OpenX compromise on speedtest.net, spreading Security Sphere 2012 fake antivirus

Status
Not open for further replies.

Jack

Administrator
Thread author
Verified
Staff Member
Well-known
Jan 24, 2011
9,378
Armorize said:
SeedTest.net, ranked 541 on Alexa with 8,141,777 unique visitors and 10,177,221 page views per month, fell victim to malvertising and was spreading the "Security Sphere 2012" fake antivirus to its visitors. By simply navigating to the website, visitors with outdated browsing environments (browser or browser plugins such as Java, Adobe Flash, Adobe PDF Reader, etc) will end up with Security Sphere permanently installed inside their systems.

Read more


Malvertising via OpenX on speedtest.net, spreading Security Sphere 2012 fake antivirus
Uploaded by ArmorizeTech on Oct 9, 2011
 
Last edited:

McLovin

Level 78
Verified
Honorary Member
Malware Hunter
Apr 17, 2011
9,228
Wow, thanks for the information Jack. Glad I now know this so that I can beware when surfing SpeedTest. I also hope that they fix it in the upcoming days because if they don't, well there will be trouble.
 

enaph

Level 29
Verified
Honorary Member
Top Poster
Well-known
Jun 14, 2011
1,858
I think it is a small fire with a lot of smoke ;)
Look at the conditions of the infection - IE6 running on Windows XP without any security software + outdated plugins.
Any HIPS or BB should avoid infection in my opinion.
 

jamescv7

Level 85
Verified
Honorary Member
Mar 15, 2011
13,070
I feel no safe in Windows even I have security application up to date. As speedtest is one of the famous site visited to test the speed and might not notice that the malicious was running background.
 

Jack

Administrator
Thread author
Verified
Staff Member
Well-known
Jan 24, 2011
9,378
WinAndLinuxTutorials said:
They just dream :p
Rogue programs are very dangerous and this type of attack is very popular.
In this particular case , I can only say that our How to remove Security Sphere 2012 (Removal Guide) got 500 views so far (of course not related with this incident and of course we aren't the only site who is giving a removal guide for this rogue...so the number of users seeking info on this rogue is a lot higher...)
This is a very nasty rogue which comes bundled with a rootkit thus making it very hard to remove.
 

win7holic

New Member
Apr 20, 2011
2,079
i try this on my OLD laptop.
and , my connection dead in 3 mins. just load speedtest.net 70% ,then stopped.
i don't know why. probably block it?
:dodgy:
 

jamescv7

Level 85
Verified
Honorary Member
Mar 15, 2011
13,070
Also telling that your computer is infected with exaggerated result of the scan.
 

win7holic

New Member
Apr 20, 2011
2,079
Not found.
Scan with Hitman pro during computer start up. as you know my config.
not detected anything.
just wanna do it again later.
curious. :dodgy:
 

AyeAyeCaptain

Level 1
Feb 24, 2011
585
IE of all browsers though, assume with Firefox + ABP + No-script then this would not work? And with CIS Def + Paranoid then the HIPS would spew up all sorts of warnings if it managed to get that far.

Inspired me to have a dive into the unknown and use some Virtual Machine software to play about with stuff, what does everyone use, Virtual Box... VmWare or whatever?
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top