<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Malware Database &#187; Codec</title>
	<atom:link href="http://malwaredatabase.net/blog/index.php/cat/codec/feed/" rel="self" type="application/rss+xml" />
	<link>http://malwaredatabase.net/blog</link>
	<description>Malware Database is a group of security professionals and a few hobbyists who each contribute to a private distributed database of malicious binaries while raising awareness on current malware trends through our website.</description>
	<lastBuildDate>Fri, 16 Jul 2010 07:11:02 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Multiple domains targeting pornographic videos distributing malware codec</title>
		<link>http://malwaredatabase.net/blog/index.php/2009/07/08/multiple-domains-targeting-pornographic-videos-distributing-malware-codec/</link>
		<comments>http://malwaredatabase.net/blog/index.php/2009/07/08/multiple-domains-targeting-pornographic-videos-distributing-malware-codec/#comments</comments>
		<pubDate>Thu, 09 Jul 2009 02:01:02 +0000</pubDate>
		<dc:creator>djpnuemo</dc:creator>
				<category><![CDATA[Codec]]></category>
		<category><![CDATA[Database Update]]></category>
		<category><![CDATA[Infection]]></category>
		<category><![CDATA[Low Detection]]></category>
		<category><![CDATA[Malicious Domains]]></category>
		<category><![CDATA[Malware]]></category>

		<guid isPermaLink="false">http://malwaredatabase.net/blog/?p=1968</guid>
		<description><![CDATA[Found these sites today while browsing on Google Video.  This redirection is triggered from having a video.google.com referrer and pushes the user through a few domains to redirect and download content.  It may be triggered by other video sites as well.  This is offering an HD codec for flash player and features a cute installation [...]]]></description>
			<content:encoded><![CDATA[<p>Found these sites today while browsing on Google Video.  This redirection is triggered from having a video.google.com referrer and pushes the user through a few domains to redirect and download content.  It may be triggered by other video sites as well.  This is offering an HD codec for flash player and features a cute installation process when you visit the site.</p>
<p>hxxp://best.viralprn.net<br />
<em><strong>Redirects to<br />
</strong></em>hxxp://only.hdpornr.net<br />
<em><strong>Loads files from</strong></em><br />
hxxp://tvcodec.net</p>
<p><img src="http://malwaredatabase.net/blog/wp-content/uploads/2009/07/hdporn.JPG" alt="" /></p>
<p><a href="http://whois.sc/viralprn.net" target="_blank">Whois entry for viralprn.net</a> 88.80.19.191</p>
<p><a href="http://whois.sc/hdpornr.net" target="_blank">Whois entry for hdpornr.net</a> 195.95.151.178</p>
<p><a href="http://whois.sc/tvcodec.net" target="_blank">Whois entry for tvcodec.net</a> 91.194.10.60<br />
PrivacyProtect.org<br />
Domain Admin (contact@privacyprotect.org)<br />
P.O. Box 97<br />
Note &#8211; All Postal Mails Rejected, visit Privacyprotect.org<br />
Moergestel<br />
null,5066 ZH<br />
NL<br />
Tel. +45.36946676</p>
<p><a href="http://whois.sc/hdenabled.com" target="_blank">Whois entry for hdenabled.com</a> 213.163.66.241</p>
<p><strong>Flash.Player.HD.v10.0.exe</strong><br />
Result: <span id="porcentaje"><span style="color: red;">12</span>/41 (29.27%)</span><br />
MD5: 947828203c38f7cc2e98277076b747a0<br />
<a href="http://www.virustotal.com/analisis/4dad8759f6e7d5a3cd1e1a450c01f80d1535b68acd8ae39f1177672278a0951f-1247104583" target="_blank">VirusTotal</a><br />
<a href="http://www.threatexpert.com/report.aspx?md5=947828203c38f7cc2e98277076b747a0" target="_blank">ThreatExpert Analysis</a><br />
hxxp://hdenabled.com/download/5a6a576343673d3d050cf77920090701/</p>
]]></content:encoded>
			<wfw:commentRss>http://malwaredatabase.net/blog/index.php/2009/07/08/multiple-domains-targeting-pornographic-videos-distributing-malware-codec/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New malware domain: exe-site.com</title>
		<link>http://malwaredatabase.net/blog/index.php/2009/07/08/new-malware-domain-exe-site-com/</link>
		<comments>http://malwaredatabase.net/blog/index.php/2009/07/08/new-malware-domain-exe-site-com/#comments</comments>
		<pubDate>Wed, 08 Jul 2009 14:34:22 +0000</pubDate>
		<dc:creator>djpnuemo</dc:creator>
				<category><![CDATA[Codec]]></category>
		<category><![CDATA[Database Update]]></category>
		<category><![CDATA[Low Detection]]></category>
		<category><![CDATA[Malicious Domains]]></category>
		<category><![CDATA[Malware]]></category>

