| Fake YouTube page |
We have found a many malicious sites that specifically target Internet Explorer or Firefox users, but not often Google Chrome users. In this example, any click on the fake video player or the fake ad attempts to install the following extension for Google Chrome: https://chrome.google.com/webstore/detail/nhmibhinlbilhaflldckbeokphjoifhi.
| JavaScrip code that installs a Chrome extension |
You may have noticed that the extension is hosted in the official Google Chrome store. Google disabled the installation of extensions for 3rd party sites in June 2012, and silent installs in late 2012.
The Chrome store page does not show any information about the extension:
Let's install the extension hosted at http://facebook-java.com/.
| List of permissions requested by the extension |
| getjava.net |
| Overrides any tab wit ha URL starting with chrome:// |
- http://goo.gl/9Ky9t => http://profonixcoder.com/yeni/pro.php
- http://goo.gl/gQhF6 => http://profonixcoder.com/yeni/twitter.php (down)
- http://goo.gl/t7snI => http://profonixcoder.com/yeni/youtube.php (down)
- http://goo.gl/jUEgY => http://profonixcoder.com/yeni/askfm.php (down)
It looks like the author of this malicious extension doesn't have a high opinion of Google's security by using Google for hosting the extension and using their URL shortener to inject the malicious JavaScript.



