« Mac users, beware of mac-xxx.com
Rogue uses ‘update manager’ »

It’s not Kaspersky…

August 24th, 2009

There’s a nasty site out there, that has nothing to do with Kaspersky and yet uses the brand name to lure users.

x.kaspersky-com.info

The page greets you with no less than 3 iframes:

k

If you check the first iframe, you notice that it uses “jpg” to hide malicious exploit code. A technique well used to bypass security scanners.

k2

That’s how one of the jpg looks like:

k3

Upon successful exploit, a file is downloaded from x.kaspersky-com.info/mm.exe

Looks like another Agent Trojan.

k4

Jerome Segura

Malware ID: 44e0c70cefe5e6db6e7115a061e86dc9.zip

    This entry was posted on Monday, August 24th, 2009 at 3:01 pm and is filed under Exploits. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

    Comments:

    • (0) comments
    • |
    • Add your comments




ParetoLogic, a Microsoft Certified Partner

 

RSS feed to this site Twitter Linkedin YouTube Channel

 

RSS feed to this site
Jerome Segura is a Security Analyst working at ParetoLogic.

You can contact him at:
MalwareDiaries Email

 

Pages

  • URL Clearing House
  • VB2009 pictures
  • Zheng™ Technology
  • About
  • Contact Us



Security Software

  • XoftSpySE Anti-Spyware
  • Anti-Virus PLUS
  • Privacy Controls



Malware Top 10

  • Koobface Worm
  • DNS Changer Trojan
  • Fake Alert Trojan
  • Windows System Suite
  • Smart Protector
  • Home Antivirus 2010
  • PC Antispyware 2010
  • System Security
  • AVCare
  • Perfect Defender 2009



Archives

  • March 2010
  • February 2010
  • January 2010
  • December 2009
  • November 2009
  • October 2009
  • September 2009
  • August 2009
  • July 2009
  • June 2009
  • May 2009
  • April 2009
  • March 2009
  • February 2009
  • January 2009
  • December 2008
  • November 2008
  • October 2008
  • September 2008
  • August 2008
  • July 2008
  • June 2008
  • May 2008
  • April 2008
  • March 2008



Categories

  • Adware (1)
  • Banker Trojans (4)
  • Botnets (3)
  • Conferences (4)
  • DDos (1)
  • Exploits (48)
  • Fake codecs (38)
  • IM threats (1)
  • Interviews (5)
  • Keyloggers (2)
  • Mac security (15)
  • Malware Trends (69)
  • Phishing (8)
  • Podcast (1)
  • ransomware (5)
  • Research (46)
  • Rogue software (53)
  • Rootkits (2)
  • scams (9)
  • Social Networking (6)
  • Uncategorized (118)
  • Wireless Security (2)
  • world map (1)



 
 
 
Microsoft is a registered trademark of Microsoft Corporation in the United States and/or other countries.

© 2010 ParetoLogic Inc.