		<guid isPermaLink="false">http://malwaredatabase.net/blog/?p=1964</guid>
		<description><![CDATA[hxxp://go-go-tube.com/xplays.php?id=40069
Whois entry for exe-site.com exe-site.com
Queenie Ziegler (queeziegl@gmail.com)
4806 Green Avenue
Fremont
California,94536
US
Tel. +001.34980976583
streamviewer.40069.exe
Result: 0/40 (0%)
MD5: 7f14d9626761ac467f85b542028259e3
VirusTotal
ThreatExpert Analysis
hxxp://exe-site.com/
]]></description>
			<content:encoded><![CDATA[<p>hxxp://go-go-tube.com/xplays.php?id=40069</p>
<p><a href="http://whois.sc/exe-site.com" target="_blank">Whois entry for exe-site.com</a> exe-site.com<br />
Queenie Ziegler (queeziegl@gmail.com)<br />
4806 Green Avenue<br />
Fremont<br />
California,94536<br />
US<br />
Tel. +001.34980976583</p>
<p><strong>streamviewer.40069.exe</strong><br />
Result: <span id="porcentaje"><span style="color: red;">0</span>/40 (0%)</span><br />
MD5: 7f14d9626761ac467f85b542028259e3<br />
<a href="http://www.virustotal.com/analisis/2ac431d9930be53375de4560db1796fc265ccc8c681177f2aec0d5d1ace10966-1247063821" target="_blank">VirusTotal</a><br />
<a href="http://www.threatexpert.com/report.aspx?md5=7f14d9626761ac467f85b542028259e3" target="_blank">ThreatExpert Analysis</a><br />
hxxp://exe-site.com/</p>
]]></content:encoded>
			<wfw:commentRss>http://malwaredatabase.net/blog/index.php/2009/07/08/new-malware-domain-exe-site-com/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Fake codec website: update-adobe.fdns.net</title>
		<link>http://malwaredatabase.net/blog/index.php/2009/06/23/fake-codec-website-update-adobe-fdns-net/</link>
		<comments>http://malwaredatabase.net/blog/index.php/2009/06/23/fake-codec-website-update-adobe-fdns-net/#comments</comments>
		<pubDate>Tue, 23 Jun 2009 15:27:02 +0000</pubDate>
		<dc:creator>djpnuemo</dc:creator>
				<category><![CDATA[Codec]]></category>
		<category><![CDATA[Database Update]]></category>
		<category><![CDATA[Infection]]></category>
		<category><![CDATA[Malicious Domains]]></category>
		<category><![CDATA[Malicious Links]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Malware Distribution]]></category>

		<guid isPermaLink="false">http://malwaredatabase.net/blog/?p=1835</guid>
		<description><![CDATA[hxxp://nevvsvine.com/go.php?sid=6
Redirects to
hxxp://q5.awardspace.com/
awardspace.com and fdns.net are legimate hosts with accounts that are being used to host and redirect to malware.
codec.exe
Result: 30/41 (73.17%)
MD5: d44b9453d4aca0a4e309fb5708b107d0
VirusTotal
ThreatExpert Analysis
hxxp://update-adobe.fdns.net/codec/
]]></description>
			<content:encoded><![CDATA[<p>hxxp://nevvsvine.com/go.php?sid=6<br />
<i><strong>Redirects to</strong></i><br />
hxxp://q5.awardspace.com/</p>
<p>awardspace.com and fdns.net are legimate hosts with accounts that are being used to host and redirect to malware.</p>
<p><strong>codec.exe</strong><br />
Result: <span id="porcentaje"><span style="color: red;">30</span>/41 (73.17%)</span><br />
MD5: d44b9453d4aca0a4e309fb5708b107d0<br />
<a href="http://www.virustotal.com/analisis/fa27b926ed620674993d2178d96e48084d2e67d86869a50a4439e17ba68f3fe0-1245770321" target="_blank">VirusTotal</a><br />
<a href="http://www.threatexpert.com/report.aspx?md5=d44b9453d4aca0a4e309fb5708b107d0" target="_blank">ThreatExpert Analysis</a><br />
hxxp://update-adobe.fdns.net/codec/</p>
]]></content:encoded>
			<wfw:commentRss>http://malwaredatabase.net/blog/index.php/2009/06/23/fake-codec-website-update-adobe-fdns-net/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New malware domain: exe-center.com</title>
		<link>http://malwaredatabase.net/blog/index.php/2009/06/18/new-malware-domain-exe-center-com/</link>
		<comments>http://malwaredatabase.net/blog/index.php/2009/06/18/new-malware-domain-exe-center-com/#comments</comments>
		<pubDate>Thu, 18 Jun 2009 15:16:09 +0000</pubDate>
		<dc:creator>djpnuemo</dc:creator>
				<category><![CDATA[Codec]]></category>
		<category><![CDATA[Database Update]]></category>
		<category><![CDATA[Infection]]></category>
		<category><![CDATA[Malicious Domains]]></category>
		<category><![CDATA[Malware]]></category>

