ie8 fix
madison

Zero Day

Ryan Naraine, Emil Protalinski and Dancho Danchev

Haiti earthquake themed blackhat SEO campaigns serving scareware

By | January 14, 2010, 3:53pm PST

Summary: Cybercriminals quickly mobilized following the news of a massive earthquake that hit Haiti on Tuesday. The blackhat SEO campaigns are only the tip of the iceberg. Here’s what else to look for, and how to make sure you’re donating money to the right organization.

Cybercriminals quickly mobilized following the news of a massive earthquake that hit Haiti on Tuesday, by introducing several hundred compromised domains embedded with bogus blackhat seo (search engine optimization) content related to Red Cross donations and general Haiti earthquake relief information.

The sites are already appearing within the first 10 search results on Google, and upon clicking on them the user is redirected to one of the most profitable monetization tactic (FBI: Scareware distributors stole $150M) that scammers use these days - scareware also known as rogueware.

Naturally, the blackhat SEO campaigns are only the tip of the iceberg. Here’s what else to look for, and how to make sure you’re donating money to the right organization.

What’s particularly interesting about the blackhat SEO campaign serving scareware (Setup_2022.exe; install.exe), is that a huge percentage of the sites are hosted within the network of Heart Shared hosting (heartinternet.co.uk), indicating some some of automatic exploitation of its customers.

The same practice of relying on compromised legitimate domains within a particular ISP was also evident in blackhat SEO campaigns that were analyzed over the last couple of months.

For instance, not only was the same practice used to affect over a million web sites (Thousands of web sites compromised, redirect to scareware) in November, 2009, but also the campaign itself was traced back to the Koobface gang, which is clearly involved in fraudulent activities going beyond the Koobface botnet.

Different fraudulent groups either multitask, or cover a specific fraud segment exclusively. According to Symantec, spam campaigns impersonating the British Red Cross are already in circulation, requesting Western Union payments to support the victims of the earthquake. Anticipating the upcoming flood of earthquake relief scams, the FBI has released the following tips in order to raise more awareness:

  • Do not respond to any unsolicited (spam) incoming e-mails, including clicking links contained within those messages.
  • Be skeptical of individuals representing themselves as surviving victims or officials asking for donations via e-mail or social networking sites.
  • Verify the legitimacy of nonprofit organizations by utilizing various Internet-based resources that may assist in confirming the group’s existence and its nonprofit status rather than following a purported link to the site.
  • Be cautious of e-mails that claim to show pictures of the disaster areas in attached files because the files may contain viruses. Only open attachments from known senders.
  • Make contributions directly to known organizations rather than relying on others to make the donation on your behalf to ensure contributions are received and used for intended purposes.
  • Do not give your personal or financial information to anyone who solicits contributions: Providing such information may compromise your identity and make you vulnerable to identity theft.

If you want to donate money to the real organizations, consider going through Google’s Support Disaster Relief in Haiti campaign page.

Kick off your day with ZDNet's daily e-mail newsletter. It's the freshest tech news and opinion, served hot. Get it.

Topics

Dancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, malware and cybercrime incident response.

Disclosure

Dancho Danchev

More details on Dancho Danchev's current and past professional affiliations, can be found in his LinkedIn profile.

Biography

Dancho Danchev

Dancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, and cybercrime incident response. He's been an active security blogger since 2007, and maintains a popular security blog sharing real-time threats intelligence data with the rest of the community on a daily basis. More details on Dancho Danchev's current and past professional affiliations, can be found in his LinkedIn profile. You can also follow him on Twitter

Related Discussions on TechRepublic

Did you know you can take part in these discussions with your ZDNet membership?
36
Comments

Join the conversation!

Just In

RE: Haiti earthquake themed blackhat SEO campaigns serving scareware
efsane Updated - 8th Apr 2011
Well done! Thank you very much for professional templates and community edition
sesli sohbet sesli chat
0 Votes
+ -
Could you please clarify..
AzuMao 15th Jan 2010
..which operating system(s) are affected by this
malware? It isn't of absolutely vital importance,
but it really would make the article more
complete.
0 Votes
+ -
If you notice in the article, that it refers to
Snooki_smoosh_smoosh 15th Jan 2010
some .exe's and the screen shot of course depicts Windows XP, and based on historical evidence that in all likely hood >97% of all attacks are targeting Windows.
0 Votes
+ -
So it's Windows' fault?
rfnajera 15th Jan 2010
So, of course, you want us to go to Linux or Mac, right?
Never mind phishing scams, which have nothing to do with the OS.
0 Votes
+ -
Nonsense!
AzuMao 15th Jan 2010
The phisher-price OS (Windows) is great for
phishing on, or being phished on!

