{"id":11405,"date":"2013-06-13T00:00:42","date_gmt":"2013-06-13T07:00:42","guid":{"rendered":"http:\/\/blog.webroot.com\/?p=11405"},"modified":"2018-01-30T12:36:45","modified_gmt":"2018-01-30T19:36:45","slug":"rogue-ads-lead-to-safemonitorapp-potentially-unwanted-application-pua","status":"publish","type":"post","link":"https://www.webroot.com/blog/2013\/06\/13\/rogue-ads-lead-to-safemonitorapp-potentially-unwanted-application-pua\/","title":{"rendered":"Rogue ads lead to SafeMonitorApp Potentially Unwanted Application (PUA)"},"content":{"rendered":"<p><strong>By Dancho\u00a0Danchev<\/strong><\/p>\n<p>Our sensors just picked up yet another rogue ad enticing users into installing the SafeMonitorApp, a <a href=\"http:\/\/blog.webroot.com\/tag\/pua\/\"><strong>potentially unwanted application (PUA)<\/strong><\/a> that socially engineers users into giving away their privacy through deceptive advertising of the rogue application&#8217;s &#8220;features&#8221;.<\/p>\n<p>More details:<\/p>\n<p><!--more--><\/p>\n<p><strong>Sample screenshot of the landing page, featuring a bogus &#8216;Norton Secured&#8217; Seal:<\/strong><\/p>\n<p style=\"text-align:center;\"><a href=\"http:\/\/webrootblog.files.wordpress.com\/2013\/06\/safemonitorapp_pua_01.png\"><img decoding=\"async\" loading=\"lazy\" class=\"aligncenter  wp-image-11407\" alt=\"SafeMonitorApp_PUA_01\" src=\"http:\/\/webrootblog.files.wordpress.com\/2013\/06\/safemonitorapp_pua_01.png\" width=\"424\" height=\"338\" \/><\/a><\/p>\n<p><strong>Sample screenshot of the installation process:<\/strong><\/p>\n<p style=\"text-align:center;\"><a href=\"http:\/\/webrootblog.files.wordpress.com\/2013\/06\/safemonitorapp_pua.png\"><img decoding=\"async\" loading=\"lazy\" class=\"aligncenter  wp-image-11409\" alt=\"SafeMonitorApp_PUA\" src=\"http:\/\/webrootblog.files.wordpress.com\/2013\/06\/safemonitorapp_pua.png\" width=\"299\" height=\"229\" \/><\/a><\/p>\n<p><strong>Rogue URL:<\/strong> <em>hxxp:\/\/www.safemonitorapp.com<\/em><\/p>\n<p>Detection rate for the Potentially Unwanted Application (PUA) &#8211; <a href=\"https:\/\/www.virustotal.com\/en\/file\/4de072c7ff47bb19675369fa1bfcb0127ad0be70a5ed823d7f98c187e3d078e6\/analysis\/\"><strong>MD5: eaa96a5208df256251e0b66616070e3a<\/strong><\/a>\u00a0&#8211; detected by 6 out of 47 antivirus scanners as a variant of Win32\/ExFriendAlert.B; SearchDonkey (fs).<\/p>\n<p><strong>Once executed, the sample drops the following MD5s on the affected hosts:<\/strong><br \/>\nMD5: ab73c0c2a23f913eabdc4cb24b75cbad<br \/>\nMD5: e563648ef955995fd109d4232d73201c<br \/>\nMD5: 389cbb8359d19d3753372ad1dea76618<br \/>\nMD5: e77df74a83b6e8c14b18f0681e4bdf46<br \/>\nMD5: edbb5cbaabcde52fa9822b5fe3f11f5a<br \/>\nMD5: f89a352a0cac2918b96df24a00a6b7ad<br \/>\nMD5: 93119058502398fefa04a2c2848c5716<br \/>\nMD5: d41d8cd98f00b204e9800998ecf8427e<br \/>\nMD5: 951c85a09dca9af7c52a8bcc17181fca<br \/>\nMD5: a783d28e15e07a38d9bbc1723ff93d1d<br \/>\nMD5: 0f904319c685830e08b793a94bcb29b3<br \/>\nMD5: c946d058e89e5dd47dd8812fe21a5a01<br \/>\nMD5: 00a0194c20ee912257df53bfe258ee4a<br \/>\nMD5: 68f5aeeaa307ca05233412ac3fb77643<br \/>\nMD5: 61fd777443084ed61c05c22e8e3c3eff<br \/>\nMD5: bf2c5f2b94cd7fd780572ed4d6d53ec6<br \/>\nMD5: 90d2959d0f5ab6bd68512fbfe1be05c4<br \/>\nMD5: 063cafc1ae75c1e6702d1fc671e7a941<br \/>\nMD5: 3a3a9223dd834d9898fdd8bf260bc373<br \/>\nMD5: 9e36cea59147bc7cd39ff85b91e9b925<br \/>\nMD5: 5c04a9320f466ba35407aba45d69be18<br \/>\nMD5: 2cfba79d485cf441c646dd40d82490fc<\/p>\n<p><strong>Phones back to s.safemonitorapp.com &#8211; 66.135.32.42, in particular, the following URLs:<\/strong><br \/>\n<em>hxxp:\/\/s.safemonitorapp.com\/InsertInstallNotice3.ashx?v=SFMN_P0_2.6.17&amp;p=590&amp;c=211&amp;m=start-myOnGuiInitStart&amp;g=&amp;i=p<\/em><br \/>\n<em>hxxp:\/\/s.safemonitorapp.com\/InsertInstallNotice3.ashx?v=SFMN_P0_2.6.17&amp;p=590&amp;c=230&amp;m=CopyFilesEnd&amp;g=db9bdab426e648d094d927b1e8e5a128&amp;i=p<\/em><\/p>\n<p><strong>The following domains are also known to have phoned back to the same IP (66.135.32.42) :<\/strong><br \/>\n<em>betterwebapps.org<\/em><br \/>\n<em>l.spyguardapp.com<\/em><br \/>\n<em>m.exfriendalert.com<\/em><br \/>\n<em>m.reboundalert.com<\/em><br \/>\n<em>m.spyalertapp.com<\/em><br \/>\n<em>m.spyguardapp.com<\/em><br \/>\n<em>m.tvgenieapp.com<\/em><br \/>\n<em>m.unfriendapp.com<\/em><br \/>\n<em>s.autoupdateserver.com<\/em><br \/>\n<em>s.betterwebapps.org<\/em><br \/>\n<em>s.exfriendalert.com<\/em><br \/>\n<em>s.infoseekerapp.com<\/em><br \/>\n<em>s.injekt.com<\/em><br \/>\n<em>s.provideodownloader.com<\/em><br \/>\n<em>s.reboundalert.com<\/em><br \/>\n<em>s.recordcheckerapp.com<\/em><br \/>\n<em>s.safemonitorapp.com<\/em><br \/>\n<em>s.searchdonkeyapp.com<\/em><br \/>\n<em>s.spyalertapp.com<\/em><br \/>\n<em>s.spyguardapp.com<\/em><br \/>\n<em>s.spyscoutapp.com<\/em><br \/>\n<em>s.tvgenieapp.com<\/em><br \/>\n<em>s.unfriendapp.com<\/em><br \/>\n<em>s.unfriendtool.com<\/em><br \/>\n<em>u.safemonitorapp.com<\/em><br \/>\n<em>u.tvgenieapp.com<\/em><br \/>\n<em>u.unfriendapp.com<\/em><br \/>\n<em>autoupdateserver.com<\/em><\/p>\n<p>What&#8217;s worth emphasizing on regarding the SafeMonitorApp in terms of preserving your privacy? Their EULA\/Privacy Policy speaks for itself:<\/p>\n<p><em>Safe Monitor is supported by advertising, which may include display, in-text and\/or interstitial ads. Users may see additional display ads on websites that the product runs on or adds functionality to. <strong>You will see approximately 1 display ad per page on content sites; however, at times as many as 5 display advertisements per page.<\/strong> On search engines there may be a search app, which may display 3 text ads beneath the application. In addition, topics or keyword phrases are automatically matched and products or services relevant to those topics or keyword phrases will appear on the webpage as a double underline. <strong>Safe Monitor may also contain interstitial advertising where full-screen webpages are displayed between the current and destination page for a restricted amount of time.<\/strong> When users access or use the Safe Monitor App, certain non-personally identifiable information is collected, stored and used for business and marketing purposes. <strong>This non-personally identifiable information includes, without limitation: IP address, unique identifier number, operating system, browser and other software information, webpage URLs visited, and search queries entered. This collected data may also be supplemented with information obtained from third parties.<\/strong><\/em><\/p>\n<p>We advise users to avoid interacting with the SafeMonitorApp.<\/p>\n<p><em>You can find more about Dancho\u00a0Danchev at his\u00a0<strong><a href=\"http:\/\/linkedin.com\/in\/danchodanchev\">LinkedIn Profile<\/a><\/strong>. You can also\u00a0<strong><a href=\"http:\/\/www.twitter.com\/danchodanchev\">follow him on Twitter<\/a><\/strong>.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>By Dancho\u00a0Danchev Our sensors just picked up yet another rogue ad enticing users into installing the SafeMonitorApp, a potentially unwanted application (PUA) that socially engineers users into giving away their privacy through deceptive advertising of the rogue application&#8217;s &#8220;features&#8221;. More details:<\/p>\n","protected":false},"author":65,"featured_media":17052,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[3005],"tags":[],"yst_prominent_words":[4209,14747,5735,14759,14757,14753,14755,14745,5251,11671,14739,14749,14761,5605,14751,14743,11681,14741,3529,3471],"acf":[],"_links":{"self":[{"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/posts\/11405"}],"collection":[{"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/users\/65"}],"replies":[{"embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/comments?post=11405"}],"version-history":[{"count":1,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/posts\/11405\/revisions"}],"predecessor-version":[{"id":23843,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/posts\/11405\/revisions\/23843"}],"wp:featuredmedia":[{"embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/media\/17052"}],"wp:attachment":[{"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/media?parent=11405"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/categories?post=11405"},{"taxonomy":"post_tag","embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/tags?post=11405"},{"taxonomy":"yst_prominent_words","embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/yst_prominent_words?post=11405"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}