Jump to content

Malwarebytes

youtube(dot)nl(dot)am, axiomsolution(dot)com


10 replies to this topic

#1
centralkong

    Advanced Member

  • Honorary Members
  • PipPipPip
  • 101 posts
  • Gender:Male
  • Location:A mason in Archades
Hi to all,
Today I was spammed by some WLM contacts with urls pointing to:

  • youtube(dot)nl(dot)am
  • axiomsolution(dot)com

And there was another one which I can't remember the name, it was something like myhdd(dot)info. (I'll surely get the link today).

If there's something you can do to block these domains via the IP Protection, I'd be :unsure: .

Feel free to contact me if you need any info.

Cheers!

#2
MysteryFCM

    Forum Deity

  • Moderators
  • PipPipPipPipPipPip
  • 4,232 posts
  • Gender:Male
  • Location:Tyneside, UK
There's also a fake YouTube site at;

microsoft.uk.to
bigmack.opendns.be

Which are on the same IP as youtube.nl.am :unsure:

http://hosts-file.ne...microsoft.uk.to
Steven Burn
Research Engineer

Posted Image

Follow us: Twitter, Become a fan: Facebook

#3
centralkong

    Advanced Member

  • Honorary Members
  • PipPipPip
  • 101 posts
  • Gender:Male
  • Location:A mason in Archades
It's already blocked, isn't it? Now that I think, that site tried to install a Java app via Chrome... Luckily Java warned me and I didn't choose "Allow" :unsure:

About the third site, it is hxxp://dl323.myfilehd.info:83/user496/cache/get.php?view=DVC-IMAGEN008.JPG (straight from the WLM chat window)

#4
Jaxryley

    Forum Deity

  • Malware Hunters
  • PipPipPipPipPipPip
  • 6,718 posts
  • Gender:Male
  • Location:West Aussie
  • Interests:Gardening and computers.
hxxp://dl323.myfilehd.info:83/user496/cache/get.php?view=DVC-IMAGEN008.JPG
Downloads a "DVC-IMAGEN008.JPG_www.myfilehd.com"
No hits at jottis
File size: 88064 bytes
-----------------------------------------------------------------------------
Runs as a "avscpa.exe" and changes quite a few reg settings.
I would hazard a guess and say it's malware?
http://rapidshare.de/files/48325902/DVC-IMAGEN008.JPG.zip.html


#5
Malcontent

    New Member

  • Members
  • Pip
  • 7 posts
One hit on virustotal:

http://www.virustotal.com/analisis/ab87d05...a4ec-1252715504

#6
centralkong

    Advanced Member

  • Honorary Members
  • PipPipPip
  • 101 posts
  • Gender:Male
  • Location:A mason in Archades
Jaxryley, please throw the files to ThreatExpert (http://www.threatexpert.com/) and bring back the reports here.

(I'd like to know what these nasties do, and it'll help MBAM developers :unsure:)

#7
MysteryFCM

    Forum Deity

  • Moderators
  • PipPipPipPipPipPip
  • 4,232 posts
  • Gender:Male
  • Location:Tyneside, UK
TE report

Attached Files


Steven Burn
Research Engineer

Posted Image

Follow us: Twitter, Become a fan: Facebook

#8
Fatdcuk

    Malware BBQ'er

  • Moderators
  • PipPipPipPipPipPip
  • 16,155 posts
  • Gender:Male
  • Location:127.0.0.1
Thanks Centralkong for the report and thanks Jax have added the URL for harvesting now :unsure:

Will look at the install shortly :)
Ade Gill
Research Engineer

Posted Image

Follow us: Twitter, Become a fan: Facebook

#9
centralkong

    Advanced Member

  • Honorary Members
  • PipPipPip
  • 101 posts
  • Gender:Male
  • Location:A mason in Archades
@MysteryFCM: Strange... Just a created process? And that's all? It's odd...
@Fatcduk: You're welcome :unsure:

#10
Fatdcuk

    Malware BBQ'er

  • Moderators
  • PipPipPipPipPipPip
  • 16,155 posts
  • Gender:Male
  • Location:127.0.0.1
No not strange that it dose'nt perform for TE, it knows to exit process if its running in sandbox test enviroment and hence no install report.
Ade Gill
Research Engineer

Posted Image

Follow us: Twitter, Become a fan: Facebook

#11
MysteryFCM

    Forum Deity

  • Moderators
  • PipPipPipPipPipPip
  • 4,232 posts
  • Gender:Male
  • Location:Tyneside, UK
It's likely sandbox/VM aware .....
Steven Burn
Research Engineer

Posted Image

Follow us: Twitter, Become a fan: Facebook





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

Follow Us