Brandon Posted December 20, 2005 Report Share Posted December 20, 2005 Story published by Websense Security LabsSource: Websense Security LabsWebsense Security Labs is seeing a large increase in the number of websites and emails that use deception and/or browser vulnerabilities to install potentially unwanted software. The common theme among these threats is the use lures of possible spyware infections on your machine. In some cases, the scam actually reports fraudulent information regarding the security of your PC.In many cases they also request money in return for cleaning the outlined security problems (we have seen as much as $500 per year).Over the last 2 weeks, we have identified more than 1500 sites that have some (or all) of the following criteria:They are hosted in Ukraine and RussiaThe website domain names are registered in countries like Vanuatu and MexicoIP netblocks hosting sites are often hosting other questionable sites such as fraudulent search enginesIP netblocks have been hosting malicious code such as Trojan horse downloaders, droppers, and hosts-file redirection softwareMalicious code that modifies DNS settings has used these netblocks for DNS resolvingDownloaded code often includes several pieces of spyware, adware, and other potentially unwanted softwareRemoving the software often requires that you to fill out a surveySeveral of the sites contain links to other sites that are hosting IE exploit code(See site for example screenshots)Websense Advisory Quote Link to post Share on other sites
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.