A couple of the downloaded, packed files appear to carry with them tricks that continue to evade AV file scanning with VirusTotal results at 5/36.
For example, a chunk of the standard download and execute shellcode that we are currently seeing pulls a file from hxxp://ascoprguide. net/lel / load.php?xpl=pdf, renames it as c:\\U.exe, and runs it on the victim's system. This "U.exe" then runs and installs other adware and spyware related components.
Other downloads are installing various Rogueware packages, like the ones we presented at Virus Bulletin 2008.

Be sure to visit the Adobe site and update your Acrobat Reader software.
0 comments:
Post a Comment