Fake Browser Update Site Installs Malware

In the first week of 2014, we came across a website using tried and tested social engineering techniques to coerce victims into installing malware. The domain http://newyear[REMOVED]fix.com, was registered on December 30, 2013. Based on our research, 94 percent of  attacks appear to be targeting users based in the United Kingdom through  advertising networks and free movie streaming and media sites.

The attackers attempt to trick victims using the following techniques:

  • A URL containing the words “new year” and “fix”
  • A professional looking template (from Google, Microsoft or Mozilla) telling the victim that a critical update is necessary for their system to function properly
  • Redirecting the user, based on their browser type, to a fake but convincing Chrome, Firefox, or Internet Explorer Web page.
  • Using a JavaScript loop to force the victim to give up and stay on site – users have to click on the “Yes/No” option 100 times in order to close the browser.

This particular social engineering attack is not novel, and plays on victims’ fear of needing to install urgent updates. Since the domain was registered only last week, it appears the attacker thought of this scheme at the very last minute, as the holiday season starts winding down.

The website, which is hosted in the Ukraine, uses a dual hybrid Web server setup by Apache and Nginx, with the latter identifying the victim’s browser and performing a redirect.

The user will see the Google Chrome, Mozilla Firefox, and Microsoft Internet Explorer templates, shown in Figures 1 to 3, based on the type of browser they are using.

Fake Browser Update 1.png

Figure 1. Page displayed to Chrome users

Fake Browser Update 2.png

Figure 2. Page displayed to Firefox users

Fake Browser Update 3.png

Figure 3. Page displayed to Internet Explorer users

Fake Browser Update 4.png

Figure 4. JavaScript loop button which requires 100 clicks to close

At the time of this blog post, the Internet Explorer version of the Web page is no longer functional. The Chrome download page serves up Chromeupdate.exe while the Firefox download page serves up Firefoxupdate.exe.

Both of these samples are detected by Symantec as Trojan.Shylock. Symantec also has the following IPS coverage in place for this attack:

Web Attack: Fake Software Update Website

To stay protected against this type of threat, Symantec recommends that users:

  • Keep antivirus definitions, operating systems, and software up-to-date.
  • Exercise caution when clicking on enticing links sent through emails, messaging services, or on social networks.
  • Only download files from trusted and legitimate sources.

Comparison of Adware in Windows and OS X: Linkular and Genieo

By definition, Adware is a program bundle which renders advertisements in order to generate revenue for its author. In a more strict sense, e.g. for security solutions, it means an application/installer whose nature lies somewhere between a potentially unwanted application and proper malware, like Trojans or Spyware. It might use more or less aggressive methods, […]

Mobile malware a real threat in 2014

      No Comments on Mobile malware a real threat in 2014

Security industry experts from around the world must have been looking in the same crystal ball to make their predictions for the new year, because everyone agreed that mobile exploits and malware would drive growth for the industry in 2014. Mobile attacks will include malicious software that steals data from legitimate apps, spyware, ransomware and […]

AVAST response to open letter from Bits of Freedom

Recently an open letter from Bits of Freedom, a group comprised of 24 digital rights organizations and academics, including the Electronic Frontier Foundation (EFF) in the US and Netzpolitik.org in Germany, was sent to security software vendors. AVAST did not receive the letter “officially,” although our company was listed among the vendors. The purpose of […]

AVAST (teddy) has conquered Brazil!

      No Comments on AVAST (teddy) has conquered Brazil!

Brazil is the only Portuguese speaking country in both South and Latin America. It is also fifth biggest country in the world, according to its geographical size and in terms of population. Brazilians represent a fascinating ethnic and cultural fusion, influenced by indigenous, European, African, and Asian cultures. With the upcoming World Cup in 2014 […]

Smartphones need protection in the Middle East and Africa

The mobile landscape in the Middle East and North African (MENA) regions are changing at a phenomenal speed. Nearly 526 million people in the region will have a mobile handset this year with only the Asia-Pacific region having more mobile users – both significantly more than in North America or Western Europe. Smartphones are the […]

avast! Free Antivirus is the most popular download of 2013

During the launch of avast! 2014 in October, CEO Vincent Steckler told a group of international journalists, “On all the download sites around the world, this year, through the end of September, we have 143 million downloads. That’s the most downloaded product – period.” After a few more months, the highest profile download site, CNET’s […]

AVAST to give away $26,000 in the new year!

New Year’s Resolutions 1. Protect my PC, smartphone, and tablet from viruses and theft 2. Recommend avast! Free Antivirus to friends 3. Win up to $10,000! Keeping  New Year’s resolutions like Lose weight or Quit smoking can be difficult on your own. But Protect my devices from viruses and theft is a resolution that avast! […]

2013: The year of avast! Antivirus in pictures

      No Comments on 2013: The year of avast! Antivirus in pictures

This year AVAST celebrated 25 years in business and reached an astounding 200 million users. We released our leanest, fastest antivirus protection ever, avast! 2014, and we protect over 50 million Android devices with antivirus and anti-theft protection. The team of experts at AVAST published 512 blog posts in 11 languages, posted 21,075 stories on […]