Interesting spyware push download tactic…
Incidents.org has another interesting post about a spyware site. One of the handlers ran across it while doing a search for an educational institution. (They’ve used a wildcard in the dns record so that they can get traffic to {fillinkeyword}.nastydomain.com) Anyway… the main page tries to install WinAntiSpyware2006FreeInstall.cab from WinSoftware Corporation, Inc. It gives the little ActiveX control popdown bar and insists that it must be installed to view the page properly. But that’s not the most interesting part…
It looks like they’re filtering access to the page based on the User Agent of the browser, if it’s IE you get the push install, if it’s not… Page not found. They discovered this because they put on the “rubber gloves” of web security research and tried pulling up the page with wget to see what it looked like. 403 denied… Then they tried out Firefox and got a 404 not found. Finally, they tried wget with the -U option to specify a User Agent… like this…
wget -U "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"
And with that (and the address), they were able to grab the index.html
I guess that’s a technique to try and slow the research of a push spyware download? According to Incidents, WinAntiSpyware2006FreeInstall.cab is detected as a trojan by some antivirus products. I wonder also if this could pave the way for spyware pushers to target specific browsers/platforms with different push downloads?
Popularity: 1% [?]
Related Posts - Qemu Windows XP install Well, I alluded yesterday to a struggle with installing Windows XP under Qemu. Here are some details on the long and (still winding) road. At this point I have a working XP install running under Qemu but, I've run out of disk space (2G) and need more space before I......
- How to Remove AntiKeep | AntiKeep Removal Guide AntiKeep is a rogue antivirus application from the same family as ReAnti and AntiAdd which we've written about in the last few days. Like many of these rogue application they will try to trick you into consenting to install it, or install without your permission. They will claim that there......
- How to Remove SoftStronghold | Soft Stronghold Removal Guide SoftStronghold is the latest rogue antivirus application in the LONG line of Wini rogues... Softveteran was the most recent (see the softveteran removal guide) but.... SoftCop (see the SoftCop removal guide.) But, the line goes much further back.... Softsoldier (How to remove SoftSoldier), ( TrustFighter TrustFighter Removal Guide, TrustSoldier removal......
Related Websites - Using Facebook To Promote Your Business? It Doesn't Have To Be Hard If you're looking for effective ways to promote your business, you can't afford to overlook Facebook. Social networking is growing with leaps and bounds each day, and if your business is not taking advantage of it, you're definitely leaving money on the table. If you want to get the most......
- FlashGet My Download I've been using FlashGet for so many years I don't even remember since when or what version it was when I tried it. At that time the software was still not very popular and most people that I knew used other download helper software. I knew about FlashGet from Download.com......
- Places You Can Consider For Mountain Biking Are you looking for some thrill and excitement? If yes, then trail biking is the thing for you. To get started with mountain cycling, the first step is to go looking for adequate places for a similar. Naturally, there are a good deal of options when it comes to selecting......
Similar Posts
- Wget user agent avoidance
- More details on php exploit from last week
- Mozilla Firefox user-agent spoofing
- Browser Statistics reaction
- User agent spoofing