Interesting spyware push download tactic…



Incidents.org has another interesting post about a spyware site. One of the handlers ran across it while doing a search for an educational institution. (They’ve used a wildcard in the dns record so that they can get traffic to {fillinkeyword}.nastydomain.com) Anyway… the main page tries to install WinAntiSpyware2006FreeInstall.cab from WinSoftware Corporation, Inc. It gives the little ActiveX control popdown bar and insists that it must be installed to view the page properly. But that’s not the most interesting part…


It looks like they’re filtering access to the page based on the User Agent of the browser, if it’s IE you get the push install, if it’s not… Page not found. They discovered this because they put on the “rubber gloves” of web security research and tried pulling up the page with wget to see what it looked like. 403 denied… Then they tried out Firefox and got a 404 not found. Finally, they tried wget with the -U option to specify a User Agent… like this…

wget -U "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"

And with that (and the address), they were able to grab the index.html

I guess that’s a technique to try and slow the research of a push spyware download? According to Incidents, WinAntiSpyware2006FreeInstall.cab is detected as a trojan by some antivirus products. I wonder also if this could pave the way for spyware pushers to target specific browsers/platforms with different push downloads?

Related Posts

Blog Traffic Exchange Related Posts
  • How to Remove AntiKeep | AntiKeep Removal Guide AntiKeep is a rogue antivirus application from the same family as ReAnti and AntiAdd which we've written about in the last few days. Like many of these rogue application they will try to trick you into consenting to install it, or install without your permission. They will claim that there......
  • Malwarebytes Anti-malware I'm usually a bit leery of new antispyware products. I do a first look at the rogue antispyware lists and just try to be as cautious as possible when moving away from the tools that I've tried and tested. I downloaded malwarebytes anti-malware very reluctantly to clean up a machine......
  • Migration to new CMS As you can see I'm in the midst of a migration to a new CMS tool. Right now I'm using wordpress which is normally considered a blogging tool. Frankly, I was reluctant to look at a blogging tool in part because the concept has such a trendy feel to it.......
Blog Traffic Exchange Related Websites
  • Using Facebook To Promote Your Business? It Doesn't Have To Be Hard If you're looking for effective ways to promote your business, you can't afford to overlook Facebook. Social networking is growing with leaps and bounds each day, and if your business is not taking advantage of it, you're definitely leaving money on the table. If you want to get the most......
  • Coin Collecting on eBay eBay has quickly become an important destination for those who are interested in coin collecting. It allows users of all kinds to quickly and easily find the coins that they are interested in, and allows them to set their own price. The thrill of the auction simply adds to the......
  • Using Facebook To Promote Your Business? It Doesn't Have To Be Hard If you're looking for effective ways to promote your business, you can't afford to overlook Facebook. Social networking is growing with leaps and bounds each day, and if your business is not taking advantage of it, you're definitely leaving money on the table. If you want to get the most......
www.pdf24.org    Send article as PDF   

Similar Posts


See what happened this day in history from either BBC Wikipedia
Search:
Keywords:
Amazon Logo

Comments are closed.


Switch to our mobile site