Twitter worm hits goo.gl, redirects to fake anti-virus
Summary: A fast-moving Twitter worm is in circulation, using Google's goo.gl redirection service to push unsuspecting users to a notorious scareware (fake anti-virus) malware campaign.
A fast-moving Twitter worm is in circulation, using Google's goo.gl redirection service to push unsuspecting users to a notorious scareware (fake anti-virus) malware campaign.
At 8:45 a.m EST today, this Twitter search shows thousands of Twitter messages continuing to spread the worm.
According to malware hunters tracking the threat, the worm's redirection chain pushes users to a Web page serving up the “Security Shield” Rogue AV. The page is using obfuscation techniques that include an implementation of RSA cryptography in JavaScript to obfuscate the page code.
Kaspersky Lab malware researcher Nicolas Brulez (see important disclosure) said the original "goo.gl" links in the Twitter messages are redirecting users to different domains with a “m28sx.html” page. That page then redirects to a static domain with a Ukrainian top level address.
As if it was not enough, this domain redirects the user to another IP address which has been linked in the past to fake anti-virus distributions. "This IP address will then do the final redirection job, which leads to the actual Fake AV site," Brulez explained.
Once a user's browser session is redirected to the malicious site, a warning message claims the computer is running suspicious applications and the user is encouraged to run a scan. As usual, the result is that the machine is infected with malicious threats and the scam is to trick the user into downloading a fake disinfection tool.
Kick off your day with ZDNet's daily email newsletter. It's the freshest tech news and opinion, served hot. Get it.
Talkback
all a twitter
Message has been deleted.
RE: Twitter worm hits goo.gl, redirects to fake anti-virus
Like this one
http://blogs.computerworld.com/mac_os_x_vulnerable_to_new_trojans
RE: Twitter worm hits goo.gl, redirects to fake anti-virus
RE: Twitter worm hits goo.gl, redirects to fake anti-virus
RE: Twitter worm hits goo.gl, redirects to fake anti-virus
No they're not.
Since the vast majority of trojans are geared towards Windows, even if there was an even split between Mac and Windows users who choose to download these things, more Windows users would be affected.
Happy to clear that up for you.
RE: Twitter worm hits goo.gl, redirects to fake anti-virus
@fairportfan - but you have no proof of this, so your statement is nothing but greenish brown FUD.
RE: Twitter worm hits goo.gl, redirects to fake anti-virus
You must still be using XP
In that case, you should hop onto Vista or 7 and see how much better security has come in the 10 years since XP was released. ;)
RE: Twitter worm hits goo.gl, redirects to fake anti-virus
Windows Vista and 7 are vulnerable to this very same attack. I've had to clean both OS from this. Fortunately it is easier to recover from with both Vista and 7, but they both get hit by it just as easily as XP did.
That would take an independent thought
Sounds like james347 is a free thinker
RE: Twitter worm hits goo.gl, redirects to fake anti-virus
Has it? Or is that the opinion of MSFT and their fanboys? I don't recall any genuine and genuinely objective secrurity experts going public with a statement to the effect that Vista or 7 has "much better security".
Your statement is also suspicious for another reason: you say "in the 10 years since XP". Well, guess what: XP's security has got a lot better over these 10 years too.
RE: Twitter worm hits goo.gl, redirects to fake anti-virus
RE: Twitter worm hits goo.gl, redirects to fake anti-virus
Yeah, because when I'm surfing the web I always put my administrator password in when a pop up asking whether I want to install xyz software pops up.
That's the only way OSX can get a "virus" which then isn't a "virus" as it's not self replicating, requiring user intervention to be installed.
There are no OSX viruses.
re: Thanks MS...
RE: Twitter worm hits goo.gl, redirects to fake anti-virus
Nice try but a total fail nonetheless.
Thanks james347
We know the truth hurts, @John Zern
;)
ahh so, how many screen names do you
Interesting that when particular users are "chastised", you appear.
As I said, Interesting.