Archive for May 16th, 2009

16
May

Blackhat CEO – “Farrah Fawcett Dead?” search leads to more malware PART 2

I blogged a couple of days ago about how I was able to find a few domains that were redirecting users to malware installation sites. These sites install rogue anti-malware applications that can be difficult to remove and try to extort money from you. (See post) As we will see below there are new domains that are still triggered by this keyword combination. Just as with all of the others, you must first come from a search provider in order for the redirection to work. Else, you’ll just see a page full of keywords.

I searched tonight to see if there were anymore, newer domains doing this given the recent news that Farrah Fawcett’s health is not doing well. We wish her nothing but the best and this just shows that the malware creators will go to any length to lure users to the sites. As you can see in the image below the search I tried in Google. The malware site was listed on the front page, but it was the last listing.

WARNING: URL’s may still be active. Proceed at your own risk.

The redirection went as follows…

hxxp://ourlittleducky.com/wordpress/wp-rss2.php?indian-express/
redirects to
hxxp://m09b.com/in.cgi?2&parameter=indian%20express
redirects to
hxxp://antispyware-components.com/promo3/?aid=1504

Whois entry for ourlittleducky.com
Whois entry for m09b.com
Registrant: PrivacyProtect.org

Whois entry for antispyware-components.com
Registrant: PrivacyProtect.org
ns1.everydns.net, ns2.everydns.net, ns3.everydns.net, ns4.everydns.net

More domains with redirects to malware:
isgorg.ie
wardspace.co.uk

Screenshot of the Privacy Center rogue program that was installed through this test.

flash_player_plugin.exe (Privacy Center)
Result: 11/39 (28.21%)
MD5: f7b492a142c4cc20095e8a37a44b2380
VirusTotal
ThreatExpert
hxxp://antispyware-components.com/promo3/get.php?aid=1504&vname=flash_player_plugin

16
May

Database Update: 62 files (Low/Moderate Detection)

Here are more files to end the week. These files are available to our members.

WARNING: URL’s may still be active. Proceed at your own risk.

softwarefortubeview.40000.exe
Result: 5/39 (12.83%)
MD5: d7977d4e90e52116450128c1dc33e86d
VirusTotal
ThreatExpert
hxxp://kor-programms.com

file.exe
Result: 4/40 (10%)
MD5: 7bf02b4d263cc22ba6f99888364be6be
VirusTotal
ThreatExpert
hxxp://kor-programms.com

ip_fw.sys
Result: 23/40 (57.5%)
MD5: ae46124499ac8b85299fd4a7f9353acf
VirusTotal
ThreatExpert

bb.jpg (msa.exe)
Result: 33/40 (82.5%)
MD5: 7c83c1207da2c0735c2b9c07e7ad5944
VirusTotal
ThreatExpert
hxxp://pictureswall.com/werber/902

item.gif
Result: 19/40 (47.5%)
MD5: e134bc3cd600c1affa1b329e6b7178af
VirusTotal
ThreatExpert
hxxp://picturesoffline.com/item/6020ec9d217af4b04db4f17df84ced99f81f00106b72c0141e8988a0d0d9a9480e9cef2814e2d76e9/d0d

msxml71.dll
Result: 14/40 (35%)
MD5: 73fcc1c2a01b4a3b1c8ffb3585afa872
VirusTotal
ThreatExpert

perce.gif
Result: 11/40 (27.5%)
MD5: 701f6720bb85f65ce8335809e093abbf
VirusTotal
ThreatExpert
hxxp://imageempires.com/perce/70101c8d512a14b0dd94e18d18dcdd29f89f6080dbb240244e596890a03969284e7cafa8a4c2678e5/500

activex.exe
Result: 14/40 (35%)
MD5: ff068e4d7cbfded46f2840047afe606e
VirusTotal
ThreatExpert

http://yy12s.com/love

AsyncMac.sys
Result: 4/40 (10%)
MD5: b043e4e0b5489c1355c778e2a20ff2ba
VirusTotal
ThreatExpert

pcidump.sys
Result: 35/40 (87.5%)
MD5: f8b8a22f61d1923650f0cebfc24051d6
VirusTotal
ThreatExpert

13311437text.exe
Result: 25/40 (62.5%)
MD5: d4c817bf2e6d331e60f16cf982a6bb5b
VirusTotal
ThreatExpert

aa1.exe
Result: 33/40 (82.5%)
MD5: f3d1faf909bc5847a26ffaa78028b4ff
VirusTotal
ThreatExpert

ys7auTeZqZ8W.dll
Result: 33/40 (82.5%)
MD5: 7e976c38328a4f776de95c9537c4db58
VirusTotal
ThreatExpert

aa2.exe
Result: 17/40 (42.5%)
MD5: ea096f8666288564d1c27bd5f9be857c
VirusTotal
ThreatExpert

aa3.exe
Result: 33/40 (82.5%)
MD5: 45ce3972d01b6d3060f7ed1950805c04
VirusTotal
ThreatExpert

Hzs3R95W.dll
Result: 32/40 (80%)
MD5: 92f4c4a03551ca983e9902c6f6211799
VirusTotal
ThreatExpert

aa4.exe
Result: 25/40 (62.5%)
MD5: 179b3ef4a452c54a1b421c0afd7d4032
VirusTotal
ThreatExpert

v6yj3gxacYQU.dll
Result: 23/40 (57.5%)
MD5: 29e725f0d887f53d6f427176040206dd
VirusTotal
ThreatExpert

aa5.exe
Result: 25/40 (62.5%)
MD5: 30274dbdf439a8609a1089532df9deef
VirusTotal
ThreatExpert

efc0c52cc1.dll
Result: 24/40 (60%)
MD5: 0b6ef146ce078ff1dec20816270692ad
VirusTotal
ThreatExpert

aa6.exe
Result: 25/40 (62.5%)
MD5: 86f779c75be470270579c967b485dc47
VirusTotal
ThreatExpert

skcfujQ5EDN.dll
Result: 25/40 (62.5%)
MD5: 9e80167d5e0320101b57519c48e54a71
VirusTotal
ThreatExpert

aa7.exe
Result: 27/40 (67.50%)
MD5: d75f96a1a819ad11114eed7ef82235f8
VirusTotal
ThreatExpert

dhDhwS7fFW.dll
Result: 29/40 (72.5%)
MD5: 0cdc26468abfc7f5a57541ff3616fa96
VirusTotal
ThreatExpert

aa8.exe
Result: 26/40 (65%)
MD5: a6d6bcfd7d031e7737c4c77292cdaca1
VirusTotal
ThreatExpert

GaZ2AKyYG.dll
Result: 26/40 (65%)
MD5: f696bfa5e9e0ccba69907dd8558b1301
VirusTotal
ThreatExpert

aa9.exe
Result: 36/40 (90%)
MD5: fe3c31bc02c2b7ce835874c25e282ab2
VirusTotal
ThreatExpert

A1A6BC2E.dll
Result: 32/39 (82.06%)
MD5: b11c2cac6219d4f6e5f173547f7ab7b1
VirusTotal
ThreatExpert

aa10.exe
Result: 30/40 (75%)
MD5: 204e83c20959c436d2bd026e812b6fce
VirusTotal
ThreatExpert

ufQCU5.dll
Result: 27/40 (67.5%)
MD5: 30cd6210694eb623024d142d2d671a64
VirusTotal
ThreatExpert

aa11.exe
Result: 28/40 (70%)
MD5: 34d76b7c1b2adc67755d3c1e2454a851
VirusTotal
ThreatExpert

taNjsFa2tT2Dh.dll
Result: 29/40 (72.5%)
MD5: 29b86524c2d35617cb51acf05b03521a
VirusTotal
ThreatExpert

aa12.exe
Result: 26/40 (65%)
MD5: 58e13fa273fc3e02a07a9f5cd5b524b7
VirusTotal
ThreatExpert

704C3595.dll
Result: 26/40 (65%)
MD5: f4364d540312e910dfdd43988b79edac
VirusTotal
ThreatExpert

aa13.exe
Result: 26/40 (65%)
MD5: 518346935e8a05efc6701b18fb44b2f3
VirusTotal
ThreatExpert

wF87W8XjgDW5Es6tuA.dll
Result: 25/40 (62.5%)
MD5: 1749566118b25d2d7132118b88464ae3
VirusTotal
ThreatExpert

aa14.exe
Result: 26/40 (65%)
MD5: 58adda235f644a7468e7f3b28080a9a1
VirusTotal
ThreatExpert

aa15.exe
Result: 28/40 (70%)
MD5: 9865facb1c26daeeb629c858cf9c7991
VirusTotal
ThreatExpert

