PC Review


Reply
Thread Tools Rate Thread

As of 8:44 pm EST Sunday night - fileden is serving up some malware

 
 
Virus Guy
Guest
Posts: n/a
 
      7th Mar 2011
If you go to fileden.com right now, the site will try to push a browser
add-on at you, as well as the file "manual.pdf".

I uploaded it to VT, where it's being detected only by Avast5 and Gdata
as JS:Pdfka-gen.
 
Reply With Quote
 
 
 
 
Virus Guy
Guest
Posts: n/a
 
      7th Mar 2011
Virus Guy wrote:

> If you go to fileden.com right now, the site will try to push a
> browser add-on at you, as well as the file "manual.pdf".
>
> I uploaded it to VT, where it's being detected only by Avast5
> and Gdata as JS:Pdfka-gen.


Here is a direct link for that file:

hxxp://z3co.co.cc/games/pdf.php?f=17
 
Reply With Quote
 
David H. Lipman
Guest
Posts: n/a
 
      7th Mar 2011
From: "Virus Guy" <(E-Mail Removed)>

| If you go to fileden.com right now, the site will try to push a browser
| add-on at you, as well as the file "manual.pdf".

| I uploaded it to VT, where it's being detected only by Avast5 and Gdata
| as JS:Pdfka-gen.

fileden.com isn't doing anything for me.

--
Dave
Multi-AV Scanning Tool - http://www.pctipp.ch/downloads/dl/35905.asp


 
Reply With Quote
 
Virus Guy
Guest
Posts: n/a
 
      7th Mar 2011
"David H. Lipman" wrote:
>
> From: "Virus Guy" <(E-Mail Removed)>
>
> | If you go to fileden.com right now, the site will try to push
> | a browser add-on at you, as well as the file "manual.pdf".
>
> fileden.com isn't doing anything for me.


Yea, I just checked (11:45 pm) and it's clean now.

But the file is still available from here:

z3co.co.cc/games/pdf.php?f=17
 
Reply With Quote
 
Virus Guy
Guest
Posts: n/a
 
      7th Mar 2011
Ant wrote:

> > But the file is still available from here:
> >
> > z3co.co.cc/games/pdf.php?f=17

>
> Five PDF exploits:
>
> Collab.collectEmailInfo
> Collab.getIcon
> media.newPlayer
> util.printd
> util.printf
>
> Shellcode downloads (URLDownloadToCacheFileA) and runs whatever
> executable this points to:
> z3co.co.cc/k.php?f=17&e=3
>
> which was 0 bytes when I tried, and the filename used to save it
> was invalid (not manual.pdf).


manual.pdf is the name you get from the link above - which is the same
even if you drop the "=17" part.

> Maybe it's geo-sensitive or just broken.


I also get a 0 length file from z3co.co.cc/k.php?f=17&e=3.
 
Reply With Quote
 
 
 
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Fileden is hacked again - serving up malware (manual.pdf) Virus Guy Anti-Virus 13 20th Mar 2011 02:21 PM
Analysis of a Malware Compromise - my first malware Leythos Windows XP Security 3 22nd Nov 2009 02:37 PM
Windows Defender has Malware seemingly has malware in it? Troubled_By_Malware Spyware Discussion 3 11th Apr 2009 07:01 PM
Calendar 7 (Monday to Sunday) not days not 6 days (Saturday+Sunday)How ?? Gerhard Silbermann Microsoft Outlook Calendar 2 16th Oct 2008 12:03 AM
Sunday night... anyone here? I need audio help! BIGTIME !! =?Utf-8?B?VHJpeGllYmVl?= Windows XP MovieMaker 1 23rd Aug 2004 02:04 AM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 04:25 PM.