Fake AV's double attack
Posted on 11.02.2010
Bookmark and Share
Fake AV is regularly at the top of the lists of peddled malware, and part of the reason it's because it is spread in a many different ways: spam, compromised websites, SEO poisoning, etc.

SophosLabs warns about a recently heavily employed attack vector: malicious applet and JavaScript contents open the way to the dynamical loading of the malicious PDFs.

In the PDFs, obfuscated JavaScript aims to exploit a number of Adobe vulnerabilities, while the applet loads a JAR file that endeavors to take advantage of an old privilege escalation vulnerability in the handling ZoneInfo objects during deserialization.

Coming at you from two sides, the likelihood of succeeding is doubled. If one of both manage to circumvent your defenses, you're in for a ride! The installer file copies itself to your system, adds Registry keys to hook system startup and drops a .html file that will be loaded on your desktop instead of your chosen background. This is how it looks like:


Enough to frighten the nonprofessionals, don't you think?

Anyways, after doing this, it inserts URLs that lead to the rogue software into the IE's list of trusted sites, and downloads the fake AV from one of them and runs it on your computer. The name of this malicious program is Internet Security 2010, and its professional look can fool people unfamiliar with this kind of scam.

Sophos has, of course, blocked the JavaScript, the PDFs, the JAR file and the installer file, along with having blacklisted the malicious sites hosting the fake AV.






Spotlight

17% of the world's PCs are unprotected

Posted on 30 May 2012.  |  In a study that analyzed data from voluntary scans from an average of 27-28 million computers per month, McAfee researchers found 17% of the world is browsing the internet completely unprotected.

Daily digest

By subscribing to our early morning news update, you will receive a daily digest of the latest security news published on Help Net Security.
  

Weekly newsletter

With over 500 issues so far, reading our newsletter every Monday morning will keep you up-to-date with security risks out there.
  

 
DON'T
MISS

Wed, May 30th
    COPYRIGHT 1998-2012 BY HELP NET SECURITY.   // READ OUR PRIVACY POLICY // ABOUT US // ADVERTISE //