Author Topic: Trojan.FakeSmoke and malicious domains  (Read 3294 times)

0 Members and 1 Guest are viewing this topic.

November 08, 2009, 07:52:32 pm
Read 3294 times

czy00

  • Jr. Member

  • Offline
  • **

  • 10
Reference: http://novirusthanks.org/blog/2009/11/blackhat-seo-used-to-spread-systemveteran-rogue-software/

Some domains missing on mdl:

hxxp://get2.tv/ Serve False Codecs
hxxp://setxlif.com/download/1c28a2cf62a7714a74cdc3ef306ee6f6/3656b9eddb95cfb9d7f013ed46b015a2 Trojan.FakeSmoke
hxxp://szickfrost.com/download/1c28a2cf62a7714a74cdc3ef306ee6f6/3656b9eddb95cfb9d7f013ed46b015a2 Trojan.FakeSmoke
hxxp://sickfrost.com/download/1c28a2cf62a7714a74cdc3ef306ee6f6/3656b9eddb95cfb9d7f013ed46b015a2 Trojan.FakeSmoke
hxxp://szick-frost.com/download/1c28a2cf62a7714a74cdc3ef306ee6f6/3656b9eddb95cfb9d7f013ed46b015a2 Trojan.FakeSmoke
hxxp://sick-frost.com/download/1c28a2cf62a7714a74cdc3ef306ee6f6/3656b9eddb95cfb9d7f013ed46b015a2 Trojan.FakeSmoke

get2.tv has always new urls for "codec"...