A forum for reverse engineering, OS internals and malware analysis 

Ask your beginner questions here.
 #4751  by crazypctech2010
 Wed Jan 26, 2011 8:21 pm
I have come across a fake AV warning and browser redirect when going to Google.com and searhing for images using the following search query "Southern region US maps with states & capitals"

The first results shown from the following domains below all cause the browser to redirect to multiple fake AV sites. Scanning with malwarebytes shows nothing so it looks like it is just a fake AV website trying to trick you into clicking yes and downloading something however how do I find out where the browser direct is coming from ?

If I go to the domains directly they do not redirect to the malicious sites
If I view the source for the page that comes up just before it reditects I see nothing in the source code identifying how it is forwarding. Can someone help me find how by clicking on these domains image results in google I am getting a fake AV webpage redirect ?

here are the domains that appear in the image search results

thegreatwillow.com
americantallship.org
acelcoservices.com
robertomerlo.com
 #4770  by crazypctech2010
 Thu Jan 27, 2011 7:39 pm
Tried that, it found nothing. Only does it on certain image results which leads me to believe its something either embedded in the image, someone is exploiting the google images search or its embedded in the website somehow...

All of the systems I tested came up clean with Malwarebytes, TDSS etc.
 #4795  by crazypctech2010
 Fri Jan 28, 2011 4:14 pm
it looks like some kind of conditional forwarding is happening with the domain

If look at the image it says thegreatwillow.com is the website. however the actual url is pattersongeorgia.com for the image ... If you type the http://pattersongeorgia.com into the browser you end up back at google.com

if you do a ping on pattersongeorgia.com you end up with this as an IP address 64.202.189.170
If you put that IP address into your browser you then end up at site which tells you "this website is temporarily unavailable, please try again later.

a lookup on the ip address results in pwfwd-v01.prod.mesa1.secureserver.net

A lookup on the domain pattersongeorgia.com results in pointing back to godaddy.com as the registrar

The Image URL I was able to grab is
http://www.google.com/imgres?imgurl=htt ... 22,r:0,s:0