{"id":1193967,"date":"2023-10-19T00:50:35","date_gmt":"2023-10-19T04:50:35","guid":{"rendered":"https:\/\/www.prime-wow.com\/?p=1193967"},"modified":"2023-10-19T00:50:35","modified_gmt":"2023-10-19T04:50:35","slug":"google-hosted-malvertising-leads-to-fake-keepass-site-that-looks-genuine","status":"publish","type":"post","link":"https:\/\/www.prime-wow.com\/?p=1193967","title":{"rendered":"Google-hosted malvertising leads to fake Keepass site that looks genuine"},"content":{"rendered":"<div id=\"rss-wrap\">\n<figure class=\"intro-image intro-left\">\n  <img decoding=\"async\" src=\"https:\/\/www.prime-wow.com\/wp-content\/uploads\/2023\/10\/warning-800x534-1.jpg\" alt=\"Warning sign\" \/><\/p>\n<p class=\"caption\" style=\"font-size:0.8em\"><a href=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2023\/08\/warning.jpg\" class=\"enlarge-link\" data-height=\"1494\" data-width=\"2240\">Enlarge<\/a> (credit: Miragec\/Getty Images)<\/p>\n<\/figure>\n<div><a name=\"page-1\" \/><\/div>\n<p>Google has been caught hosting a malicious ad so convincing that there\u2019s a decent chance it has managed to trick some of the more security-savvy users who encountered it.<\/p>\n<div class=\"image shortcode-img center large\"><a href=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2023\/10\/malicious-keepass-ad-google.png\"><img decoding=\"async\" alt=\"Screenshot of the malicious ad hosted on Google.\" src=\"https:\/\/www.prime-wow.com\/wp-content\/uploads\/2023\/10\/malicious-keepass-ad-google-640x477-1.png\" \/><\/a><\/p>\n<p class=\"caption\" style=\"font-size:0.8em\"><a href=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2023\/10\/malicious-keepass-ad-google.png\" class=\"caption-link\" rel=\"nofollow\">Screenshot of the malicious ad hosted on Google.<\/a> (credit: Malwarebytes)<\/p>\n<\/div>\n<p>Looking at the ad, which masquerades as a pitch for the open-source password manager Keepass, there\u2019s no way to know that it\u2019s fake. It\u2019s on Google, after all, which claims to vet the ads it carries. Making the ruse all the more convincing, clicking on it leads to \u0137eepass[.]info, which when viewed in an address bar appears to be the <a href=\"https:\/\/keepass.info\/\">genuine Keepass site<\/a>.<\/p>\n<div class=\"image shortcode-img center large\"><a href=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2023\/10\/fake-keepass-website.png\"><img decoding=\"async\" alt=\"Screenshot showing keepass.info in the URL and Keepass logo.\" src=\"https:\/\/www.prime-wow.com\/wp-content\/uploads\/2023\/10\/fake-keepass-website-640x393-1.png\" \/><\/a><\/p>\n<p class=\"caption\" style=\"font-size:0.8em\"><a href=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2023\/10\/fake-keepass-website.png\" class=\"caption-link\" rel=\"nofollow\">Screenshot showing keepass.info in the URL and Keepass logo.<\/a> (credit: Malwarebytes)<\/p>\n<\/div>\n<p>A closer link at the link, however, shows that the site is <em>not<\/em> the genuine one. In fact, \u0137eepass[.]info \u2014at least when it appears in the address bar\u2014is just an encoded way of denoting xn--eepass-vbb[.]info, which it turns out, is pushing a malware family tracked as FakeBat. Combining the ad on Google with a website with an almost identical URL creates a near perfect storm of deception. <\/p>\n<\/div>\n<p><a href=\"https:\/\/arstechnica.com\/?p=1977141#p3\">Read 6 remaining paragraphs<\/a> | <a href=\"https:\/\/arstechnica.com\/?p=1977141&amp;comments=1\">Comments<\/a><\/p>\n<p>&#013;<br \/>\n&#013;<br \/>\nSource: Ars Technica &#8211; <a href=\"https:\/\/arstechnica.com\/?p=1977141\" target=\"_blank\" rel=\"noopener\">Google-hosted malvertising leads to fake Keepass site that looks genuine<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Enlarge (credit: Miragec\/Getty Images) Google has been caught hosting a malicious ad so convincing that there\u2019s a decent chance it has managed to trick some of the more security-savvy users who encountered it. Screenshot of the malicious ad hosted on &hellip; <a href=\"https:\/\/www.prime-wow.com\/?p=1193967\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":1193968,"comment_status":"open","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"ngg_post_thumbnail":0,"footnotes":""},"categories":[27,110],"tags":[73],"class_list":["post-1193967","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ars-technica","category-unfiltered-rss","tag-ars-technica"],"_links":{"self":[{"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/posts\/1193967","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1193967"}],"version-history":[{"count":0,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/posts\/1193967\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/media\/1193968"}],"wp:attachment":[{"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1193967"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1193967"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1193967"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}