CESIL Posted January 20, 2010 Posted January 20, 2010 Hi All We have an odd situation here that I wonder if you could try and replicate... Several times over the past week users have called me to look at a virus alert that they have got on their computer... ...thing is it is not a real virus alert, just a web page that looks like a windows screen with a fake virus scan running that then offers a download of an anti-virus package. I have been investigating and have found the following... If I search Google for "free subtraction worksheets" or other education related terms I get a page of results that work ok. If I then tick the radio control for "pages from the uk" and search again I get results as usual but some of them have links in the form http://xxxxxxxxx.yy.zz/fyprwa/bfz.php?jxhw=free+subtraction+worksheets where the domain appears to be genuine but the link takes me to the fake virus scanner. I am trying to determine whether this is a google issue or an infection at our end...can anybody else replicate my problem?
Edu-IT Posted January 20, 2010 Posted January 20, 2010 It's the same here. activebrokers.co.uk/ytpcsr/fzx.php?dyza...subtraction+worksheets ispycctv.net/cwnpmv/sqa.php?vgrf=subtraction...worksheet
smadison Posted January 20, 2010 Posted January 20, 2010 Works fine from here as my search gives me the google page with results such as maths worksheets
Edu-IT Posted January 20, 2010 Posted January 20, 2010 Works fine from here as my search gives me the google page with results such as maths worksheets Oh it works but there are links on page 1 and page 2 such as those above.
Michael Posted January 20, 2010 Posted January 20, 2010 Very, very interesting. It does look like a Google issue. I wonder if it's related to the attacks on Google recently?
Martin Posted January 20, 2010 Posted January 20, 2010 Does anyone know how to read (rather than execute) the "bfz.php" or similar file that is provided in the Google links? Looks like Google is just indexing loads of compromised web-sites, rather than being at fault itself? Running Firefox with NoScript just seems to pull up a page of junk (text and further links), so maybe it is some script kicked of by PHP that gives the virus scanner message (and i don't want to risk running it, hence wondering what the source of the PHP code is)? mb
OutToLunch Posted January 20, 2010 Posted January 20, 2010 (edited) Very, very interesting. It does look like a Google issue. I wonder if it's related to the attacks on Google recently? I think it's more that those pages have a low rank on google.com but high rank on google.co.uk - if you switch to a filtered search where it shows you when the pages appeared on Google, they're very spread out - not all in the last week etc. Looks more like it's a compromised site issue where the randomly named php script is uploaded onto a site open to some kind of exploit. Edit - if you're bored enough to nslookup a few of the sites in those results it seems to confirm what I said above, very small IP range, probably a few compromised servers on a webhost somewhere... Default Server: google-public-dns-a.google.com Address: 8.8.8.8 > activebrokers.co.uk Server: google-public-dns-a.google.com Address: 8.8.8.8 Non-authoritative answer: Name: activebrokers.co.uk Address: 79.170.40.230 > clmi.co.uk Server: google-public-dns-a.google.com Address: 8.8.8.8 Non-authoritative answer: Name: clmi.co.uk Address: 79.170.40.247 > theilliteratekniferack.com Server: google-public-dns-a.google.com Address: 8.8.8.8 Non-authoritative answer: Name: theilliteratekniferack.com Address: 79.170.40.230 > jim-gray.co.uk Server: google-public-dns-a.google.com Address: 8.8.8.8 Non-authoritative answer: Name: jim-gray.co.uk Address: 79.170.40.10 > hackersunited.co.uk Server: google-public-dns-a.google.com Address: 8.8.8.8 Non-authoritative answer: Name: hackersunited.co.uk Address: 79.170.40.10 > formbyurc.co.uk Server: google-public-dns-a.google.com Address: 8.8.8.8 Non-authoritative answer: Name: formbyurc.co.uk Address: 79.170.40.10 Final edit - definitely a host issue. If you wget the pages with and without a google.co.uk referrer you will get the normal text without google referrer and a 302 redirect to the malware site if used. This came up ages ago, can't find the thread I posted in about the compromised site - I know it was one with school related bits on... Edited January 20, 2010 by OutToLunch
Martin Posted January 20, 2010 Posted January 20, 2010 I have reported this to Heart Internet, who appear to be hosting the compromised web-sites! mb
Michael Posted January 20, 2010 Posted January 20, 2010 I agree from the nslookups it is a host issue. I particularly like this domain name: theilliteratekniferack.com Just seems very random! I wonder what kind of website it really is?
zx2012 Posted January 20, 2010 Posted January 20, 2010 I get this warning from Google Chrome when I click on the link. "Malware Detected! Warning: Visiting this site may harm your computer! The website at sweetlemongrass.com appears to host malware - software that can hurt your computer or otherwise operate without your consent. Just visiting a site that hosts malware can infect your computer. For detailed information about the problems with this site, visit the Google Safe Browsing diagnostic page for ------------.com."
mossj Posted January 20, 2010 Posted January 20, 2010 (edited) it's compromised sites, not hosts or search engines. Rather than inject a virus stright into the code a hacker has made it so you only get it if you go through search engines. After all what webmaster google's his own site? Edited January 20, 2010 by mossj
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now