« Home mortgage site gets owned and pwned
Site ‘Under construction’ hosts malware »

Spy on your wife, get infected

October 22nd, 2009

Our HoneyPots caught this site spymycomputer.com and one of its products “spy man”

spyman

I decided to take a closer look:

First, as reported by our HoneyPots, the site initiates two drive-bys:

driveby

The drive-by files are not very well detected yet, as shows this Virus Total scan:

http://www.virustotal.com/analisis/e1eb5f2d9df855c9ed33ea76908c79a8e57bef0c505225b3945c910c200bb6e8-1256205382

The source code of spymycomputer.com contains 3 iframes:

url

frantsuz.com was listed by Google: http://google.com/safebrowsing/diagnostic?site=frantsuz.com/

abbcp.cn is already blacklisted by our friend Steven Burn over at hpHosts:

hp

As far as the software itself, “Spy Man” you may want to think about it twice before installing it:

vt2

Key logging programs have always had a bad reputation… Well, the name itself  “Spy Man” sounds a little bit like a Cold War espion character ;-)

Jerome Segura

Malware ID: 8cbe7e2692a5bdaabfc6b2253c7624e7.zip

Malware ID: f00173d0a26085d3333578f2d90e5c64.zip

    This entry was posted on Thursday, October 22nd, 2009 at 12:34 pm and is filed under Exploits. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

    Comments:

    • (0) comments
    • |
    • Add your comments




RSS feed to this site Twitter Linkedin YouTube Channel

 

RSS feed to this site Jerome Segura is a Security Analyst working at ParetoLogic.

You can contact him at:
MalwareDiaries Email

 

Pages

  • Live Malware Map
  • VB2009 pictures
  • Zheng™ Technology
  • About
  • Contact Us



Security Software

  • XoftSpySE Anti-Spyware
  • Anti-Virus PLUS
  • Privacy Controls



Malware Top 10

  • Koobface Worm
  • DNS Changer Trojan
  • Fake Alert Trojan
  • Windows System Suite
  • Smart Protector
  • Home Antivirus 2010
  • PC Antispyware 2010
  • System Security
  • AVCare
  • Perfect Defender 2009



Archives

  • November 2009
  • October 2009
  • September 2009
  • August 2009
  • July 2009
  • June 2009
  • May 2009
  • April 2009
  • March 2009
  • February 2009
  • January 2009
  • December 2008
  • November 2008
  • October 2008
  • September 2008
  • August 2008
  • July 2008
  • June 2008
  • May 2008
  • April 2008
  • March 2008



Categories

  • Adware (1)
  • Banker Trojans (3)
  • Botnets (2)
  • Conferences (4)
  • DDos (1)
  • Exploits (33)
  • Fake codecs (30)
  • IM threats (1)
  • Interviews (5)
  • Keyloggers (1)
  • Mac security (15)
  • Malware Trends (67)
  • Phishing (7)
  • Podcast (1)
  • ransomware (1)
  • Research (33)
  • Rogue software (47)
  • Rootkits (2)
  • scams (3)
  • Social Networking (4)
  • Uncategorized (110)
  • Wireless Security (1)
  • world map (1)



 
 
 

© 2009 ParetoLogic Inc.