Archive for January, 2009

25
Jan

New Rogue: Total Defender

PandaLabs reports that a new Rogue Antivirus program called Total Defender appeared over the weekend.


The following data is included for informational purposes only. Please do not attempt to view or download files from the website.

Domain: Total-Defender. com
IP: 94.247.2.41
Country: Latvia
Host: DATORU EXPRESS SERVISS Ltd.
Organization: ZlKon

File: total-defender-setup.exe

Total Defender Rogue Antivirus

Connects to:

0    200    HTTP    94.247.2.41    /ck.php    21
1    200    HTTP    94.247.2.41    /tdd.php?i=1
2    200    HTTP    94.247.2.41    /ck.php
3    301    HTTP    94.247.2.41    /tdp.php?ak=24DIGITHASH
4    200    HTTP    CONNECT    pp-pay.net:443
5    200    HTTP    CONNECT    pp-pay.net:443
6    200    HTTP    CONNECT    pp-pay.net:443
7    200    HTTP    CONNECT    bill-support.com:443

Additional Info:

An interesting thing we noticed is that the Rogue did not attempt to scare us into purchasing it, rather telling us that the computer was secure after the scan.  The Rogue authors are probably doing this to keep a high amount of Rogue installations active for the purposes of data theft or for hire services.

Total Defender Rogue Antivirus

09
Jan

Fake news and CNN.com websites featuring malware

A new attack involving fake news and CNN websites is spreading malware.  The attack is very similar to the Classmates.com attack where an email is sent to the victim with a link to a fake CNN.COM website that features a fake video that is really a trojan and rootkit.

Interestingly, the content looks like it was ripped off of CNN’s website because the links referenced CNN.com content.

WARNING: Websites hosting malicious content!fake-cnn-site-with-fake-video

Domains involved:
createnewsforccn.com
downloadplayersnews.com
enemyisraelattack.com
exlporernews.com
israelgazaconflict.com
newsforusacnn.com
startinstalladobe.com

Fake video malware file:
Adobe_Player10.exe

–mwdisector




SANDBOX

SANDBOX ANALYSIS PAGE




 

January 2009
M T W T F S S
« Dec   Feb »
 1234
567891011
12131415161718
19202122232425
262728293031