		<guid isPermaLink="false">http://malwaredatabase.net/blog/?p=1806</guid>
		<description><![CDATA[http://tubes-portal.com/xplays.php?id=40014&#038;name=The+Ultimate+Fighter+S09E12+HDTV+-aAF
Whois entry for exe-center.com 64.20.38.171
PrivacyProtect.org
Domain Admin (contact@privacyprotect.org)
P.O. Box 97
Note &#8211; All Postal Mails Rejected, visit Privacyprotect.org
Moergestel
null,5066 ZH
NL
Tel. +45.36946676 
streamviewer.40014.exe
Result: 2/41 (4.88%)
MD5: 717d8bd4b640554b83735c41f32178cd
VirusTotal
ThreatExpert Analysis
hxxp://exe-center.com/
]]></description>
			<content:encoded><![CDATA[<p>http://tubes-portal.com/xplays.php?id=40014&#038;name=The+Ultimate+Fighter+S09E12+HDTV+-aAF</p>
<p><a href="http://whois.domaintools.com/exe-center.com" target="_blank">Whois entry for exe-center.com</a> 64.20.38.171<br />
PrivacyProtect.org<br />
Domain Admin (contact@privacyprotect.org)<br />
P.O. Box 97<br />
Note &#8211; All Postal Mails Rejected, visit Privacyprotect.org<br />
Moergestel<br />
null,5066 ZH<br />
NL<br />
Tel. +45.36946676 </p>
<p><strong>streamviewer.40014.exe</strong><br />
Result: <span id="porcentaje"><span style="color: red;">2</span>/41 (4.88%)</span><br />
MD5: 717d8bd4b640554b83735c41f32178cd<br />
<a href="http://www.virustotal.com/analisis/e36011e7c7aaa069ff03ec08ff2b3393949e7b3dc8f828801d6585583d579c34-1245338268" target="_blank">VirusTotal</a><br />
<a href="http://www.threatexpert.com/report.aspx?md5=717d8bd4b640554b83735c41f32178cd" target="_blank">ThreatExpert Analysis</a><br />
hxxp://exe-center.com/</p>
]]></content:encoded>
			<wfw:commentRss>http://malwaredatabase.net/blog/index.php/2009/06/18/new-malware-domain-exe-center-com/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Database Update: 11 files (Low/Moderate Detection)</title>
		<link>http://malwaredatabase.net/blog/index.php/2009/06/14/database-update-11-files-lowmoderate-detection/</link>
		<comments>http://malwaredatabase.net/blog/index.php/2009/06/14/database-update-11-files-lowmoderate-detection/#comments</comments>
		<pubDate>Mon, 15 Jun 2009 02:08:34 +0000</pubDate>
		<dc:creator>djpnuemo</dc:creator>
				<category><![CDATA[Codec]]></category>
		<category><![CDATA[Database Update]]></category>
		<category><![CDATA[Malicious Domains]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Rogue Security Software]]></category>

		<guid isPermaLink="false">http://malwaredatabase.net/blog/?p=1760</guid>
		<description><![CDATA[Files added to our database today.
WARNING: URL&#8217;s still may be active. Proceed at your own risk.
load.exe
Result: 16/40 (35%)
MD5: 9b8b5fe782fa05bcfc5e4a181935b776
VirusTotal
ThreatExpert Analysis
hxxp://playslotbet.cn:8080/load.php
remtool_conf.exe
Result: 14/40 (35%)
MD5: 4cf579669a74db8eee1b83568ec10132
VirusTotal
ThreatExpert Analysis
hxxp://windowsupdate.microsoft.com.ssl.newmail.ru/updates=removalid928hduwuHDDIEop/cookiesession0-conflicker-downad/

webexplorer.exe
Result: 4/40 (10.00%)
MD5: ba3355a73d69027d6fff6472a2a59ff3
VirusTotal
ThreatExpert Analysis

streamviewer.40014.exe
Result: 17/40 (42.5%)
MD5: 1660088c2b0e7e024404c6638c2b357a
VirusTotal
ThreatExpert Analysis
load.exe
Result: 1/39 (2.57%)
MD5: 21bc40db23465c8bb8655b3074514562
VirusTotal
ThreatExpert Analysis
hxxp://filmoflife.cn:8080/load.php
update.exe or svchost.exe
Result: 3/40 (7.5%)
MD5: 6d4349e2c1379d05369e5b50e1d5a74e
VirusTotal
ThreatExpert Analysis
hxxp://naf77.biz/myy/load.php?id=0
update_901.pdf
Result: 7/40 (17.5%)
MD5: 62a0403b9acddd38ab47a003fa47288c
VirusTotal
Wepawet Analysis
hxxp://naf77.biz/myy/pdf.php
installer_70141.exe
Result: 13/40 (32.5%)
MD5: 543538619b77c28791e8092a737b2237
VirusTotal
ThreatExpert Analysis
hxxp://gojaxty.cn/

svchost.exe or dop.exe
Result: 15/40 (37.5%)
MD5: 6cf16e07d49dd0a8bff0c847d640dba5
VirusTotal
ThreatExpert [...]]]></description>
			<content:encoded><![CDATA[<p>Files added to our database today.</p>
<p><strong>WARNING:</strong> URL&#8217;s still may be active. Proceed at your own risk.</p>
<p><strong>load.exe</strong><br />
Result: <span id="porcentaje"><span style="color: red;">16</span>/40 (35%)</span><br />
MD5: 9b8b5fe782fa05bcfc5e4a181935b776<br />
<a href="http://www.virustotal.com/analisis/221c65f451cf9ee1ed7135792632c0e7d982f97389d315c42ff8130ac3c239f6-1245027935" target="_blank">VirusTotal</a><br />
<a href="http://www.threatexpert.com/report.aspx?md5=9b8b5fe782fa05bcfc5e4a181935b776" target="_blank">ThreatExpert Analysis</a><br />
hxxp://playslotbet.cn:8080/load.php</p>
<p><strong>remtool_conf.exe</strong><br />
Result: <span id="porcentaje"><span style="color: red;">14</span>/40 (35%)</span><br />
MD5: 4cf579669a74db8eee1b83568ec10132<br />
<a href="http://www.virustotal.com/analisis/d6523a0e49f206812c3c9e9181b719477f446e92add4cf132e6f2b79b2982081-1245027963" target="_blank">VirusTotal</a><br />
<a href="http://www.threatexpert.com/report.aspx?md5=4cf579669a74db8eee1b83568ec10132" target="_blank">ThreatExpert Analysis</a><br />
hxxp://windowsupdate.microsoft.com.ssl.newmail.ru/updates=removalid928hduwuHDDIEop/cookiesession0-conflicker-downad/</p>
<p style="padding-left: 30px;">
<strong>webexplorer.exe</strong><br />
Result: <span id="porcentaje"><span style="color: red;">4</span>/40 (10.00%)</span><br />
MD5: ba3355a73d69027d6fff6472a2a59ff3<br />
<a href="http://www.virustotal.com/analisis/446c62618d308bf0c882e1590af78f25550a2f412aa32a51d11450dcde904353-1244814540" target="_blank">VirusTotal</a><br />
<a href="http://www.threatexpert.com/report.aspx?md5=ba3355a73d69027d6fff6472a2a59ff3" target="_blank">ThreatExpert Analysis</a>
</p>
<p><strong>streamviewer.40014.exe</strong><br />
Result: <span id="porcentaje"><span style="color: red;">17</span>/40 (42.5%)</span><br />
MD5: 1660088c2b0e7e024404c6638c2b357a<br />
<a href="http://www.virustotal.com/analisis/b6bad5390d98d816b47f206a6e738fb26492b4dfc039135a4e2331e93cad05ec-1245027955" target="_blank">VirusTotal</a><br />
<a href="http://www.threatexpert.com/report.aspx?md5=1660088c2b0e7e024404c6638c2b357a" target="_blank">ThreatExpert Analysis</a></p>
<p><strong>load.exe</strong><br />
Result: <span id="porcentaje"><span style="color: red;">1</span>/39 (2.57%)</span><br />
MD5: 21bc40db23465c8bb8655b3074514562<br />
<a href="http://www.virustotal.com/analisis/4707f76fb8820981491a0a9c71509118d4a4fdb610547a4508b07ca5d14302b3-1245028143" target="_blank">VirusTotal</a><br />
<a href="http://www.threatexpert.com/report.aspx?md5=21bc40db23465c8bb8655b3074514562" target="_blank">ThreatExpert Analysis</a><br />
hxxp://filmoflife.cn:8080/load.php</p>
<p><strong>update.exe</strong> or <strong>svchost.exe</strong><br />
Result: <span id="porcentaje"><span style="color: red;">3</span>/40 (7.5%)</span><br />
MD5: 6d4349e2c1379d05369e5b50e1d5a74e<br />
<a href="http://www.virustotal.com/analisis/e08381984ea26103fa49c24c58026cd65e2da154b3497b205dc63de107e6193c-1245028349" target="_blank">VirusTotal</a><br />
<a href="http://www.threatexpert.com/report.aspx?md5=6d4349e2c1379d05369e5b50e1d5a74e" target="_blank">ThreatExpert Analysis</a><br />
hxxp://naf77.biz/myy/load.php?id=0</p>
<p><strong>update_901.pdf</strong><br />
Result: <span id="porcentaje"><span style="color: red;">7</span>/40 (17.5%)</span><br />
MD5: 62a0403b9acddd38ab47a003fa47288c<br />
<a href="http://www.virustotal.com/analisis/0b47ec6124c7a299ce4281c33b8c03f9ac5a7e4324e4d23210a32cfeb6f7d94b-1245028375" target="_blank">VirusTotal</a><br />
<a href="http://wepawet.cs.ucsb.edu/view.php?hash=62a0403b9acddd38ab47a003fa47288c&#038;type=js" target="_blank">Wepawet Analysis</a><br />
hxxp://naf77.biz/myy/pdf.php</p>
<p><strong>installer_70141.exe</strong><br />
Result: <span id="porcentaje"><span style="color: red;">13</span>/40 (32.5%)</span><br />
MD5: 543538619b77c28791e8092a737b2237<br />
<a href="http://www.virustotal.com/analisis/f3f4598017f350c31a05ec0d2d910193e4b25f96f1f0a1fad094b2d384918f22-1245029354" target="_blank">VirusTotal</a><br />
<a href="http://www.threatexpert.com/report.aspx?md5=543538619b77c28791e8092a737b2237" target="_blank">ThreatExpert Analysis</a><br />
hxxp://gojaxty.cn/</p>
<p style="padding-left: 30px;">
<strong>svchost.exe</strong> or <strong>dop.exe</strong><br />
Result: <span id="porcentaje"><span style="color: red;">15</span>/40 (37.5%)</span><br />
MD5: 6cf16e07d49dd0a8bff0c847d640dba5<br />
<a href="http://www.virustotal.com/analisis/e08381984ea26103fa49c24c58026cd65e2da154b3497b205dc63de107e6193c-1245030956" target="_blank">VirusTotal</a><br />
<a href="http://www.threatexpert.com/report.aspx?md5=6cf16e07d49dd0a8bff0c847d640dba5" target="_blank">ThreatExpert Analysis</a><br />
hxxp://antivirusplusnow.com/
</p>
<p style="padding-left: 30px;">
<strong>antivirus.exe</strong> or <strong>rundll32.exe</strong><br />
Result: <span id="porcentaje"><span style="color: red;">10</span>/39 (25.65%)</span><br />
MD5: d2d54a283f593c7a2d25be9de58592a3<br />
<a href="http://www.virustotal.com/analisis/138f6e7cee43d5b72ed5eecd06a679818a8ebcaa05ec31207e3bcdf8ebf321e6-1245031452" target="_blank">VirusTotal</a><br />
<a href="http://www.threatexpert.com/report.aspx?md5=d2d54a283f593c7a2d25be9de58592a3" target="_blank">ThreatExpert Analysis</a><br />
hxxp://antivirusplusnow.com/install/
</p>
<p style="padding-left: 30px;">
<strong>InternetExplorer.dll</strong><br />
Result: <span id="porcentaje"><span style="color: red;">12</span>/40 (30%)</span><br />
MD5: 669a64b42a4d9d90b4eadc35000f8656<br />
<a href="http://www.virustotal.com/analisis/2e23cb486cff25d0456f2b1e5ae17edf2cc03bbf0883241dd5bcb8cbbe01227e-1245031418" target="_blank">VirusTotal</a><br />
<a href="http://www.threatexpert.com/report.aspx?md5=669a64b42a4d9d90b4eadc35000f8656" target="_blank">ThreatExpert Analysis</a><br />
hxxp://antivirusplusnow.com/install/</p>
]]></content:encoded>
			<wfw:commentRss>http://malwaredatabase.net/blog/index.php/2009/06/14/database-update-11-files-lowmoderate-detection/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New malware domain: last-exe-portal.com</title>
		<link>http://malwaredatabase.net/blog/index.php/2009/06/13/new-malware-domain-last-exe-portal-com/</link>
		<comments>http://malwaredatabase.net/blog/index.php/2009/06/13/new-malware-domain-last-exe-portal-com/#comments</comments>
		<pubDate>Sat, 13 Jun 2009 16:21:59 +0000</pubDate>
		<dc:creator>djpnuemo</dc:creator>
				<category><![CDATA[Codec]]></category>
		<category><![CDATA[Malicious Domains]]></category>
		<category><![CDATA[Malware]]></category>

