Blog da Zscaler

Receba as últimas atualizações do blog da Zscaler na sua caixa de entrada

Security Research

SEO Spam Research

image
JULIEN SOBRIER
May 17, 2010 - 2 Min. de leitura

Hacked sites may have their pages modified with invisible IFRAMES or malicious JavaScript, or new dynamic pages are created to redirect users to a fake anti-virus page or a scam. In some cases, new folders are created, and filled with hundreds or thousands of Search Engine Optimization (SEO) page spams. These pages are intended to score well with popular searches. They contains links to other domains, either malware sites or scams. This post from Sucuri Security reports that recently hacked websites contains a .files/ folder filled with such SEO spam.

With the help of Google, it easy to find a list of these hidden folders. Look for ""index of .files/" and one example of a file listed in the blog post, for example "2009 pro bowl.html": "index of .files/" 2009 pro bowl.html. Now you have access to hundred of pages set up by attackers. This is a very valuable source of information to understand how attackers are using SEO, and which domains names are involved in the attack.

All the pages have the same structure, but are actually quite different from the SEO spam pages I saw before:

  • each page targets a particular search (for example, 2010 Winter Olympics), as usual
  • the page alternates one paragraph of text, and one link (unusual, there are usually very few links)
  • each link text has nothing to do with the content of the page (unusual)
  • each link points to a different domain: fng-international.com, achaemprego.projects.heavyworks.ne, aceuplink.net, etc.

 

 

 
Image
SEO spam page


The links redirects to different types of sites: fake antivirus pages, fake search engines to scam advertising networks, etc. Some of the links do not redirect all users to malicious sites, but only those who come from a Google/Yahoo/Bing search.

The list of file names also shows which topics are targeted by the attacker: pretty much anything! Winter Olympics, the latest Google phones, celebrities, Apple news, how to write a sonnet (!), home sales, etc.

From these files, we gathered 27,453 unique URLs from 96 different domains. This will keep me busy for a while :-)

-- Julien

form submtited
Obrigado por ler

Esta postagem foi útil??

Aviso legal: este post no blog foi criado pela Zscaler apenas para fins informativos e é fornecido "no estado em que se encontra", sem quaisquer garantias de exatidão, integridade ou confiabilidade. A Zscaler não se responsabiliza por quaisquer erros, omissões ou por quaisquer ações tomadas com base nas informações fornecidas. Quaisquer sites ou recursos de terceiros vinculados neste post são fornecidos apenas para sua conveniência, e a Zscaler não se responsabiliza por seu conteúdo ou práticas. Todo o conteúdo está sujeito a alterações sem aviso prévio. Ao acessar este blog, você concorda com estes termos e reconhece que é de sua exclusiva responsabilidade verificar e utilizar as informações conforme apropriado para suas necessidades.

Receba as últimas atualizações do blog da Zscaler na sua caixa de entrada

Ao enviar o formulário, você concorda com nossa política de privacidade.