Home > ParetoLogic Blogs > Malware Diaries > Rogueware buys you BMWs
Reply
 
Thread Tools Display Modes
  #1  
Old 08-01-2009, 02:00 AM
Michael Michael is offline
Administrator
Join Date: May 2007
Posts: 313
Default Rogueware buys you BMWs

As I was investigating some fake codec sites, late on a Friday night, I stumbled upon this one:

money

The malware is hosted on downloadxxtube.com. Interestingly enough, the page is totally open for the curious like me. You can see an "exe" folder where that file is hosted, but the thing that first caught my attention was those BMW pics...

money2

Is that what online criminals dream of?

money3

Don't get me wrong, I think BMWs are splendid cars and if I had the budget I would be more than tempted!

The domain registratio info below. Created mid-July.

money4

File detection on VirusTotal:

money5

There is another domain hosting the same payload on that IP (78.159.98.70): showmeall-tube-xx.com

Ah... a sports car. Maybe some day...

Jerome Segura
Reply With Quote
Reply

« Previous Thread | Next Thread »

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump


Terms of Use