R3v3rs3e's Blog

Posts Tagged ‘fake codec’

Porntube Anyone? Bonus Scareware!

Posted by Steve Espino on February 23, 2010

Blog entry here

Posted in Malicious Intent, Rogue Apps | Tagged: , , , , , , , , , | Leave a Comment »

Fake codec used by porn site

Posted by Steve Espino on December 7, 2009

Here’s another porn site distributing malware under the guise of video codecs:

hxxp://adultsvideo.cn/

Unsuspecting users wanting to view the adult videos are tricked into downloading and installing the fake codec.

The fake codec can be downloaded from this url:

hxxp://freebigutilites.com/ActiveX-Video-Codec.45092.exe

The server spits out files that have different MD5s each time.

ThreatExpert report here

PC Tools Spyware Doctor with Antivirus detects this fake codec as Trojan.FakeAlert.

Update:

Here’s another site that purports to host “Free Full Lenght Movie” porn clips and uses fake video codecs in order to lure unsuspecting users into downloading and installing their rogue antivirus software:

hxxp://freeanalsextubemovies.com/video1483/porn/

Clicking anywhere on the video screen area gives us the following link to a file named video.exe:

hxxp://homeamateurclips.com/video/video.exe

The award-winning PC Tools Spyware Doctor with Antivirus blocks this fake software as RogueAntiSpyware.SecurityTool.

Posted in Malicious Intent | Tagged: , , , , , , , , , , , , | Leave a Comment »

Koobface on the Move, Serving Scareware

Posted by Steve Espino on September 18, 2009

The PC Tools Malware Research Centre has been seeing new movement on the koobface front Lately.

koob_fiddle

As koobface-serving domains are being taken down as early as the good guys discover them, the bad guys are at it and they respond by registering new ones. At the moment, their, C&C server is hosted in China with IP Address 61.235.117.83.

The bad guys are still using a fake facebook website, as well as posing as a fake codec, in order to distribute koobface.

fake_facebook

Clicking anywhere on the page, presents us with a file named setup.exe. Here are some of the IPs being used to distribute koobface:

koob_script

115.130.27.204
123.202.200.84
151.204.31.67
196.206.65.53
221.126.0.105
24.215.207.229
41.238.76.198
61.93.34.23
67.206.253.52
68.47.48.240
69.18.107.115
69.254.215.173
70.122.242.250
70.212.232.126
71.116.37.213
71.130.216.179
71.194.236.32
71.80.105.40
72.13.138.210
72.190.87.208
75.181.171.110
75.251.94.44
76.119.98.22
76.22.160.28
76.23.203.64
81.192.192.160
98.140.58.163
98.244.224.140
98.26.40.38
99.22.74.229

The javascript component being by used by koobface, remains bascically the same as before

And as before, koobface is still serving up scareware. From time to time, users are presented with a My Computer online scan, going through these domains:

rogue

gotrioscan(dot)com
plazec(dot)info

At some instances, we also get these warnings:

hardware_error
Internet_Antivirus_Pro

At the moment, these warnings are serving Internet Antivirus Pro.

In order to be protected against these attacks, users of PC Tools Spyware Doctor are advised to use the latest PC Tools update.

An earlier post about koobface can be found here.

Update:
Koobface has been going at it and here’s another one that spoofs youtube and serves koobface malware as a fake codec:

hxxp://71.197.170.226/d=www.marcellaburnard.com/0x3E8/view/console=yes/?go

Posted in Malicious Intent, Rogue Apps | Tagged: , , , , , , , , , , , , , , , , , , , | 4 Comments »

Porn site distributes scareware

Posted by Steve Espino on August 27, 2009

Another website has recently been spotted to be serving up malware in the guise of fake video codecs.

This one praises itself as “The Best Nude Celebrity Movie Site”
hxxp://alyssafan.net/1.html

face_codec

But in order to watch the any video, we would need to download and install their “Certified ActiveX video codec (VAC codec) use to protect content Copyrights”

The fake fake codec can be downloaded here:
hxxp://alyssafan.net/Mediacodec_v4.8.exe

One of the components used in this attack is an onfuscated javascript file that can be found in the %temp% folder.

obfuscated

This script translates to:

deobfuscated

This script downloads:
hxxp://ue4x08f5myqdl.cn/u3.exe

Which then gives us scareware Safety Center:

safetycenter

Beware of fake video codecs!

Posted in Uncategorized | Tagged: , , , , , , , , , , , , , , , | 2 Comments »

Eric Dane threesome video links used to serve DNS Changer malware

Posted by Steve Espino on August 19, 2009

cover

A recently leaked threesome sex tape, involving Grey’s Anatomy’s “McSteamy” Eric Dane and wife Rebecca Gayheart, has been circulating around the internet. And we all know that controversial stuff like these are often taken advantage of and used to distribute malware using techniques such as social engineering and SEO (search-engine optimization). Users of one particular website have been spotted to be talking about the sex tape. There was no video on the site itself so people wanting to see the video might be enticed to clicking the links posted by fraudulent users and are tricked into downloading and installing malware on their computers.

There’s one such post suggesting we go to hentaiplace.org to watch the leaked video:

3somecomment

Here the malware poses as a fake video codec Divxcoder that users need to install in order to watch the video.
hxxp://hentaiplace.org/play.php?id=Eric_Dane_and_Rebecca_Gayheart_sex_tape

hentaiplace

Following the download link hxxp://hentaiplace.org/promo.php, we are redirected to hxxp://fiopolosa.com/download/7933547766773d3dd846130c20090815/FlashCodecPlugin.exe

The malware presents the user with a License Agreement while doing its dubious deeds in the background. And you don’t even need to agree to the License Agreent to install the malware!

divxcoder

The malware changes the affected computer’s DNS settings to use the following IP Addresses as DNS servers:
85.255.112.80
85.255.112.168

This means that the affected computer’s will have to contact these IPs for name resolution and this gives the bad guys a really good opportunity to redirect users to fake websites and steal passwords, login details and other confidential information.

PCTools Spyware Doctor detects the malware as Trojan.DNS_Changer.

This malware employs Rootkit.TDSS and Trojan.TDSServ in order to hide its presence on the infected machine.

Posted in Malicious Intent | Tagged: , , , , , , , , , , , , , , , , , , , | Leave a Comment »

 
Follow

Get every new post delivered to your Inbox.