« A day in the life of a Malware Analyst
File extensions matter »

Beware of search engines helpers

May 13th, 2008

 You may come across some sites that offer online searches in cool formats. For example, we found this Italian website that does a search in both Google and Yahoo!.

It works well and presents the results in two diffent window panes:

However, digging into the source code for that page, we found an infamous drive-by download (loader.exe) that happens to be nothing less than a Trojan Downloader.

That Trojan will download additional malware (dialer, password stealer) onto your computer.

As a general rule, it is safer to use your search engine directly from the main site (i.e. google.com). Many sites offer a search from their own page that claims to search the major search engines. However, it is often biased results that are returned, or even worse, malicious programs.

JSegura

    This entry was posted on Tuesday, May 13th, 2008 at 2:46 pm and is filed under Exploits. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

    Comments:

    • (0) comments
    • |
    • Add your comments




RSS feed to this site Twitter Linkedin YouTube Channel

 

RSS feed to this site Jerome Segura is a Security Analyst working at ParetoLogic.

You can contact him at:
MalwareDiaries Email

 

Pages

  • Live Malware Map
  • About
  • Contact Us



Malware Top 10

  • Privacy Center
  • Pro AntiSpyware 2009
  • Antivirus XP
  • Antivirus 2009
  • Antivirus 360
  • Internet Antivirus Pro
  • Ultimate Antivirus 2008
  • Ultimate Cleaner
  • Ultimate Defender
  • Renus



Archives

  • July 2009
  • June 2009
  • May 2009
  • April 2009
  • March 2009
  • February 2009
  • January 2009
  • December 2008
  • November 2008
  • October 2008
  • September 2008
  • August 2008
  • July 2008
  • June 2008
  • May 2008
  • April 2008
  • March 2008



Categories

  • Botnets (2)
  • Exploits (14)
  • Fake codecs (14)
  • IM threats (1)
  • Keyloggers (1)
  • Mac security (4)
  • Malware Trends (64)
  • Phishing (5)
  • Research (25)
  • Rogue software (45)
  • Rootkits (2)
  • Uncategorized (66)
  • Wireless Security (1)



 
 
 

© 2009 ParetoLogic Inc.