There’s no end in sight for the malspam campaign that we’ve been blogging about. This is a new round of spam emails we’ve received again with current events in the subject and body to get the user to click the link. The file get_flash_update.exe is still being pushed with these websites. They are still changing the landing page as you’ll see below. Some are on the same domains, but different landing pages (livestreaming.html, top.html, whatsup.html).
Warning: These sites are active. Proceed at your own risk.
hxxp://chantal-carlioz.fr/livestreaming.html
hxxp://didierbrockly.info/livestreaming.html
hxxp://jabezinformatica.com/livestreaming.html
hxxp://jugendtanzgruppe.de/livestreaming.html
hxxp://ministerstwo.nazwa.pl/livestreaming.html
hxxp://moveonforu.oranc.co.kr/livestreaming.html
hxxp://quimigama.net/livestreaming.html
hxxp://rmodelismo.com/livestreaming.html
hxxp://rogger.it/livestreaming.html
hxxp://sabineanton.de/livestreaming.html
hxxp://scemprestimoconsignado.com.br/livestreaming.html
hxxp://steveellery.com/livestreaming.html
hxxp://thalies.com/livestreaming.html
hxxp://www.femyp.com/livestreaming.html
hxxp://www.firma-thummerer.de/livestreaming.html
hxxp://www.nawaro-management.de/livestreaming.html
hxxp://www.outwork-for-you.de/livestreaming.html
hxxp://www.porzellanklinik-hinz.de/livestreaming.html
hxxp://www.restekiste.com/livestreaming.html
hxxp://www.tch-clubhaus.de/livestreaming.html
hxxp://z0l7.com/livestreaming.html
hxxp://duka-coaching.dk/top.html
hxxp://www.promo2.es/top.html
hxxp://fedecopy.com.ar/top.html
hxxp://www.urresti.es/top.html
hxxp://www.browsetomy.gmxhome.de/top.html
hxxp://www.aquasphere.cz/top.html
hxxp://halkjaer.biz/whatsup.html
hxxp://frankietomattos.com/whatsup.html
hxxp://duka-coaching.dk/whatsup.html
hxxp://manuelarodriguez.com.br/whatsup.html
hxxp://snoopen.de/whatsup.html


any ideas what cryptor/packer they are using on these files?
I haven’t had the chance to look at it but here are the first 64 bytes from the EP. Now I need to find the time to disassemble. 68 74 0E FB 00 33 EB 5D 33 D9 3A C6 81 C8 E8 E6 74 02 33 D0 53 8B FA 40 5D 42 BE 00 00 20 00 40 85 C8 4F F9 8D 1D C8 2D 47 01 84 C4 8B D5 81 F8 19 E0 81 02 68 95 F4 A9 00 4D 84 CB 84 CA 57 4F