« Spy on your wife, get infected
Mac OS X virus free? »

Site ‘Under construction’ hosts malware

October 23rd, 2009

Our Honeypots caught the following site: dataprovedor.com.

Is this site really under construction? It looks like some kind of web portal.

provedor

Regardless, let’s get to the subject that got us here in the first place: The malware.

In a sub directory called images you can see two files, one is an exe, the other a php which redirects to the exe.

I found it rather smart that the file name for the exe is in the form of DSCXXXXX. For those who own a Sony camera (or possibly other Sony products) this is the default name to which images are saved to.

So, one bonus point for the social engineering trick.

files

The time stamp also indicates that those files have been uploaded recently, to what I think is a hacked server.

The online file checker Jotti reveals that the file may be part of the Banload Trojans family, but is poorly detected at the time of writing:

jotti

Jerome Segura

Malware ID: 2b65626b2442521307d68a53c0b5e6aa.zip

    This entry was posted on Friday, October 23rd, 2009 at 3:09 pm and is filed under Exploits. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

    Comments:

    • (0) comments
    • |
    • Add your comments




RSS feed to this site Twitter Linkedin YouTube Channel

 

RSS feed to this site Jerome Segura is a Security Analyst working at ParetoLogic.

You can contact him at:
MalwareDiaries Email

 

Pages

  • Live Malware Map
  • VB2009 pictures
  • Zheng™ Technology
  • About
  • Contact Us



Security Software

  • XoftSpySE Anti-Spyware
  • Anti-Virus PLUS
  • Privacy Controls



Malware Top 10

  • Koobface Worm
  • DNS Changer Trojan
  • Fake Alert Trojan
  • Windows System Suite
  • Smart Protector
  • Home Antivirus 2010
  • PC Antispyware 2010
  • System Security
  • AVCare
  • Perfect Defender 2009



Archives

  • November 2009
  • October 2009
  • September 2009
  • August 2009
  • July 2009
  • June 2009
  • May 2009
  • April 2009
  • March 2009
  • February 2009
  • January 2009
  • December 2008
  • November 2008
  • October 2008
  • September 2008
  • August 2008
  • July 2008
  • June 2008
  • May 2008
  • April 2008
  • March 2008



Categories

  • Adware (1)
  • Banker Trojans (3)
  • Botnets (2)
  • Conferences (4)
  • DDos (1)
  • Exploits (33)
  • Fake codecs (30)
  • IM threats (1)
  • Interviews (5)
  • Keyloggers (1)
  • Mac security (15)
  • Malware Trends (67)
  • Phishing (7)
  • Podcast (1)
  • ransomware (1)
  • Research (33)
  • Rogue software (47)
  • Rootkits (2)
  • scams (3)
  • Social Networking (4)
  • Uncategorized (110)
  • Wireless Security (1)
  • world map (1)



 
 
 

© 2009 ParetoLogic Inc.