Affiliate web-based malware

Paul Baccas Sophos

For the past year researchers at SophosLabs have been tracking malicious websites with our technology partners and via product-based reporting.

Most web attacks are fairly simple and straightforward in nature, though the components of the attack are arbitrarily complex. However, some attacks are more complex in nature and include the passing of information to 'grey' sites before installing malware. These complex attacks are very reminiscent of the links we would see were we to analyse a revenue-generating/advertising/pop-up network. These affiliate-based links look to all intents and purposes like a 'legitimate' network with the added bonus of delivering malware.

This paper will attempt to show some simple attacks with a more detailed analysis of some affiliate malware delivery systems.

 del.icio.us  digg this! digg this

Quick Links

Poll
The Japanese government is reported to have commissioned a 'defensive virus'. Is 'defensive' malware ever a good idea?
Yes
No
I don't know
Leave a comment
View 10 comments

99 Subscription Promo

Malware Prevalence
Autorun |#######|
Encrypted/Obfuscated |#####|
Heuristic/generic |#####|
Sality |####|
Zbot |####|
 View this month's full report

Virus Bulletin currently has 224,162 registered users.