<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Andreas Baumhof &#187; bitcoin</title>
	<atom:link href="http://www.tidos-group.com/blog/category/bitcoin/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.tidos-group.com/blog</link>
	<description>malware research, IT Security and life in general :-)</description>
	<lastBuildDate>Mon, 16 Nov 2020 18:25:55 +0000</lastBuildDate>
	<language>en-US</language>
		<sy:updatePeriod>hourly</sy:updatePeriod>
		<sy:updateFrequency>1</sy:updateFrequency>
	<generator>https://wordpress.org/?v=3.9.40</generator>
	<item>
		<title>Search Engine Poisoning (malicious ad)</title>
		<link>http://www.tidos-group.com/blog/2013/09/19/search-engine-poisoning-malicious-ad/</link>
		<comments>http://www.tidos-group.com/blog/2013/09/19/search-engine-poisoning-malicious-ad/#comments</comments>
		<pubDate>Thu, 19 Sep 2013 06:44:08 +0000</pubDate>
		<dc:creator><![CDATA[abaumhof]]></dc:creator>
				<category><![CDATA[bitcoin]]></category>
		<category><![CDATA[identity theft]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[phishing]]></category>

		<guid isPermaLink="false">http://www.tidos-group.com/blog/?p=487</guid>
		<description><![CDATA[A very valid question that comes up all the time is &#8220;how do people get infected with malware&#8221; or &#8220;how do people lost personal information?&#8221; and there are so many ways that people are blown away by some of the examples I show them. Today I came across one nice one again&#8230; Malicious Ad&#8217;s or [&#8230;]]]></description>
				<content:encoded><![CDATA[<p>A very valid question that comes up all the time is &#8220;how do people get infected with malware&#8221; or &#8220;how do people lost personal information?&#8221; and there are so many ways that people are blown away by some of the examples I show them.</p>
<p>Today I came across one nice one again&#8230; Malicious Ad&#8217;s or Search Engine Poisoning&#8230; I used coinbase for some bitcoin activities and I wanted to transfer some bitcoins. So I typed in &#8220;bitcoin&#8221; into google and this is what came up <a href="http://www.tidos-group.com/blog/wp-content/uploads/2013/09/coinbase1.png"><img class="aligncenter size-full wp-image-485" alt="coinbase1" src="http://www.tidos-group.com/blog/wp-content/uploads/2013/09/coinbase1.png" width="800" height="745" /></a></p>
<p>So far so good and everything looks great. I now just click on the first link as this is an ad where someone pays Google money and Google not being evil, must mean that this is good, right? wrong.</p>
<p>All visual signs suggest that this is legitimate and the URL goes to google.com, but that should be ok as well, right? A look at the source reveals that this goes to google before it goes to one URL shortener to another URL shortener and then to the final destination!)</p>
<p><a href="http://www.tidos-group.com/blog/wp-content/uploads/2013/09/coinbase5.png"><img class="aligncenter size-large wp-image-497" alt="coinbase5" src="http://www.tidos-group.com/blog/wp-content/uploads/2013/09/coinbase5-1024x545.png" width="625" height="332" /></a></p>
<p>&nbsp;</p>
<p>after the first URL shortener, we&#8217;ll see this!<a href="http://www.tidos-group.com/blog/wp-content/uploads/2013/09/coinbase2.png"><img class="aligncenter size-large wp-image-491" alt="coinbase2" src="http://www.tidos-group.com/blog/wp-content/uploads/2013/09/coinbase2-1024x404.png" width="625" height="246" /></a></p>
<p>oops&#8230;</p>
<p>Luckily it was already known that this site is up to no good, as this server did hold a number of &#8220;nice&#8221; phishing pages designed to steal your bitcoin wallet information. With the current price of over 120 USD for one bit coin, that could be a very lucrative business</p>
<p>Some examples are:</p>
<p><a href="http://www.tidos-group.com/blog/wp-content/uploads/2013/09/coinbase3.png"><img class="aligncenter size-large wp-image-492" alt="coinbase3" src="http://www.tidos-group.com/blog/wp-content/uploads/2013/09/coinbase3-1024x615.png" width="625" height="375" /></a> <a href="http://www.tidos-group.com/blog/wp-content/uploads/2013/09/coinbase4.png"><img class="aligncenter size-large wp-image-493" alt="coinbase4" src="http://www.tidos-group.com/blog/wp-content/uploads/2013/09/coinbase4-1024x615.png" width="625" height="375" /></a></p>
<p>&nbsp;</p>
<p>Approximately 1h after notifying google, the malicious ad was gone, but please make sure you double-check where you click on.</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.tidos-group.com/blog/2013/09/19/search-engine-poisoning-malicious-ad/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
