On mySimon: 2009 Mercedes-Benz SLK-Class
BNET Business Network:
BNET
TechRepublic
ZDNet

February 20th, 2009

Rogue security software spoofs ZDNet Reviews

Posted by Dancho Danchev @ 9:09 am

Categories: Anti Virus, Botnets, Browsers, Malware, Passwords

Tags: Security, Cybercrime, Online Scam, Rogue Security Software, Anti-virus-1, CNET, PCMag, Dancho Danchev

Impersonation is a form of flattery by itself, however, not when it comes to the very latest round of rogue security software this time impersonating ZDNet, CNET’s and PC Magazine’s reviews section, making it look like legitimate and highly respected technology sites have actually reviewed and recommend the rogue security software.

According to Lawrence Abrams from Bleeping Computer the latest rogue security software Anti-virus-1 redirects infected users attempting to visit the sites to a legitimately looking reviews of the scareware. By using this novel approach the rogue software vendor’s aim is to add more legitimacy to Anti-virus-1’s existence in general. However, if they truly wanted to achieve better social engineering result, they could have at least used a more recent version of the impersonated sites.

Here’s how it’s done anyway:

Upon installation the software modifies the HOSTS file and redirects affected users attempting to visit the review sites to a centralized location used for the hosting and promotion of even more rogue security software:

O1 - Hosts: 217.20.175.74 www.review.2009softwarereviews.com
O1 - Hosts: 217.20.175.74 review.2009softwarereviews.com
O1 - Hosts: 217.20.175.74 a1.review.zdnet.com
O1 - Hosts: 217.20.175.74 www.d1.reviews.cnet.com
O1 - Hosts: 217.20.175.74 www.reviews.toptenreviews.com
O1 - Hosts: 217.20.175.74 reviews.toptenreviews.com
O1 - Hosts: 217.20.175.74 www.reviews.download.com
O1 - Hosts: 217.20.175.74 reviews.download.com
O1 - Hosts: 217.20.175.74 www.reviews.pcadvisor.c.uk
O1 - Hosts: 217.20.175.74 reviews.pcadvisor.co.uk
O1 - Hosts: 217.20.175.74 www.reviews.pcmag.com
O1 - Hosts: 217.20.175.74 reviews.pcmag.com
O1 - Hosts: 217.20.175.74 www.reviews.pcpro.co.uk
O1 - Hosts: 217.20.175.74 reviews.pcpro.co.uk
O1 - Hosts: 217.20.175.74 www.reviews.reevoo.com
O1 - Hosts: 217.20.175.74 reviews.reevoo.com
O1 - Hosts: 217.20.175.74 www.reviews.riverstreams.co.uk
O1 - Hosts: 217.20.175.74 reviews.riverstreams.co.uk
O1 - Hosts: 217.20.175.74 www.reviews.techradar.com

And whereas modifying the HOSTS file is a bit of a noisy approach to hijack traffic, given the fact that end user managed to get — ironically — infected with a non-existent security software on their way to protect themselves from security threats, there’s a high chance that this HOSTS modification will remain undetected.

This “visual social engineering” approach is perhaps one of the key success factors for the rise of rogue security software. From the real-time scanning applets showing how badly affected a visitor is, to the bogus software rewards and awards the application has already won by using , vendors of rogue security software know the value of “what you see is what you get”, or at least we want you think so.

From a psychological perspective, the rise of rogue security software demonstrantes the end user’s impulsive decision making based on the oldest known motivation factor - fear which in 2009 is transformed into fear of losing data. And while in the past cybercriminals used to brandjack legitimate security software, today’s revenue-sharing affiliate based model for spreading rogue security software is in fact building new brands that despite their short product cycle are already affecting hundreds of thousands of users.

Dancho DanchevDancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, malware and cybercrime incident response. He's been an active security blogger since 2007, and maintains a popular security blog. See his full profile and disclosure of his industry affiliations.

Email Dancho Danchev

Subscribe to Zero Day via Email alerts or RSS.

Related Discussions on TechRepublic

Did you know you can take part in these discussions with your ZDNet membership?

  • Talkback
  • Most Recent of 4 Talkback(s)
RE: Rogue security software spoofs ZDNet Reviews
There are several free apps out there that will help you get rid of this. I work for a state institution and we are working on getting an Enterprise package for spyware. But I am sure we will still ne... (Read the rest)
Posted by: dbisse@... Posted on: 03/02/09 You are currently: a Guest | | Terms of Use
Message has been deleted.  David GroberZDNet Moderator | 02/23/09
RE: Rogue security software spoofs ZDNet Reviews  docqualizer | 02/23/09
RE: Rogue security software spoofs ZDNet Reviews  zanderqin | 02/23/09
RE: Rogue security software spoofs ZDNet Reviews  dbisse@... | 03/02/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here