| 14 |
| Sep |
Article from Rik Ferguson
Filed under: Site Compromise,Underground Economy,malware | RSS 2.0 | TB | Tags: cybercrime, malware, Rogue AV, web | 16 Comments
Earlier today, the New York Times issued a warning over Twitter and also on the front page of the web site. The newspaper advised visitors that they had had reports from “some NYTimes.com readers” relating to a malicious pop-up window while browsing the site.
In the warning, the influential newspaper stated their belief that the pop-ups were the result of an “unauthorised advertisement”. From some online discussion it looks as though the problem may have been ongoing for upwards of 24 hours.
The pop-up window itself, (screen shot captured by quick-witted reader of All Things Digital) was the all-too-familiar sight of rogue antivirus software informing the NYTimes reader that their computer is infected with random, spurious, non-existent malware and promising “Full System Cleanup” for a fee of course.
The malicious software being punted in this case, is similar to what we were seeing in much of the black-hat SEO around the 9/11 attacks, as reported previously on the TrendLabs malware blog.
In this particular example, the malicious site and sofware is being hosted by a German provider, Hetzner AG, which has a colourful track record when it comes to spewing dodgy content, having hosted literally hundreds of malicious URLS.
Here’s a really simple tip to remember. If you *ever* see a browser pop-up window that arrives uninvited, telling you your PC is infected, ignore it, it is a scam. Close the window, empty your browser cache and to be on the safe side, run a real scanner like HouseCall. To be more fully protected in future, make sure you install an antimalware program that will also block malicious URLs, rather than simply looking for malicious files.
UPDATE: Troy Davis was fortunate enough to be able to examine the attack in real-time and provides an excellent code level analysis here.
UPDATE: The fake AV program being pushed in this attack was called Personal Antivirus and is very much a classic piece of scareware.
On install the application will start “scanning” your machine for problems. On a completely fresh installation of Windows Vista, it supposedly detected 38 threats.
Of course none of these imaginary threats can be removed until you pay to activate you copy of this useless software, not only giving away your cash but also of course all your credit card and personal details at the same time, double-whammy for the cybercrooks.
If you choose not to activate the software immediately you will then be served at random intervals with fake messages informing you of yet more detected problems, when you hit the “Block” button, you are again prompted to pay for the software, and so it continues…
For cleanup, use HouseCall or any other reputable security software, a helpful list of what is real (as opposed to FakeAV) can be found here.
If the software you are being punted isn’t on the list, then do not install it.
| Amber Porter Cox: Tuesday, 15. September 2009 um 12:47 am |
|
|
You should have the ability to ‘share’ this information across social sites, since your readers are using them. Just makes sense. |
|
| Rik Ferguson: Tuesday, 15. September 2009 um 10:07 am |
|
|
Hi Amber, yes I know it is lacking right now, but blog improvements are in the works and that is definitely high on the priority list. Thanks for reading by the way. |
|
| Malvertisements in NYTimes.com Lead to FAKEAV | Malware Blog | Trend Micro: Tuesday, 15. September 2009 um 12:32 pm |
|
|
[...] reported in detail by Trend Micro researcher Rik Ferguson in the Counter Measures blog, the New York Times issued warnings through both Twitter and its website’s front page about [...] |
|
| Malvertisements in NYTimes.com Lead to FAKEAV - All About Virus: Tuesday, 15. September 2009 um 11:55 pm |
|
|
[...] detail by Trend Micro researcher Rik Ferguson in the Counter Measures blog, the New York Times issued warnings through both Twitter and its [...] |
|
| JMan: Wednesday, 16. September 2009 um 6:03 pm |
|
|
And as I said above, we should be able to prosecute these folks, not just with “fines,” but with JAIL TIME! |
|
| Anti-Virus & Anti-Malware website. » Malvertisements in NYTimes.com Lead to FAKEAV: Wednesday, 16. September 2009 um 10:20 pm |
|
|
[...] reported in detail by Trend Micro researcher Rik Ferguson in the Counter Measures blog, the New York Times issued warnings through both Twitter and its website’s front page about [...] |
|
| Jason: Thursday, 17. September 2009 um 8:05 pm |
|
|
I recommend the removal of this threat. Instructions for removal can be found here: http://www.helpmyos.com/removal-guides-f41/how-to-remove-personal-antivirus-t1119.htm |
|
| Marlene: Sunday, 20. September 2009 um 2:35 pm |
|
|
Unbelievable that people believe these ads. They used to pop up all the time on our computers. Everyone here knew they were malware. Why would any company who uses computers in their business click to download these? |
|
| Malvertisements in NYTimes.com Lead to FAKEAV - All About Virus: Thursday, 24. September 2009 um 5:40 am |
|
|
[...] detail by Trend Micro researcher Rik Ferguson in the Counter Measures blog, the New York Times issued warnings through [...] |
|
| New York Times pushes Fake AV malvertisement. AV hongkong 香港: Friday, 25. September 2009 um 7:16 pm |
|
|
[...] here: New York Times pushes Fake AV malvertisement. By admin | category: av model | tags: install-the-application, japanese, machine, [...] |
|
| Noch ein Grund für Paid Content: Hacker knacken Ad-Server der “New York Times” | Basic Thinking Blog: Friday, 16. October 2009 um 3:51 pm |
|
|
[...] Sicherheitsteam von TrendMicro berichtet, dass die Viren, vor denen gewarnt wurde, reine Erfindungen seien. Noch etwas wurde herausgefunden: Die falschen Virenscanner, die zum Verkauf angeboten [...] |
|
| Rogue AV on the rise - /gg FTW!: Sunday, 18. October 2009 um 3:31 am |
|
|
[...] [...] |
|
| Malvertisements in NYTimes.com Lead to FAKEAV – Security Threat Research News: Monday, 7. December 2009 um 5:42 am |
|
|
[...] reported in detail by Trend Micro researcher Rik Ferguson in the Counter Measures blog, the New York Times issued warnings through both Twitter and its website’s front page about [...] |
|
| AmirShaw | Rogue NYTimes.com ad leads to fake anti-Virus: Saturday, 24. April 2010 um 1:55 pm |
|
|
[...] Read More [...] |
|






Monday, 14. September 2009 um 1:54 am
[...] This post was mentioned on Twitter by Darlene Duncan-Dobbs. Darlene Duncan-Dobbs said: RT @rik_ferguson New York Times pushes FakeAV malvertisement – http://bit.ly/2OsjeU Good advice! [...]