If you like paying through your nose, that is.
0 Votes
+ -
Ignorance and brainwashing
Crestview Updated - 15th Jan 2010
Still plague the computer industry. Thanks for the demonstration.

Anybody with the brain of a toad can avoid ALL of it, even my little kids don't get "infections".
0 Votes
+ -
You don't need "infections" to get phished. You
just need an email account, and an OS (with a
browser).

I will once again recommend Windows for this, if
you like paying through your nose.
You yourself point out that you don't need an infection to be affected by this. I don't see anything inthe article indicating that this is a OS specific issue. Anybody could follow a bad link with any OS.

You have several postings on this article and I haven't read one yet that makes any sense or even relates to the article.

Seriously, do you just get bored in your basement between mosque and chicken choking?

What is your deal?
0 Votes
+ -
Hey *Gwoman*..
AzuMao 16th Jan 2010
..I was just pointing out that it can happen with
any OS, but that Windows should be preferred if
you like paying through your nose. That's pretty
much the only difference between them when it
comes to phishing. That you pay through your nose
for Windows.
0 Votes
+ -
re:So it's Windows' fault?
schmandel@... 15th Jan 2010
You're fine as you are, the wolves of this world need sheep to prey on.
0 Votes
+ -
Yes and no
Federico Churca Torrusio 15th Jan 2010
Being a very big player on the market, it's just natural that most OS-specific attacks will be directed to the sector with most market share. The article does, as you say, note about OS-independent attacks like phishing.
0 Votes
+ -
Okay. Thanks for clarifying.
AzuMao 15th Jan 2010
Another attack not to worry about.
  • Flagged
What the hell is a blackhat SEO campaign?
Would be nice if you explain yourself.
0 Votes
+ -
"Blackhat SEO Campaign"
dippleydokus 15th Jan 2010
SEO - Search Engine Optimization.
Blackhat - loosely, a bad person.

So, a balckhat SEO capaigm would be a campaign organized by bad people using search engine optimization to scam the unwary.

Suggest you install 1-Click Answers and never be mystified by an acronym again. happy
0 Votes
+ -
Blackhat
phleroy 15th Jan 2010
In old Western Movies the bad cowboys always wore black hats. The savior wore a white hat.

That is where it comes from.
I find it somewhat short of amazing that the FBI, with all their resources and expertise, cannot precisely identify the physical location of these websites; the banks and accounts where the donations are sent by the unwary; or post office boxes used by these jerks and close them down - or better yet, shoot them. Somehow, I don't think they would be any loss to society.
0 Votes
+ -
Re: FBI
kidtree 15th Jan 2010
It would be nice to shut down all the bad guys and sell their body parts, but it's easier said than done. Most of them are prime examples of "cloud computing," using the global nature of the web to hide. A bad guy in one country might use servers in several other countries and a web address that indicates he's in another. Some of the malware they dish out infects your computer and recruits it as a member of a "botnet," spreading itself to all your email & messaging contacts. So at the same time you're asking that the FBI should be shutting these guys down, your own computer may be gathering stolen financial & identity info (yours and others') and forwarding it to some anonymous server overseas.
0 Votes
+ -
And what's Google doing about it?
jpdemers@... 15th Jan 2010
How hard can it be to prevent these cretins' websites from showing up in search results? That's how most people end up on these sites in the first place.
Isn't EVERTHING WINDOWS' fault! We wouldn't want to blame anything on the real bad guys in these scams now would we~...
This kind of Blackhat SEO has dominated Google search
results, for any major news story, for about 2 years
now.

I don't believe I've performed a search for a current
event, at any time in the last six months, that didn't
have an obvious 'smell-of-phish', in one of the top 10
URLs, returned from a Google search.

Reverse tracking usually brings me to an Eastern
European or Russian host.

Most of sites target Windows and IE vulnerabilities.
A few sites target vulnerabilities common to all
browsers and all OSs.
I think if the sheep became wolves and paid more attention, then roles are reversed. Every Wolf has its fleas, Tis easy enough to scratch! The American Red Cross would probably be the best bet to donate money to the victims and thier families.
And pictures are everywhere without even having to look that hard. Yahoo for instance has many pictures of the devistation, as does all the major telivision networks, if your into that kind of thing.
I think that people who take advantage of the suffering of people are guided by... could it be... SATAN!!!!!
0 Votes
+ -
Don't forget..
AzuMao 16th Jan 2010
..God tortured Job (one of if not the most
faithful believers in God) half to death and
killed all of his family, just because Satan
told him to.

And also drowned (almost) everyone, just for
shits and giggles.


So they also might be God.
0 Votes
+ -
Actually IIRC
lehnerus2000 18th Jan 2010
As I recall, God allowed Satan to do it, because of a bet!

God did drown everyone and "nuke" Sodom and Gomorrah though.

lehnerus2000
0 Votes
+ -
That can't be it.
AzuMao 19th Jan 2010
God is omniscient, and doesn't play dice, right?
So he must have known the outcome ahead of time.
0 Votes
+ -
I didn't say...
lehnerus2000 20th Jan 2010
I didn't say that God plays fair.

lehnerus2000
Didn't see the heartinternet.co.uk in any of the five I looked at, do you see a common vulnerability they are exploiting?

http://praetorianprefect.com/archives/2010/01/scareware-purveyors-spammers-and-crooks-take-advantage-of-haiti-earthquake/
I googled "donate to haiti disaster relief" and all but 1 result were well known legimate charities with the exception of 1. Maybe Google manually edited the results to blackball these fraudulent sites. One useful tool I use is Web of Trust, a plug in for Firefox where uses rate websites as to their reliability and trusworthiness. It sometimes gives false positives but it is definitely a good first defense.
One key thing so many people are too lazy to do or ignorant of what to do is to search the message headers of incoming SPAM & find the originating ISP. If it has come from one of the bigger ISP's then forward the message to the abuse section of the ISP. You will need to set the message to show the headers then cut & paste the header to the top of the forwarded email so they can see the details as the header will change as soon as you forward it & they need to see the original header. If you don't see a major ISP's name in the header that is another reason to not open any attachments.

For Western Union= spoof@westernunion.com
Yahoo[even foreign Yahoo's]=abuse@yahoo.com
Gmail=abuse@gmail.com
For MSN or Hotmail=report_spam@msn.com
Live email=report_spam@live.com
Even AOL=TOSEmail1@aol.com

There are many more just look for them. The more people who forward them to those abuse centers the quicker they can get them shut down. If they don't know one of their boxes is being used to spout SPAM how are the supposed to shut them down??
Why do these always turn into either Windows/Linux bs or idiot user bs.
Simple fact is not everyone is computer savy and/or likes linux.
Why not put the energy into blaming the bottom dwellers who do this. Root them out and distroy them. If it wasn't for these low lifes the debate on windows/linux etc etc wouldn't exist.
Put the blame where it lies!!!
0 Votes
+ -
Crooked information
IslandBoy_77 20th Jan 2010
Ah, no. If you read the account, you will see that Satan came to God as part of some sort of "review" that took place in the spiritual realm. God asked him what he'd been up to. If the vernacular, Satan said he'd been cruising the planet (earth). God asked him what he thinks of Job. Satan says "he'll break if you let me at him". Of course, God knew Job well, and allowed Satan to have at Job except to take his life. The people who died - Jobs children - did so because Satan killed them. Am I comfortable with how the scenario went down? No - I would not want to go through what Job went through. But then, millions of people over the centuries have been brutally tortured and killed by Satan - not God - and endured worse than Job: witness the Greek Wars, the Roman conquests, the ravages of Genghis Khan, the Scythians and the Vandals, WWI, WWII, the Korean War, the Vietnam War (which showed human / Satanic cruelty at it's most wicked), the Khmer Rouge & Pol Pot, Stalin's Purges, Idi Amin, the Somali warlords, Darfur, Saddam Hussein, modern Iran - the list goes on.

And in regards to the flood, like most people you have not been informed who it was that got drowned by the deluge: they were Nehalem - the fallen ones. Human / fallen angel hybrids. Noah and his sons were the last of the human race - the rest were not human, did not have human spirits, and it was only their bodies that God allowed to be destroyed. Their spirits, unfortunately, survived, and are now what we call demons (always seeking embodiment).

The world is a far weirder place than you or I can reasonably comprehend - the stuff that goes on all around us in the spirit world is what shapes our day to day lives, not the physical stuff itself. And one last thought: for God, history has already happened - it's just you and I that perceive yesterday, today and tomorrow. Does that remove our freewill ("it's already happened")? No. God sees what we ended up choosing to do, and He responded to our choices in advance since He saw it all before we did. Freaky, no?
0 Votes
+ -
So why..
AzuMao 20th Jan 2010
Ah, no. If you read the account, you will see that Satan came to God as part of some sort of "review" that took place in the spiritual realm. God asked him what he'd been up
to. If the vernacular, Satan said he'd been cruising the planet (earth). God asked him what he thinks of Job. Satan says "he'll break if you let me at him". Of course, God knew
Job well, and allowed Satan to have at Job except to take his life. The people who died - Jobs children - did so because Satan killed them. Am I comfortable with how the
scenario went down? No - I would not want to go through what Job went through. But then, millions of people over the centuries have been brutally tortured and killed by Satan -
not God - and endured worse than Job: witness the Greek Wars, the Roman conquests, the ravages of Genghis Khan, the Scythians and the Vandals, WWI, WWII, the Korean War, the
Vietnam War (which showed human / Satanic cruelty at it's most wicked), the Khmer Rouge & Pol Pot, Stalin's Purges, Idi Amin, the Somali warlords, Darfur, Saddam Hussein,
modern Iran - the list goes on.


..prevent Job from dying, but not the children? God is omniscient so he must have known ahead of time that Satan would continue being evil no matter how much Job proved
himself, right? So what was the point?

And in regards to the flood, like most people you have not been informed who it was that got drowned by the deluge: they were Nehalem - the fallen ones. Human / fallen angel
hybrids. Noah and his sons were the last of the human race - the rest were not human, did not have human spirits, and it was only their bodies that God allowed to be destroyed.
Their spirits, unfortunately, survived, and are now what we call demons (always seeking embodiment).


Again, he must have known ahead of time that their spirits would survive and possess people, so what was the point? And what about all the other animals? Wasn't it just the
humans that bred with the fallen angels? So why not just kill those, and leave everything else intact? He's omnipotent, so it's not like he couldn't choose what to kill and
what not to.. right?
0 Votes
+ -
If you have the power...
lehnerus2000 20th Jan 2010
If you have the power and the foreknowledge and you do nothing then you are almost as guilty as the perpetrator.

You are wrong. Satan believed that he could make anyone turn away from God. God said, "I'll take that bet, as long as I get to choose the test subject". So God selected a fanatic who wouldn't break and Satan fell for it.

According to your own "handbook", all of the World's problems are the result of God ignoring the consequences of his decisions (creating Satan even though he KNEW that he would run amok).

At least MS has the excuse that it's not omniscient.

lehnerus2000
0 Votes
+ -
DHL & UPS Scams
lehnerus2000 Updated - 20th Jan 2010
I have been getting multiple scam emails purporting to be from DHL and/or UPS.

They state:
"Dear customer!
The courier company was not able to deliver your parcel by your address.
Cause: Error in shipping address.
You may pickup the parcel at our post office personaly!
Please attention!
The shipping label is attached to this e-mail.
Please print this label to get this package at our post office.
Please do not reply to this e-mail, it is an unmonitored mailbox.
Thank you.
"
They include a zip file attachment (also note the spelling error).

There is also a PayPal scam email.

Just a friendly heads up.

lehnerus2000
Well done! Thank you very much for professional templates and community edition
sesli sohbet sesli chat

Join the conversation!

Formatting +
BB Codes - Note: HTML is not supported in forums
  • [b] Bold [/b]
  • [i] Italic [/i]
  • [u] Underline [/u]
  • [s] Strikethrough [/s]
  • [q] "Quote" [/q]
  • [ol][*] 1. Ordered List [/ol]
  • [ul][*] · Unordered List [/ul]
  • [pre] Preformat [/pre]
  • [quote] "Blockquote" [/quote]
ie8 fix
Click Here
ie8 fix

The best of ZDNet, delivered

ZDNet Newsletters

Get the best of ZDNet delivered straight to your inbox

Facebook Activity

White Papers, Webcasts, & Resources
ie8 fix
ie8 fix