Tuesday February 9, 2010 11:23 PM AEST
 
Latest Comments
"I too have been a labor voter for many years and will not be voting for them again. The ..."
by maxt | Feb 9, 2010 7:56 PM
 
"I’ve just had a user receive a rehashed version of this with an attached html file containing a ..."
by Owen Lutz | Feb 9, 2010 6:01 PM
 
"hi"
by manish kumar | Feb 9, 2010 4:27 PM
 
"Hey 'hey con-roy' ... from Google Australia's head of policy Iarla Flynn"We don't believe that ..."
by Keep it real | Feb 9, 2010 3:33 PM
 
"@penno Off-site storage is a good solution unless you have some decent backup software to ..."
by Charmgene | Feb 9, 2010 2:36 PM

Britney, Paris used as hook in new spam botnet

  • Email a Friend
  • Print Page
By Staff Writers
Feb 6, 2008 2:02 PM
Tags: new | spam | botnet | britney | spears | paris | hilton | internet | security
Emails embedded with fake Britney Spears and Paris Hilton Google search links are part of a new spam botnet that leads users to malware hosted by the notorious Russian Business Network (RBN).
Instead of embedding a typical URL link, security vendor BitDefender today said the e-mails use Google search result links such as 'www.google.com/pagead/iclk? sa=l&ai=trailhead&num=69803&adurl=http://.......com,' in an attempt to evade url-based spam filters.

The spam botnet directs users to a site offering explicit videos of celebrities including ‘New naked Britney video’ and ‘Paris Hilton New Video Auditioning Topless’ which hosts malware.

Once downloaded and executed, the malicious downloader, dubbed Trojan.Downloader.Exchange.A, downloads and executes more malware.

According to BitDefender’s Defence Center blog when users inspect the link, they will see a link to Google, however Google in turn redirects to the site specified as parameter in the URL.

“It seems that Google uses these types of URL's to redirect users who click on advertisement served up by Google's AdSense program, however insufficient parameter validation means that malware authors can modify the URL and use it to redirect users to arbitrary sites,” according to the blog.

According to BitDefender, the malware host, RBN has a reputation as a safe haven of spammers and malware authors worldwide.

"BitDefender has detected an increased overlap between spammers and malware authors, a veritable vicious circle where spam is used to spread malware which in turn spreads more spam,” said BitDefender Head of AntiVirus Research, Sorin Dudea. “Fighting one is fighting the other too."

Dubbed celebrity spam, over the past year many celebrities including Britney Spears and Paris Hilton's names have been used in the technique that aims to dupe users into clicking on malicious links.

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
 
Messaging Whitepapers