and instead we’re greeted with a page that looks like this.




Anyone who tries making sense of the text will quickly realize that it’s a list of random dictionary words strung together to make it seem like it’s a real site. Of course, they never actually intend for you to see the page since there’s some script code that redirects you to the common FakeAV page seen all over the web. If you weren’t running an addon such as NoScript, you’d see the following page.




All this is a good reminder that whenever a hot news topic pops up, there are people out there trying to take advantage of the situation. Stick to known news sites you are familiar with and be sure to keep your proxy, URL database, and anti-virus software up to date.

No comments: