Thursday, December 03, 2009

Celebrity-Themed Scareware Campaign Abusing DocStoc and Scribd

UPDATED: DocStoc has removed all the participating profiles and their documents.

A currently ongoing scareware campaign is using celebrity-themed blackhat SEO tactics in order to hijack legitimate traffic by abusing the popular DocStoc and Scribd document-sharing services. What's the single most interesting thing about this campaign anyway? It's fact that one of the domains parked on the same IP that the rest of the malware and exploit serving ones are -- they naturally multitask and engage in drive-by attacks -- newsoff .net has been registered with the same email as the original gumblar .cn domain.

Once the user clicks on the bogus video window embedded as an active document, which as matter of fact doesn't issue any warning that the user is leaving the site, a redirection takes place through shurus .net/in.cgi?3 -> b.corlock .net/main.html - - Email: where the user is asked to download load.exe.

Parked on the same IP is the rest of the domains portfolio, which is also involved in separate drive-by campaigns:
offnews .cn - Email:
newsoff .net - Email: - Ooh la la, the original gumblar .cn has been registered with the same email
curah .net - Email:
corlock .net - Email:
klirok .net - Email:
murrr .net - Email:
shurus .net - Email:

Sample Scribd activity per username:
lupan13 - 1,148 documents; 3,301 total reads
jess357 - 877 documents; 15,202 total reads
mumukan - 875 documents; 19,791 total reads
cekalo - 874 documents; 2,926 total reads

Sample Docstoc activity per username:
valaman - Docs: 460; Views: 13224
zalupa - Docs: 407; Views: 14397
monilit - Docs: 871; Views: 5265
babaka - Docs: 252; Views: 183
namaska - Docs: 139; Views: 8
rumaska - Docs: 829; Views: 172
zuzya - Docs: 748; Views: 280
malina13 - Docs: 66; Views: 15377
yoqeojegu - Docs: 9; Views: 3284
ryjokoleqayebi - Docs: 10; Views: 326
jopan13 - Docs: 397; Views: 43876
iculyodysocehi - Docs: 10; Views: 3721
lupan13 - Docs: 414; Views: 29275

Upon execution it drops the Home AntiVirus 2010 scareware which features a "Spyware Alert!" security warning explaining the dangers of Worm.Win32.NetSky. The scareware (SetupAdvancedVirusRemover.exe) is downloaded from downloadavr13 .com - - Email: Parked on the same IP is a well known portfolio of scareware domains, first observed in July and most recently in September:

10-open-davinci .com
advanced-virusremover2009 .com - Email:
advancedvirus-remover2009 .com - Email:
advanced-virus-remover2009 .com - Email: - seen in July, 2009
advancedvirusremover-2009 .com - Email:
advanced-virusremover-2009 .com - Email:
advancedvirus-remover-2009 .com - Email:
advanced-virus-remover-2009 .com - Email:
advancedvirusremover-2010 .com - Email:
advanced-virus-remover-2010 .com - Email:
anti-virus-xp-pro2009 .com - Email:
best-scan .biz - Email:
best-scan .com - Email:
best-scan-pc .biz - Email:
best-scanpc .com - Email:
best-scan-pc .com
best-scanpc .net
best-scan-pc .net
coolcount1 .com - Email:
coolcount2 .com - Email:
downloadavr10 .com - Email:
downloadavr11 .com - Email:
downloadavr12 .com - Email:

downloadavr13 .com - Email:
downloadavr3 .com - Email:
downloadavr4 .com - Email:
downloadavr5 .com - Email:
downloadavr6 .com - Email:
downloadavr7 .com - Email:
downloadavr8 .com - Email:
downloadavr9 .com - Email:
hard-xxx-tube .com
malware-scan .net - Email:
malware-scaner .net - Email: .in - Email:
onlinescanxppro .com - Email:
pc-scanner .info - Email:
pc-scanner-2010 .net - Email:
pc-scannerr .biz - Email:
pc-scannerr .com - Email:
pc-scannerr .info - Email:
pc-scannerr .net - Email:
pc-scannerr .us - Email:
testavrdown .com - Email:
testavrdownnew .com - Email:
trucount3005 .com - Email: - money-mule recruitment connection
trucountme .com - Email: - already profiled
white-xxx-tube .com - Email:
xxx-white-tube .biz - Email:
xxx-white-tube .net - Email:

DocStoc and Scribd have been notified.

Related posts:
The Ultimate Guide to Scareware Protection
Scareware Campaign Using Google Sponsored Links
Massive Scareware Serving Blackhat SEO, the Koobface Gang Style
Dissecting the Ongoing U.S Federal Forms Themed Blackhat SEO Campaign
U.S Federal Forms Blackhat SEO Themed Scareware Campaign Expanding
Blackhat SEO Campaign Hijacks U.S Federal Form Keywords, Serves Scareware
A Peek Inside the Managed Blackhat SEO Ecosystem 
Dissecting a Swine Flu Black SEO Campaign
Massive Blackhat SEO Campaign Serving Scareware
From Ukrainian Blackhat SEO Gang With Love
From Ukrainian Blackhat SEO Gang With Love - Part Two
From Ukraine with Scareware Serving Tweets, Bogus LinkedIn/Scribd Accounts, and Blackhat SEO Farms
Fake Web Hosting Provider - Front-end to Scareware Blackhat SEO Campaign at Blogspot  

This post has been reproduced from Dancho Danchev's blog.