Wednesday, July 7, 2010

Movie Sites Spreading Malware

Web sites which allow visitors to watch or download movies and television programs are increasingly being used by organized criminal gangs to infect computers with stealth type malware.

The following list of 425 infectors and domains is yet unknown to the popular blacklists. Worse, due to detection rates as well as outdated signatures, it is unlikely that the anti-virus software of most consumers and businesses will detect or protect from these sites.

There are many other movie sites serving as infectors, these are merely those not yet widely known.

If your employees or family members are illegally watching or downloading movies, the odds are high that you have a serious problem on your hands (other than the associated legal and civil liability).

If you utilize the free Smoothwall firewall, you can protect your home or business from these threats by making use of the BlackHole DNS files at Emerging Threats: http://doc.emergingthreats.net/bin/view/Main/HoneywallSamples




%24virusname

www.ultradvdcollection.com

%28Suspicious%29+-+DNAScan

u7.search-on.co.kr

ADSPY%2FAdvantage.A.140

67.19.52.179

ADSPY%2FAdvantage.A.140

www.npssoftware.com

ADWARE%2FZango.IU.27

origin-ics.hotbar.com

Adware.ADTV.1592

update.adtrigger.net

Artemis%210FB4ED405D82

cfteam.net

Artemis%21F1D322E9BD0B

www.mtsconverter.com

ASD.Prevention

free-porn-4u.in

ASD.Prevention

free-porn-video.co.tv

ASD.Prevention

getfreepornclips.in

ASD.Prevention

mediaonsearch.com

ASD.Prevention

sirenpornvideos.in

Backdoor.Linux.PHP.b%21IK

www.actualtv.ro

Backdoor.PHP.Agent%21IK

g1atv.com

Backdoor.PHP.Pbot%21IK

actualtv.ro

Backdoor.Win32.Gootkit%21IK

www.novustvnet.com

BDS%2FMSIL.IrcBot.DU

www.alarmingvideos.com

BDS%2FPHP.Agent.CR.1

tv-k.dk

BDS%2FPHP.Agent.DB

kkotlove.or.kr

BDS%2FPHP.Agent.DW.3

sputv.ru

BDS%2FPHP.Agent.EI

bombhot.se

BDS%2FPHP.Agent.EI

www.visionsnet.com

BDS%2FPHP.ali.13

cctv-spares.com

BDS%2FPHP.Small.T.1

j-vision.co.kr

BDS%2FPHP.Small.T.1

www.j-vision.co.kr

BDS%2FPHP.Small.T.11

cityofsound.tv

BehavesLike%21IK

cfteam.net
Compromised+website+%2F+Leads+to+Liberty+Exploit+Toolkit
auctionchannel.com.sg

