« Sex tapes and malware
Imageshack.us typo pushes malware »

Angelina and Zango cash

September 4th, 2009

I came across the following site today: angelinajmovies.cn

If you browse the site you immediately get a file:

anjel1

which VirusTotal detects as:

vt1

If you refresh the page you now get this second file (sorry I used Firefox here, but you get the same result in IE):

anjel2

which VirusTotal detects as:

vt2

And if you refresh the page angelinajmovies.cn for a third time you get:

anjel3

Wait, let’s zoom in a little bit:

anjel4

Yes, you see it right, Zango it is.

Dreamcatcher player, sorry DreamMediaPlayer or whatever.

The landing page reminds me so much of the fake codec pages. I bet they might even have used the same template.

Bad on all fronts!

Jerome Segura

Malware ID: 67e252ee84a6b5d0e2706ccc3e36a106.zip

Malware ID: bea4676cddd48770b56c54db8b07f370.zip

Malware ID: c115d8251fe12d92567e55cad1d379e9.zip

    This entry was posted on Friday, September 4th, 2009 at 9:02 am and is filed under Exploits, Fake codecs. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

    Comments:

    • (0) comments
    • |
    • Add your comments




RSS feed to this site Twitter Linkedin YouTube Channel

 

RSS feed to this site Jerome Segura is a Security Analyst working at ParetoLogic.

You can contact him at:
MalwareDiaries Email

 

Pages

  • Live Malware Map
  • VB2009 pictures
  • Zheng™ Technology
  • About
  • Contact Us



Security Software

  • XoftSpySE Anti-Spyware
  • Anti-Virus PLUS
  • Privacy Controls



Malware Top 10

  • Koobface Worm
  • DNS Changer Trojan
  • Fake Alert Trojan
  • Windows System Suite
  • Smart Protector
  • Home Antivirus 2010
  • PC Antispyware 2010
  • System Security
  • AVCare
  • Perfect Defender 2009



Archives

  • November 2009
  • October 2009
  • September 2009
  • August 2009
  • July 2009
  • June 2009
  • May 2009
  • April 2009
  • March 2009
  • February 2009
  • January 2009
  • December 2008
  • November 2008
  • October 2008
  • September 2008
  • August 2008
  • July 2008
  • June 2008
  • May 2008
  • April 2008
  • March 2008



Categories

  • Adware (1)
  • Banker Trojans (3)
  • Botnets (2)
  • Conferences (4)
  • DDos (1)
  • Exploits (33)
  • Fake codecs (30)
  • IM threats (1)
  • Interviews (5)
  • Keyloggers (1)
  • Mac security (15)
  • Malware Trends (67)
  • Phishing (7)
  • Podcast (1)
  • ransomware (1)
  • Research (33)
  • Rogue software (47)
  • Rootkits (2)
  • scams (3)
  • Social Networking (4)
  • Uncategorized (110)
  • Wireless Security (1)
  • world map (1)



 
 
 

© 2009 ParetoLogic Inc.