On TV.com: 24 Movie is On the Clock
BNET Business Network:
BNET
TechRepublic
ZDNet

April 15th, 2009

Scareware pops-up at FoxNews

Posted by Dancho Danchev @ 6:41 am

Categories: Anti Virus, Botnets, Browsers, Hackers, Malware

Tags: Web, Advertisement, Campaign, Scareware, Security, Malvertising, Dancho Danchev, Security, Viruses And Worms, Internet

There have been numerous reports from affected users that a scareware variant of PersonalAntivirus and ExtraAntivirus has been poping-up at FoxNews.com during the last couple of days, through a malvertising campaign.

This most recent case of malvertising (MSN Norway serving Flash exploits through malvertising; Fake Antivirus XP pops-up at Cleveland.com) once demonstrates that whenever a direct access to a high-trafficked site cannot be obtained through a compromise, cybercriminals are logically exploiting third-party content/ad networks to achieve their goals.

Reproducing malvertising campaigns is tricky due to the geolocated nature in which the ads are served, as well as the cybercriminals’ awareness on the fact that the amount of traffic which they expose to scareware is logically increasing the risk of having their campaign exposed. A risk which they hedge by temporarily inactivating the campaign or basically rotating the geolocation preferences and displaying the malicious ads to random countries.

Interestingly, in FoxNews.com’s case Google’s Safe Browsing diagnostic page is stating that “Malicious software is hosted on 3 domain(s), including 2mdn.net/, s3.wordpress.com/, llnwd.net” with 2mdn.net part of DoubleClick’s network, with another interesting note stating that “Yes, this site has hosted malicious software over the past 90 days. It infected 18 domain(s)“, confirmed by another report as well. These isolated incidents in the sense that the campaign’s lifecycle is shortened based on collective reporting of affected users, are also taking place at other ad networks such as ContextWeb, and Yieldmanager.com.

Here’s a brief analysis of the campaign which now appears to have been removed by FoxNews. Until the next time. According to SandShark, the warning issued by Google’s Safe Browsing was in respect to the a domain redirector rd-point .net which is still active and is redirecting to the rogue ExtraAntivirus (extrantivirus .com) followed by previous known redirectors to another scareware RapidAntivirus.

It’s worth pointing out that a scareware pop-up at a high-trafficked web site that is basically relying on the social engineering factor, is not as ugly as the introduction of a hybrid scareware demanding ransom for the decryption of files, or client-side exploits. With the list of the major web properties that have been historically affected by much more malicious malvertising incidents (e.g. MySpace, Excite, Expedia, Rhapsody) continuously expanding, maintaining a decent situational awareness next to a client-side vulnerabilities free host, mitigates a great percentage of the currently active threats.

Who’s to blame anyway - the advertising networks for working with phony content publishers, the affected web sites for not policing themselves, or the web site visitor for the lack of situational awareness on emerging threats/scams like scareware?

Talkback!

Dancho DanchevDancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, malware and cybercrime incident response. He's been an active security blogger since 2007, and maintains a popular security blog. See his full profile and disclosure of his industry affiliations.

Email Dancho Danchev

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 42 Talkback(s)
It's iteresting what the demographics say...
Interestingly, I was, just a couple hours ago, looking at the network stats of Fox News for an ad placement.

The actual Fox viewer (according to Nielson), is college educated, a majority earn ... (Read the rest)
Posted by: info@... Posted on: 05/07/09 You are currently: a Guest | | Terms of Use
Fox News IS scareware.(nt)  storm14k | 04/15/09
Plus 1 Zillion (nt)  ejhonda | 04/15/09
Fox News is the BEST!  Tiggster | 04/15/09
For God's sake...  ths40 | 04/15/09
Why didn't you make that charge against the OP?  frgough | 04/15/09
Fox Snus  Dave S2 | 04/15/09
No  bluebuddha1973 | 04/16/09
malfox  susanai | 04/16/09
Why should they be shut down?  hasta la Vista, bah-bie | 04/17/09
Political ideology, no.  74hodag74 | 04/17/09
Denial is a powerful thing  hasta la Vista, bah-bie | 04/17/09
Yep...the best FUD channel on TV.  storm14k | 04/15/09
Fox news the best???  bluebuddha1973 | 04/16/09
R U kidding?  skidoor | 04/17/09
It's iteresting what the demographics say...  info@... | 05/07/09
Re; Fox News is the BEST!  hkommedal | 04/16/09
Liberal elites??  74hodag74 | 04/17/09
You beat me to it! 2nded! nt  T1Oracle | 04/15/09
LMAO  NStalnecker | 04/15/09
What's wrong with Faux News?  Dr. John | 04/15/09
Liberal Propaganda failing  pizzaman7 | 04/15/09
LMAO!!!  storm14k | 04/15/09
All I have to say is  bluebuddha1973 | 04/16/09
fox  susanai | 04/16/09
scareFox  susanai | 04/16/09
Maybe we should shut you down too...  hasta la Vista, bah-bie | 04/17/09
Gotta Love it ....  Linux_4u! | 04/15/09
At least be fair and balanced  Dorkyman | 04/15/09
I cry baloney  lefty.crupps | 04/15/09
Message has been deleted.  bluebuddha1973 | 04/16/09
It's always such a sweet feeling to see  frgough | 04/15/09
I don't get it  lefty.crupps | 04/16/09
Bad Joke  sboverie@... | 04/16/09
I'd take Messiah44 anyday over...  storm14k | 04/15/09
LOL!  eMJayy | 04/15/09
RE: Scareware pops-up at FoxNews  nospam@... | 04/15/09
And the website visitor..  hasta la Vista, bah-bie | 04/17/09
RE: Scareware pops-up at FoxNews  bluebuddha1973 | 04/16/09
This blog post is mis-titled  Speednet | 04/16/09
Totally agree  hasta la Vista, bah-bie | 04/17/09
When Communist News Network or British Backstab Corp. starts infecting  invmgr@... | 04/17/09
RE: Scareware pops-up at FoxNews  Steve KTG | 04/19/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement
Click Here

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here