Fake video codecs replacing fake AV pages still threatening

Status
Not open for further replies.

Prorootect

Level 69
Thread author
Verified
Nov 5, 2011
5,855
.
Fake video codecs replacing fake AV pages still threatening topic here ..

The best description of this metamorphosis is on the Zscaler blog:

*Fake video codecs replacing fake AV pages: http://research.zscaler.com/2010/06/fake-video-codecs-replacing-fake-av.html

.. then ..

* Fake video codecs still going strong: http://research.zscaler.com/2011/12/fake-video-codecs-still-going-strong.html

Quotes:
'We've recently seen fake AV pages being replaced by fake video pages - malicious pages showing a Flash based video player, along with an error telling the user that he has to download a new codec to play the video. This is certainly not a new technique used by attackers, but it is interesting to see that these attacks are showing up on the same pages that were previously used to deliver a fake antivirus attacks.'
.. and on the last read:
' I recently encountered an interesting example employing both fake AV and fake codecs in a single attack. When a victim visits a page, they are presented with a warning message stating “You don’t have the correct Codec installed. Download should start automatically, if not, please click here to download”.

Aaa .. beware, beware! Download starts automatically! But I have enabled my IE tweak (NO downloads; look on this topic on VOP site: EASY Anti-Malware Protection by Stop Downloads IE Anti-Executable: http://forums.voiceofthepublic.com/smf2/index.php/topic,82.0.html ), then it's OK here. Here.;)

And test this malware link, if you wish - look on 'Free Online On-demand URL Security Scanners' topic here: http://malwaretips.com/Thread-Free-Online-On-demand-URL-Security-Scanners

Thank you both, Julien Sobrier & Pradeep Kulkarni.
.
 

Prorootect

Level 69
Thread author
Verified
Nov 5, 2011
5,855
THE ZLOB SHOW: TROJAN POSES AS FAKE VIDEO CODEC, LOADS MORE THREATS: on TrendMicro.com:
http://about-threats.trendmicro.com/ArchiveVulnerability.aspx?language=us&name=THE%20ZLOB%20SHOW:%20TROJAN%20POSES%20AS%20FAKE%20VIDEO%20CODEC,%20LOADS%20MORE%20THREATS

Quote:
'Once unsuspecting users click on the link, they are indeed redirected to a site that contains a video file. However, this video does not seem to be working because it needs a special codec in order to play properly. Thus, these users are then prompted to download and install the "codec", which is actually a copy of the Trojan.'

This scenario is repeated for a long time ..:dodgy:
.
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top