Is Canon India Website is Malicious ?

There is an interesting case that I want to share with you.

I am not sure if you guys are aware of it but last year researchers at Google released a paper at the Usenix conference titled “The Ghost in the Browser”.

The paper outlined research efforts at Google that spanned several months analyzing websites, their content, and the amount of malicious code discovered within the sites.

It was discovered that the URLs that Google generate as search results, a big number of those are malicious and it might harm the user’s computer. To keep its users away from such malicious URLs, Google start flagging these websites, by posting a warning sign; this site may harm your computer.

There is a big probability that if you are using Google search engine, you might have came across such scenario. There is a similar scenario that I came across and I would like to share it with you.

I read this on Suman kumar’s blog that Google has flagged Canon India website canon.co.in as potential malicious; Canon India’s Website is an Attack Site?

Google Search Result

I did a search for canon.co.in using Google, found out that it has been flagged as harmful and there is a warning against visiting it.

Google Search Results for for canon.co.in

I ignore this warning, and click on the URL; it took me to another page explaining clearly that this site harmful and you can access it at your own risk but there is no way Google will let you in.

canon.co.in is a harmful website

This could be real dangerous situation for those legitimate websites, doing business on-line. I don’t think there are many people willing to visit these websites by ignoring Google warning. Now let’s have a look at the solutions offered by various web application security companies for such situations.

Finjan

I have Finjan installed in my computer for safe browsing.According to Finjan

The page canon.co.in was not available for scanning, but another page in the same domain canon.co.in/contactCanonsales.asp had been scanned and is safe for browsing (see the green flag).

Finjan Results for Canon.co.in 

Scanning canon.co.in using URL Analysis at Finjan’s website results in URL currently unavailable

Canon Website URL currently unavailable

HackAlert

HackAlert™ is a site monitoring service from Armorize Technologies.

HackAlert identifies malicious code injection on web applications and let’s you know instantly about hijacking attempts. I scan the complete website canon.co.in using HackAlert and find out that out of total 89 URLs that canon.co.in have, only one is suspicious.It has defined it as suspicious because there are 4 suspicious links pointing to it.

HackAlert Analysis for Canon.co.in

These links are just suspicious and not executable (else HackAlert would mark them Malicious) so I took a chance by “copy & paste” one of the link in my browser, and here is what I get.

HackAlert would mark them Malicious

I click on “why was this site blocked?” and it did get a detail report.

Detail Report

Alright Google and HackAlert did a good job to warm me against visiting http://www.canon.co.in as it has links pointing to netcfg9.ru and it has been detected with malware.

Let’s see the results for more tools.

McAfee

According to McAfee Site Advisor, it is clean and green.

According to McAfee Site Advisor Canon India Website is Clean and Green

Link Scanner

Link Scanner even congratulate for not finding any exploits

Link Scanner not finds any exploits in Canon india website

Link Scanner not finds any exploits in Canon india website-1

Trend Micro – Web Reputation Query

Trend Micro says this site is known to them as non-malicious.

Trend Micro says Canon india website is non-malicious

It’s a good example of how legitimate sites can be hacked and weaponized to distribute malware to the visitors.The worst case scenario is when the website owner is informed about such security breach by their customers who find out about this while trying to access the website. Google has done a good job by flagging these websites but it doesn’t notify the website owner. Among the other tools I have analyzed so far, HackAlert was able to detect the Malicious URL and if you are monitoring your website using HackAlert it does send an e-mail or SMS notification to you.

Related Articles


3 comments so far

  1. Mahesh
    #1

    Once McAfee SiteAdvisor had considered ymail to be a threat.

    Giving it a Yellow Status.

    Now, it has fixed the problem.

  2. haider_up32
    #2

    i wrote a related post here:-http://techtemper.blogspot.com/search/label/Wild%20Wild%20Web

    No only canon but emerson ups site ,upcat dental official sites and couple of others were hacked

  3. haider_up32
    #3

    avg uses link scanners engine…google and firefox results are most reliable ..there are other sites too which check any webpage for malicious links

Leave a Reply





XHTML: You can use these tags: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>