Saturday, March 28, 2009

loyaldown-loyaltube Fake Codec and RogueAV

loyaldown09.com, loyaltube10.com Fake Codec and Rogue Antivirus

loyaldown09.com, loyaltube10.com are site that distribute fake codec.
We also have on this network sites which host rogue application like
XP-Police-Antivirus and Win-PC-Defender

Fake codec and fake scanner page screenshot

loyaltube10.com [213.163.65.10]
loyaldown09.com [213.163.65.9]

hxxp://loyaltube10.com/scan/?id=..



hxxp://loyaltube10.com/tube/?id=...&title=adult+movie




Analysis:


Redirectors used: hxxp://us-euro.biz/in.cgi?4&parameter=wifi
[195.190.13.234]
Analysis here

 Site URLs:hxxp://loyaltube10.com/scan/?id=.. 
  hxxp://loyaltube10.com/tube/?id=197&title=adult+movie 
  hxxp://loyaldown11.com/codec/.exe 
    
   hxxp://loyaldown11.com/codec/189.exe 
  hxxp://loyaldown11.com/codec/197.exe 
    
    
 File info:codec.exe 
    
 File size107011 bytes 
 MD5704298be5c6bf8671517c79b827c9206 
    
    
 ThreatExpert:Report 
 VirusTotal:Report 
 Anubis:Report (related: WinPC Defender) 
    
 First received03.29.2009 01:17:30 (CET)
 
 Results6/39 (15.39%) 
    
 Alias:(Suspicious) - DNAScanCAT-QuickHeal 
  Suspicious File eSafe 
  Downloader-BONMcAfee 
  Downloader-BONMcAfee+Artemis 
  TrojanDropper:Win32/Insebro.AMicrosoft 
  Malware-Cryptor.Win32.ZorqVBA32 



 Site URLs:hxxp://tubeloyal.com/scan/?id-.. 
  hxxp://loyaldown11.com/codec/.exe 
    
    
 File info:codec.exe 
    
 File size107008 bytes 
 MD5eb61517f7f0906dc0e60f0e0afd1bbf1 
    
    
 ThreatExpert:Report 
 VirusTotal:Report 
 Anubis:Report (related: WinPC Defender) 
    
 First received03.29.2009 01:41:38 (CET)
 
 Results6/39 (15.39%) 
    
 Alias:(Suspicious) - DNAScanCAT-QuickHeal 
  Suspicious File eSafe 
  Downloader-BONMcAfee 
  Downloader-BONMcAfee+Artemis 
  TrojanDropper:Win32/Insebro.AMicrosoft 
  Malware-Cryptor.Win32.ZorqVBA32 

Associated websites:
 
[213.163.65.10]
loyaltube.com
loyaltube09.com
loyaltube10.com
rakompoporyadkunazaryadku.com
setupdatdownload.com
tubeloyal.com
velzevuladmin.com
win-pc-defender.com
xp-police-09.com
xp-police-2009.com
xp-police-antivirus.com
xp-police-av.com
xp-police-engine.com

[213.163.65.9]
loyaldown09.com
loyaldown11.com