Google Images: Malware lurks at every corner.

Status
Not open for further replies.

MrXidus

Super Moderator (Leave of absence)
Thread author
Apr 17, 2011
2,503
897
1,667
Australia
I use Google images quite alot in my day to day internet life, And quite recently I noticed many images when clicked on to see larger preview often ends up being a malicious page, Most of which are fake scanner pages. But recently I seen a new one that managed to bypass BitDefenders TrafficLight,

- TrafficLight alerted me of the page, appeared to have stopped it then the page loaded normally pass TrafficLight.

What's interesting to me about this scanner page is its not your usual Windows XP style page but a Windows 7 looking type. New to me atleast.

Check out my screen captures of it. (Coded because they're large images)

Code:
http://i.imgur.com/8sbVg.png
Code:
http://i.imgur.com/vZXoa.png

What are your thoughts on this? I only encounter these types of pages through Google images, never have I come across them within Google search or any other site, (Excluding MDL).

It's getting quite annoying encountering these types of pages on Google images, What are your suggestions for preventing them? Cheers.

EDIT: I am starting to count and since posting this thread I have come across 3 more scanner pages. I am going to try using ClearCloud DNS again and see how it goes.
EDIT 2: Using Trend Micro with ClearCloud gets rid of these for good.
 
My thoughts are generally malware writers do that especially like currents events and search through images, malware writers are just doing it just to trick people and infect.
 
  • Like
Reactions: tallorder
Well, I don't think you have a secure DNS in your config. Maybe add Clearcloud or Norton. It will help block these annoying things :)
 
  • Like
Reactions: tallorder
Something similar here (Malware using Social Engineering):
http://malwaretips.com/Thread-IE9-versus-Chrome-which-one-blocks-malware-better

Firefox 4 uses the same fake scanner as IE.
 
  • Like
Reactions: tallorder
Well I think you will see often having a block fake page that is same to the original Firefox.
 
Well having a DNS will surely protect you, I tried in google (but searches for link) it blocked the sites that are trying to redirect.
 
  • Like
Reactions: tallorder
Say what you will about WOT. It's a good way to catch these Fake scanners and other threats and annoyances early. Hence why I still use it.
 
Tomo172 said:
Say what you will about WOT. It's a good way to catch these Fake scanners and other threats and annoyances early. Hence why I still use it.

yep
:)
and let us to choose for site good or bad to open :D
 
I have noticed this issue as well lately. Linkscanner usually catches it, if not CIS gets it but it's still unnerving to see so many malicious links on something as popular as Google images.
 
I had a same result when I searched a Comodo logo...it came up with one of those fake scanner pages....there are a lot more that are starting to creep out.
 
  • Like
Reactions: tallorder
Honestly I've never encounter an image search that redirect from fake scanner page, only in google search for links does.
 
Good to hear!

They also have good customer service. So if you came across a false positive, they can have it fixed in as short as the next day :)
 
  • Like
Reactions: tallorder
I've managed to stumble upon a fake scanner while using Google Images... :)
The most impressive aspect is that this images manage to rank very high .... The one selected was #2 in the Google search query :) .
Most likely cyber criminals are using SEO tehniques to rank high in Google Images Search...and they did take a very smart decision.Usually site developers aren't very interested in Google Images so they won't make their images SEO Friendly..
Anyway this is the rogue that I've "manage" to find :

Rogue name : Win 7 Home Security 2011
Download name : AntiSpyWareSetup.exe
Site :
[attachment=362]
GUI :
[attachment=363]
Alert :
[attachment=364]
Fake Windows Control Panel :
[attachment=365]
Tray Icon :
[attachment=366]
 

Attachments

  • 1.png
    1.png
    161.9 KB · Views: 543
  • 2.png
    2.png
    173.3 KB · Views: 563
  • 3.png
    3.png
    99.8 KB · Views: 534
  • 5.png
    5.png
    99.6 KB · Views: 514
  • 6.png
    6.png
    20.4 KB · Views: 544
Google Web search can be used to locate dozens of results for compromised WordPress.org sites hosting html designed to poison Google Images search results.
 
Last edited:
  • Like
Reactions: tallorder
Status
Not open for further replies.

You may also like...