Author Topic: Zombies AppInstaller comes with Adware...  (Read 1603 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33913
  • malware fighter
Zombies AppInstaller comes with Adware...
« on: June 17, 2013, 05:07:06 PM »
See: https://www.virustotal.com/nl/url/809222fb117363b692c4d4fafb055f6f4d81ba0343cf893336da0d3761a01d57/analysis/
and file analysis here: https://www.virustotal.com/nl/file/7b034484e91b543255144ff56a6c46006ac872b589162ca32ac775c2b18dd6b4/analysis/1371416968/

DrWeb's URL checker detects:
Checking:htxp://dl.fagdmr.com/n/3.0.9.2/5365993/zombies.exe
Engine version:7.0.4.9250
Total virus-finding records:4134341
File size:186.16 KB
File MD5:14b5f4eab5b0b20ce47a5ff121d06fbb

htxp://dl.fagdmr.com/n/3.0.9.2/5365993/zombies.exe contains an advertising software Adware.Downware.1125
URL gives IDS alerts at urlquery-> http://urlquery.net/report.php?id=3176627
Does avast treat this as PUP?

polonus

Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33913
  • malware fighter
Re: Zombies AppInstaller comes with Adware...
« Reply #1 on: June 17, 2013, 10:59:07 PM »
See: http://anubis.iseclab.org/?action=result&task_id=129d1ab6d4ff7e29449258c60825875f9&format=html#chapter1
For that download site: http://malc0de.com/database/index.php?search=dl.fagdmr.com
Particular adware that also is data harvesting: http://www.hotforsecurity.com/blog/adware-shifts-focus-from-advertising-to-data-harvesting-2942.html
Adware/Solimba and eguivalents...
above link was posted in E-Threats by link article author  Loredana Botezatu,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!