
antivirus-scanonline.com
indafuckfuck.com
newcontents2008.comavwav.com
anykindclips.comdirtyxxxvids.com
clipsmachines.comthesoft-portal-08.com
Sample detecton rates for the codecs obtained :
Scanners Result: 8/32 (25%)
W32/PolyZlob!tr.dldr; Trojan:Win32/Tibs.gen!ldsFile size: 119296 bytes
MD5...: dc5538af557cb4c311cb86d6574400baSHA1..: 5cf1602db8c4fdd3c5ac5101e5a6c5daa77f5ff1
Scanners Result: 6/32 (18.75%)
Trojan-Downloader.Win32.FraudLoad.axa; Trojan.Dldr.FraudLoad.axa
File size: 60416 bytesMD5...: 14938bfe35128687e05f7f8ccbd29c7d
SHA1..: cf651e959fff945c9659321e79ba2788062b721dScanners Result: 14/32 (43.75%)
Trojan-Downloader.Win32.Zlob.lps; TrojanDownloader:Win32/Zlob.IBFile size: 18432 bytes
MD5...: 9b3bbcd4549970a92eb1b11c46a451bbSHA1..: 679508aba4e547935d5e4104a735c754b40de49e
Scanners Result: 18/32 (56.25%)
Trojan-Downloader.Win32.Delf.ilx; TrojanDownloader:Win32/Chengtot.A
File size: 91683 bytesMD5...: 727e3f353281229128fdb1728d6ef345
SHA1..: 3f9c9000b273e8bf75db322382fbaabf333faf26Once we've managed to obtain several of the fake codec domains, passive DNS monitoring and using third-party tools helps us expose a huge portfolio of rogue domains such as :

musicportalfree.com
online-dvdrip.com
widget-porn.com
gt-funny.com
gt-movies.com
gt-stars.com
hot-sextube.com
hot-pornotube-2008.com
hot-pornotube08.com
hotpornotube08.com
porn-youtube-08.org
uriy.org
sextube20008.com
streamxxxvideo.com
xxxgirlsgirls.com
porno-tube20008.com
2008adultstreamportal2008.com
2008adults2008.com
adult18tube2008.com
sextube18adult.com
all-videos-home.com
adultstreamportal2008.com
onlinestreamvide.com
adultvideos4all.com
sex18tube2008.com
adultxx-18.com
mymediasex.com
ladyxxxworld.com
adultstreamportal.com
young-girls-board.com
porn-youtube08.net
adultfreemarket.info
adult-codec08.com
adult-tubecodec08.com
adult-tubecodec2008.com
adulthot-codec08.com
adulttubecodec2008.com
hot-tubecodec20.com

media-tubecodec2008.com
porn-tubecodec20.com
hot-sextubecodec.com
sexporntubecodec14.com
sexporntubecodec32.com
sexporntubecodec77.com
sexporntubecodec98.com
adult-codec08.com
adult-codec2008.com
adult-tubecodec08.com
adult-tubecodec2008.com
adulthot-codec08.com
adulthot-codec20008.com
adulthot-codec2008.com
adulthotcodec032008.com
adulthotcodec072008.com
adulthotcodec092008.com
adulthotcodec29018.com
adulthotcodec29098.com
adulttubecodec2008.com
media-tubecodec2008.com
sexhotcodec09.com
sexhotcodec1.com
sexhotcodec11.com
sexhotcodec12.com
sexhotcodec90.com
thehotcodec21.com
thehotcodecgt.com
thehotcodechq.com
thehotcodeclk.com
thehotcodecrt.com
thehotcodecxx.com
thehotcodeczz.com
What you see is not always what you get online, however, the infrastructure providers in the majority of malware campaigns tend to remain the same.
No comments:
Post a Comment