<<<
NEWS FROM THE LAB - Monday, October 12, 2009
>>>
 

 
Gately Death Goes to Rogue AV Posted by WebSecurity @ 03:09 GMT

Stephen Gately (of Irish boyband Boyzone fame) passed away on October 10th 2009.

So here's what searching for news of his passing turned up:

Stephen Gately, rogue results

On checking the who.is for the website, we noticed this little detail: "Creation Date: 2009-10-09". Hmm.

Anyway, the site redirects visitors to a site that tells you:
Stephen Gately, rogue results
It doesn't matter if the user clicks on "OK" or "Cancel"; the site still goes on to display the following image, which mimics a computer scan:

Stephen Gately, rogue results

And the grand finale, a prompt to install something:

Stephen Gately, rogue results

Rogue AV strikes again. This particular malware site shares an IP address with other known malware sites such as forexbids.cn, norah-jones.cn, watermelonfun.cn, my-pc-scanner7.com and anamericanbeauty.com.

Some of these sites might already be down, but all the same, probably not wise to visit them. These websites are blocked by our Browsing Protection.

—————

Updated to add: A related SEO attack which leads to the same website originates from:

Stephen Gately, rogue results

Stephen Gately, rogue results

The redirect path this attack takes is as follows:

Stephen Gately, rogue results


WebSecurity post by — Choon Hong & Chu Kian