{"id":3004,"date":"2010-07-09T15:07:09","date_gmt":"2010-07-09T22:07:09","guid":{"rendered":"http:\/\/blog.webroot.com\/?p=3004"},"modified":"2018-01-30T11:12:55","modified_gmt":"2018-01-30T18:12:55","slug":"blog-comment-spam-points-to-drive-by-site","status":"publish","type":"post","link":"https://www.webroot.com/blog/2010\/07\/09\/blog-comment-spam-points-to-drive-by-site\/","title":{"rendered":"Blog Comment Spam Points to Drive-By Site"},"content":{"rendered":"<p class=\"getsocial\" style=\"text-align: left;\"><img decoding=\"async\" style=\"border: 0; margin: 0; padding: 0;\" alt=\"\" src=\"http:\/\/getsocialserver.files.wordpress.com\/2009\/02\/gs2003.png\" \/><a title=\"Add to Facebook\" href=\"http:\/\/www.facebook.com\/sharer.php?u=http:\/\/blog.webroot.com\/2010\/07\/09\/blog-comment-spam-points-to-drive-by-site\" target=\"_blank\"><img decoding=\"async\" style=\"border: 0; margin: 0; padding: 0;\" alt=\"Add to Facebook\" src=\"http:\/\/getsocialserver.files.wordpress.com\/2009\/02\/gs2013.png\" \/><\/a><a title=\"Add to Digg\" href=\"http:\/\/digg.com\/submit?phase=2&amp;url=http%3A%2F%2Fblog.webroot.com%2F2010%2F07%2F09%2Fblog-comment-spam-points-to-drive-by-site&amp;title=Blog%20Comment%20Spam%20Points%20to%20Drive-By%20Site\" target=\"_blank\"><img decoding=\"async\" style=\"border: 0; margin: 0; padding: 0;\" alt=\"Add to Digg\" src=\"http:\/\/getsocialserver.files.wordpress.com\/2009\/02\/gs2023.png\" \/><\/a><a title=\"Add to Del.icio.us\" href=\"http:\/\/del.icio.us\/post?url=http%3A%2F%2Fblog.webroot.com%2F2010%2F07%2F09%2Fblog-comment-spam-points-to-drive-by-site&amp;title=Blog%20Comment%20Spam%20Points%20to%20Drive-By%20Site\" target=\"_blank\"><img decoding=\"async\" style=\"border: 0; margin: 0; padding: 0;\" alt=\"Add to Del.icio.us\" src=\"http:\/\/getsocialserver.files.wordpress.com\/2009\/02\/gs2033.png\" \/><\/a><a title=\"Add to Stumbleupon\" href=\"http:\/\/www.stumbleupon.com\/submit?url=http%3A%2F%2Fblog.webroot.com%2F2010%2F07%2F09%2Fblog-comment-spam-points-to-drive-by-site&amp;title=Blog%20Comment%20Spam%20Points%20to%20Drive-By%20Site\" target=\"_blank\"><img decoding=\"async\" style=\"border: 0; margin: 0; padding: 0;\" alt=\"Add to Stumbleupon\" src=\"http:\/\/getsocialserver.files.wordpress.com\/2009\/02\/gs2043.png\" \/><\/a><a title=\"Add to Reddit\" href=\"http:\/\/reddit.com\/submit?url=http%3A%2F%2Fblog.webroot.com%2F2010%2F07%2F09%2Fblog-comment-spam-points-to-drive-by-site&amp;title=Blog%20Comment%20Spam%20Points%20to%20Drive-By%20Site\" target=\"_blank\"><img decoding=\"async\" style=\"border: 0; margin: 0; padding: 0;\" alt=\"Add to Reddit\" src=\"http:\/\/getsocialserver.files.wordpress.com\/2009\/02\/gs2053.png\" \/><\/a><a title=\"Add to Blinklist\" href=\"http:\/\/www.blinklist.com\/index.php?Action=Blink\/addblink.php&amp;Description=&amp;Url=http%3A%2F%2Fblog.webroot.com%2F2010%2F07%2F09%2Fblog-comment-spam-points-to-drive-by-site&amp;Title=Blog%20Comment%20Spam%20Points%20to%20Drive-By%20Site\" target=\"_blank\"><img decoding=\"async\" style=\"border: 0; margin: 0; padding: 0;\" alt=\"Add to Blinklist\" src=\"http:\/\/getsocialserver.files.wordpress.com\/2009\/02\/gs2063.png\" \/><\/a><a title=\"Add to Twitter\" href=\"http:\/\/twitter.com\/home\/?status=Blog%20Comment%20Spam%20Points%20to%20Drive-By%20Site+%40+http%3A%2F%2Fblog.webroot.com%2F2010%2F07%2F09%2Fblog-comment-spam-points-to-drive-by-site\" target=\"_blank\"><img decoding=\"async\" style=\"border: 0; margin: 0; padding: 0;\" alt=\"Add to Twitter\" src=\"http:\/\/getsocialserver.files.wordpress.com\/2009\/02\/gs2073.png\" \/><\/a><a