Interesting spyware push download tactic…



Incidents.org has another interesting post about a spyware site. One of the handlers ran across it while doing a search for an educational institution. (They’ve used a wildcard in the dns record so that they can get traffic to {fillinkeyword}.nastydomain.com) Anyway… the main page tries to install WinAntiSpyware2006FreeInstall.cab from WinSoftware Corporation, Inc. It gives the little ActiveX control popdown bar and insists that it must be installed to view the page properly. But that’s not the most interesting part…


It looks like they’re filtering access to the page based on the User Agent of the browser, if it’s IE you get the push install, if it’s not… Page not found. They discovered this because they put on the “rubber gloves” of web security research and tried pulling up the page with wget to see what it looked like. 403 denied… Then they tried out Firefox and got a 404 not found. Finally, they tried wget with the -U option to specify a User Agent… like this…

wget -U "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"

And with that (and the address), they were able to grab the index.html

I guess that’s a technique to try and slow the research of a push spyware download? According to Incidents, WinAntiSpyware2006FreeInstall.cab is detected as a trojan by some antivirus products. I wonder also if this could pave the way for spyware pushers to target specific browsers/platforms with different push downloads?

Related Posts

Blog Traffic Exchange Related Posts
  • Qemu Windows XP install Well, I alluded yesterday to a struggle with installing Windows XP under Qemu. Here are some details on the long and (still winding) road. At this point I have a working XP install running under Qemu but, I've run out of disk space (2G) and need more space before I......
  • How to Remove AntiKeep | AntiKeep Removal Guide AntiKeep is a rogue antivirus application from the same family as ReAnti and AntiAdd which we've written about in the last few days. Like many of these rogue application they will try to trick you into consenting to install it, or install without your permission. They will claim that there......
  • Migration to new CMS As you can see I'm in the midst of a migration to a new CMS tool. Right now I'm using wordpress which is normally considered a blogging tool. Frankly, I was reluctant to look at a blogging tool in part because the concept has such a trendy feel to it.......
Blog Traffic Exchange Related Websites
  • Will Google Reign Forever How many of you use Google all the time? Let’s get a show of hands. Let’s see…one, two, three, four…looks like a lot of you. Great, but maybe you should ask yourself why. Why do you automatically turn to Google when you need to find information? The answer is......
  • Using Facebook To Promote Your Business? It Doesn't Have To Be Hard If you're looking for effective ways to promote your business, you can't afford to overlook Facebook. Social networking is growing with leaps and bounds each day, and if your business is not taking advantage of it, you're definitely leaving money on the table. If you want to get the most......
  • How To Make Pre-Selling Work For You Affiliate marketing is one of the most profitable business models online and it is incredibly competitive as well. There are lots of affiliate marketers who just promote their products and wonder why their sales aren't higher. There is a simple reason for this; they don't do very well at pre-selling......
www.pdf24.org    Send article as PDF   

Similar Posts


See what happened this day in history from either BBC Wikipedia
Search:
Keywords:
Amazon Logo

Comments are closed.


Switch to our mobile site