« More Mac malware
All too familiar Mac OS X Trojan »

The Mac Trail to 213.182.197

June 18th, 2009

Since following this Mac Trojan I have come across several valuable links.

In particular I am investigating 213.182.197

Check out what’s on there:

base record name ip reverse route as

bests.at a 213.182.197.2 (none) ?

fcoder.at a 213.182.197.2 (none)

kirgo.at a 213.182.197.2 (none)

8070372.com a 213.182.197.4 (none)

zeus-logs.biz a 213.182.197.4 (none)

- 213.182.197.7 (none)

bestxvids.info a 213.182.197.8 mxs.newhostgroup.ru

freewebxxx.info a 213.182.197.8 mxs.newhostgroup.ru

hotfreexxx.info a 213.182.197.8 mxs.newhostgroup.ru

mail.2todays.com a 213.182.197.8 mxs.newhostgroup.ru

mail.freewebxxx.info a 213.182.197.8 mxs.newhostgroup.ru

mail.hotfreexxx.info a 213.182.197.8 mxs.newhostgroup.ru

mail.newhostgroup.ru a 213.182.197.8 mxs.newhostgroup.ru

mail.tubeololo.org a 213.182.197.8 mxs.newhostgroup.ru

mail.worldtube.su a 213.182.197.8 mxs.newhostgroup.ru

ns1.2todays.com a 213.182.197.8 mxs.newhostgroup.ru

ns1.freewebxxx.info a 213.182.197.8 mxs.newhostgroup.ru

ns1.good777.ru a 213.182.197.8 mxs.newhostgroup.ru

ns1.goxxxweb.info a 213.182.197.8 mxs.newhostgroup.ru

ns1.sabroski.com a 213.182.197.8 mxs.newhostgroup.ru

ns1.tubeololo.org a 213.182.197.8 mxs.newhostgroup.ru

ns1.zoosexvideo.net a 213.182.197.8 mxs.newhostgroup.ru

ns2.goxxxweb.info a 213.182.197.8 mxs.newhostgroup.ru

ns2.hotfreexxx.info a 213.182.197.8 mxs.newhostgroup.ru

ns2.siteload.cn a 213.182.197.8 mxs.newhostgroup.ru

ns2.yesey.net a 213.182.197.8 mxs.newhostgroup.ru

ns2.zoosexvideo.net a 213.182.197.8 mxs.newhostgroup.ru

sabroski.com a 213.182.197.8 mxs.newhostgroup.ru

seexxxfree.info a 213.182.197.8 mxs.newhostgroup.ru

uniquexsoftware.com a 213.182.197.8 mxs.newhostgroup.ru

vipwarezz.com a 213.182.197.8 mxs.newhostgroup.ru

worldtube.su a 213.182.197.8 mxs.newhostgroup.ru

www.freewebxxx.info a 213.182.197.8 mxs.newhostgroup.ru

www.goxxxweb.info a 213.182.197.8 mxs.newhostgroup.ru

www.sabroski.com a 213.182.197.8 mxs.newhostgroup.ru

www.seexxxfree.info a 213.182.197.8 mxs.newhostgroup.ru

mxs.newhostgroup.ru ptr 213.182.197.8

ns2.bestxvids.info a 213.182.197.10 (none)

ns2.freewebxxx.info a 213.182.197.10 (none)

ns2.good777.ru a 213.182.197.10 (none)

ns2.mac-videos.com a 213.182.197.10 (none)

ns2.newhostgroup.ru a 213.182.197.10 (none)

ns2.viagrabe.com a 213.182.197.10 (none)

ns2.worldtube.su a 213.182.197.10 (none)

barmatuxa.info a 213.182.197.12 (none)

zapalinfo.info a 213.182.197.12 (none)

ns1.bestxvids.info a 213.182.197.13 (none)

ns1.hotfreexxx.info a 213.182.197.13 (none)

ns1.siteload.cn a 213.182.197.13 (none)

ns1.tube84.com a 213.182.197.13 (none)

wkontkte.ru a 213.182.197.13 (none)

hostnsload.cn a 213.182.197.14 (none)

mail.hostnsload.cn a 213.182.197.14 (none)

mail.megavipsite.cn a 213.182.197.14 (none)

mail.siteload.cn a 213.182.197.14 (none)

megavipsite.cn a 213.182.197.14 (none)

siteload.cn a 213.182.197.14 (none)

adultelitiest.ru a 213.182.197.20 (none)

dns-lv9720.com a 213.182.197.20 (none)

mail.dangerousteens.com a 213.182.197.20 (none)

mail.dns-lv9720.com a 213.182.197.20 (none)

mail.openstat.ws a 213.182.197.20 (none)

mail.toponline-video.net a 213.182.197.20 (none)

ns1.dns-lv9720.com a 213.182.197.20 (none)

ns2.dns-lv9720.com a 213.182.197.20 (none)

openstat.ws a 213.182.197.20 (none)

toponline-video.net a 213.182.197.20 (none)

- 213.182.197.21 (none)

ns1.freednshostserver.com a 213.182.197.23 (none)

ns2.bio-a.ru a 213.182.197.23 (none)

ns2.dub-dubom.ru a 213.182.197.23 (none)

ns2.icq-stanet-platnoy.ru a 213.182.197.23 (none)

ns2.iqdoza.ru a 213.182.197.23 (none)

ns2.lifezilla.ru a 213.182.197.23 (none)

ns2.litegreatestdirect.cn a 213.182.197.23 (none)

ns2.mixmediadirect.cn a 213.182.197.23 (none)

ns3.freednshostway.com a 213.182.197.23 (none)

- 213.182.197.28 (none)

traffanalizer.cn a 213.182.197.40 (none)

- 213.182.197.227 (none)

*.1st.abdulabah.cn a 213.182.197.229 (none)

1st.abdulabah.cn a 213.182.197.229 (none)

807037.com a 213.182.197.229 (none)

bjbotnet.cn a 213.182.197.229 (none)

domenzmonz.cn a 213.182.197.229 (none)

firex-labz.com a 213.182.197.229 (none)

groos.ru a 213.182.197.229 (none)

kazantipwords.ru a 213.182.197.229 (none)

lafi.babjr.cn a 213.182.197.229 (none)

mssys.net a 213.182.197.229 (none)

muhamed.cn a 213.182.197.229 (none)

odnoklassniki.groos.ru a 213.182.197.229 (none)

www.1st.abdulabah.cn a 213.182.197.229 (none)

www.abdulabah.cn a 213.182.197.229 (none)

www.acidbot.cn a 213.182.197.229 (none)

www.lafi.babjr.cn a 213.182.197.229 (none)

yes04ka.cn a 213.182.197.229 (none)

- 213.182.197.230 (none)

Checking out a very obvious one, mac-videos.com. Mac OS X users visiting this site can get infected with Jahlav Trojan.

mac00

The sample flies totally under the radar, as shows this VirusTotal screenshot:

mac01

When you think it’s over, here is more from 213.182.197.13:

21318219713as

You can see the fake PornTube sites riddled with malware and, worth pointing out, a social networking site called Vkontakte. It is the equivalent of Facebook in Russia, Ukraine and Belarus.

It is not the real site though, a little typo, similar designs….

phish11

This, is the legitimate site:

phish2

The trail never seems to end! Fake codecs, illegal adult content, phishing sites… Stay clear off those sites!

Jerome Segura

    This entry was posted on Thursday, June 18th, 2009 at 11:43 am and is filed under Malware Trends, Research. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

    Comments:

    1.      by
    • (0) comments
    • |
    • Add your comments




RSS feed to this site Twitter Linkedin YouTube Channel

 

RSS feed to this site Jerome Segura is a Security Analyst working at ParetoLogic.

You can contact him at:
MalwareDiaries Email

 

Pages

  • Live Malware Map
  • VB2009 pictures
  • Zheng™ Technology
  • About
  • Contact Us



Security Software

  • XoftSpySE Anti-Spyware
  • Anti-Virus PLUS
  • Privacy Controls



Malware Top 10

  • Koobface Worm
  • DNS Changer Trojan
  • Fake Alert Trojan
  • Windows System Suite
  • Smart Protector
  • Home Antivirus 2010
  • PC Antispyware 2010
  • System Security
  • AVCare
  • Perfect Defender 2009



Archives

  • November 2009
  • October 2009
  • September 2009
  • August 2009
  • July 2009
  • June 2009
  • May 2009
  • April 2009
  • March 2009
  • February 2009
  • January 2009
  • December 2008
  • November 2008
  • October 2008
  • September 2008
  • August 2008
  • July 2008
  • June 2008
  • May 2008
  • April 2008
  • March 2008



Categories

  • Adware (1)
  • Banker Trojans (3)
  • Botnets (2)
  • Conferences (4)
  • DDos (1)
  • Exploits (32)
  • Fake codecs (30)
  • IM threats (1)
  • Interviews (5)
  • Keyloggers (1)
  • Mac security (14)
  • Malware Trends (67)
  • Phishing (7)
  • Podcast (1)
  • ransomware (1)
  • Research (33)
  • Rogue software (47)
  • Rootkits (2)
  • scams (3)
  • Social Networking (4)
  • Uncategorized (104)
  • Wireless Security (1)
  • world map (1)



 
 
 

© 2009 ParetoLogic Inc.