In January, I talked about high-profile websites, which had been hacked to redirect users to
fake online stores. One unique aspect of the hack was the fact that the attackers had set up additional web servers on non-standard ports. Most of the domains I listed in the post were cleaned up pretty quickly.
Three months later, there are still a number of hijacked sites redirecting to the same fake stores. One day recently, I found 68 hijacked domains, mostly college and government sites, including:
- Berkeley: cshe.berkeley.edu
- Harvard: research4.dfci.harvard.edu
- Purdue University: web.ics.purdue.edu
- Oklahoma State University: osu.okstate.edu
- Australian Government: brokenhill.ses.nsw.gov.au
 |
| List of hijacked websites redirecting to a fake store found in 1 day |
While some of the pages are still hosted on alternate web servers, like hxxp://nigelbeale.com:8080/download?online=329 now, most pages have actually been added to the hacked web server, on port 80.
The fake stores have not changed much. They all claim to provide discounted software from Microsoft, Adobe, Apple, etc., for download. Visually, they all look the same and we still see new domains used for the fake online stores.
 |
| Fake software store |
A Google search for “buy windows 7 pro”, for example, still shows primarily hijacked sites as the top of the results. It is very disappointing that Google has not cleaned up their search results after several months…and Bing doesn’t do a better job on this one either.
 |
| Google search for “buy windows 7 pro”. Most redirect to a fake store. |
Protect yourself with Zscaler Safe Shopping
The majority of the fake stores are still not flagged by blacklists used by popular browsers or by antivirus software. Firefox users can instead leverage the free Zscaler Safe Shopping add-on we released a couple of months back, in order to be warned when they visit a fake online store.
– Julien

Related Posts
- Fake Security Software Websites – Still popular in 2011
Fake security software is a form of computer malware that misleads users into installing and potentially paying for fake security software. The sites convince users to download the malicious software ... - High profile websites hijacked to lead to fake stores
Recently, a lot of high profile .EDU and .GOV were hijacked to redirect users to fake online stores. Google searches related to buying software ("buy windows 7 key", where to buy microsoft, "purchase ... - Heavy obfuscation used by Fake Antivirus websites
Just a few days back, I published a post discussing the popularity of fake antivirus websites in 2011. As I mentioned in the blog, attackers are continually creating new domains and websites promoting... - Zscaler Safe Shopping – Stay protected against compromised or fake stores online
We're happy to release yet another free Firefox plugin to protect consumers online.
Introducing Zscaler Safe Shopping
This product has been submitted to the official Mozilla Add-ons sites, but wil... - Blackhat spam SEO & Fake AV: they are still there
It's quite depressing to see that Google still contains numerous links to spam pages which lead to fake AV sites. While there are fewer of them, they are still there. This, despite the fact that attac... - Government, Military and Education websites hacked and up for sale
The new year 2011 has a few new surprises for us. And I think the biggest one so far is the discovery of an interesting hacking site offering services to hack government and military websites and sel... - Pro-WikiLeaks hackers attack Zimbabwe government websites
Hacktivists have struck a blow against the regime in Zimbabwe by attacking a number of government websites. The cyber-assault appears to have been in support of newspapers who published secret cables... - Doctor Who: Attack of the Fake Episode Websites
If you like Doctor Who, you’re probably rather excited at the prospect of the upcoming season finale. You’ve chewed over the spoilers for the penultimate episode and you really, really want to see wha... - Still more fake PornTube sites
On my weekly stroll thru various search engines for the term: ""PornTube: best movies collection." I usually find 15-20 new malicious sites, all using the same page layout. However I fo... - Fake Obama websites spreading malware
Similar to eCard spam mails, we are now seeing US president-elect Barack Obama themed mails which contain links to fake websites. These sites host a malicious executable and this malware belongs to th...
Posted on 14 April 2011. Tags: College, Fake, Government, Hundreds, Redirecting, still, Store's, Websites
The above information is reprinted from and copyrighted © by Zscaler.