A0C86020.dll
Result: 29/40 (72.5%)
MD5: 4a8027ad128960568e07e6942dba7ceb
VirusTotal
ThreatExpert

aa16.exe
Result: 25/40 (62.5%)
MD5: ded5f396225f11d6c14bb9ae99ed729e
VirusTotal
ThreatExpert

yp77Tt3UCG74J.dll
Result: 23/39 (58.98%)
MD5: f6a963b74b626f219e7d3c7c1375dff2
VirusTotal
ThreatExpert

aa17.exe
Result: 27/40 (67.5%)
MD5: abcad41852e581b5aba35d698433ba5c
VirusTotal
ThreatExpert

qB5BKZy7vR5m.dll
Result: 25/40 (62.5%)
MD5: 8653dfef6e49dfda9df2b7af0618404d
VirusTotal
ThreatExpert

aa18.exe
Result: 34/40 (85%)
MD5: 95dd5c5511da8c8755b5b05efaf828f5
VirusTotal
ThreatExpert

elementwdao.dll
Result: 34/40 (85%)
MD5: 303785cc612532aae239b38c80dd6a2c
VirusTotal
ThreatExpert

aa19.exe
Result: 35/40 (87.5%)
MD5: 51e530accf7b1497cbf59fdfd013af35
VirusTotal
ThreatExpert

aa20.exe
Result: 34/40 (85%)
MD5: 2a2d0620cd59209665b2d59a91f3416f
VirusTotal
ThreatExpert

VnTU2WAqUcZA6.dll
Result: 33/40 (82.5%)
MD5: 9c1d01a02d6746cd30efaefd5944ee78
VirusTotal
ThreatExpert

aa21.exe
Result: 27/40 (67.5%)
MD5: 36364dc345ec0f0cfb69095e7f6d3a20
VirusTotal
ThreatExpert

08223B03.dll
Result: 29/40 (72.5%)
MD5: b2ebd5d8bf78fca27d443e0988cc5d9f
VirusTotal
ThreatExpert

aa22.exe
Result: 27/40 (67.5%)
MD5: 586c71aac36d21397ccc76f99a132053
VirusTotal
ThreatExpert

122B901E.dll
Result: 29/40 (72.5%)
MD5: 5408d7ac9672ced57ea5bc7a813077b4
VirusTotal
ThreatExpert

aa23.exe
Result: 24/40 (60%)
MD5: e5ba7046f1bd3c0d0d4f813a7b52c148
VirusTotal
ThreatExpert

aa24.exe
Result: 33/40 (82.5%)
MD5: c419b6f73bf5b43c27817681149fa2a2
VirusTotal
ThreatExpert

ed78ab9.dll
Result: 31/40 (77.5%)
MD5: 81fb4e0509836b35d679fe3dfb7c8475
VirusTotal
ThreatExpert

aa25.exe
Result: 38/40 (95%)
MD5: 1ab8c718cebe2b049c390469305a39d1
VirusTotal
ThreatExpert

aa26.exe (SGInit.exe)
Result: 28/40 (70%)
MD5: 6fa5ff1b3103d109a99029a54241a577
VirusTotal
ThreatExpert

SGCQ.dll
Result: 26/40 (65%)
MD5: 6d1aa7232af454468dff583b35503ecc
VirusTotal
ThreatExpert

aa27.exe
Result: 26/40 (65%)
MD5: c3d19c4179dbfa6b69b159592b1862d9
VirusTotal
ThreatExpert

JBn2ypqY23vWX.dll
Result: 25/40 (62.5%)
MD5: 7983b84ea8e739e0c239121cdf5e211a
VirusTotal
ThreatExpert

aa33.exe
Result: 18/40 (45%)
MD5: 0d23eb52afa504e4986130d590ab3d08
VirusTotal
ThreatExpert

aa34.exe
Result: 18/40 (45%)
MD5: 18c914d376251d0ce189e6b910ded4c4
VirusTotal
ThreatExpert




SANDBOX

SANDBOX ANALYSIS PAGE




 

May 2009
M T W T F S S
« Apr   Jun »
 123
45678910
11121314151617
18192021222324
25262728293031