More rogue Flash ads
Rogue ads infiltrate Expedia and Rhapsody sites.
Following on from last month's feature on the SWF.AdHijack family (see VB, January 2008, p.12), malicious Flash ads were found to have made their way into popular travel site Expedia.com and music download site Rhapsody.com.

According to Trend Micro researchers, the Expedia site was infiltrated by a variant of the SWF.AdHijack family - clicking on the ad led to a number of redirections, which eventually resulted in the installation of a piece of rogue anti-spyware detected by Trend as TROJ_GIDA.A.
The malicious ad found on the Rhapsody site similarly redirected users to a page that attempted to install a bogus program on the user's machine by reporting a (non-existent) system infection, and then urging them to purchase the software needed to 'clean' the infections.
Investigators estimate that the ads were active on the Rhapsody site for six days before being removed. According to Expedia an 'imposter advertiser' managed to circumvent the company's advertising policy. At the time of writing the company didn't know how long the ad had been active.
01 February 2008
Tags:
flash ads, rogue ads, rogue anti-malware.
del.icio.us
digg this
ARF published as IETF standard
Abuse report format helps auto-handling of email complaints
02 September 2010
Microsoft releases new fix for DLL vulnerability
Earlier workaround believed to be too complex for most users.
01 September 2010
Malicious tweets link to fake TweetDeck update
Twitter resets passwords for accounts that appear to have been hacked.
01 September 2010
94% of Internet users befriend unknown 'good-looking woman'
Sensitiva data shared after two-hour chat. (1 comment)
31 August 2010
Investment boost for Quick Heal
Indian security firm gets hefty cash injection.
27 August 2010

Quick Links
![]() |
Poll
When do you install software updates?Leave a comment
View 12 comments

2 hours ago
6 hours ago
Jobs
In Virus Bulletin's jobs pages among others:- Malware Analyst (Ft. Belvoir, VA, United States)
- Virus analyst (Saint-Petersburg, Russian Federation)
Virus Bulletin currently has 208,224 registered users.



