The SysAdmin Network

No more hiding in the server room

A weird malware site I came across that has me baffled

 First off a fair warning. The websites I'm going to mention below, as of this writing, WILL cause re-directs to various random malware sites if you perform the steps I'm going to mention below.

 If this happens, just immediately Task Manager and close your browser and nothing will happen to your pc.

 Maybe some of you more experienced SysAdmin sorts have seen this before and know how they did it but I haven't, so here goes.

 I had a User accidentally find a malicious website while searching for a specific neighborhood bar. The name of the bar is Bleachers Bar, so he typed that into Bing.

 The first link he got was www.bleachersbar.net and when he clicked the hyper-linked url from the search, it re-directed him to a fake anti-virus malware site.

 Here's where it gets weird. If you manually just type www.bleachersbar.net into your browser's address bar, it goes to their legitimate website. It's only the hyper-link from either a Bing or Google search that goes to malware sites. Now the next funny part. The same issue happens with their domain registrant.

 I did a Who Is on www.bleachersbar.net and got Technology Enrichment Group - Grashaw & Co as their registrant. If you Google Technology Enrichment Group - Grashaw & Co

you'll get www.grashaw.com and if you click the hyper-link search result, same thing happens. However, typing www.grashaw.com into the browser bar works fine.

As of this writing, this still happens. However, I've since contacted both of these sites to let them know of the issue so they might fix it before you get the chance to see it.
How the hell does this work? Manually go to site, fine, click hyper-link search result, malware. O_o ???

 

 

Views: 28

Reply to This

Replies to This Discussion

They do it by checking the referrer header sent by the browser which tells them the URL of the page where the link was from. It's usually done so that it's more difficult to detect that the web site has been hijacked, since people in the company usually don't go to their own site from search links.
Makes sense. I've emailed the bar a couple times because they're basically arguing with me about it.
They should be happy someone actually reported it. I also find it funny that the registrant's site is also poisoned. You'd think that they would know since they're a website company.

RSS

© 2012   Created by Elizabeth Ayer and Michael Francis.   Powered by

Badges  |  Report an Issue  |  Terms of Service