Symantec Connect
  • Login
  • Register
  • Security
    • All of Connect
    • Backup and Archiving
    • Clustering and Replication
    • Endpoint Management & Virtualization
    • Storage Management
    • Security
    • Inside Symantec
    • Vision User Conference
    • Partners
    • Developers
    •  
  • Overview
  • Forums
  • Articles
  • Blogs
  • Downloads
  • Events
  • Videos
  • Groups
  • Ideas
Login to participate
Security ResponseRSS

Free Online Movie Blogs Serving up Trojan for Windows and Mac

Deepak Patil
August 20th, 2009
Tags: Endpoint Protection (AntiVirus), Emerging Threats, Emerging Threats, Malicious Code, Malicious Code, Security, Security Response
Facebook Twitter

We have recently observed that attackers are actively exploiting new movie releases to distribute malware. The general practice is to host a blog on a (relatively) reputable site, which in actual fact redirects users to a malicious website hosting malware.

The movie “Obsessed” was released in April 2009 and in order to watch it online for free, users might search for a phrase that includes keywords such as movie, free, video, online, watch, etc.—along with the movie’s name, of course. So, a search phrase such as “obsessed movie online free full video” would yield results similar to the following:

imagebrowser image

The first search result we received was from digg.com. The digg.com page that was listed is flooded with the keywords related to movie:

imagebrowser image

However, when a user clicks on the link it redirects to a blog hosted on blogspot.com:

imagebrowser image

Then, once the user clicks on an image that appears to be a video player window, it redirects to a codec download. Unfortunately this turns out to be a fake codec. More investigation revealed that blogspot.com has been abused by attackers with multiple, similarly styled posts. The immediate and interesting observation is that these blogs are using similar templates.

The table below shows attackers are closely pursuing new movie releases in order to spread malware:

imagebrowser image

For example, the image below shows the blog that was posted for the movie InkHeart. This blog used a template similar to the one used in the previous sample and it also redirects users to a website that is hosting malware:

imagebrowser image

These blogs usually contain a link that redirects users to malicious sites using multiple redirections. This enables cybercriminals to continually change the site that finally delivers the malware.

Interestingly enough, the malicious site to which users are being redirected is serving malware for Windows as well as for Mac OS. This is based on the user-agent string of the browser. For a Windows browser agent it delivers a Trojan intended for the Windows operating system, and for a Mac OS browser agent it delivers a Trojan for the Mac operating system. The following image shows the same URL delivering a Win32 Executable for IE8, as well as a .dmg file for Safari4 when the user agent for the Mac OS is used:

imagebrowser image

Symantec antivirus products detect this threat as Trojan.Fakeavalert for Windows and as OSX.RSPlug.A for Mac OS. Users should be aware of these social engineering techniques and should use caution when visiting any such sites. Symantec customers are protected from this attack with the latest antivirus and IPS definitions.

+1 (1 vote)
  • Deepak Patil's blog
  • Comments RSS Feed

About Security Response Blog

Our security research centers around the world provide unparalleled analysis of and protection from malware, security risks, vulnerabilities, and spam.
Filter by:

Recent Blog Posts

  • Microsoft Patch Tuesday - February 2010
    Robert Keith - February 09, 2010
  • Sale! This Offer is Valid EVERY Week
    Mayur Kulkarni - February 05, 2010
  • SpyEye Bot versus Zeus Bot
    Peter Coogan - February 04, 2010
  • 利用双重漏洞发动攻击的木马Trojan.Hydraq
    Livian Ge - February 03, 2010
  • Phishing Using Pornographic Content as Bait
    Mathew Maniyara - February 03, 2010

Blog Tags

10.x 11.x 9.x and Earlier Brightmail Gateway Emerging Threats Endpoint Encryption Endpoint Protection (AntiVirus) Evolution of Security General Symantec How to IT Risk Management Internet Security Threat Report Malicious Code Mobile & Wireless Online Fraud Platforms & Hardware Restore Security Security Security Risks Spam Vulnerabilities & Exploits Windows
© 2010
  • Symantec Corporation
  • Contact Us
  • Get RSS
  • Newsletter
  • Privacy Policy
  • Symantec.com