NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Security / Incidents

Incidents


Online Scare Advertising Tactics Leak into the Real World

Attack vector of new scareware distribution campaign originates in a parking lot

By Lucian Constantin, Web News Editor

5th of February 2009, 11:16 GMT

Adjust text size:


Real world social engineering used to distribute malware
Enlarge picture
Security researchers have documented a new malware attack, with an intriguing physical component. The attackers have used fake parking violation fliers in order to direct people to a malicious website installing malware.

A lot of individuals are sensitive to spam and are able to realize when they're being served a link that they should not visit. However, their senses have been trained for the online environment and spammers have realized this, thus it is understandable why they keep on developing new social engineering techniques applicable to the real world.

Such a tactic has been recently observed and described by Lenny Zeltser, security consultant for the SANS Internet Storm Center. The analyst reports that yellow fliers have been placed on the windshield of cars from a parking lot in Grand Forks, North Dakota. The said flyers, bearing a title saying “PARKING VIOLATION,” have directed car owners to a website for more information.

“This vehicle is in violation of standard parking regulations. To view pictures with information about your parking preferences, go to [URL],” the message on the flier reads. The website in question greets the visitors with some images of poorly-parked cars and an additional linked message, which advises that “To view pictures of your or someone else's horrible parking or to upload pictures: CLICK ME FOR THE PICTURE SEARCH TOOLBAR.”

Upon visiting the link, an executable file called PictureSearchToolbar.exe is prompted for download. Obviously, downloading and installing it is not a good idea, as it is a malware dropper, which queries a remote server and installs other malicious applications onto the victim's computer.

The additional malware prompts fake security warnings in Internet Explorer while the users are browsing. Clicking on the warning, which ironically claims that the computer is infected, takes them to a website where they are advised to download and install a rogue and useless anti-virus scanner, which, according to the SANS researcher, is detected only by a few anti-virus engines.

Lokesh Kumar, malware analyst at McAfee, points out that the malicious applications distributed through this campaign are part of the Vundo family of trojans, and refers to this new approach as “an innovative social engineering technique, where the virtual world meets the real world.”

“Attackers continue to come up with creative ways of tricking potential victims into installing malicious software. Merging physical and virtual worlds via objects that point to websites is one way to do this. I imagine we'll be seeing such approaches more often,” SANS's Lenny Zeltser concludes.

TAGS:

scareware distribution | social engineering | PictureSearchToolbar.exe | parking violation | windshield flier
Read by 914 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
NOT RATED 0 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Google Video SEO Poisoning

Government Websites and Microsoft Help Push Scareware

Scareware Advertisers Close to Being Arrested

Google Ads Spread Scareware

The Embassy of India in Spain Pushes Malware via Website

Barack Obama's Website Used to Push Malware

Paris Hilton's Website Compromised

Google Code Abused by Hackers

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM