CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

Fake security software

 
Post new topic   Reply to topic       All -> FavForums -> Web Malware Links [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
AlphaCentauri

SIRT Handler
Premium Member

Joined: Nov 20, 2003
Posts: 2898

Premium

PostPosted: Sun Aug 17, 2008 6:49 pm    Post subject: Fake security software
Reply with quote

Spammed link http://www.vo-software.de/1.html is advertised as being a Britney Spears video. It is actually an animated gif of a video loading. I have Noscript, and the site does absolutely nothing in my browser. But I can see an i-frame which links to 79.135.167.18/antivirus/

The only reverse dns I can find for 79.135.167.18 is ns1.maseratto.info . I add the directory name and voilą!
ns1.maseratto.info/antivirus/ is the same page. (maseratto.info, on the other hand is a blank page, and maseratto.info/antivirus/ fails to load.)

Both claim to offer "Antivirus XP 2008." Again, without javascript, the site does nothing and I can't find what the URL of the payload is. But I would be highly surprised if a visitor running ActiveX and Javascript would come away without a malware infection.

Back to top
View users profile Send private message
tetak

MIRT Team Lead
Premium Member

Joined: Jan 19, 2007
Posts: 5879

MIRT Premium

PostPosted: Wed Aug 20, 2008 7:34 pm    Post subject:
Reply with quote

The site has been cleaned of malware.


_________________
Got Windows XP? Help protect your PC from malware with Microsofts anti-spyware program Windows Defender.

Download it for free from http://www.microsoft.com/athome/security/spyware/software/default.mspx
Back to top
View users profile Send private message
AlphaCentauri

SIRT Handler
Premium Member

Joined: Nov 20, 2003
Posts: 2898

Premium

PostPosted: Sat Aug 30, 2008 6:30 pm    Post subject:
Reply with quote

http://www.dhs.com.co/index99.html has been getting spammed for several days, and the download, video99.exe, is well-detected: http://www.virustotal.com/analisis/0f5f9aa7372a3896418204f5e5e3de0b

But the site hasn't gotten cleaned yet.

I tried to visit dhs.com.co to find a contact link, and it's one of those stupid sites that won't let you enter if you don't let their .swf file run. (Hel-looo! I'm here precisely because the files on your site can't be trusted!) But I found an iframe on that page. http://www.dhs.com.co/stat.html, which refreshes to http://79.135.167.18/cgi-bin/index.cgi?user2

I'm over my depth figuring out what I can learn from that link, and there is no "video99.exe" file there. But there is an "install.exe" which is a different download, also fairly well detected: http://www.virustotal.com/analisis/1764cba4b13d39f11757b3af21c02236

What's the story on 79.135.167.18? It's well known at spamhaus http://www.spamhaus.org/query/bl?ip=79.135.167.18 as part of a IP range controlled by criminals. It would seem to be a good idea for ISP's to block access to it if so many of these hacked sites seem to depend on it.

Back to top
View users profile Send private message
Spockish

Captain
Captain


Joined: May 19, 2006
Posts: 340


PostPosted: Sun Aug 31, 2008 12:00 pm    Post subject:
Reply with quote

Why should ISP's have to block it?

Why isn't the damn IP address demolished by a responsible authority?

Back to top
View users profile Send private message
AlphaCentauri

SIRT Handler
Premium Member

Joined: Nov 20, 2003
Posts: 2898

Premium

PostPosted: Sun Aug 31, 2008 2:40 pm    Post subject:
Reply with quote

Spockish wrote:
Why should ISP's have to block it?

Why isn't the damn IP address demolished by a responsible authority?


It's a Turkish ISP. I'd love to see the EU require Turkey to wrest control of their IP range back from the Russian Business Network as a condition of membership, since Turkey does seem motivated to do what it takes to be accepted.

Back to top
View users profile Send private message
tetak

MIRT Team Lead
Premium Member

Joined: Jan 19, 2007
Posts: 5879

MIRT Premium

PostPosted: Sat Oct 25, 2008 3:12 pm    Post subject:
Reply with quote

MIRT report sent - CastleCops Link/p1115166-MIRT_21322_Trojan_Downloader_on_79_135_167_18_AS44097.html


_________________
Got Windows XP? Help protect your PC from malware with Microsofts anti-spyware program Windows Defender.

Download it for free from http://www.microsoft.com/athome/security/spyware/software/default.mspx
Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Web Malware Links All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You cannot download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer