Adhost Blog

Questions?

24/7/365 Support
1-888-323-4678

support@adhost.com

Spammers using Google to hotlink to phishing sites

Posted in Industry
 

The Internet Storm Center recently reported on how spammers are now using Google’s “I’m Feeling Lucky” feature to redirect phishing links, in an effort to mask their trails.

Systems administrators at Adhost actually reported the first uses of this technique nearly two months before ISC’s report, which was reported to them through their submission forms and also was passed around to other administrators.

This might be interesting – we’ve gotten spam that is using Google’s “I’m Getting Lucky” feature to essentially do a referral bounce using Google!

Here’s the link from the spam, a typical “mortgage refinancing” spam otherwise:

http://www.google.com/search?hl=en&q=earthmortgage123+As+
direct+lender+Earth+Mortgage+eliminated+high-commissioned+
Employment+Opportunities&btnI=gndo1

The key is the “&btnI=gndo1″ at the end – what this does is trigger the “I’m Getting Lucky” button from their front page, which automatically sends you to the first hit on the search. Therefore, if you go to that link, you go to Google, which does the search that only gets one hit – the spammer’s page – and then via I’m Getting Lucky, you unluckily get sent right to their site.

This is just one example of how Adhost systems administrators and engineers are constantly working to detect, diagnose and protect systems against several attack vectors online, from phishing attacks, to spam, to denial of service attacks, and more!

posted by Mike Sweetser 2:34 pm September 21, 2007
permalink | digg this | technorati
 
Articles   |   Site Map   |    Privacy Policy   |    Terms And Conditions    |    sales@adhost.com
Local Phone: (206) 404-9000 | Toll Free: (888) ADHOST-1 (234-6781)
Fisher Plaza, 140 4th Ave N Suite 360, Seattle, WA 98109
ADHOST © 1996-2008 | Seattle Colocation | About Adhost | Newsletter Sign-up | Blog