This page...
hxxp://rodrigoeastbury.moqxqpuxz .cc/red_spots_on_face_that_wont_go_away.html
...automatically redirected to a page on langlan .net, which redirected to a page at pconlinescan .net, which loaded a fake virus scan that to the novice user may appear to be an actual Windows security alert (click on the screenshot to see it full size):
The malware authors obviously designed this scam page to look like Windows XP's default blue theme. (As you can see in this screenshot, even in a Mac browser the page looks the same.) If the panicked victim clicks on the "Remove all" button (or, in fact, anywhere on the page—even the Cancel or red X buttons), malware is downloaded onto the machine. This malware is not yet detected by most antivirus software, but I'm submitting a sample to multiple security vendors so it should be more widely detected within the next day or so.
File details courtesy of VirusTotal and VirSCAN:
File name: setup_build206_157.exeFor more details regarding the malicious payload and associated domains, see:
File size: 263168 bytes
MD5 : aedd952609bd1c6056df337443fb951e
SHA1 : 8b09fa1e55e5e5501ed5b9f6833e71d04fb12b01
SHA256: 7b89c480f25f14b2bc744a141fb252d796bdcd90f77dcff7e4a8bce06963e508
Variously identified as: TR/Dldr.Fake.PS.14, Trojan-Downloader.Win32.FraudLoad.fkt, Trojan.Dldr.Fake.PS.14, Mal/Behav-321, TROJ_AGENT.PQAB, etc.
- http://www.threatexpert.com/report.aspx?md5=aedd952609bd1c6056df337443fb951e
- https://www.virustotal.com/analisis/7b89c480f25f14b2bc744a141fb252d796bdcd90f77dcff7e4a8bce06963e508-1252007849
- http://virscan.org/report/4dd8b4fb3039b69d687745d4cdeafe56.html
- http://info.prevx.com/aboutprogramtext.asp?PX5=BC9DD10E00B25DFA048604F1DE8F0E007BC124AC
- http://safeweb.norton.com/report/show?url=pconlinescan.net
- http://www.mywot.com/en/scorecard/pconlinescan.net
- http://www.mywot.com/en/scorecard/langlan.net
- http://www.mywot.com/en/scorecard/moqxqpuxz.cc
- http://www.mywot.com/en/scorecard/prestotunerst.cn
- https://www.siteadvisor.com/sites/prestotunerst.cn#reviewercommentssummary
- http://www.mywot.com/en/scorecard/securefield.net
- http://safeweb.norton.com/report/show?url=securefield.net
- https://www.siteadvisor.com/sites/securefield.net#reviewercommentssummary
- http://www.mywot.com/en/scorecard/windowsprotectionsuite.com


2 comments: