Google
Worm creates an exact copy of Google
R E L A T E D   C O N T E N T
ADVERTISEMENT

Worm creates fake Google site

Spoofed webpage is identical, but displays alternative ads

Robert Jaques, vnunet.com 19 Sep 2005
ADVERTISEMENT

Security firm Panda Labs has detected a worm which attempts to spoof Google. P2Load.A spreads via P2P networks using the file-sharing programs Shareaza and Imesh.

The worm copies itself to the shared directory of these programs as an executable file called 'Knights of the Old Republic 2', referring to a computer game related to the Star Wars saga.

When P2Load.A is run, it displays an error message informing the user that a file does not exist and offers it for download. The download modifies the user's start page, showing advertising and spoofing the identity of Google.

To do this, the worm modifies the HOSTS file on the computer so that when users try to access Google, they are redirected to a page hosted on a server in Germany that looks exactly the same as Google, but is not controlled by the search giant.

The page is an exact copy of Google and redirects users even if they make a mistake when entering the address - such as 'wwwgoogle.com', 'www.gogle.com' or 'www.googel.com' - leaving users unaware of the change.

When users run a search, the results are shown correctly or with slight variations in the order in which they would be shown in Google. However, the sponsored links, which are usually shown at the top of the search results and correspond to companies that pay for this service, are different.

For certain searches, other links appear which have been specified by the creator of this malware, resulting in increased traffic to these websites.

"The creator of this worm has taken advantage of the importance of a company appearing among the first few links in the search results of an internet browser," said Luis Corrons, director of Panda Labs.

"Its aims are to increase visits to the pages linked by the creator of this malware, or to earn an income from companies that want to appear in the first few results in computer where the identity of Google has been spoofed.

"In both cases, the motivation of the author of this malware is purely financial."


All Hacking

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| Aston Carter
Java, J2EE, Developer, Spring, Hibernate, London, city, Graduate. This is an amazing opportunity to join a successful city based team working at the cutting edge of development. My client is looking for strong Java/J2EE developers ... more >
| Aston Carter
E-Commerce, Greenfield, Agile, Java, J2EE, , JavaScript, SQL, London, City Graduate This is an exceptional opportunity for a talented Java, J2EE developer keen to work in a successful development team within arguable the best agile ... more >
| Rullion Computer Personnel Ltd
2nd Line Support Analyst London £35, 000 to £40, 500 My client is a global market leader in the Internet Applications Industry. The company is continually progressing and looking for areas of growth and this ... more >
| Rullion Computer Personnel Ltd
Security Architect / Information Security Specialist – St Albans - Global Leader - Shine At The Highest Level Security Solution Architect / Information Security Architect required by renowned blue-chip organisation offering the finest security projects ... more >
More job opportunities