DeCaptcher+CAPTCHA+Breaker

tvremote.tv

Directs+to+Rogue

gaysvideos.net

Directs+to+Rogue

pornmoviecollection.com

Directs+to+Trojan

free-best-movies.com

Directs+to+Trojan

olympionik.limewebs.com

DLOADER.Trojan

www.tvnsports.com

Downloader.Generic9.CAWP

videohubb.in

DR%2FAgent.dtvl

www.loycn.com

DR%2FBancos.U

www.gratisweb.com

DR%2FDelphi.Gen

sextuli.com

DR%2FDelphi.Gen

xxb0txx.xx.funpic.de

DR%2FDldr.FraudLoad.wzuu

cfteam.net

DR%2FDldr.FraudLoad.wzuu.1

cfteam.net

DR%2FDldr.FraudLoad.wzuu.2

cfteam.net

DR%2FDldr.FraudLoad.wzuu.3

cfteam.net

DR%2FDldr.FraudLoad.wzuu.5

cfteam.net

DR%2FDldr.FraudLoad.wzuv

cfteam.net

DR%2FDldr.FraudLoad.wzuv.2

cfteam.net

DR%2FDldr.FraudLoad.wzuv.3

cfteam.net

DR%2FDldr.NSIS.Agent.GH

down.nzell.com

DR%2FPdfka.ava

1st-movies.org

DR%2FRansom.Kerlofost.W.7

cinema-film-4you.ru

DR%2FRelevant.A.127

uporto.tucows.com

DR%2FVapsup.yxr

www.copydvdcopy.net

DR%2FVapsup.zcg

www.copydvdcopy.net

DR%2FVapsup.zcg

www.dvdrippers.org

DR%2FVapsup.zcg

www.ripprotecteddvd.com

Fraud+%2F+Scam

downloadmovie.me

Fraud+%2F+Scam

liveraces.tv

Fraud+%2F+Scam

netmoviesnow.com

Fraud+%2F+Scam

online-futbol.tv

Fraud+%2F+Scam

themoviedownloadspro.com

Gen.AdWare%21IK

dvdtompegx.com

Generic17.CNQP

porno-video-hunt.co.cc

HEUR%2FHTML.Malware

fullporntubemovies.com

Heuristic.BehavesLike.JS.Infected.A

provideoland.com
Heuristic.BehavesLike.Win32.Dropper.M
cfteam.net

HTML%2FCrypted.Gen

216.240.140.199

HTML%2FCrypted.Gen

dc-digital.tv

HTML%2FCrypted.Gen

felipemiguel.com

HTML%2FCrypted.Gen

gulfstreamlighting.com

HTML%2FCrypted.Gen

insert-coin.tv

HTML%2FCrypted.Gen

mitchtv.net

HTML%2FCrypted.Gen

pragya.tv

HTML%2FCrypted.Gen

tvph-stream.go.ro

HTML%2FCrypted.Gen

vivo.dannydan.co.uk

HTML%2FCrypted.Gen

www.randabanda.it

HTML%2FFakeAlert.rd.1

blank-record.com

HTML%2FInfected.WebPage.Gen

video.alisko.org

HTML%2FInfected.WebPage.Gen

www.188movie.com

HTML%2FInfected.WebPage.Gen

www.tvkoo.com

HTML%2FMalicious.PDF.Gen

www.ccanlitv.com

HTML%2F"red"irect.P

quazen.com

HTML%2FRevir.Gen

jkbioindia.com

HTML%3AFramer-inf

amadoras.videossexocaseiro.com

HTML%3AIlliframe-C

dc-digital.tv

HTML.Crypted%21IK

video.rybnik.com.pl

HTML.Infected%21IK

amateurvideoindex.com

HTML.Infected.WebPage%21IK

www.cztvu.ah163.net

JS%2FiFrame.ktv

217.144.192.4

JS%2FiFrame.ktv

www.france-italie.net

JS%2FiFrame.rdo

images.cntvs.com

JS%2F"red"irect.qrk

page.freett.com

JS%2F"red"irector.IE

crosportvez.hr

JS%2F"red"irector.k.795

orcenikolov.mt.net.mk

JS%3AFakeCodec-AA

cqb-inc.com

JS%3AScriptIP-inf

erstesdes.org

JS%3AScriptIP-inf

tvpc.com

JS%3AScriptIP-inf

www.tvpc.com