		<guid isPermaLink="false">http://malwaredatabase.net/blog/?p=1741</guid>
		<description><![CDATA[
Whois entry for last-exe-portal.com 64.20.38.171
Leota Allison (leotallison@gmail.com)
340 Wood Street
Saginaw
Michigan,48607
US
Tel. +001.97094875848

go-exe-go.com
gruzzilla.com
super-exe-home.com
streamviewer.40014.exe
Result: 12/40 (30%)
MD5: 1660088c2b0e7e024404c6638c2b357a
VirusTotal
 ThreatExpert Analysis
hxxp://last-exe-portal.com/
]]></description>
			<content:encoded><![CDATA[<p><img src="http://malwaredatabase.net/blog/wp-content/uploads/2009/06/codec.JPG"></p>
<p><a href="http://whois.sc/last-exe-portal.com" target="_blank">Whois entry for last-exe-portal.com</a> 64.20.38.171<br />
Leota Allison (leotallison@gmail.com)<br />
340 Wood Street<br />
Saginaw<br />
Michigan,48607<br />
US<br />
Tel. +001.97094875848</p>
<p><img src="http://malwaredatabase.net/blog/wp-content/uploads/2009/06/as8.png"><br />
go-exe-go.com<br />
gruzzilla.com<br />
super-exe-home.com</p>
<p><strong>streamviewer.40014.exe</strong><br />
Result: <span id="porcentaje"><span style="color: red;">12</span>/40 (30%)</span><br />
MD5: 1660088c2b0e7e024404c6638c2b357a<br />
<a href="http://www.virustotal.com/analisis/b6bad5390d98d816b47f206a6e738fb26492b4dfc039135a4e2331e93cad05ec-1244909825" target="_blank">VirusTotal</a><br />
<a href="http://www.threatexpert.com/report.aspx?md5=1660088c2b0e7e024404c6638c2b357a" target="_blank"> ThreatExpert Analysis</a><br />
hxxp://last-exe-portal.com/</p>
]]></content:encoded>
			<wfw:commentRss>http://malwaredatabase.net/blog/index.php/2009/06/13/new-malware-domain-last-exe-portal-com/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>New malware domain: my-exe-work.com</title>
		<link>http://malwaredatabase.net/blog/index.php/2009/06/11/new-malware-domain-my-exe-work-com/</link>
		<comments>http://malwaredatabase.net/blog/index.php/2009/06/11/new-malware-domain-my-exe-work-com/#comments</comments>
		<pubDate>Thu, 11 Jun 2009 21:27:24 +0000</pubDate>
		<dc:creator>djpnuemo</dc:creator>
				<category><![CDATA[Codec]]></category>
		<category><![CDATA[Database Update]]></category>
		<category><![CDATA[Malicious Domains]]></category>
		<category><![CDATA[Malware]]></category>

		<guid isPermaLink="false">http://malwaredatabase.net/blog/?p=1723</guid>
		<description><![CDATA[This was found from a known malware codec website.

