Author Topic: tubezz. org produces new malware everyday in the name of activeX  (Read 7068 times)

0 Members and 1 Guest are viewing this topic.

Offline sg09

  • Full Member
  • ***
  • Posts: 175
    • Current Technology Discounts
http: //tubezz. org/ produces new malware evryday in the name of ActiveX. I reported a few and they are now detected. Is it possible to monitor the site, so that new malwares can be detected as they are produced? Also block the webpage please.
Anyone who knows how to loose can certainly learn how to win.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: tubezz. org produces new malware everyday in the name of activeX
« Reply #1 on: March 26, 2010, 02:32:49 PM »
Hi sg09,

This site is suspicious:
This page seems to be <suspicious>
3 hidden external links found.

Don't panic. This test is not 100% accurate. Check the detailed report below to find out what's wrong with the page. If you see actual evidence of parasites, please take action to eradicate them.

For more comprehensive diagnostics consider the following additional tests.
Check Unmask Parasites blog for information about the latest website exploits.

Website security is an ongoing process. Bookmark this service and check your web pages regularly.

Report
General
Title: tubezz - Best Videos Funny Movies
URL: hxtp://tubezz.org
Google: not currently listed as suspicious* (details)  
Last checked: 0 minutes ago (results are cached for 1 hour)
This report:  

External References
- click.hotlog.ru safe? - displaying 1 of 1
<A> hidden link - hxtp://click.hotlog.ru/?639897

- u10955.08.spylog.com safe? - displaying 1 of 1
<A> hidden link - hxtp://u10955.08.spylog.com/cnt?cid=1095508&f=3&p=0

- update-center.net safe? - displaying 1 of 1
<IFrame> hidden link - hxtp://update-center.net/microsoft/get_update.php?sid=2

- malecafe.net safe? - displaying 1 of 1
<A> link - hxtp://malecafe.net/tpg/go.php?sid=7

- wXw.metacafe.com safe? - displaying 1 of 1
<A> Learn more here - hxtp://www.metacafe.com/Openads//adclick.php?bannerid=2948&zoneid=169&source=%3Bnumber-0%3Bff-on%3BLEID-564%3BpageType-today%3Bcategory-0%3Bheader-hxtp%3A%2F%2Fwww.metacafe.com%3Bmetacafe.com&dest=http%3A%2F%2Fwww.metacafe.com%2Fwikicafe&ismap=

- tools.spylog.ru safe? - displaying 1 of 1
<Script> link - htxp://tools.spylog.ru/counter_cv.js

General information:
Location of website     Russian Federation


Threat report
Threats found: 1


  Drive-bydownloads
Threats found: 1
Listed below:

Name of threat:  HTTP Misleading Application Download Request  
Location:  xttp://tubezz.org/hqt/index.php  

Cleansing script found here: http://forum.kaspersky.com/lofiversion/index.php/t161729.html

polonus
 
« Last Edit: March 26, 2010, 02:37:54 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline sg09

  • Full Member
  • ***
  • Posts: 175
    • Current Technology Discounts
Re: tubezz. org produces new malware everyday in the name of activeX
« Reply #2 on: March 26, 2010, 02:46:39 PM »

Cleansing script found here: http://forum.kaspersky.com/lofiversion/index.php/t161729.html


Similar report in malwarebyte forum
http://forums.malwarebytes.org/index.php?showtopic=43747
@polonus: Actually I am not infected. I was redirected to the site by some means and while tried to load the video it asked me to install an activeX named
Activex_Setup.45158.exe
I scanned this in virustotal and few AV detected this, then I manually quarantine it and send it to Avast for analysis and later found to be virus. Next day intensionally I went to that site and found that new virus is their with the same name.
Thanks for your help polonus..
« Last Edit: March 26, 2010, 02:53:29 PM by sg09 »
Anyone who knows how to loose can certainly learn how to win.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: tubezz. org produces new malware everyday in the name of activeX
« Reply #3 on: March 26, 2010, 04:06:36 PM »
Hi sg09,

Knew you were not personally infected with this, and thanks for reporting, but I gave that for people that were and were looking for additional info on this malware. Your behavior is very responsible behavior, thanks again, forewarned is forearmed,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline sg09

  • Full Member
  • ***
  • Posts: 175
    • Current Technology Discounts
Re: tubezz. org produces new malware everyday in the name of activeX
« Reply #4 on: March 26, 2010, 04:21:12 PM »
but I gave that for people that were and were looking for additional info on this malware.
I knew and I should thank u for that.... :)
Your behavior is very responsible behavior
thanks... :P
forewarned is forearmed
True.... :)
Anyone who knows how to loose can certainly learn how to win.

Offline sg09

  • Full Member
  • ***
  • Posts: 175
    • Current Technology Discounts
Re: tubezz. org produces new malware everyday in the name of activeX
« Reply #5 on: March 27, 2010, 09:07:12 PM »
I tested the site today, Avast blocked a url in it
boobtubepro.com/xplays.php?id=45158
But the activeX still there, a new one ab course.
http://www.virustotal.com/analisis/c81b533a387fcd08f25cf041fabf3af1f209638d886f877653363bcc823d542e-1269720204
Anyone who knows how to loose can certainly learn how to win.