title=\"Add to Technorati\" href=\"http:\/\/www.technorati.com\/faves?add=http%3A%2F%2Fblog.webroot.com%2F2010%2F07%2F09%2Fblog-comment-spam-points-to-drive-by-site\" target=\"_blank\"><img decoding=\"async\" style=\"border: 0; margin: 0; padding: 0;\" alt=\"Add to Technorati\" src=\"http:\/\/getsocialserver.files.wordpress.com\/2009\/02\/gs2083.png\" \/><\/a><a title=\"Add to Furl\" href=\"http:\/\/www.furl.net\/storeIt.jsp?u=http%3A%2F%2Fblog.webroot.com%2F2010%2F07%2F09%2Fblog-comment-spam-points-to-drive-by-site&amp;t=Blog%20Comment%20Spam%20Points%20to%20Drive-By%20Site\" target=\"_blank\"><img decoding=\"async\" style=\"border: 0; margin: 0; padding: 0;\" alt=\"Add to Furl\" src=\"http:\/\/getsocialserver.files.wordpress.com\/2009\/02\/gs2093.png\" \/><\/a><a title=\"Add to Newsvine\" href=\"http:\/\/www.newsvine.com\/_wine\/save?u=http%3A%2F%2Fblog.webroot.com%2F2010%2F07%2F09%2Fblog-comment-spam-points-to-drive-by-site&amp;h=Blog%20Comment%20Spam%20Points%20to%20Drive-By%20Site\" target=\"_blank\"><img decoding=\"async\" style=\"border: 0; margin: 0; padding: 0;\" alt=\"Add to Newsvine\" src=\"http:\/\/getsocialserver.files.wordpress.com\/2009\/02\/gs2103.png\" \/><\/a><img decoding=\"async\" style=\"border: 0; margin: 0; padding: 0;\" alt=\"\" src=\"http:\/\/getsocialserver.files.wordpress.com\/2009\/02\/gs2113.png\" \/><\/p>\n<p><a href=\"http:\/\/webrootblog.files.wordpress.com\/2010\/07\/20100709_blogcom_commentobs.jpg\"><img decoding=\"async\" loading=\"lazy\" class=\"alignleft size-full wp-image-3007\" title=\"20100709_blogcom_commentobs_crop\" alt=\"\" src=\"http:\/\/webrootblog.files.wordpress.com\/2010\/07\/20100709_blogcom_commentobs_crop.jpg\" width=\"279\" height=\"118\" \/><\/a>I just want to take a moment to thank the malware author who posted a spam comment to the Webroot Threat Blog blog the other day. You guys make my job <em>so easy<\/em>.<\/p>\n<p>The spam comment, which reads <em>Hello. I the beginner. I wish to show to you,scandal story<\/em> and links to a drive-by download site, is a tremendous help to our researchers, who are always on the lookout for new threats.<\/p>\n<p>Of course, the malware distributor could have employed a more effective hook to convince someone to click a link than the one he used.<\/p>\n<p>The link claims to point to a page hosted on the free <strong>Blogspot <\/strong>blog site to a nude video &#8212; not of Paris Hilton, Venus Williams, or Erin Andrews &#8212; but of&#8230;<strong>Diane Sawyer<\/strong>, the respected, award-winning anchor of ABC&#8217;s World News Tonight.<\/p>\n<p>&#8220;<a href=\"http:\/\/webrootblog.files.wordpress.com\/2010\/07\/20100709_blogcom_dianesawyernude.jpg\" target=\"_blank\">Diane Sawyer Nude<\/a>&#8221; &#8212; seriously? News anchor porn? Whatever happened to malware authors touting nude photos of <em>starlets <\/em>as an enticement?<br \/>\n<!--more--><\/p>\n<p><a href=\"http:\/\/webrootblog.files.wordpress.com\/2010\/07\/20100709_blogcom_dianesawyervidlink.jpg\"><img decoding=\"async\" loading=\"lazy\" class=\"alignnone size-medium wp-image-3016\" title=\"20100709_blogcom_dianesawyervidlink\" alt=\"\" src=\"http:\/\/webrootblog.files.wordpress.com\/2010\/07\/20100709_blogcom_dianesawyervidlink.jpg?w=300\" width=\"300\" height=\"298\" \/><\/a><\/p>\n<p>The Blogspot page has a static image that looks like a streaming video player embedded in the page below a portrait of Sawyer, and the text <em>Watch Diane Sawyer Nude: Click HERE<\/em>. Click the &#8220;video&#8221; and you&#8217;re instead redirected to a Javascript file on the Web site <strong>adultsvid.cn<\/strong>, which redirected my computer to a page on another Web site, <strong>metds.org<\/strong>. The Javascript appears to redirect users to different pages &#8212; 38 total, all named after slightly younger stars of stage and screen &#8212; presumably, depending on the subject of the comment spam.