Internet Domain Registry

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Sunday, 18 October 2009

Hacked Newspaper loads Google News with malware sites

Posted on 01:37 by Unknown
Certain news searches on the Google News site today were pointing users to some troubling websites which seemed to be hosted by the "Chipley Bugle". Having never heard of the Chipley Bugle, I first confirmed that it was a real newspaper from a few sources, including a visit to archive.org's Wayboack Machine, which confirms that the paper has been online since at least 2000.

This is the first time that I've seen a real newspaper used to feed malware-oriented news stories to Google News.

A search for News stories where the source was "chipley_bugle" starts out with normal stories for a small town paper, such as:

BBB reports great turnout
and
Chipola Little Indians program for grades 1-8

It falls apart pretty quickly after that. The next several hundred entries, all posted about 18 hours ago, are for "news stories" with pornographic names of all varieties, and incoherent news stories, such as:

www.privatevoyeur.com
Chipley Bugle - 18 hours ago
At this top benzi knows how to progress hr the ravaged significat and female-to-female time she exists in age to have an boyfriend.

or

www.egotastic.com
Chipley Bugle - 18 hours ago
Naked inmates must be reflected websites, critized producers , and began www.egotastic.com. Janice makes him a late law, flossing him ...

You can verify this behavior by going to Google News and searching for "source:chipley_bugle", although I would recommend not following any of the links!



Many of the "news stories", such as the one above, use the names of real porn websites. If the website is followed, it displays a webpage such as this one, which appears from the URL to actually be on the Chipley Bugle website!



The graphics are actually being called by the Chipley Bugle's website from "imageshack.us", but the webpage is being loaded by what looks to be some content injected into the newspapers content-management system.

A "real" news story for the Chipley Bugle uses a URL like this one:

http://www.chipleybugle.com/index.php?option=com_content&view=article&id=2464:fwc-fills-top-law-enforcement-position&catid=3:local-news&Itemid=23

All of the fake news stories that lead to porn sites use URLs like this one:

http://chipleybugle.com/graduation2009/sponsors/?option=com_content&view=article&id=2415:breast-cancer-awareness-symposium&catid=10:events&Itemid=98

Regardless of whether you say "Enter" or "Exit", the web page forwards thevisitor away from the newspaper site to very hard core porn site calling itself "PornTube". All of the images there lead to the following malware, by claiming a new Adobe Player is needed to view the movie:

The malware has these characteristics:

File name: adobeflashplayerv10.0.32.18.exe
File size: 17920 bytes
MD5 : 5f49907a0e20b4ddebc6c31bde9eb6f1

Its currently only detected by 8 of 41 anti-virus products at VirusTotal, however several anti-virus products will still protect from this type of attack by blocking the malicious website on which the malware is hosted:

davaidavai.cn

which is hosted in the Ukraine on the IP address 80.91.176.190.

This IP address is well-known as a malware infection site, hosting such domains as:

kon4a.org
allsearchweb.org
turbosoftware.org
tubeololo.org
trailerfobia.cn
videopublicclub.cn
xratedtube.cn
xvideostube.cn
go-xtube.cn
hugextube.cn
xmoviesarchive.cn
pumpingstorm.cn
prodaemdeshevo.cn
showallwebs.cn
exclusiveprices.cn
weblmovies.cn
go-xmovies.cn
klikaemnavidos.cn
archieprodaet.cn
ourbestsearch.info
allvideoz.info

again, avoid these webpages as they all lead to malware!

The newest web domain was created toay by a user using the email:

scaryscream@gmail.com

The registrar was one frequented by Ukrainian criminals regularly, the Chinese registrar: 广东时代互联科技有限公司 (also known as "now.cn").



Other in the group used other emails and registrars, such as:

