New DNS Changer Trojan
I came across a site that looked somewhat familiar while doing some Robtex lookups.
celebs-naked.net
It links to multiple “pay” pornsites, but the main page is made up of popular videos… they all require a special codec of course.
The URL to the file is:
exe-site.com/streamviewer.40056.exe
Each time you download the file, a new MD5 will be generated (server side). This makes it very difficult for traditional AV engines to detect.
virus Total analysis reveals that only Kaspersky and Sophos are detecting this threat at the time of writing.
Watch out, site and links can infect your PC!
Jerome Segura
Malware ID: 58815489ba25c44b9a85fc7470c238eb.zip
No related posts.
Related posts brought to you by Yet Another Related Posts Plugin.



Leave a Reply