Bing ad serves malware to would-be Google Chrome switchers

Jack

Administrator
Thread author
Verified
Staff Member
Well-known
Jan 24, 2011
9,379
Earlier today I visited Bing and searched for google chrome. The results were accompanied by a handful of ads in prominent positions at the top and along the right side. Nothing unusual about that, except for two nearly identical ads that appeared side-by-side at the top of the list. Here’s what they looked like (I’ve obscured the URL names to make the test tougher).

00-side-by-side-ads.png


One of those ads was legitimate, and the other led to a malware attack. Can you tell which was which?

Here’s the landing page for the first ad:

00-landing-page-1.png


And here’s where clicking the second ad led:

00-landing-page-2.png


If you look closely enough, you can probably figure out that the first site is Google’s legitimate Chrome download page and the second one is fake, but the differences are subtle. A nontechnical observer would have a very difficult time figuring out that one of those big blue Download Google Chrome buttons is the real deal and one is fake.
Rea more
 

Ink

Administrator
Verified
Jan 8, 2011
22,489
If the same link/file, then Internet Explorer 9 will block the download.

http://www.zdnet.com/photos/how-browsers-and-security-software-can-keep-you-safer-online/6275070
 

jamescv7

Level 85
Verified
Honorary Member
Mar 15, 2011
13,070
Its a double file extension. So you can tell that it the first time its a legit file but it isn't.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top