{"id":743,"date":"2007-11-15T18:29:18","date_gmt":"2007-11-15T18:29:18","guid":{"rendered":"https:\/\/www.darknet.org.uk\/2007\/11\/doubleclick-involved-in-malware-distribution\/"},"modified":"2015-09-09T19:39:49","modified_gmt":"2015-09-09T11:39:49","slug":"doubleclick-involved-in-malware-distribution","status":"publish","type":"post","link":"https:\/\/www.darknet.org.uk\/2007\/11\/doubleclick-involved-in-malware-distribution\/","title":{"rendered":"Doubleclick Involved in Malware Distribution"},"content":{"rendered":"

[ad]<\/p>\n

We recently reported on thousands of people being hooked by big sites distributing malware<\/a>, it now seems Doubleclick was the one at fault.<\/p>\n

It’s a pretty neat trick and a good spin on Social Engineering leveraging on the trustworthy nature of the sites.<\/p>\n

CNN even?<\/p>\n

Rogue anti-spyware software that pushes fraudulent PC scans has found its way onto DoubleClick and legitimate sites, including CNN, The Economist, The Huffington Post and the official site of the Philadelphia Phillies.<\/p>\n

DoubleClick officials told eWEEK that they have recently implemented a security monitoring system to catch and disable a new strain of malware that has spread over the past several months. This system has already captured and disabled about 100 ads, the company said in a statement, although it didn’t mention this episode in particular.<\/p>\n

The bogus anti-spyware onslaught is only part of a bigger wave that’s also included porno ads being swapped for normal ads on sites such as The Wall Street Journal. It’s not yet clear whether the same fraudsters are behind both the porn and the fraudulent anti-spyware ads.<\/p><\/blockquote>\n

I really hope they do put some serious measure in place that don’t just use a signature for this particular case…something a little more intelligent I hope.<\/p>\n

Sunbelt Software has confirmed that Trojans were being downloaded from ads served by DoubleClick as recently as Nov. 11. This malware is the kind that repeatedly pops bogus warning messages about computer infections in users’ faces until they give up in despair and pay $30 to $40 for a junk “security” program.<\/p>\n

“The stuff that’s installed is this rogue anti-spyware software that \u2026 gives you fake alerts, [such as] ‘Your computer is infected, you must run this.’ Basically it’s extortion. \u2026 They try to push you to buy their software,” Sunbelt President Alex Eckelberry told eWEEK.<\/p>\n

The malware application is a variant on WinFixer<\/a>, a piece of malware that pretends to be a diagnostic tool. <\/p><\/blockquote>\n

I hope we can educate people about these kind of things, sad to say as some of the comments mentioned in the previous post…a lot of people will fall for this – why? Simply because they don’t know any better.<\/p>\n

<\/p>\n

Source: eWeek<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"

[ad] We recently reported on thousands of people being hooked by big sites distributing malware, it now seems Doubleclick was the one at fault. It’s a pretty neat trick and a good spin on Social Engineering leveraging on the trustworthy nature of the sites. CNN even? Rogue anti-spyware software that pushes fraudulent PC scans has […]<\/p>\n","protected":false},"author":25,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_seopress_robots_primary_cat":"","_seopress_titles_title":"","_seopress_titles_desc":"","_seopress_robots_index":"","_genesis_hide_title":false,"_genesis_hide_breadcrumbs":false,"_genesis_hide_singular_image":false,"_genesis_hide_footer_widgets":false,"_genesis_custom_body_class":"","_genesis_custom_post_class":"","_genesis_layout":"","footnotes":""},"categories":[7,24],"tags":[142],"featured_image_src":null,"featured_image_src_square":null,"author_info":{"display_name":"Darknet","author_link":"https:\/\/www.darknet.org.uk\/author\/darknet\/"},"_links":{"self":[{"href":"https:\/\/www.darknet.org.uk\/wp-json\/wp\/v2\/posts\/743"}],"collection":[{"href":"https:\/\/www.darknet.org.uk\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.darknet.org.uk\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.darknet.org.uk\/wp-json\/wp\/v2\/users\/25"}],"replies":[{"embeddable":true,"href":"https:\/\/www.darknet.org.uk\/wp-json\/wp\/v2\/comments?post=743"}],"version-history":[{"count":0,"href":"https:\/\/www.darknet.org.uk\/wp-json\/wp\/v2\/posts\/743\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.darknet.org.uk\/wp-json\/wp\/v2\/media?parent=743"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.darknet.org.uk\/wp-json\/wp\/v2\/categories?post=743"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.darknet.org.uk\/wp-json\/wp\/v2\/tags?post=743"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}