Author Topic: Malcreants to mask malware domains using TinyURL.....  (Read 2472 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Malcreants to mask malware domains using TinyURL.....
« on: January 30, 2009, 02:16:06 PM »
Hi malware fighters,

TinyURL masks malicious links
Again a popular webservice is being abused by malcreants.:
TinyURL directs to malicious websites to circumvent various security systems.
TinyURL service enables to change long URLs by shorters ones,
so they these links can be easier mailed.
TinyURL then automatically redirects to the right webpage.
It was only a matter of time before cybercrime started
to abuse these kind of webservices on a grand scale.

Cybercriminals know to easily circumvent Google Safe Browser security,
according to security firm Finjan:. http://www.finjan.com/MCRCblog.aspx?EntryId=2153
Safe browser has an  up-to-date database of malicious sites
that are then blocked automatically for users.
This plug-in that can be used inside Google Chrome and Firefox,
does not recognize the malicious sites because of the shorte UR.
The warning Safe Browser normally shows, is not shown.
The browser user is redirected immediately to the bad site.

Next to TinyURL there are various other similar services,
like Kurl, bit.ly and w3t.org.
bit.ly was also being abused by cyber criminals, as Finjan's survey showed.
In the mean time the malicious links have been deleted,
but the chance is there that usingurl-shorteners
is going to be a general malware pattern to hide their own malicious domains is obvious.

polonus.


Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!