Author Topic: Domain hosting Crimepack  (Read 5298 times)

0 Members and 1 Guest are viewing this topic.

March 18, 2010, 10:35:31 pm
Read 5298 times

br0wnd

  • Newbie

  • Offline
  • *

  • 1
hxxp://pilon5.ru/crime - Hosting Crimepack exploit kit

Inadvertently revealed by someone trying to sell Crimepack on a Russian forum.  Whoops :)

Here's a screenshot that revealed most of the domain:  http://2.bp.blogspot.com/_hx7QmGN8TlM/S6Kgh_z6zmI/AAAAAAAAACA/yN6nr70mL-4/s1600-h/redactfail.jpg

Also linked to the same email as the registrant:  http://www.malwaredomainlist.com/mdl.php?search=ch1t3r%40gmail.com&colsearch=All&quantity=50&inactive=on


March 19, 2010, 05:51:49 pm
Reply #2

SysAdMini

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 3335
Code: [Select]
roguenet.info/skuff/index.php
Ruining the bad guy's day


March 23, 2010, 02:37:13 am
Reply #4

MysteryFCM

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 1693
  • Personal Text
    Phishing Phanatic
    • I.T. Mate
Coming via malvertisements now?

http://forums.avg.com/ww-en/avg-free-forum?sec=thread&act=show&id=75313

Still looking into it (don't have a test machine atm as I'm not at home).
Regards

Steven Burn
I.T. Mate / hpHosts
it-mate.co.uk / hosts-file.net

March 23, 2010, 07:51:47 am
Reply #5

MysteryFCM

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 1693
  • Personal Text
    Phishing Phanatic
    • I.T. Mate
Regards

Steven Burn
I.T. Mate / hpHosts
it-mate.co.uk / hosts-file.net

March 23, 2010, 07:52:49 am
Reply #6

CkreM

  • Special Access
  • Hero Member

  • Offline
  • *

  • 567
Quote
Hi,

I can confirm that this is a false alarm, unfortunately. Please accept our apologies for the inconvenience.

We will release new LinkScanner database update to rectify this soon. It will not be detected with the LinkScanner version 193 (this information can be found in AVG user interface upon double-clicking the LinkScanner componnet).
As a temporary solution (until the update), please disable the LinkScanner component.

Thanks.

***************AVG Team

Edit:
1 minute late :D
Mal-Aware

March 23, 2010, 08:00:02 am
Reply #7

MysteryFCM

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 1693
  • Personal Text
    Phishing Phanatic
    • I.T. Mate
Regards

Steven Burn
I.T. Mate / hpHosts
it-mate.co.uk / hosts-file.net