Google Typo Crashes Systems

edited April 2005 in Science & Tech
Spyware authors and phishing fraudsters yanked an old scam out of the playbook Wednesday by directing malicious code at Internet users who may be prone to typing or spelling deficiencies, according to security researchers.
Finnish security firm F-Secure said they discovered an attack aimed at Web surfers attempting to land on Google's (Quote, Chart) homepage, but who may have mistyped the Web address.

Internet users who punch in "Googkle.com" are treated to a host malicious code, as the computer gets slammed with a heap of the unwanted software that is automatically downloaded and installed. The malware includes: Trojan droppers, Trojan downloaders, backdoors, a proxy Trojan and a spying Trojan. A few adware-related files are also installed, the firm said.

"Our investigation revealed that the whole infection starts from the 'googkle.com' Web site. This Web site, as well as a few related Web sites are owned by people with Russian names. Also, several malicious files that are downloaded from these Web sites have Russian texts," F-Secure said in a statement.

When "googkle.com" opens in a browser, it shows two popup windows that are linked to several Web sites, F-Secure said. The first popup reveals a phishing-style Trojan that requests individuals' online banking information. The other deposits phony antivirus alerts on the desktop and attempts to pull victims into other infected sites.

The phony alert is created by changing an HTML file on the desktop that allows the user to click on the notice. It leads the victim to 'topantivirus.biz,' which in turn provides links to other Web sites, according to F-Secure.
Source: Internet News

Comments

  • SpywareShooterSpywareShooter 127.0.0.1
    edited April 2005
    Home Search Assistant has something to do with this. I traced googkle.com and got nothing that I recognized, but when I did a ping on topantivirus.biz I recognized the first 2 digits of the IP, 69.50, as being infamous HSA/CWS IPs. Plus the registrant "Mike Algernon" has come up in various whois searches.
  • NosferatuNosferatu Arizona
    edited April 2005
    Hmm, I went there with Firefox and nothing... not even a popup. I cringe when I think of IE users visiting that page. I love you Firefox :D
  • profdlpprofdlp The Holy City Of Westlake, Ohio
    edited April 2005
    KingFish wrote:
    ...directing malicious code at Internet users who may be prone to typing or spelling deficiencies...
    Lordy. That's nearly everybody on the whole Internet... :rolleyes:
  • SpywareShooterSpywareShooter 127.0.0.1
    edited April 2005
    It's definately HSA. I took a peek at the source code in FF (I haven't tried it in IE although it shouldn't do any harm) and it linked to a page at ntsearch.com, a site which all us spyware gurus should know as HSA. I visited the page at ntsearch and viewed the source code to find that it ran an exploit from ntsearch.com/popengine/POP.CHM::/saveandrun.htm
  • edited April 2005
    Can we nuke the company headquarters?
  • FreemymelodyFreemymelody On Earth
    edited April 2005
    I agree with you profdlp.
    I waish we can KinFish...lol...
  • SpywareShooterSpywareShooter 127.0.0.1
    edited April 2005
    googkle.com has been taken down :)
Sign In or Register to comment.