Blog Zscaler

Recevez les dernières mises à jour du blog de Zscaler dans votre boîte de réception

Security Research

Fake Security Software Websites – Still Popular In 2011

image
THREATLABZ
mars 08, 2011 - 3 Min de lecture
Fake security software is a form of computer malware that misleads users into installing and potentially paying for fake security software. The sites convince users to download the malicious software by displaying fake security warnings such as “Your computer is infected” etc. End users are clearly not educated about such attacks, as the campaigns remain highly successful. Below is a short blog analyzing a recent infection on a friend’s machine to illustrate the problem.
 

We continue to see numerous infected sites, which are redirecting users to fake security software campaigns. The pages display animated fake security warnings to users in order to scare them and convince them to download and install a binary, which is generally packaged as fake antivirus software. The victim will be infected with a downloader Trojan that will then download additional malware. Below are a few screenshots of animations typically used in the attacks:

Image

 

 

 

After this initial load animation, the user will be prompted with another security warning:

Image

 

 

 

Once a user clicks on the OK button, additional animated fake security warnings will be displayed.

Image

 

 

 

At this point, the user is prompted to download the fake antivirus software.

Image

 

 

 

 

 

This same campaign has been used over and over again and can be found hosted at thousands of domains.

Image

 

 

 

 

 

 

 

 

Image

ImageAll of the above animations are from the same malicious website. The content is randomly changed for each new visit to the site. Once installed the victim is forced to activate or buy a license key to remove these fake threats from the system. Here are some tips for users who still wants to stay away from those attacks.

1) No real Antivirus vendor displays such security warnings, animations and popups.

2) No website will scan a system when visited and display immediate warnings about threats on the system.

3) No real Antivirus vendor will force you to download an execuatble.

4) When you need AV software, go directly to the site of a reputable vendor yourself.

5) Keep an eye on address bar for the URL name and redirected URL names.

6) Keep any eye on the status bar of the browser, which is present at the bottom to spot redirection taking place.

7) If you want to download executable but are unsure that it is legitimate, it can be scaned against various antivirus vendiors by submitting it to a service such as VirusTotal If popular vendors triggers or declare the file as malicious, immedeatly delete it from the system.

8) Install a common antivirus solution and keep it updated with latest virus definitions.

9) Last but not least, never pay for such fake security software.

The VirusTotal results for the fake security software from the above example show that it was detected by only 21/42 popular AV vendors. Even now, we are still seeing a large number of fake security software websites promoting their fake products.

 

Stay safe

 

Umesh

form submtited
Merci d'avoir lu l'article

Cet article a-t-il été utile ?

Clause de non-responsabilité : Cet article de blog a été créé par Zscaler à des fins d’information uniquement et est fourni « en l’état » sans aucune garantie d’exactitude, d’exhaustivité ou de fiabilité. Zscaler n’assume aucune responsabilité pour toute erreur ou omission ou pour toute action prise sur la base des informations fournies. Tous les sites Web ou ressources de tiers liés à cet artcile de blog sont fournis pour des raisons de commodité uniquement, et Zscaler n’est pas responsable de leur contenu ni de leurs pratiques. Tout le contenu peut être modifié sans préavis. En accédant à ce blog, vous acceptez ces conditions et reconnaissez qu’il est de votre responsabilité de vérifier et d’utiliser les informations en fonction de vos besoins.

Recevez les dernières mises à jour du blog de Zscaler dans votre boîte de réception

En envoyant le formulaire, vous acceptez notre politique de confidentialité.