New issue
Advanced search Search tips

Issue 800439 link

Starred by 2 users

Issue metadata

Status: WontFix
Owner: ----
Closed: Jan 2018
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: 2
Type: Bug-Security



Sign in to add a comment

Unknown infection changed lnk file for opening malware sites on every Google Chrome launch

Reported by mikhail....@gmail.com, Jan 9 2018

Issue description

UserAgent: Mozilla/5.0 (X11; Linux x86_64; rv:59.0) Gecko/20100101 Firefox/59.0

Steps to reproduce the problem:
1. If you launch attached lnk file than malware sites would be opened.

What is the expected behavior?

What went wrong?
Google Chrome needed better protection from this.
Also this infection changed system proxy settings with this script:
http://no-blok.net/wpad.dat?30253e2d9364370ae828a8de722df3af26083107

Did this work before? N/A 

Chrome version: 65.0.3311.3  Channel: dev
OS Version: 10
Flash Version: 

I am expected that Google Chrome can itself check lnk file which launch browser. And also can verify system proxy settings and said to user if something was changed.
 
Google Chrome.lnk
2.5 KB Download
proxy-settings.PNG
31.5 KB View Download
Status: WontFix (was: Unconfirmed)

If you have more details about the malware download that infected your PC, we can submit it to the SafeBrowsing block list, but compromised and infected machines are necessarily outside of the browser's threat model, as outlined here: https://chromium.googlesource.com/chromium/src/+/master/docs/security/faq.md#Why-arent-compromised_infected-machines-in-Chromes-threat-model
 
The LNK file attached to this bug opens Chrome with the following command line argument:

https:// launchpage. org/?uid=oTlKGKjchx0cXe9WsoZxObMJbDp5ettzlx4LNYaCXOMBe5GnLQ4irVZCMxK1%2BRtZyw%3D%3D5

That page appears to be a replacement version of Chrome's new tab page; it's not clear whether or not it's malicious.

The proxy configuration script sends a variety of traffic to 50.7.146.51:7274, an IP owned by noblockweb.biz

In some cases, the Chrome Cleanup Tool (https://www.google.com/chrome/cleanup-tool/index.html) is useful for helping to resolve malware infections in your operating system.

For me, it would be important to know as soon as possible that something went wrong. While my data did not leak into an unknown direction. Therefore, once again to warn me if the proxy setting was changed it would not be superfluous. Also, it would not be superfluous to explain why the left sites are being opened. I did not immediately realize that someone edited the lnk file. If Google want to help keep security, then when browser open a new tab in such way in this way, it should ask user, do you really wanted to open this site. And in case the user responded negatively already to reveal help why this could happen.
Project Member

Comment 3 by sheriffbot@chromium.org, Apr 18 2018

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment