Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Subscribe
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Subscribe
    Home Applications
    • Applications
    • Cloud
    • Cybersecurity
    • Networking

    London Stock Exchange Site Served Up Malicious Ads, Fake AV

    Written by

    Fahmida Y. Rashid
    Published February 28, 2011
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      The London Stock Exchange can’t seem to catch a break. Less than 48 hours after a technical glitch stopped all trading, Google flagged the stock exchange’s Website for malware.

      Users trying to get to londonstockexchange.com via Google Chrome or Mozilla Firefox were shown a warning page on Feb. 27 that warned the site may contain malware. Chrome and Firefox both use Google’s malware blocklist to flag suspected sites.

      Merely viewing the stock exchange’s main homepage caused malware to be downloaded in a drive-by attack, Paul Mutton, an information security consultant based in Wiltshire, England, wrote on the High Severity security blog. He was alerted to the issue by some users on Twitter.

      Google’s Safe Browsing feature provides diagnostic information for the site’s malware history. “Of the 281 pages we tested on the site over the past 90 days, 65 page(s) resulted in malicious software being downloaded and installed without user consent,” the diagnostic page read on Feb. 27. The diagnostic page claimed to have found two scripting exploits, two Trojans and one exploit. A successful infection resulted in an average of five new processes on the compromised machine, according to the page.

      The problem turned out to be a malicious advertisement being served up by a third-party ad network, according to the stock exchange. The malicious advertisement has been removed and the exchange was working with Google to take down the warning message, LSE said.

      The London Stock Exchange site itself has not hosted any malware, nor has it been used to infect other sites, according to the diagnostic page. With “malvertising,” cyber-criminals can easily use a large number of legitimate Websites to download malware in the background without directly compromising the sites, but indirectly via a malicious ad on a third-party network.

      Malvertising have become a primary attack vector, according to Anup Ghosh, founder and chief scientist of Invincea.

      In this case, the ad was being served up by third-party provider Unanimis and Borsa Italiana, and the malware was actually hosted on stripli.com, a site that Google had already flagged as being suspicious, according to diagnostic page.

      Compromised users were hit by a fake antivirus program which appeared in the system tray and prevented other processes such as Task Manager from running, Mutton said. The malware also changed the wallpaper to a text background that warned in bright red letters, “Warning! Your’re in danger! Your computer is infected with spyware!”

      The malware affected only the site’s banner advertisements and did not compromise the rest of the stock exchange’s Website, according to Unanismis. “The affected advertisements have been removed and all sites continue to operate normally,” the company said. “For clarity the LSE Website was not impacted by this malware, not did it propagate malware,” according to the statement.

      A London Stock Exchange spokesperson told Mutton it was inaccurate to claim the stock exchange site was propagating malware since users had to click through to be infected, according to an earlier version of Mutton’s post.

      London Exchange Hit Repeatedly by Glitches

      Mutton disagreed because his computer was compromised just by accessing the page without clicking on anything. Furthermore, Mutton asserted it does not matter where the malware executable is actually hosted. “If their Website includes content from other sites, which is designed to propagate malware, then transitively, their site will also be propagating malware,” said Mutton.

      While the link for the main homepage does not appear to be flagged on the Google search results for the stock exchange as of Feb. 28, the link for AIM, the London Stock Exchange’s international market for smaller companies, still displays the “This site may harm your computer” warning.

      With the malvertisement removed, Google’s Safe Browsing page on Feb. 28 reported just one malicious page out of five tested.

      The stock exchange has had a number of technical problems recently. The exchange’s migration to the new SUSE Linux platform caused problems for brokers, and on Feb. 25, a technical glitch in how pricing is displayed caused all trading to be put on hold for hours.

      The LSE was not the only victim of this particular malvertisement, as it has affected seven other domains, including reviewcentre.com, a product reviews site for a variety of products and services including laptops, hotels and cars, and viamichelin.com, a travel planning site for the United Kingdom and Europe, according to the suspected malware’s Safe Browsing page provided by Google.

      Web security firm WebSense also said that other sites using Unanimis had been hit by the same malicious ad over the weekend, including movie site Myvue and auto trading site Autotrader. There were also reports that the UK-version of eBay was affected, according to WebSense. The Safe Browsing page for ebay.co.uk said six malicious pages had been found, but did not list Unanimis as the intermediary distributing the malware.

      In the case of AutoTrader, the site downloaded ads from its service providers while the user was browsing the site. When the malicious advertisement was loaded, the site redirected the user, and then again to the site that actually contained an exploit kit which targeted Internet Explorer, Adobe Acrobat Reader and Java, WebSense said. The dropped files installed the rogue antivirus and then demanded users pay $59.95 to remove the malware it had “found,” according to WebSense’s analysis of the kit.

      According to WebSense, the dropped files have a low rate of detection by antivirus software.

      Antivirus solutions continue to be “ineffective” addressing online threats, Ghosh told eWEEK. Whitelisting can’t prevent malware “sneaking in through third-party ads,” and users aren’t protected when they trust their native browsers, he said.

      Just keeping the antivirus definitions up-to-date is clearly not enough, as Mutton had just updated his security settings that morning before going to the stock exchange site.

      “The strongest way to address this threat, and the only known solution to this problem, is to seamlessly isolate the browser from the host operating system in a clean, fully virtualized environment,” Ghosh said, referring to Invincea’s browser product that runs in a virtual machine.

      Fahmida Y. Rashid
      Fahmida Y. Rashid

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.