http://hi-my-tube.com/xplays.php?id=40014&#038;name=david+carradine
Whois entry for my-exe-work.com 66.197.171.6
Scott Bradford (scttbrdfrd08@gmail.com)
4921 Oakridge Lane
Macon
Guam,31206
US
Tel. +001.97094875848 
streamviewer.40014.exe
Result: 5/40 (22.5%)
MD5: 7dafe64e443f60b9f512cd9d1526a595
VirusTotal
 ThreatExpert Analysis
hxxp://my-exe-work.com/streamviewer.40014.exe
]]></description>
			<content:encoded><![CDATA[<p>This was found from a known malware codec website.</p>
<p><img src="http://malwaredatabase.net/blog/wp-content/uploads/2009/06/codec.jpg" alt="" /></p>
<p>http://hi-my-tube.com/xplays.php?id=40014&#038;name=david+carradine</p>
<p><a href="http://whois.sc/my-exe-work.com" target="_blank">Whois entry for my-exe-work.com</a> 66.197.171.6<br />
Scott Bradford (scttbrdfrd08@gmail.com)<br />
4921 Oakridge Lane<br />
Macon<br />
Guam,31206<br />
US<br />
Tel. +001.97094875848 </p>
<p><strong>streamviewer.40014.exe</strong><br />
Result: <span id="porcentaje"><span style="color: red;">5</span>/40 (22.5%)</span><br />
MD5: 7dafe64e443f60b9f512cd9d1526a595<br />
<a href="http://www.virustotal.com/analisis/7ebe30a346ba0bb1fdeaca8057a33d762554c09a5481c295fa1e25445a7df20b-1244755531" target="_blank">VirusTotal</a><br />
<a href="http://www.threatexpert.com/report.aspx?md5=7dafe64e443f60b9f512cd9d1526a595" target="_blank"> ThreatExpert Analysis</a><br />
hxxp://my-exe-work.com/streamviewer.40014.exe</p>
]]></content:encoded>
			<wfw:commentRss>http://malwaredatabase.net/blog/index.php/2009/06/11/new-malware-domain-my-exe-work-com/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New codec domains: exe-file-boom.com &amp; hi-my-tube.com</title>
		<link>http://malwaredatabase.net/blog/index.php/2009/06/10/new-codec-domains-exe-file-boomcom-hi-my-tubecom/</link>
		<comments>http://malwaredatabase.net/blog/index.php/2009/06/10/new-codec-domains-exe-file-boomcom-hi-my-tubecom/#comments</comments>
		<pubDate>Wed, 10 Jun 2009 20:28:03 +0000</pubDate>
		<dc:creator>djpnuemo</dc:creator>
				<category><![CDATA[Blackhat SEO]]></category>
		<category><![CDATA[Codec]]></category>
		<category><![CDATA[Database Update]]></category>
		<category><![CDATA[Malicious Domains]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Rogue Security Software]]></category>

		<guid isPermaLink="false">http://malwaredatabase.net/blog/?p=1694</guid>
		<description><![CDATA[Found these domains spreading a fake codec today.  Bother were registered today.

Whois entry for exe-file-boom.com 66.197.171.6
Isaac Donnelly (isaacdonn@gmail.com)
3711 Eastland Avenue
Hattiesburg
Mississippi,39402
US
Tel. +001.88795890983

exe-file-boom.com
my-exe-profile.com
web-exe-depositary.com
mp3downloadablesongs.com
Whois entry for hi-my-tube.com 216.240.143.7
Stephine Smith (stsmisss@gmail.com)
2810 Kovar Road
Westboro
Maine,01581
US
Tel. +001.76778989543

