Well, Bing My Google!
Today we have a confluence of several mixed signals, amounting to a bit of confusion and a potential threat. Suppose you were searching Microsoft BingTM for a download of the popular browser, Google Chrome. You may get a screen like this:
![]() |
And that is just as you would expect it to look. Most people would click the very top link, which is, as it says right on the page, a paid advertisement. You would get redirected to a download page where you could get an immediate connection to download Chrome. This is where that link would take you.
![]() |
However, if you clicked the Download button, which is the big blue one in the upper right-hand corner, your Internet Explorer (IE) browser would interfere, telling you that this download is suspect of infection.
And if you would not pay attention to this, you’ll end up having an infected system. Trend Micro threat response engineer Kathleen Notario noted that once the file is downloaded, it is saved as chrome_11.0.696.68.exe (currently detected as TSPY_ONLINEG.MU) in your system. This spyware then drops cleanhtm.exe and cleanhtm.dll into the %Application Data% directory. These files have rootkit capabilities that enable them to hide processes and files. TSPY_ONLINEG.MU also modifies the HOSTS file by adding the following entries:
- {BLOCKED}.{BLOCKED}.118.187 www.google.com
- {BLOCKED}.{BLOCKED}.118.188 search.yahoo.com
- {BLOCKED}.{BLOCKED}.118.188 www.bing.com
This will eventually direct the user to the IP addresses owned by the perpetrators whenever the listed sites are accessed.
Funny that the ad server is not aware of threats the same as the browser. I am not pointing fingers here. Expect a lot of similar ruses in the near future though. The world of Internet threats has become complicated enough that gaps in the fence are a regularly occurring security story.
Irony Supplement
So who exactly would be using a browser from the largest OS company and its associated search engine to download a different browser from the largest search engine company that now makes an OS and a browser with the same name as competition to Big Redmond?
The Point
We live in a developing world. Get all the protection you can stand, especially on your browser. The big boys are not always looking out for you. (By the way, Trend Micro also blocks the site and identifies it as malicious and we have been in touch Microsoft’s Security Response Team about this incident.)
Post from: TrendLabs | Malware Blog – by Trend Micro
Spotlight
Cloud Computing
- Security in backups means more than just encryption
- Employees must buy into the company policy for better cloud security
- Desktop virtualization can enhance security performance
- Cybersecurity cooperation becoming military necessity
Virtualization
- Virtualization-specific challenges could threaten data security
- Evolving threats put security skills in high demand
- Virtualization security requires education, access control management
- Tips for launching effective virtual security tools
Internet Safety
- Virtualization-specific challenges could threaten data security
- Evolving threats put security skills in high demand
- Virtualization security requires education, access control management
- Tips for launching effective virtual security tools
Vulnerabilities & Exploits
CTO Insights
First Line of Defense
Newsletter
Stay up to date with the latest news and information on online threats.
Recent News
- FBI trying to train financial execs on cyber threats
- Wall Street has data security concerns over Bloomberg reporting
- Security in backups means more than just encryption
- Employees must buy into the company policy for better cloud security
Tag Cloud
cloud cloud computing cloud computing security Cloud Security Compliance & Regulations Consumerization Current News cybercrime Data Privacy data security Encryption Government Policy Internet Protection Internet Safety Internet Safety - DO NOT USE Internet Security Malware Mobile Security Mobility Policy Policy - DO NOT USE Privacy Privacy & Policy Private Cloud Public Cloud Reports Research Spotlight threat intelligence threat research Trend Labs Underground Economy virtualization Vulnerabilities Vulnerabilities - DO NOT USE web security web threats





Comments
No comments yet