Keyword+poisoning+%2F+Leads+to+Trojan+FakeVimes
wellnessraising.com

Koobface+URLs

02ebe0f.netsolhost.com

Koobface+URLs

an-tec.es

Koobface+URLs

bastianellozambelli.it

Koobface+URLs

careyadkinsdesign.com

Koobface+URLs

ciditalia.it

Koobface+URLs

eastcoastgassers.com

Koobface+URLs

neuesdach.ch

Koobface+URLs

rauret.fr

Leads+to+Koobface

0305f97.netsolhost.com

Leads+to+Koobface

alldance.it

Leads+to+Koobface

bradrichmond.com

Leads+to+Koobface

clarkecasa.net

Leads+to+Koobface

frenchbean.co.uk

Leads+to+Koobface

gosin.be

Leads+to+Koobface

grossmanco.com

Leads+to+Koobface

guest.worldviewproduction.com

Leads+to+Koobface

isteinaudi.it

Leads+to+Koobface

jsacm.com

Leads+to+Koobface

mindbodyandsolemt.com

Leads+to+Koobface

musicomm.ca

Leads+to+Koobface

noleggioquad.it

Leads+to+Koobface

padelbcn.comyr.com

Leads+to+Koobface

plymouth-tuc.org.uk

Leads+to+Koobface

youniverse.site50.net

LockScreen.M

wasaporn.com

Malware%2FWin32.Generic

mediaplusltd.com

New+Malware.lw

hegudinyfemicy.dyndns.tv

New+Malware.lw

irelujykuiri.webhop.net

New+Malware.lw

ymufigedokuci.servebbs.com

Packed%2FWin32.Katusha

dvaita.org

Packed%2FWin32.Katusha

todayporntube.in

Packed%2FWin32.Katusha

top100animalclips.in

Packed.Win32.Klone%21IK

adsifyanfka700.3322.org

PAK_Generic.009

www.stvsoft.com

PERL%2FShellbot.aa

cityofsound.tv

PERL%2FShellbot.AB

www.actualtv.ro

PHP%2FAgent.BG

cctv-spares.com

PHP%2FBackDoor.AR

daegu-cctv.com

PHP%2FBackDoor.AR

songdosarang.org

PHP%2FBackDoor.AR

tv-k.dk

PHP%2FBackDoor.AR

visionsnet.com

PHP%2FBackDoor.AR

www.miranda.gov.ve

PHP%2FBackDoor.BB

actualtv.ro

PHP%2FBackDoor.BB

www.actualtv.ro

PHP%2FBackDoor.JU

mpress.com.ua

PHP%2FC99Shell.149816

www.miranda.gov.ve

PHP%2FC99Shell.C

www.kallab.at

PHP%2FC99Shell.C

www.miranda.gov.ve

PHP%2FC99Shell.ck.92

tv1.fileave.com

PHP%2FC99Shell.F

ccridertv.com

PHP%2FC99Shell.L

bellagemsjewelry.com

PHP%2FIRCBOT.21970

tvi33.com

PHP%2FIRCBOT.30850

ltvmedia.net

PHP%2FIRCBOT.A

songdosarang.org

PHP%2FIRCBOT.A

topdvdset.com

PHP%2FIRCBOT.EH

tv-k.dk

PHP%2FMailer.P

www.miranda.gov.ve

PHP%2FPastie.637

www.miranda.gov.ve

PHP%2FPbot.A.6

actualtv.ro

PHP%2FPbot.A.6

sputv.ru

PHP%2FPbot.A.6

www.actualtv.ro

PHP%2FPbot.C

emetv.es

PHP%2FSendmail.11235

www.toneslinger.net

PHP%2FShell.961.BB

www.miranda.gov.ve

PHP%2FShellbot.7642

sportvision.cl

PHP%2FSmall.C

ar-vision.com

PHP%2FSmall.C

www.ar-vision.com

PHP%2FSmall.E

daegu-cctv.com

PHP%2FSmall.E

www.daegu-cctv.com

PHP%2FZapchast.C

ltvmedia.net

PHP%2FZapchast.C

sputv.ru

PHP%2FZapchast.C

www.sputv.ru

PHP.Agent-4

bellagemsjewelry.com

PHP.Agent-4

songdosarang.org

PHP.Agent-4

