The reason this site is not listed as suspicious (by Google) is it
doesn't try to load anything without your knowledge. Instead it uses
some sort of "social engineering" to make cluless people download and
install the spyware. Google's automatic scanners are not humans and
they can't be manipulated this way.

However people behind those sites does not only use passive social
engineering. To make people visit their "download sites" they hack
into legitimate web sites and add redirect rules for that site
visitors. The redirect first shows a warning that the visitor's
computer is infected and tells them they need and antivirus, and then
redirects to the "download" site like the one in this topic. To make
the redirect undetectable by site owners, they only redirect visitors
from search engines or the ones without the site cookies.

I checked one of such hacked sites recently with UnmaskParasites.com
and the report revealed a chain of three redirects (with the last
being a similar some-antivirus-2009 download site).

Just wonder, although such a site cannot be detected as an attack
site, maybe it qualifies for "phishing"?

Denis
http://UnmaskParasites.com
--~--~---------~--~----~------------~-------~--~----~
You received this message through the Google Groups "stopbadware" group.
To post to this group, send email to [email protected]
To unsubscribe from this group, send email to
[EMAIL PROTECTED]
For more options, visit this group at
http://groups.google.com/group/stopbadware?hl=en
-~----------~----~----~----~------~----~------~--~---

Reply via email to