Author Topic: WARNING: Malware, scams and RedStation ....  (Read 6006 times)

0 Members and 1 Guest are viewing this topic.

May 31, 2010, 07:56:11 pm
Read 6006 times

MysteryFCM

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 1693
  • Personal Text
    Phishing Phanatic
    • I.T. Mate
WARNING: Malware, scams and RedStation (AS35662, 81.94.192.0/20)

Quote
Remember the SMS fraud housed on the RapidSwitch range? Well, now we've got yet another network involved.

This time, it's the turn of RedStation, AS35662. I've already dropped them an e-mail, but the notice on their contact page suggests this is going to have been a completely pointless exercise.

http://hphosts.blogspot.com/2010/05/warning-malware-scams-and-redstation.html
Regards

Steven Burn
I.T. Mate / hpHosts
it-mate.co.uk / hosts-file.net

May 31, 2010, 08:19:14 pm
Reply #1

SysAdMini

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 3335
Someone reported similar sites.

Rogue Malwarebytes websites

Code: [Select]
http://malwarebytes-2010.com
http://malwarre.2010-fr.net/
http://malwarebytes-2010fr.com/

the person who reported those sites claims that those sites direct
to download pages here:
Code: [Select]
http://www.allbrowsers.net/fr/install_malware.exe?a=
http://www.uenti.net/fr/install_malware_2.exe?a=
http://www.allbrowsers.net/fr/install_malwarre2010.exe?a=

I wasn't able to confirm this. Maybe download works for specific countries only.
Ruining the bad guy's day

May 31, 2010, 08:21:52 pm
Reply #2

MysteryFCM

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 1693
  • Personal Text
    Phishing Phanatic
    • I.T. Mate
I've already had uenti.net taken down :) (was housed by Leaseweb), so that one should no longer work. The others still work though.

/edit

Interesting ... the allbrowsers.net "Malwarebytes" download URLs aren't working anymore
Regards

Steven Burn
I.T. Mate / hpHosts
it-mate.co.uk / hosts-file.net

May 31, 2010, 10:59:54 pm
Reply #3

MysteryFCM

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 1693
  • Personal Text
    Phishing Phanatic
    • I.T. Mate
Haven't looked at the file yet (too tired), but this one is still live;

Code: [Select]
http://www.allbrowsers.net/fr/exe/mbam-setup.exe
File is > 4MB. Properties suggest it's actually a non-modified installer for MBAM v1.44.

Source codes for all of the sites referenced in the blog, is attached in case they go down.

/edit

Struckout the above as I've just noticed I'm a little late in discovering the MBAM setup file.
Regards

Steven Burn
I.T. Mate / hpHosts
it-mate.co.uk / hosts-file.net

June 01, 2010, 08:16:42 am
Reply #4

CkreM

  • Special Access
  • Hero Member

  • Offline
  • *

  • 567
Mal-Aware

June 01, 2010, 02:29:45 pm
Reply #5

MysteryFCM

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 1693
  • Personal Text
    Phishing Phanatic
    • I.T. Mate
Yep, they are/were using it as part of an SMS fraud (kudos to S!RI :))
Regards

Steven Burn
I.T. Mate / hpHosts
it-mate.co.uk / hosts-file.net

June 02, 2010, 03:37:49 pm
Reply #6

MysteryFCM

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 1693
  • Personal Text
    Phishing Phanatic
    • I.T. Mate
Regards

Steven Burn
I.T. Mate / hpHosts
it-mate.co.uk / hosts-file.net

June 03, 2010, 01:53:33 pm
Reply #7

MysteryFCM

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 1693
  • Personal Text
    Phishing Phanatic
    • I.T. Mate
Regards

Steven Burn
I.T. Mate / hpHosts
it-mate.co.uk / hosts-file.net

June 04, 2010, 10:30:13 pm
Reply #8

MysteryFCM

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 1693
  • Personal Text
    Phishing Phanatic
    • I.T. Mate
Regards

Steven Burn
I.T. Mate / hpHosts
it-mate.co.uk / hosts-file.net