HomeSecurityExpired domains: They can redirect you to malicious sites!

Expired domains: They can redirect you to malicious sites!

It has certainly happened to most users, if not all, to try to open a site and discover that this site no longer exists, but has been replaced by a landing page indicating that the domain has expired or is about to be renewed. In some cases, the resulting page simply contains links related to the expired site. In other cases, the page is hosted by an auction site that aims to sell the expired domain name. These landing or auction pages appear to contain links that direct users to legitimate sites. In reality, however, things are different, as expired domains hide many risks – one of them is the redirection of users to malicious sites.

In particular, a report released this week by Kaspersky points out that some of these seemingly “innocent” pages are very likely to be hiding malware. Examining an app for an online game, Kaspersky researchers found that the app tried to redirect them to an unsolicited URLthat had been put up for sale on an auction site. Instead of being taken to the correct stub website, the second-stage redirect took them to a blacklisted page.

expired domains

Kaspersky then discovered about 1,000 sites for sale from the same auction service. The second stage of redirection for these sites led users to more than 2,500 spam URLs. In addition, many of these URLs were created to download the Shlayer Trojan, a malware that attempts to install adware on Mac.

Tracking activity from March 2019 to February 2020, Kaspersky researchers found that 89% of these second-stage redirects took users to pages related to advertising, while 11% took them to malicious sites. In some cases, the pages contained malicious code. There were also cases where users were asked to install malware or download infected Microsoft Office and PDF.

The ultimate goal in such cases is profit. People are paid to direct users to specific pages, whether they are legitimate advertising pages or malicious ones. One of the malicious pages received an average of 600 redirects over ten days. With the pages attempting to install the Shlayer Trojan, the attackers were paid with each installation of the malware on a targeted device.

malicious sites

Kaspersky researchers believe that the cybercriminals behind this malware campaign are part of a well-organized and possibly managed network that can divert traffic to malicious sites. They could do this by using redirects from legitimate domain names and exploiting the resources of a well-known domain auction site.

Dmitry Kondratyev, junior malware analyst at Kaspersky, explained that there is not much users can do to avoid being redirected to a malicious page. He also said that there is no way to know if visitors are being redirected to pages that download malware, and it is difficult to manage expired domains. He also emphasized that malicious advertising programs are complex, which makes them difficult to detect and combat. Therefore, the best defense for users against expired domains and the ensuing consequences is to have a comprehensive security solution on their device, according to Kondratyev. While this type of attack can be difficult to mitigate and combat, users can take steps to prevent trojans from infecting their devices.

Kaspersky suggests users follow two basic steps:

  • Install programs and updates only from trusted sources.
  • Use a reliable security solution with anti- phishing that prevent redirects to suspicious pages.
📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS