On Metacritic: BioShock 2: Is it a disappointment?
BNET Business Network:
BNET
TechRepublic
ZDNet

January 27th, 2009

Google Video search results poisoned to serve malware

Posted by Dancho Danchev @ 12:13 pm

Categories: Anti Virus, Browsers, Google, Malware, Passwords, Web 2.0

Tags: Security, Cybercrime, Google Video, YouTube, Fake Flash Player, DNSChanger, Dancho Danchev

From the real-time syndication of hot Google Trends keywords, maintaining AdWords campaigns, to the plain simple blackhat search engine optimization tactics, cybercriminals are constantly looking for new ways to acquire traffic by enjoying the clean reputation of each and every Web 2.0 property. From LinkedIn, Bebo, Picasa and ImageShack, to Twitter, everyone’s targeted efficiently using automated account registration tools.

During the last couple of days, a single group involved in a countless number of blackhat SEO campaigns across the Web, started massively targeting Google Video with a campaign that has already managed to hijack approximately 400,000 search queries in order to trick users into visiting a bogus and malware serving (W32/AutoTDSS.BNA!worm) adult web site.

Here’s how the campaign works, and how they’re attempting to cloak it from the eyes of security researchers.

What’s particularly interesting about this campaign relying entirely on Google Video traffic to flourish, is that instead of sticking to the adult content in their keywords inventory, the cybercriminals have been in fact syndicating legitimate YouTube video titles from a variety of topics. Therefore, the number of legitimate videos used is proportional to the comprehensiveness of the campaign, in this case, over 400,000 search queries, a number that is increasing in real-time since they keep having their bogus content crawled by Google Video.

Moreover, based on the fact that they maintain a portfolio of 21 publisher domains with bogus and non-existent video content currently crawled, a simple tactic that they’re using could entirely hijack a search query at Google Video. How come? By simply duplicating the content on their publisher domains, the top 5 search results for a particular video can be easily served from any of the 21 publisher domains, making it look like different sites have the same content.

The search engine results poisoning works as follows. Upon clicking, a Google Video user coming across to any content from any of their 21 publisher domains, is taken to a single redirection point (porncowboys .net/continue.php), then to the well known adult site template abused by cybercriminals (xfucked .org/video.php?genre=babes&id=7375), where the user is told that “Your Flash Version is too old. Your browser cannot play this file. Click “OK” to download and install update for Flash Video Player” and the malware is served if he’s tricked into it (trackgame .net/download/FlashPlayer.v3.181.exe).

The cybercriminals are also taking advantage of a well known evasive technique - http referer checking or “cloaked maliciousness. For instance, the malware redirection to the fake flash player is only served if the potential victim is coming from Google Video. If a researcher is basically browsing around the content of their sites, the legitimate YouTube videos are legitimately syndicated. Excluding this case, it’s worth pointing out that on the majority of occasions cybercriminals do not fully take advantage of the evasive features available within the traffic management kits they use behind the campaigns, making their campaigns easier for analyzing.

Google’s Security Team has been notified and action is expected to be taken anytime now.

Dancho DanchevDancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, malware and cybercrime incident response. He's been an active security blogger since 2007, and maintains a popular security blog. See his full profile and disclosure of his industry affiliations.

Email Dancho Danchev

Subscribe to Zero Day via Email alerts or RSS.

Related Discussions on TechRepublic

Did you know you can take part in these discussions with your ZDNet membership?

