Users fall for web ad virus stunt

'Get your PC infected here' gets 400 hits

Written by Ian Williams

Belgian IT security professional Didier Stevens has conducted an interesting social experiment after purchasing the domain name drive-by-download.info

Stevens created an advertisement on Google AdWords offering users the chance to infect their PC with malware simply by clicking on a link.

The ad stated: 'Is your PC virus-free? Get it infected here!'. The ad was displayed 259,723 times and 409 people clicked on the link.

The site contains no malware, but security experts warned that similar methods are used by hackers to get users to visit sites containing viruses and malware that infect the user's machine.

Stevens ran the ad for six months for around $23, which means that it cost only six cents per click or per potentially compromised machine.

"I designed my ad to make it suspect, but even then it was accepted by Google without problem and I got no complaints to date, and many users clicked on it," Stevens wrote on his blog.

"Now you may think that they were all stupid Windows users, but there is no way to know what motivated them to click on my ad. I did not submit them to an IQ test."

Lenny Zeltser, a security consultant at Gemini Systems, said: "Perhaps there is no need for attackers to create advanced redirection chains or elaborate deception schemes. As Stevens's experiment confirmed, people will click on anything." 

Google has since disapproved and removed the ad, stating that it violates AdWords editorial guidelines.

Tags:

Further reading

Malware spreading via Skype

Beware URLs bearing gifts   More...

Security firm publishes video of Google AdWords scam

Evidence posted on YouTube   More...

Cyber-crooks subvert Google AdWords

Experts unveil 'hard evidence' of fraud   More...

Related articles

vnunet.com analysis: Browser wars changing security game

Variety and competition bring new protections and new threats   More...

Hackers step up search results attack

Big-name sites compromised in IFrame redirect scam   More...

Cyber-criminals move with the times

Adware giving way to more serious threats   More...

Hackers set up stolen FTP account trading floor

Database discovered containing more than 8,700 harvested FTP account details   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

25 Jul 2008

7.85 MBPodcast Special: Views from the Valley More...

24 Jul 2008

3.68 MBSpammer jailed, Esquire e-cover, and network passwords More...

23 Jul 2008

2.99 MBSmall time security, official 'spying' requests and a spammer jail break More...

Poll

EUROPEAN E-COMMERCE

EUROPEAN E-COMMERCE

Are you happy making an online purchase from another European country?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

Credit card transaction

Credit card fraud rampant in the UK

Attempted frauds go unreported and ignored, analysts claim   More...

Intel

Intel rolls out new embedded line-up

System-on-a-chip offerings promise footprint and power saving   More...

Advertisement

Network cables

Tech giants collaborate on wireless HD

Another attempt at cable-free transmission in the home   More...

iPhone fever fills AT&T coffers

US provider cashes in on Apple smartphone   More...

Advertisement