Prevx Blog

Jul 12th

The key to all your Adult Pleasure (Zdnet, Chinese Gov?)

Posted by: Jacques Erasmus

Bookmark Now

In the last day or so we've seen yet another change in codecs used by the popular zlob infection.

This time around its called Micro-Codec. The filenames are normally structured like MICRO-CODEC[0-9][0-9][0-9][0-9].EXE.

These come and go on a daily basis, but this one warranted more then 2 minutes of our time.

Here's what we found:

One of the main sites that point users to the codec download is listed below.

noooo Registered and running from Singapore, it's been used in the past to peddle illegal porn, a quick google search shows this clearly, however to our suprise we found some very reputable sites containing guestbook and talkback spam containing these links.

Clearly there has been a breakdown in filtering these out somewhere along the line. Countless users are being directed to these sites from reputable sites, and having a link on all these sites improves the pagerank of said malicious site, making it easier to find via Google.

See Image below for some mid afternoon humour. (There are currently 734 sites linking to this site!)

blooper By the way - The Domaintools Reverse IP for this server looks quite juicy, see below!

reverse_ip_adultsexkey And finally.... Have you seen this person?

whois

2 comments so far

  1. Burak on Jul 12 17:42, 2007
  2. Yes.We must be carefully.Thanks.

  3. Lord KiRon on Jul 17 4:12, 2007
  4. Funny

    The registration is on Russian, literally it says :

    1. Name: Kitaesa - chinees guy (offensive)

    2. Glavnaya ulica - "main" street

    3. Glavniy Gorod - "main" town

Leave a reply








Yearly Archives

Stay Updated

YouTube Channel

Find us on Facebook