« Web Threats
Press coverage for new Mac Malware variant »

Antonella Barba used to deliver malware

June 12th, 2009

American Idol singer Antonella Barba’s name (and more!)  is being used in malware campaigns.

I found at least two different websites registered using her name, that are pushing malware.

barba2

barba3

The page is pretty straightforward… with the alleged video being the center of attention:

barba1

If you click on the video, it will redirect you to a page that tries to load streamviewer.40009.exe

barba4

The file is hosted on yet another domain created June 11, so still very recent.

barba5

A Robtex analysis reveals some interesting connections:

barba6

You can see the domain names for scareware programs:

barba7

The malware file is not very well detected:

barba8

A clue to what it might be doing as a payload is revealed by this Fiddler analysis:

barba9

It looks like some click fraud using ad banners:

barba11

barba12

Every now and again, amongst redirections and pop ups you will see it trying to push rogueware:

barba10

Once again, this is a reminder of how celebrities are used in malware attacks. Their private lives interest people, which makes them a prime target for hackers.

Warning: all links are live and can infect your PC.

Jerome Segura

    This entry was posted on Friday, June 12th, 2009 at 4:32 pm and is filed under Fake codecs, Rogue software. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

    Comments:

    1.      by
    • (0) comments
    • |
    • Add your comments




RSS feed to this site Twitter Linkedin YouTube Channel

 

RSS feed to this site Jerome Segura is a Security Analyst working at ParetoLogic.

You can contact him at:
MalwareDiaries Email

 

Pages

  • Live Malware Map
  • VB2009 pictures
  • Zheng™ Technology
  • About
  • Contact Us



Security Software

  • XoftSpySE Anti-Spyware
  • Anti-Virus PLUS
  • Privacy Controls



Malware Top 10

  • Koobface Worm
  • DNS Changer Trojan
  • Fake Alert Trojan
  • Windows System Suite
  • Smart Protector
  • Home Antivirus 2010
  • PC Antispyware 2010
  • System Security
  • AVCare
  • Perfect Defender 2009



Archives

  • November 2009
  • October 2009
  • September 2009
  • August 2009
  • July 2009
  • June 2009
  • May 2009
  • April 2009
  • March 2009
  • February 2009
  • January 2009
  • December 2008
  • November 2008
  • October 2008
  • September 2008
  • August 2008
  • July 2008
  • June 2008
  • May 2008
  • April 2008
  • March 2008



Categories

  • Adware (1)
  • Banker Trojans (3)
  • Botnets (2)
  • Conferences (4)
  • DDos (1)
  • Exploits (32)
  • Fake codecs (30)
  • IM threats (1)
  • Interviews (5)
  • Keyloggers (1)
  • Mac security (14)
  • Malware Trends (67)
  • Phishing (7)
  • Podcast (1)
  • ransomware (1)
  • Research (33)
  • Rogue software (47)
  • Rootkits (2)
  • scams (3)
  • Social Networking (4)
  • Uncategorized (104)
  • Wireless Security (1)
  • world map (1)



 
 
 

© 2009 ParetoLogic Inc.