« Unsanitized repo of fake codecs
New Koobface variant »

Malware repo gets updated

July 3rd, 2009

This is an update from my previous post. I noticed an update to one of the pages on the malicious site

oymoma-tube.freehostia.com

Check the screen below and see the July 3rd time stamp:

hottube

The page hot-tube.htm is now pushing a rogue, namely XP Deluxe Protector, disguised as a free codec:

hottube2

Upon execution, fake alert messages such as this one:

hottube3

Eventually the scareware will run:

hottube4

This sample is poorly detected, especially for being a variant of an already known rogue:

hottube5

Paretologic detects this file as:

clipboard01

Jerome Segura

Malware ID: dcfe992aa25bb1849c1e9f8c2c5d3c5b.zip

    This entry was posted on Friday, July 3rd, 2009 at 8:37 am and is filed under Fake codecs, Rogue software. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

    Comments:

    • (0) comments
    • |
    • Add your comments




RSS feed to this site Twitter Linkedin YouTube Channel

 

RSS feed to this site Jerome Segura is a Security Analyst working at ParetoLogic.

You can contact him at:
MalwareDiaries Email

 

Pages

  • Live Malware Map
  • VB2009 pictures
  • Zheng™ Technology
  • About
  • Contact Us



Security Software

  • XoftSpySE Anti-Spyware
  • Anti-Virus PLUS
  • Privacy Controls



Malware Top 10

  • Koobface Worm
  • DNS Changer Trojan
  • Fake Alert Trojan
  • Windows System Suite
  • Smart Protector
  • Home Antivirus 2010
  • PC Antispyware 2010
  • System Security
  • AVCare
  • Perfect Defender 2009



Archives

  • November 2009
  • October 2009
  • September 2009
  • August 2009
  • July 2009
  • June 2009
  • May 2009
  • April 2009
  • March 2009
  • February 2009
  • January 2009
  • December 2008
  • November 2008
  • October 2008
  • September 2008
  • August 2008
  • July 2008
  • June 2008
  • May 2008
  • April 2008
  • March 2008



Categories

  • Adware (1)
  • Banker Trojans (3)
  • Botnets (2)
  • Conferences (4)
  • DDos (1)
  • Exploits (33)
  • Fake codecs (30)
  • IM threats (1)
  • Interviews (5)
  • Keyloggers (1)
  • Mac security (15)
  • Malware Trends (67)
  • Phishing (7)
  • Podcast (1)
  • ransomware (1)
  • Research (33)
  • Rogue software (47)
  • Rootkits (2)
  • scams (3)
  • Social Networking (4)
  • Uncategorized (110)
  • Wireless Security (1)
  • world map (1)



 
 
 

© 2009 ParetoLogic Inc.