ricm512@yahoo.com who used OnlineNIC
or
exshit@yandex.ru who used Directi Internet Solutions
or
win32parit.b@gmail.com who also used 广东时代互联科技有限公司
Email ThisBlogThis!Share to XShare to Facebook
Posted in | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • 2009 Year in Review
    As 2009 comes to a close I wanted to take a minute to thank all of the people who have been helpful to this blog this year, and to share bac...
  • What about the Social Security Numbers? (The Utah Data Breach and your SSN)
    The Utah Data Breach This week the continuing saga of the Utah Medicaid Data Breach continued to unfold. If you haven't been following...
  • Top Brands Imitated by Malicious Spam
    WebSense recently released an InfoGraphic titled "Top Five Subject Lines in Phishing Emails." for January 1, 2013 through Septemb...
  • Carder Christopher Schroebel gets Seven Years
    21 years old and thinking about Cybercrime as a career choice?  Think again.  Seattle-based U.S. Attorney Jenny Durkan told a press conferen...
  • Stop the Rumors: Quit SMSing about WalMart Gang Initiations
    My daughter and her teenage friend were sitting on the couch watching TV today when they began getting text messages on their phone. Here...
  • New BBC spam mocks Georgia's President, Spreads New Virus
    This morning we've received more than 300 copies of a new "BBC" spam campaign which mocks Georgia's President and spreads ...
  • New Year's Waledac Card
    We haven't seen a new version of Waledac since Independence Day (July 4, 2009), but it looks like its back! I'm on vacation today, s...
  • Digital Certificates Update
    A quick update from the previous post. The Digital Certificates spam campaign against Merrill Lynch continues, but the good guys seem to be ...
  • ATM Cashers in 26 Countries steal $40M
    CBS News in New York has a video on their website this morning title Cyber-attacks behind possibly record-breaking bank heist . Former FBI ...
  • A New Year and Anti-Virus Products Are Still Losing
    One of our most popular blog posts in 2008 was back in August - Anti-Virus Products Still Fail on Fresh Viruses . I'm sad to report tha...

Categories

  • china
  • computer security careers
  • conficker
  • cyberwar
  • digital certificates
  • facebook
  • fake av
  • gumblar
  • koobface
  • law enforcement
  • malware
  • pharmaceuticals
  • phishing
  • public policy
  • spam
  • twitter
  • twitter malware
  • waledac
  • zbot

Blog Archive

  • ►  2013 (21)
    • ►  December (4)
    • ►  November (1)
    • ►  October (1)
    • ►  September (1)
    • ►  August (3)
    • ►  July (1)
    • ►  June (1)
    • ►  May (5)
    • ►  April (3)
    • ►  March (1)
  • ►  2012 (18)
    • ►  August (1)
    • ►  June (1)
    • ►  May (7)
    • ►  April (2)
    • ►  March (7)
  • ►  2011 (28)
    • ►  November (3)
    • ►  October (1)
    • ►  August (4)
    • ►  July (6)
    • ►  June (1)
    • ►  May (2)
    • ►  April (2)
    • ►  March (6)
    • ►  February (1)
    • ►  January (2)
  • ►  2010 (80)
    • ►  December (6)
    • ►  November (10)
    • ►  October (6)
    • ►  September (12)
    • ►  August (5)
    • ►  July (4)
    • ►  June (11)
    • ►  April (7)
    • ►  March (8)
    • ►  February (4)
    • ►  January (7)
  • ▼  2009 (92)
    • ►  December (12)
    • ►  November (11)
    • ▼  October (16)
      • Facebook Safety & Million Member Facebook Groups
      • FACEBOOK PHISH! Users Beware!
      • Fake FDIC spam campaign spreads Zeus malware
      • FBI and SOCA make a media splash at RSA Europe
      • Phishing For Love: Banking Insiders
      • TowerNet CapitalOne: Avalanche returns after 15 mo...
      • Zipped Malware Attachments in Spam: Here comes Con...
      • Hacked Newspaper loads Google News with malware sites
      • Targeted URLs in spam . . .OWA Settings update
      • IRS Zeus via Geocities
      • A weekend of Old News
      • The FBI's Biggest Domestic Phishing Bust Ever
      • Microsoft "Your e-mail will be blocked" phish
      • A Day in the Life of Spam
      • Cyber Security Awareness Month: Day Two
      • Cyber Security Awareness Month: Day One
    • ►  September (7)
    • ►  July (5)
    • ►  June (10)
    • ►  May (2)
    • ►  April (6)
    • ►  March (7)
    • ►  February (6)
    • ►  January (10)
  • ►  2008 (101)
    • ►  December (7)
    • ►  November (17)
    • ►  October (11)
    • ►  September (10)
    • ►  August (22)
    • ►  July (12)
    • ►  June (3)
    • ►  May (7)
    • ►  April (5)
    • ►  March (2)
    • ►  February (1)
    • ►  January (4)
  • ►  2007 (31)
    • ►  December (3)
    • ►  November (9)
    • ►  October (3)
    • ►  September (2)
    • ►  August (5)
    • ►  July (5)
    • ►  January (4)
  • ►  2006 (5)
    • ►  December (2)
    • ►  October (3)
Powered by Blogger.

About Me

Unknown
View my complete profile