sputv.ru

PHP.Agent-4

svision-online.de

PHP.Agent-4

thefamilycenter.tv

PHP.Agent-4

www.bellagemsjewelry.com

PHP.Agent-4

www.miranda.gov.ve

PHP.Agent-4

www.songdosarang.org

PHP.Agent-4

www.sputv.ru

PHP.Id-30

tv-k.dk

PHP.Id-30

visionsnet.com

PHP.Id-30

www.tv-k.dk

PHP.Id-30

www.visionsnet.com

PHP.Spy

www.miranda.gov.ve

PUA.HTML.Infected.WebPage-2

banners.hotbox.com

Rogue+Software

videotoflashconverter.com

Scam

now-download-movies.com

SPR%2FPHP.ID

www.sntv.it
Suspicious%3AW32%2FMalware%21Gemini
imgcdn.pandora.tv

Suspicious+file

download.pplive.com

Suspicious+file

t.11ad.com

Suspicious+File

www.iriverplus.com:80

Suspicious.Insight

cfteam.net

TR%2FAgent.37414

cfteam.net

TR%2FAgent.AR.368

gpgp.ws

TR%2FBagle.trash

vincere-videopoker-online.com

TR%2FBagle.trash

www.sportverein-kranzberg.de

TR%2FBuzus.cehh

66.115.146.145

TR%2FCodecPack.kuz.11

designnewmedia.com

TR%2FCodecPack.kuz.11

idigitaldata.com

TR%2FCodecPack.kuz.11

todaybestfreeporn.in

TR%2FCodecPack.kuz.11

videohubb.in

TR%2FCodecPack.kuz.4

adnetmultimedia.com

TR%2FCodecPack.kuz.4

thestartmedia.com

TR%2FCrypt.FKM.Gen

scritainformatica.com.br

TR%2FCrypt.XDR.Gen

odkaufnakd122.3322.org

TR%2FCrypt.XPACK.Gen

www.cztvu.ah163.net

TR%2FCrypt.ZPACK.Gen

centralspa.ca

TR%2FCrypt.ZPACK.Gen

pinkeve.com

TR%2FCrypt.ZPACK.Gen

portaledonna.org

TR%2FCrypt.ZPACK.Gen

www.naturstein-thiel.de

TR%2FCrypt.ZPACK.Gen

www.sealux.cz

TR%2FCrypt.ZPACK.Gen

www.turbobipower.go.ro

TR%2FDelf.tvc

golodprogress.com

TR%2FDldr.Agent.fhx.15

albinofarm.moviecoupons.com

TR%2FDldr.Banload.axbr

83.103.44.141

TR%2FDldr.FraudLoad.xaih

afa15.com.ne.kr

TR%2FDldr.FraudLoad.xaih

artelux.es

TR%2FDownloader.Gen

updator.funtvi.kr

TR%2FDropper.Gen

imagequest360.com

TR%2FDropper.Gen

rouwenhorstuitvaart.nl

TR%2FDropper.Gen

us2-www.0texkax7c6hzuidk.com

TR%2FDropper.Gen

www.ccanlitv.com

TR%2FDropper.Gen

www.hentaimoviez.com

TR%2FDropper.Gen

www.musicomm.ca

TR%2FDropper.Gen

www.tvopen.com

TR%2FFakeAV.we.33

romabikepolo.org

TR%2FGendal.37418

cfteam.net

TR%2FMuss.A.6

168.150.251.105

TR%2FMuss.A.6

ditto.arpa.org

TR%2FPCK.Tdss.Z.6298

movies.freeddns.com

TR%2FPHPShell.U

ltvmedia.net

TR%2FRansom.XBlocker.ard.2

core3023.onlinevideochanel.com

TR%2FVB.Downloader.Gen

meinv.tv

TR%2FVundo.Gen

82.98.193.102

Trj%2FCI.A

inugodiguqoquno.ath.cx

Troj%2FJS"red"ir-AI

www.adultpornvideopics.com

Trojan%2FDropper.FrauDrop.jl

x2xsoft.com

Trojan%2FWin32.Fakeav

todaypornstars.in

Trojan%2FWin32.FraudPack

hot4youxxx.in
Trojan-Downloader.Java.OpenStream%21IK
mirkinodeswrs.net
Trojan-Downloader.JS.Agent
windpowerresearchblogger.moviecoupons.com

