The ongoing 2012 UEFA European Championship is the latest sporting event used by cybercriminals to lure users into their malicious schemes. So far, we have uncovered a malicious site with a domain name that copies the official UEFA Euro 2012 site and web pages leading to survey scam pages and ad tracking sites.
Malicious Domain Hosts Multiple Threats
While conducting proactive research, we spotted the site {BLOCKED}uro2012.com, which tried to mimic the official site http://www.uefa.com/uefaeuro/. Upon our investigation, this site actually hosts several malware, once of which is the FAKEAV variant TROJ_FAKEAV.HUU. Once executed in the system, this malware displays a supposed scan result of the infected system. This may prompt users to purchase the bogus antivirus program and activate the said product.

The FAKEAV “activation page” is actually a phishing page designed to trick users into giving out sensitive information. TROJ_FAKEAV.HUU was also found to disable web browsers (Internet Explorer, Mozilla Firefox, and Google Chrome).

Blackhat SEO Continues Its Streak
Cybercriminals also used the fight between Portugal and Czech Republic last June 21 as its social engineering ploy for Blackhat Search Engine Optimization (BHSEO).



UEFA 2012 Web Extension, Facebook Clicjacking
We also encountered a bogus Google Chrome extension hosted on Chrome Web Store. Based on our analysis, once users add the said extension to the browser and is launched, it redirects to the malicious site http://www.{BLOCKED}linetv.biz/livesports.php that also leads to affiliate/ad tracking sites.


Rik Ferguson also spotted spammed messages that use Euro 2012 team scores, as seen below:

Trend Micro Protects Users From These Threats
Trend Micro users are already protected from these threats via Smart Protection NetworkT, which blocks these malicious URLs and detects the related malware, as well as blocking the spammed messages. Using sporting events such as the UEFA Euro 2012 as bait to malicious sites is a popular social engineering technique, thus users should visit and bookmark reliable websites for their latest UEFA fix. To know more about web threats that target sports fans, you may read our FAQ entry Sports as Bait: Cybercriminals Play to Win.
Leave a reply