<\/p>\n<p><a href=\"http:\/\/webrootblog.files.wordpress.com\/2010\/07\/20100709_blogcom_celebscript.jpg\"><img decoding=\"async\" loading=\"lazy\" class=\"alignnone size-full wp-image-3010\" title=\"20100709_blogcom_celebscript_crop\" alt=\"\" src=\"http:\/\/webrootblog.files.wordpress.com\/2010\/07\/20100709_blogcom_celebscript_crop.jpg\" width=\"612\" height=\"70\" \/><\/a><\/p>\n<p>In this script, Sawyer&#8217;s name gave way to those of somewhat younger actresses, including Mila Kunis, Elisha Cuthbert, Kristen Bell, Eliza Dushku, Summer Glau, Zooey Deschanel, Sarah Chalke, and Tina Fey, and 30 others. <em>There&#8217;s<\/em> the old, familiar social engineering we know and <span style=\"text-decoration: line-through;\">love<\/span> hate.<\/p>\n<p><a href=\"http:\/\/webrootblog.files.wordpress.com\/2010\/07\/20100709_blogcom_closeclub_large.jpg\"><img decoding=\"async\" loading=\"lazy\" class=\"alignnone size-full wp-image-3019\" title=\"20100709_blogcom_closeclubvideo\" alt=\"\" src=\"http:\/\/webrootblog.files.wordpress.com\/2010\/07\/20100709_blogcom_closeclubvideo.jpg\" width=\"213\" height=\"146\" \/><\/a><\/p>\n<p>You eventually land on a page for a Web site that calls itself <strong>Close Club Video<\/strong>, featuring another (entirely bogus) image that looks like another streaming video window.<\/p>\n<p>But it didn&#8217;t matter which celebrity strikes your fancy: Each of the redirections lead to the same destination, a page which tries to push a fake Flash codec download to visitors from the domain <strong>video-codec.co.tv<\/strong>. The download process begins after a slick, also-fake animation of an Adobe Flash Player update alert message slides down the screen.<\/p>\n<p><a href=\"http:\/\/webrootblog.files.wordpress.com\/2010\/07\/20100709_blogcom_fakeflash.jpg\"><img decoding=\"async\" loading=\"lazy\" class=\"alignnone size-full wp-image-3015\" title=\"20100709_blogcom_fakeflash_crop\" alt=\"\" src=\"http:\/\/webrootblog.files.wordpress.com\/2010\/07\/20100709_blogcom_fakeflash_crop.jpg\" width=\"494\" height=\"185\" \/><\/a><\/p>\n<p>Click anywhere on the page, and you end up triggering the download of the fake codec:<\/p>\n<p><a href=\"http:\/\/webrootblog.files.wordpress.com\/2010\/07\/20100709_blogcom_downloadlink.jpg\"><img decoding=\"async\" loading=\"lazy\" class=\"alignnone size-full wp-image-3011\" title=\"20100709_blogcom_downloadlink\" alt=\"\" src=\"http:\/\/webrootblog.files.wordpress.com\/2010\/07\/20100709_blogcom_downloadlink.jpg\" width=\"401\" height=\"291\" \/><\/a><\/p>\n<p>The fake codec Web page is actually pretty amusing to play with. Most of the content &#8212; an animated GIF of an Ajax &#8220;loading&#8221; spinner, the number of &#8220;views&#8221; of the video &#8212; is static and unchanging.<\/p>\n<p>But if you modify the query string in the URL, you can replace the text &#8220;Diane Sawyer sex tape&#8221; and get the page to display any text you like.<\/p>\n<p><a href=\"http:\/\/webrootblog.files.wordpress.com\/2010\/07\/20100709_blogcom_rockstupid_hilite.jpg\"><img decoding=\"async\" loading=\"lazy\" class=\"alignnone size-full wp-image-3012\" title=\"20100709_blogcom_rockstupid_crop\" alt=\"\" src=\"http:\/\/webrootblog.files.wordpress.com\/2010\/07\/20100709_blogcom_rockstupid_crop.jpg\" width=\"560\" height=\"175\" \/><\/a><\/p>\n<p>Unfortunately, the payload of the page is significantly less amusing.<\/p>\n<p>The <strong>flash_video.exe<\/strong> payload (in repeat performances, the site delivered a file named <strong>flash_video_update.exe<\/strong>) was actually an installer of a file we classify to <strong>Trojan-DermoDNS<\/strong>,<strong> <\/strong>a modified version of the <strong>Trojan-Downloader-Dermo<\/strong> that downloads, in addition to an installer for <strong>Adware-Sabotch<\/strong>, a payload which modifies the DNS settings of the infected computer so it resolves IP addresses through a server in Russia instead of your local ISP&#8212;potentially giving the operator of that Russian server a way to subtly manipulate what appears in the browser on an infected computer.<\/p>\n<p>Existing bulk-detection signatures are able to squelch the DermoDNS and Sabotch payloads, and all but one of the domains involved in the attack were already blocked in the desktop product&#8217;s Communications Shield at the time we discovered the scam. We&#8217;ve added the new domain to our latest definitions set.<\/p>\n<p>But the best way to avoid an infection is to be smart about what you download and run. Refrain from running random applications. If you need to update the Adobe Flash player, head to <a href=\"http:\/\/get.adobe.com\/flashplayer\/\" target=\"_blank\">the official Adobe download site<\/a> to download the latest version, and don&#8217;t trust an unknown Web site that claims to deliver Flash to your PC.<br \/>\n<a title=\"wordpress blog stats\" href=\"http:\/\/www.statcounter.com\/wordpress.com\/\" target=\"_blank\"><img decoding=\"async\" alt=\"wordpress blog stats\" src=\"http:\/\/c.statcounter.com\/4868061\/0\/92d716bc\/1\/\" \/><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>I just want to take a moment to thank the malware author who posted a spam comment to the Webroot Threat Blog blog the other day. You guys make my job so easy. The spam comment, which reads Hello. I the beginner. I wish to show to you,scandal story and links to a drive-by download [&hellip;]<\/p>\n","protected":false},"author":65,"featured_media":17052,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[3005],"tags":[],"yst_prominent_words":[4985,7179,7805,7803,4481,7423,7539,7187,7807,4525,18085,3919,23213,7813,4371,7809,7815,4071,4313,4621],"acf":[],"_links":{"self":[{"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/posts\/3004"}],"collection":[{"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/users\/65"}],"replies":[{"embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/comments?post=3004"}],"version-history":[{"count":2,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/posts\/3004\/revisions"}],"predecessor-version":[{"id":25847,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/posts\/3004\/revisions\/25847"}],"wp:featuredmedia":[{"embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/media\/17052"}],"wp:attachment":[{"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/media?parent=3004"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/categories?post=3004"},{"taxonomy":"post_tag","embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/tags?post=3004"},{"taxonomy":"yst_prominent_words","embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/yst_prominent_words?post=3004"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}