Home > ParetoLogic Blogs > Malware Diaries > Angelina and Zango cash
Reply
 
Thread Tools Display Modes
  #1  
Old 09-04-2009, 06:02 PM
Michael Michael is offline
Administrator
Join Date: May 2007
Posts: 313
Default Angelina and Zango cash

I came across the following site today: angelinajmovies.cn

If you browse the site you immediately get a file:

anjel1

which VirusTotal detects as:

vt1

If you refresh the page you now get this second file (sorry I used Firefox here, but you get the same result in IE):

anjel2

which VirusTotal detects as:

vt2

And if you refresh the page angelinajmovies.cn for a third time you get:

anjel3

Wait, let's zoom in a little bit:

anjel4

Yes, you see it right, Zango it is.

Dreamcatcher player, sorry DreamMediaPlayer or whatever.

The landing page reminds me so much of the fake codec pages. I bet they might even have used the same template.

Bad on all fronts!

Jerome Segura

Malware ID: 67e252ee84a6b5d0e2706ccc3e36a106.zip

Malware ID: bea4676cddd48770b56c54db8b07f370.zip

Malware ID: c115d8251fe12d92567e55cad1d379e9.zip
Reply With Quote
Reply

« Previous Thread | Next Thread »

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump


Terms of Use