Twopular.com (Twitter Aggregator Site) Leads to Potentially Destructive Nginx Virus

By Sumo3000 in Computer Security | 33 views
Rate it:
1 Star2 Stars3 Stars4 Stars5 Stars (1 votes, average: 5.00 out of 5)
Loading ... Loading ...
More... More

Our security researchers ran across the twopular.com (do not visit) site and took special notice to the ‘Welcome to nginx!’ text on the page, which is an indication of the site being down but displaying a characteristic of the Nginx Virus.

Twopular.com is a site that allows you to search for trending Twitter topics but may have been taken down recently. The Nginx error message shown in Figure 2 below, ‘Welcome to nginx!’ is commonly displayed on a PC where the web browser application has been rerouted when attempting to visit a particular website. Typically, this redirect happens when a system has been infected with malware.

Figure 1. Twopular.com screenshot
Twopular is a twitter aggregator

Figure 2. ‘Welcome to nginx!’ screenshot
Nginx error message

This type of malware affects web browsers (Chrome, Firefox, Internet Explorer, Opera) and reroutes the browser to either a hacked site or some type of unwanted site that may promote malware. The particular case of twopular.com, it appeared to be a legitimate Twitter aggregator site with useful information before it was taken down.

The video below is a short live demonstration of attempting to load the legitimate twopular.com site but being redirected to a ‘Welcome to nginx!’ threat message.

Hackers could utilize the downed twopular.com site to exploit PC users with malware similar to well-known ransomware threats such as the Ukash Virus or Nginx Virus. It remains evident that computer users must be careful when visiting sites that offer free tools or services. In the case of Twopular.com, it offered free Twitter aggregation. As it turns out, it offers absolutely nothing now that it looks to be down.

This entry was last updated on 08/24/12 and posted on 08/22/12. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

Leave a Comment

Note: Abusive comments are not allowed. Please do not post comments regarding technical support issues. ESG customers that have issues with SpyHunter should open a customer support ticket.

*
To prove you're a person (not a spam script), type the security word shown in the picture. Click on the picture to hear an audio file of the word.
Click to hear an audio file of the anti-spam word

Follow ESG

Home | SpyHunter Risk Assessment Model | Privacy Policy | End User License Agreement | Additional Terms and Conditions
Copyright 2003-2012. Enigma Software Group USA, LLC. All Rights Reserved.