Yandex narod.ru hosted ransom (LockEmAll variant)
hxxp://comdunnbeantrocart.narod.ru/xxx_video.exe
MBRLock
hxxp://beeporn.in/xxxvideo.avi.exe
Redirector to LockEmAll
hxxp://imiziporno.ru/in.cgi?2
Currently points to
hxxp://superporbbaa.ru/xxx_video.exe
Looks like they finally moved from Amazon.
Redirector to pornorolik, by changing ID in cgi param you can get to different locations
hxxp://bim-dot.ru/er3tggg.cgi?13
Another type of ransom
Redirector
hxxp://housevideo1.ru/xvid/cc/click.php?id=1
Payload
hxxp://pornhouse8.ru/xxxvideo.avi.exe