Malicious Banner Ads Target Expedia.com and Rhapsody.com

January 29th, 2008 by Bernadette Irinco (Technical Communications)

For a time, online advertisements have been a constant source of not only nuisance but of malware as well. Earlier this month, we’ve seen malicious banner ads being served on popular Web sites, such as Myspace, Excite, and Blick. This time, TrendLabs was alerted to malicious banner ads infiltrating legitimate special interest Web sites such as Expedia.com and Rhapsody.com.

According to Trend Micro security experts, certain malicious .SWF banners have hacked their way into Expedia.com, a popular site for travel enthusiasts worldwide. Trend Micro detects the said malicious flash banner as SWF_ADHIJACK.A. Based on initial analysis, clicking on this ad leads to several redirections, which eventually result to the installation of a rogue antispyware detected as TROJ_GIDA.A.

Music lovers are also targeted by mal-banners as Rhapsody.com, a music site owned by RealNetworks, is found to be carrying malicious flash banners as well. The malicious .SWF URL found in Rhapsody.com is said to be similar to the notorious Skyauction advertisements that were also found to infiltrate the Blick Web site mentioned earlier.

In any industry, advertising has proven to be an effective way to sell products. Apparently, this holds true in the malware industry as well. It provides another means for malware authors to effectively spread their malicious codes, and earn profits at the same time. With this knowledge, there’s no doubt that malware authors shall do more malvertising, targeting more and more popular Web sites to “advertise” their malware.

Be a smart buyer and don’t fall for false advertising. Not only might you not get your money’s worth, you might also end up spending more without you knowing it.

Print Posts
1 Star2 Stars3 Stars4 Stars5 Stars (3 votes, average: 4.67 out of 5)
Loading ... Loading ...

Trackback

TrackBack URL for this entry:
http://blog.trendmicro.com/malicious-banners-target-expediacom-and-rhapsodycom/trackback/

Listed below are links to weblogs that reference Malicious Banner Ads Target Expedia.com and Rhapsody.com:

  • ITinternals » Blog &hellip  |  Tracked on January 31st, 2008 at 8:28 am

    [...] Malicious Banner Ads Target Expedia.com and Rhapsody.com Rogue ads infiltrate Expedia and Rhapsody [...]

  • neobe’s Blog - Actu&hellip  |  Tracked on February 6th, 2008 at 12:41 pm

    [...] en Ukraine et en Russie ont également été touchés.   Ce sont des experts de chez Trend Micro qui ont donné l’alerte cela provient de publicités à base de shockwave.   Sur [...]


Subscribe in a reader

Most Recent Posts

Most Popular Posts

Links

Blogroll


Scan for free!