Home > ParetoLogic Blogs > Malware Diaries > Antonella Barba used to deliver malware
Reply
 
Thread Tools Display Modes
  #1  
Old 06-13-2009, 01:32 AM
Michael Michael is offline
Administrator
Join Date: May 2007
Posts: 313
Default Antonella Barba used to deliver malware

American Idol singer Antonella Barba's name (and more!) *is being used in malware campaigns.

I found at least two different websites registered using her name, that are pushing malware.

barba2

barba3

The page is pretty straightforward... with the alleged video being the center of attention:

barba1

If you click on the video, it will redirect you to a page that tries to load streamviewer.40009.exe

barba4

The file is hosted on yet another domain created June 11, so still very recent.

barba5

A Robtex analysis reveals some interesting connections:

barba6

You can see the domain names for scareware programs:

barba7

The malware file is not very well detected:

barba8

A clue to what it might be doing as a payload is revealed by this Fiddler analysis:

barba9

It looks like some click fraud using ad banners:

barba11

barba12

Every now and again, amongst redirections and pop ups you will see it trying to push rogueware:

barba10

Once again, this is a reminder of how celebrities are used in malware attacks. Their private lives interest people, which makes them a prime target for hackers.

Warning: all links are live and can infect your PC.

Jerome Segura
Reply With Quote
Reply

« Previous Thread | Next Thread »

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump


Terms of Use