On mySimon: Heys Athena 3 Piece Ultra Lite Luggage
BNET Business Network:
BNET
TechRepublic
ZDNet

January 20th, 2009

Malware-infected WinRAR distributed through Google AdWords

Posted by Dancho Danchev @ 10:15 am

Categories: Anti Virus, Browsers, Google, Hackers, Malware, Passwords, Spyware and Adware

Tags: Security, AdWords, WinRAR, Rogue Antivirus, Zango, Dancho Danchev

Fake Download Malware WinrarScammers are at it again - taking advantage of Google sponsored ads for acquiring traffic in order to redirect it to malware-infected copies of legitimate software. win.rar GmbH is warning users of an ongoing fraudulent AdWords campaign pushing a malware-infected copy of WinRAR, the popular archiving application. Starting from the basic fact that, both, legitimate and malicious users can purchase their visibility, the fake WinRAR release is only the tip of the iceberg.

Let’s take a peek at the campaign impersonating Download.com — impersonation is a form of flattery — and discuss a separate campaign promising to deliver free copies of the free in general, WinRAR and WinZip, managed by a Zango adware affiliate.

Zango Winzip Google AdWordsUpon searching for WinRAR, the bogus ad appears at the top of the search results, with the actual fake Download.com site located at dreamcentury .cn/winrar.htm. Upon execution, the fake WinRAR sets the foundation for the second part of the scam, since the affected users would be periodically redirected to rogue security software sites, urging them to take action and disinfect themselves.

Zango Winzip Google AdWordsWinRAR is also impersonated in another currently active AdWords campaign, next to WinZip, with the second campaign operated by Zango affiliate, a well known adware vendor. Zango’s campaign is naturally not delivering any copies of WinRAR or WinZip, instead it’s pushing a copy of their toolbar taking advantage of fraudulent practices.

The participants in Zango’s affiliate network and the rogue security software one, are generating revenues based on the number of installations, with the affiliate model’s high payout rates as the main incentive for the introduction of new tactics.  And whereas Google’s AdWords seems to be part of their ad budget in this particular case, sponsored ads are only part of the (fraudulent) marketing mix, with blackhat search engine optimization tactics remaining the traffic acquisition tactic of choice.

Dancho DanchevDancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, malware and cybercrime incident response. He's been an active security blogger since 2007, and maintains a popular security blog. See his full profile and disclosure of his industry affiliations.

Email Dancho Danchev

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 11 Talkback(s)
RE: Malware-infected WinRAR distributed through Google AdWords
distributed that way from downloads.com as well

Try IZARC (Read the rest)
Posted by: jbristowe@... Posted on: 01/24/09 You are currently: a Guest | | Terms of Use
Time to use another search engine.  osreinstall | 01/20/09
Just google searched it...  JT82 | 01/20/09
Re: Just google searched it...  ddanchevZDNet Moderator | 01/20/09
The more the plumbing  Alan Smithie | 01/20/09
Why does this surprise anybody?  terry flores | 01/20/09
I downloaded a macro making program  BALTHOR | 01/20/09
You mean it's not already a scam?  CobraA1 | 01/20/09
7Zip is good, true - but it does NOT pack RAR  johnhaverysamuel | 01/21/09
RE: Malware-infected WinRAR distributed through Google AdWords  MooMooMooMooMoo | 01/21/09
Just don't click on sponsored links  Greenknight_z | 01/22/09
RE: Malware-infected WinRAR distributed through Google AdWords  jbristowe@... | 01/24/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here