Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security > Spyware Threats

November 13th, 2007, 15:23 GMT · By Bogdan Popa

Fake YouTube Attempting to Infect Visitors

SHARE:

Adjust text size:


The fake YouTube page
Enlarge picture
A new phishing scheme is now aiming to lure users into visiting a malicious copy of YouTube in order to infect their computers with Trojan-Dropper.W32/Agent.CPL. Security vendor F-Secure today reported that some Internet consumers received spam messages asking them to click on a YouTube clip attached to the message.
The link is actually redirecting the users to a fake YouTube website which informs them that they must install Adobe Flash Player in order to view the video. "Hello, you either have JavaScript turned off or an old version of Adobe's Flash Player. Get the latest Flash player," the message reads.

Clicking on the provided link to download the Flash Player will bring you to a new page to get install_flash_player.exe, an executable containing the requested file. "The page, located on a .cn server, prompts for the installation of Adobe's Flash Player. If you download the file, it's named install_flash_player.exe. Just as the real Flash Player download would be…", F-Secure wrote in a blog post published today.

Obviously, the executable file comes with Trojan-Dropper.W32/Agent.CPL but it's not pretty clear how dangerous it is for computers... Probably the Trojan horse is supposed to enable the attackers to bring other infected material on the victims' computers in order obtain administrator privileges and get any data they want. "Firefox browser is already warning about the fraudulent nature of this site, and we have detection with our 2007-11-12_04 database, so we don't expect a very big catch for this particular rock phishing site", F-Secure continued.

If you want to avoid a successful exploitation through the phishing scheme, you're advised to avoid clicking on the links inserted into the spam messages and refuse installing applications which come from other pages than the genuine one. Just look in your browser address bar to be sure the website you visit is not part of a phishing attack.
FILED UNDER:
phishing
youtube
adobe
trojan

TELL US WHAT YOU THINK:

10,304 hits · 5 comments · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


New Gmail Security Feature?

Kaspersky Gets More Expert Help!

Women Smarter Than Men When It Comes to IT Security

100.000 New Phishing Websites Every Week

Asia Stomps Phishers!

READER COMMENTS:


Comment #1 by: vex on 19 Nov 2008, 11:42 UTC reply to this comment

my view on these Websites are that they nmust be Desprate to try and Fake youtube , it is Clearly obvvisous , when you Click on the link , look at the Address bar , it will say Something like

www.utube.com/6263


Comment #2 by: no nickname LOL :) on 02 Mar 2011, 01:03 UTC reply to this comment

OOH Thank you for posting this. Very helpful and now I know what to look for just in case.


Comment #3 by: lolz on 22 Aug 2011, 16:48 UTC reply to this comment

I clicked on it. should I be worried?


Comment #4 by: Manny on 17 Dec 2011, 22:21 UTC reply to this comment

What is the website called?


Comment #5 by: cpuHacka101 on 15 Jan 2012, 20:07 UTC reply to this comment

There's a site called youtu.be I wonder if it does that

Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM