29
Jul
08

New URL redirecting to malicious codec (VIDEO)

We have detected a new URL promoting various malicious “codec” binaries.

Update Here (7/30/08)

URL: hxxp://winxp-antivirus.com (Proceed at your own risk)

The first site we were redirected to prompted us to download wmcodec_upgrade.exe and upon running that the following files were created:

C:\WINDOWS\system32\RichVideoCodec.dll
C:\Program Files\RichVideoCodec\escan.exe
C:\Program Files\RichVideoCodec\InstallRegerLib.dll
C:\DOCUME~1\User\LOCALS~1\Temp\nsw8.tmp\System.dll
Source: SunBelt Sandbox

VirusTotal: Result: 6/35 (17.14%)

Upon reloading winxp-antivirus.com we were redirected over to porntubev20.com and prompted to download a codec to watch pornography clips.

The codec file for porntubev20.com pointed to hxxp://codechost.com/codecpack.v.1.0.89.exe

VirusTotal: Result: 11/35 (31.43%) (3 suspicious)

You may see a video of our encounter here: (Pornography omitted)

The Camtasia Studio video content presented here requires JavaScript to be enabled and the latest version of the Macromedia Flash Player. If you are you using a browser with JavaScript disabled please enable it now. Otherwise, please update your version of the free Flash Player by downloading here.


3 Responses to “New URL redirecting to malicious codec (VIDEO)”


  1. 1 Tam Jul 30th, 2008 at 5:56 am

    I feel that I should tell you the porn that was censored out was Not censored out on the very last frame, so when the video ends, and says ‘Replay,’ you see a great shot of NSFW material.

    Also, what programs do you use for you screen capturing and editing?

  2. 2 lithium Jul 30th, 2008 at 6:48 am

    Thank you for bringing it to my attention. I have replaced the video with a newer version that does not have the NSFW last frame.

    I am using Camtasia Studio by TechSmith to capture and edit video.

  1. 1 investigated #winxp-antivirus.com #mortgage-e.biz at Malware Database Pingback on Jul 30th, 2008 at 2:34 am

Leave a Reply

You must login to post a comment.




SANDBOX

SANDBOX ANALYSIS PAGE




 

July 2008
M T W T F S S
« Jun   Aug »
 123456
78910111213
14151617181920
21222324252627
28293031