This page...
hxxp://rodrigoeastbury.moqxqpuxz .cc/red_spots_on_face_that_wont_go_away.html
...automatically redirected to a page on langlan .net, which redirected to a page at pconlinescan .net, which loaded a fake virus scan that to the novice user may appear to be an actual Windows security alert (click on the screenshot to see it full size):
The malware authors obviously designed this scam page to look like Windows XP's default blue theme. (As you can see in this screenshot, even in a Mac browser the page looks the same.) If the panicked victim clicks on the "Remove all" button (or, in fact, anywhere on the page—even the Cancel or red X buttons), malware is downloaded onto the machine. This malware is not yet detected by most antivirus software, but I'm submitting a sample to multiple security vendors so it should be more widely detected within the next day or so.
File details courtesy of VirusTotal and VirSCAN:
File name: setup_build206_157.exeFor more details regarding the malicious payload and associated domains, see:
File size: 263168 bytes
MD5 : aedd952609bd1c6056df337443fb951e
SHA1 : 8b09fa1e55e5e5501ed5b9f6833e71d04fb12b01
SHA256: 7b89c480f25f14b2bc744a141fb252d796bdcd90f77dcff7e4a8bce06963e508
Variously identified as: TR/Dldr.Fake.PS.14, Trojan-Downloader.Win32.FraudLoad.fkt, Trojan.Dldr.Fake.PS.14, Mal/Behav-321, TROJ_AGENT.PQAB, etc.
- http://www.threatexpert.com/report.aspx?md5=aedd952609bd1c6056df337443fb951e [site is no longer accessible]
- https://www.virustotal.com/gui/file/7b89c480f25f14b2bc744a141fb252d796bdcd90f77dcff7e4a8bce06963e508/details
- http://virscan.org/report/4dd8b4fb3039b69d687745d4cdeafe56.html [site is no longer accessible]
- http://info.prevx.com/aboutprogramtext.asp?PX5=BC9DD10E00B25DFA048604F1DE8F0E007BC124AC [site is no longer accessible]
- https://safeweb.norton.com/report/show?url=pconlinescan.net
- https://www.mywot.com/en/scorecard/pconlinescan.net
- https://www.mywot.com/en/scorecard/langlan.net
- https://www.mywot.com/en/scorecard/moqxqpuxz.cc
- https://www.mywot.com/en/scorecard/prestotunerst.cn
- https://www.siteadvisor.com/sites/prestotunerst.cn#reviewercommentssummary [reviewer comments no longer available]
- https://www.mywot.com/en/scorecard/securefield.net
- https://safeweb.norton.com/report/show?url=securefield.net
- https://www.siteadvisor.com/sites/securefield.net#reviewercommentssummary [reviewer comments no longer available]
- https://www.mywot.com/en/scorecard/windowsprotectionsuite.com
ok, so here's my question. If you can't click on it to close it (because it activates it) how do you get it to stop running or get rid of it?
ReplyDeleteIs it to ME< the task manager is totally a zoo to read, I'm SURE not for IT people, thank you very much.... (where as the old one, when you had something like that happen, it would show RIGHT THERE and you could take care of it) Trouble is, it might be wonderful for all you IT people out there that can read the task manager in all that detail, and know what you are reading, but I can't believe that I am the only one to feel this way about all this information we know nothing about now..good grief... Is it me?
Windows defender picked it up (and I think deleted it) Half the people in the world probably don't even know NOT to even click on it. But how in the world do you end task when you don't know what you are looking for anymore...
Frustrated at the new task manager...
If you can't figure out which button is the real window close button, hold down the Alt key on the keyboard and press F4. This will close the frontmost window in pretty much any Windows application. To close the frontmost window on a Mac, hold down Command (the Apple logo or cloverleaf key) and press W.
ReplyDelete