*.best-crystal-tube.com
*.big-tube-list.com
*.champtube2009.com
*.chipeztube2009.com
*.get-mega-tube.com
*.happy-tube-video.com
*.my-flare-tube.com
*.my-tube-zone.com
*.powerful-tube.com
*.tubecollection2009.com
*.video-tube-dot.com
*.wondertubes2009.com
better-tube-show.com
big-tube-list.com
fllcorp.com
get-mega-tube.com
megacooltubes2009.com
ns2.best-crystal-tube.com
ns2.big-tube-list.com
ns2.champtube2009.com
ns2.chipeztube2009.com
ns2.get-mega-tube.com
ns2.happy-tube-video.com
ns2.megaporntubes09.com
ns2.my-flare-tube.com
ns2.my-tube-zone.com
ns2.powerful-tube.com
ns2.tall-tubex.com
ns2.tube-xxx-tv2009.com
ns2.tubecollection2009.com
ns2.video-tube-dot.com
ns2.wondertubes2009.com
premier-tube-site.com
sunny-tube-house.com
www.best-crystal-tube.com
www.big-tube-list.com
www.champtube2009.com
www.chipeztube2009.com
www.get-mega-tube.com
www.my-tube-zone.com
streamviewer.40014.exe
Result: 9/40 (22.5%)
MD5: 78a3631fbc7d93ce07c33233416a2176
VirusTotal
 ThreatExpert Analysis
hxxp://exe-file-boom.com/streamviewer.40014.exe
a.exe
Result: 11/39 (28.21%)
MD5: 2e326fd4048bdf28308a9bb5ced08ed7
VirusTotal
ThreatExpert Analysis
hxxp://thenewpic.com/item/a5acc232141aba8b24603e1b24eb084d0e020a6c16c76e38e6582142a6c4df427ca48b89cc4e0cf0a/4400d031142/titem.gif
b.exe or msa.exe
Result: 5/39 (12.83%)
MD5: c665052347ce07a9626c6cdcdb0e56d8
 VirusTotal
 ThreatExpert Analysis
hxxp://theimagesphoto.com/werber/04d04071f42/217.gif 
]]></description>
			<content:encoded><![CDATA[<p>Found these domains spreading a fake codec today.  Bother were registered today.</p>
<p><img src="http://malwaredatabase.net/blog/wp-content/uploads/2009/06/codec.jpg" alt="" /></p>
<p><a href="http://whois.sc/exe-file-boom.com" target="_blank">Whois entry for exe-file-boom.com</a> 66.197.171.6<br />
Isaac Donnelly (isaacdonn@gmail.com)<br />
3711 Eastland Avenue<br />
Hattiesburg<br />
Mississippi,39402<br />
US<br />
Tel. +001.88795890983</p>
<p><img src="http://malwaredatabase.net/blog/wp-content/uploads/2009/06/as21.png" alt="" /><br />
exe-file-boom.com<br />
my-exe-profile.com<br />
web-exe-depositary.com<br />
mp3downloadablesongs.com</p>
<p><a href="http://whois.sc/hi-my-tube.com" target="_blank">Whois entry for hi-my-tube.com</a> 216.240.143.7<br />
Stephine Smith (stsmisss@gmail.com)<br />
2810 Kovar Road<br />
Westboro<br />
Maine,01581<br />
US<br />
Tel. +001.76778989543</p>
<p><a href="http://malwaredatabase.net/blog/wp-content/uploads/2009/06/as5.png" target="_blank" rel="lightbox[1694]"><img src="http://malwaredatabase.net/blog/wp-content/uploads/2009/06/as5.png" alt="" width="268" height="600" /></a><br />
*.best-crystal-tube.com<br />
*.big-tube-list.com<br />
*.champtube2009.com<br />
*.chipeztube2009.com<br />
*.get-mega-tube.com<br />
*.happy-tube-video.com<br />
*.my-flare-tube.com<br />
*.my-tube-zone.com<br />
*.powerful-tube.com<br />
*.tubecollection2009.com<br />
*.video-tube-dot.com<br />
*.wondertubes2009.com<br />
better-tube-show.com<br />
big-tube-list.com<br />
fllcorp.com<br />
get-mega-tube.com<br />
megacooltubes2009.com<br />
ns2.best-crystal-tube.com<br />
ns2.big-tube-list.com<br />
ns2.champtube2009.com<br />
ns2.chipeztube2009.com<br />
ns2.get-mega-tube.com<br />
ns2.happy-tube-video.com<br />
ns2.megaporntubes09.com<br />
ns2.my-flare-tube.com<br />
ns2.my-tube-zone.com<br />
ns2.powerful-tube.com<br />
ns2.tall-tubex.com<br />
ns2.tube-xxx-tv2009.com<br />
ns2.tubecollection2009.com<br />
ns2.video-tube-dot.com<br />
ns2.wondertubes2009.com<br />
premier-tube-site.com<br />
sunny-tube-house.com<br />
www.best-crystal-tube.com<br />
www.big-tube-list.com<br />
www.champtube2009.com<br />
www.chipeztube2009.com<br />
www.get-mega-tube.com<br />
www.my-tube-zone.com</p>
<p><strong>streamviewer.40014.exe</strong><br />
Result: <span id="porcentaje"><span style="color: red;">9</span>/40 (22.5%)</span><br />
MD5: 78a3631fbc7d93ce07c33233416a2176<br />
<a href="http://www.virustotal.com/analisis/28eb9951aa20bb5c9e81e1447cf98d3863c671d45d05f21df5c973d06f4b8c12-1244664829" target="_blank">VirusTotal</a><br />
<a href="http://www.threatexpert.com/report.aspx?md5=78a3631fbc7d93ce07c33233416a2176" target="_blank"> ThreatExpert Analysis</a><br />
hxxp://exe-file-boom.com/streamviewer.40014.exe</p>
<p style="padding-left: 30px;"><strong>a.exe</strong><br />
Result: <span id="porcentaje"><span style="color: red;">11</span>/39 (28.21%)</span><br />
MD5: 2e326fd4048bdf28308a9bb5ced08ed7<br />
<a href="http://www.virustotal.com/analisis/5c5533a40241b20e8f099f8dd7f0e17b023b576cc08811ce12491a0a5d42f161-1244665504" target="_blank">VirusTotal</a><br />
<a href="http://www.threatexpert.com/report.aspx?md5=2e326fd4048bdf28308a9bb5ced08ed7" target="_blank">ThreatExpert Analysis</a><br />
hxxp://thenewpic.com/item/a5acc232141aba8b24603e1b24eb084d0e020a6c16c76e38e6582142a6c4df427ca48b89cc4e0cf0a/4400d031142/titem.gif</p>
<p style="padding-left: 30px;"><strong>b.exe </strong>or <strong>msa.exe</strong><br />
Result: <span id="porcentaje"><span style="color: red;">5</span>/39 (12.83%)</span><br />
MD5: c665052347ce07a9626c6cdcdb0e56d8<br />
<a href="http://www.virustotal.com/analisis/74cb7af289500833e7b456291a90c993e6db6a88a55a0bf364f1eaab9e205b94-1244665507" target="_blank"> VirusTotal</a><br />
<a href="http://www.threatexpert.com/report.aspx?md5=c665052347ce07a9626c6cdcdb0e56d8" target="_blank"> ThreatExpert Analysis<br />
</a>hxxp://theimagesphoto.com/werber/04d04071f42/217.gif<a href="http://www.threatexpert.com/report.aspx?md5=c665052347ce07a9626c6cdcdb0e56d8" target="_blank"> </a></p>
]]></content:encoded>
			<wfw:commentRss>http://malwaredatabase.net/blog/index.php/2009/06/10/new-codec-domains-exe-file-boomcom-hi-my-tubecom/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New rogue domain: mybest-xxx.com</title>
		<link>http://malwaredatabase.net/blog/index.php/2009/06/07/new-rogue-domain-mybest-xxxcom/</link>
		<comments>http://malwaredatabase.net/blog/index.php/2009/06/07/new-rogue-domain-mybest-xxxcom/#comments</comments>
		<pubDate>Sun, 07 Jun 2009 20:59:53 +0000</pubDate>
		<dc:creator>djpnuemo</dc:creator>
				<category><![CDATA[Codec]]></category>
		<category><![CDATA[Database Update]]></category>
		<category><![CDATA[Malicious Domains]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Rogue Security Software]]></category>

		<guid isPermaLink="false">http://malwaredatabase.net/blog/?p=1685</guid>
		<description><![CDATA[This is another domain spreading malware in codecs and rogue installers.  This is on a known malware IP address.
/promo1/ Fake Adult-archive.net website
/promo2/ Fake porntube.com website
/promo3/ Fake scanning page
/promo4/ Fake sextube website
Whois entry for mybest-xxx.com 78.129.166.166
Contact: info@rustelekom.biz
Domain name: mybest-xxx.com
Registrant Contact:
Vasilij Lanus ()
Fax:
Prospekt Mira 2.3.4
Moscow, 112111
RU
]]></description>
			<content:encoded><![CDATA[<p>This is another domain spreading malware in codecs and rogue installers.  This is on a known malware IP address.</p>
<p><strong>/promo1/</strong> Fake Adult-archive.net website<br />
<strong>/promo2/</strong> Fake porntube.com website<br />
<strong>/promo3/</strong> Fake scanning page<br />
<strong>/promo4/</strong> Fake sextube website</p>
<p><a href="http://whois.sc/mybest-xxx.com" target="_blank">Whois entry for mybest-xxx.com</a> 78.129.166.166<br />
Contact: info@rustelekom.biz<br />
Domain name: mybest-xxx.com<br />
Registrant Contact:<br />
Vasilij Lanus ()<br />
Fax:<br />
Prospekt Mira 2.3.4<br />
Moscow, 112111<br />
RU</p>
]]></content:encoded>
			<wfw:commentRss>http://malwaredatabase.net/blog/index.php/2009/06/07/new-rogue-domain-mybest-xxxcom/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Malware codec website: tvtube.myphotos.cc</title>
		<link>http://malwaredatabase.net/blog/index.php/2009/06/04/malware-codec-website-tvtubemyphotoscc/</link>
		<comments>http://malwaredatabase.net/blog/index.php/2009/06/04/malware-codec-website-tvtubemyphotoscc/#comments</comments>
		<pubDate>Thu, 04 Jun 2009 17:44:06 +0000</pubDate>
		<dc:creator>djpnuemo</dc:creator>
				<category><![CDATA[Codec]]></category>
		<category><![CDATA[Database Update]]></category>
		<category><![CDATA[Infection]]></category>
		<category><![CDATA[Malicious Domains]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Rogue Security Software]]></category>

		<guid isPermaLink="false">http://malwaredatabase.net/blog/?p=1650</guid>
		<description><![CDATA[Found this website distributing a malware codec that will install a rogue security program.  The myphotos.cc domain is a dymanic DNS service.

The referrer that brought us to tvtube.myphotos.cc was olimpians.ru.  This domain contained a php file that had the following line to direct us to the codec website.
window.location=&#8221;http://&#8221;+&#8221;tvtube&#8221;+&#8221;.myphotos.cc&#8221;+&#8221;/&#8221;;
Whois entry for olimpians.ru 77.221.130.29
codec.exe (PC Defender)
Result: 19/39 [...]]]></description>
			<content:encoded><![CDATA[<p>Found this website distributing a malware codec that will install a rogue security program.  The myphotos.cc domain is a dymanic DNS service.</p>
<p><img src="http://malwaredatabase.net/blog/wp-content/uploads/2009/06/tvtube.jpg" alt="" /></p>
<p>The referrer that brought us to tvtube.myphotos.cc was olimpians.ru.  This domain contained a php file that had the following line to direct us to the codec website.</p>
<blockquote><p>window.location=&#8221;http://&#8221;+&#8221;tvtube&#8221;+&#8221;.myphotos.cc&#8221;+&#8221;/&#8221;;</p></blockquote>
<p><a href="http://whois.sc/olimpians.ru" target="_blank">Whois entry for olimpians.ru</a> 77.221.130.29</p>
<p><strong>codec.exe</strong> (PC Defender)<br />
Result: <span id="porcentaje"><span style="color: red;">19</span>/39 (48.72%)</span><br />
MD5: 675777f309675e1fa7455c5ca4303ff6<br />
<a href="http://www.virustotal.com/analisis/c38ef64792ee78272c237a1753187d9ba0cccaa5059d31c2fb727bf90492d656-1244136775" target="_blank">VirusTotal</a><br />
<a href="http://www.threatexpert.com/report.aspx?md5=675777f309675e1fa7455c5ca4303ff6" target="_blank"> ThreatExpert Analysis</a></p>
]]></content:encoded>
			<wfw:commentRss>http://malwaredatabase.net/blog/index.php/2009/06/04/malware-codec-website-tvtubemyphotoscc/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
