Home > ParetoLogic Blogs > Malware Diaries > New ad-clicker Trojan
Reply
 
Thread Tools Display Modes
  #1  
Old 07-01-2009, 01:54 AM
Michael Michael is offline
Administrator
Join Date: May 2007
Posts: 313
Default New ad-clicker Trojan

Our Honeypots caught this drive-by download from the following site:

sid

Looks like another blog... the word 'porn' is used, well, abundantly.

The site is registered to some guy in Panama.

tube

Other domains sharing nameserver:

tube2

They all point to this fake codec site:

01

The malware file, as with many fake codecs is from exe-xxx-file.com.

A quick Virus Total analysis reveals that this file is pretty much unknown to most AV vendors:

o2

If you happen to be infected with that Trojan, it will not go un-noticed:

lv

cof

cong

Those links are dangerous, stay away unless you know what you're doing.

Jerome Segura

Malware ID: 749ebc5c812c3d26022a4df847b11d09.zip
Reply With Quote
Reply

« Previous Thread | Next Thread »

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump


Terms of Use