  • Talkback
  • Most Recent of 77 Talkback(s)
It's about personal responsibility
Thanks for the overview but it doesn't touch on the primary
issue. I have read just about all the posts and aside from
blatantly rude and ignorant posts each one has a kernel of
usefulness... (Read the rest)
Posted by: compu-mechanic Posted on: 04/19/09 You are currently: a Guest | | Terms of Use
Windows affected (who cares)  Christian_<>< | 01/28/09
Hasn't "Flash" been ported?  kd5auq | 01/28/09
Do not tell that to opensource_luser01  GuidingLight | 01/28/09
Oh my heavens!  Christian_<>< | 01/28/09
Liar, Liar, Pants on Fire...  Wolfie2K3 | 01/28/09
He he ... well said Wolfie2K3 !!  RealPauper | 01/29/09
Also interesting ...  RealPauper | 01/29/09
more lies...  barence773 | 01/29/09
No it doesn't work without drivers ...  RealPauper | 01/30/09
This is what I've been afraid of...  djchandler | 01/30/09
10,000,000 and counting... ??  RealPauper | 01/28/09
Ok, here's your sign ...  RealPauper | 01/29/09
YOU "Try again!"  RealPauper | 01/29/09
What Kind of IT are you?  Timewellwasted | 02/24/09
Message has been deleted.  MyMac | 01/28/09
How intresting...  Heatlesssun1 | 01/28/09
How intresting...  game_girl36@... | 01/28/09
The very first virus i saw...  fairportfan | 01/28/09
Same here  djchandler | 01/30/09
pirated software  vilppuu@... | 01/29/09
Consider this...  djchandler | 01/30/09
Macs were NEVER impervious ...  RealPauper | 01/29/09
heh  johnnylumber | 01/28/09
Absolutely correct...  Heatlesssun1 | 01/28/09
Things change  914four | 01/28/09
I forgot  Sparhawk_z | 01/28/09
Except of course  wcb42ad | 01/28/09
You mac Zealots....  Crestview | 01/28/09
Yes...  Snowy_River | 01/28/09
Some points  daengbo | 01/28/09
WHAT ?!?!?!  RealPauper | 01/28/09
Web expoits can cross OS boundries  SysAdmin202 | 01/29/09
to (who cares)  rolloroy | 01/28/09
Stones and glass houses  CosmoAgain | 01/28/09
Assinin ?  Neutron Man | 01/28/09
assinin ... ??  RealPauper | 01/29/09
RHEL  neverhome | 01/28/09
Who cares?  Crestview | 01/28/09
Who cares?  game_girl36@... | 01/28/09
And WHY should I care  Crestview | 01/28/09
You missunderstood my meaning  Crestview | 01/28/09
To Windows affected (who cares)  game_girl36@... | 01/28/09
You misunderstood my meaning  Crestview | 01/28/09
Immune ???  RealPauper | 01/28/09
You may not care that it's a windows infection ...  RealPauper | 01/29/09
Yes, it is time to clean up the internet !........  rtirman37@... | 01/28/09
If Bill Gates REALLY cared about Malware ....  Too Old For IT | 01/28/09
Too true  Sparhawk_z | 01/28/09
WHAT ?!?!?  RealPauper | 01/29/09
Will you just LISTEN to yourself for a moment?  Wolfie2K3 | 01/28/09
The FUD abounds...  Heatlesssun1 | 01/28/09
RE: Google Video search results poisoned to serve malware  toglesby@... | 01/28/09
Avast! freeware antivirus also stopped it  Crestview | 01/28/09
RE: Google Video search results poisoned to serve malware  Godrunner | 01/28/09
It is!  Crestview | 01/28/09
RE: Google Video search results poisoned to serve malware  gary_krutsinger@... | 01/28/09
They ARE getting smarter  Crestview | 01/28/09
Smart people...  Wolfie2K3 | 01/28/09
RE: Google Video search results poisoned to serve malware  pebear | 01/28/09
RE: Google Video search results poisoned to serve malware  JerryRocky | 01/28/09
The fix..?  Wolfie2K3 | 01/28/09
All of this stuff should be easily traceable...  sinephase | 01/28/09
Why "we need a law" won't work  oldbaritone | 01/29/09
Storytime: clueless users on the rise  vilppuu@... | 01/29/09
Good Point.  testpoint | 02/01/09
It's about personal responsibility  compu-mechanic | 04/19/09
Other searches were poisoned for a while recently.  topsecret@... | 01/29/09
Stick to the thread  murphym@... | 01/29/09
It's a living  urug_xinu | 01/29/09
RE: Google Video search results poisoned to serve malware  jhtowns@... | 01/29/09
You can't fix stupid  dqkennard | 01/30/09
You Cant Fix Stupid  infoz | 01/30/09
But you can hobble stupid...  djchandler | 01/30/09
Uneducated but not stooopid!  rdtraversi | 01/30/09
That's just common sense smart.  djchandler | 01/30/09
RE: Google Video search results poisoned to serve malware  stormr69 | 01/31/09
Warning: site has Mac version now  velocity2009 | 04/09/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here