Spyware, Viruses, & Security

Alert

Fake Browser Updates Drop Shylock Malware

by Carol~ Forum moderator / August 20, 2013 3:16 AM PDT

ThreatTrack Security Labs:

We're no stranger to fake and often malicious Internet browsers that are served up on equally fake and malicious Web sites. These latest samples found by Matthew, one of our threat researchers in the AV Labs, are hosted on the domain, browseratrisk(dot)com.

It is found that once users access pages on this malicious domain with either Internet Explorer (IE), Firefox or Chrome, it opens a fake "update" page for the said browsers and auto-downloads the fake files. Below are screenshots of these pages:

[Screenshot: Fake Firefox - Shylock Dropper]
[Screenshot: Fake Chrome - Shylock Dropper]
[Screenshot: Fake IE - Shylock Dropper]

Users may find it difficult to close and navigate to other tabs after download, thanks to certain loop commands on the page's code, which we've seen before.

If users choose to install the downloaded fake browser updates, it then drops a variant of either Sirefef or Shylock/Caphaw malware, which VIPRE will detect as Win32.Malware!Drop. As you may recall, Shylock had hit the news in January of this year as the banking Trojan capable of using Skype chat to spread. Note that the dropped file may change at roughly every three to four hours.

The website server is also known to house Blackhole Exploit kits. Below are just some of pages of the domain that contains the said exploit:

Continued : http://www.threattracksecurity.com/it-blog/fake-browser-updates-drop-shylock-malware/

Post a reply
Discussion is locked
You are posting a reply to: Fake Browser Updates Drop Shylock Malware
The posting of advertisements, profanity, or personal attacks is prohibited. Please refer to our CNET Forums policies for details. All submitted content is subject to our Terms of Use.
Track this discussion and email me when there are updates

If you're asking for technical help, please be sure to include all your system info, including operating system, model number, and any other specifics related to the problem. Also please exercise your best judgment when posting in the forums--revealing personal information such as your e-mail address, telephone number, and address is not recommended.

You are reporting the following post: Fake Browser Updates Drop Shylock Malware
This post has been flagged and will be reviewed by our staff. Thank you for helping us maintain CNET's great community.
Sorry, there was a problem flagging this post. Please try again now or at a later time.
If you believe this post is offensive or violates the CNET Forums' Usage policies, you can report it below (this will not automatically remove the post). Once reported, our moderators will be notified and the post will be reviewed.
Popular Forums
icon
Computer Help 47,885 discussions
icon
Computer Newbies 10,322 discussions
icon
iPhones, iPods, & iPads 3,188 discussions
icon
Security 30,333 discussions
icon
TVs & Home Theaters 20,177 discussions
icon
HDTV Picture Setting 1,932 discussions
icon
Phones 15,713 discussions
icon
Windows 7 6,210 discussions
icon
Networking & Wireless 14,510 discussions

Tech for the holiday

Find recipes for July 4 with these foodie apps

The Fourth of July means fireworks, fun and food. If you're planning on a barbecue this weekend, we've got the apps to help you find holiday-inspired recipes.