Trojan-Downloader.JS.Agent%21IK

lisa1.moviecoupons.com

Trojan-Downloader.JS.Agent%21IK

nwfilm.com
Trojan-Downloader.JS.Agent.fhx
housebythecemeterythe.moviecoupons.com

Trojan-Downloader.JS.Twetti%21IK

www.freehitmovies.org

Trojan-Downloader.Small.CCG

club.telepolis.com

Trojan.Agent.ATV

cfteam.net

Trojan.Downloader-67882

www.u.cn

Trojan.Generic.KD.13862

porno-video-hunt.co.cc

Trojan.Generic.KD.17275

video-fix.co.cc

Trojan.Generic.KD.17334

lovepornhub.in

Trojan.Generic.KD.17564

superxxxporn.in

Trojan.Generic.KD.17821

cenijypufupyn.merseine.nu

Trojan.Generic.KD.17821

jusiabolooruq.dyndns.tv

Trojan.Generic.KD.17918

ibujopucycibor.gotdns.org

Trojan.Generic.KD.17918

ouhytotomijesu.go.dyndns.org

Trojan.Generic.KD.17918

rolosudenydek.blogsite.org

Trojan.Generic.KD.17918

yjypekiqiumasep.homeunix.net

Trojan.Generic.KD.18037

opubepepuocup.is-a-geek.org

Trojan.Generic.KD.18037

purieojoruji.go.dyndns.org

Trojan.Generic.KD.18037

tuteusiokigimu.gotdns.org

Trojan.Generic.KD.18037

usybepukihyjok.game-host.org

Trojan.Generic.KD.18103

hubiryriiusato.gotdns.com

Trojan.Generic.KD.18103

ususimyadocona.dyndns.biz

Trojan.JS.IFrame%21IK

www.gratisweb.com

Trojan.Tdss.2459

ejesetigifoo.dynalias.net

Trojan.Tdss.2459

iseyceysiqy.dnsalias.net

Trojan.Win32.Alureon.h+%28v%29

netyeryudec.getmyip.com

Trojan.Win32.FraudPack.apxg

hotxxxtubevideo.com

Trojan.Win32.Shutdowner%21IK

cfteam.net

TrojWare.Win32.Agent.%7EDFX

cfteam.net

TrojWare.Win32.Agent.%7EHJA

cfteam.net

TrojWare.Win32.Agent.%7EHJH

cfteam.net

TrojWare.Win32.Agent.%7EHUP

cfteam.net

TrojWare.Win32.Agent.%7EHYB

cfteam.net

TrojWare.Win32.Agent.%7EJUI

cfteam.net

TROJ_B"red"O.SMXC

rylysequkofa.thruhere.net

TROJ_FAKEAV.SMAK

designnewmedia.com

TROJ_FAKEAV.SMAK

digitalinformationmedia.com

TROJ_FAKEAV.SMAK

digitaltoolsworld.com

TROJ_FAKEAV.SMAK

finestutilitesguide.com

TROJ_FAKEAV.SMAK

newdatalink.com

TROJ_FAKEAV.SMAX

fileformatutilities.com

TROJ_FAKEAV.SMAX

finestutilitesguide.com

TROJ_FAKEAV.SMAX

mostdvd.com

TROJ_FAKEAV.SMAX

pornwithanimals.in

TROJ_FAKEAV.SMAX

thegoodfiles.com

UnclassifiedMalware

gioia-m.jp

unknown_exe

cddvdwriter.com

unknown_exe

cfteam.net

unknown_exe

download.ppStream.com

unknown_exe

ftp.spisnet.sk

unknown_exe

movietoolbox.net

unknown_exe

www.cddvdcopy.net

unknown_exe

www.cddvdwriter.com

unknown_exe

www.clonedvd.net

unknown_exe

www.computerdelhi.com

unknown_exe

www.copydvdcopy.net

unknown_exe

www.livetv.us.com

unknown_exe

www.mytalkingbuddy.com

unknown_exe

www.oneclicktools.com
unknown_file_%24INSTDIR%2FPowerDVDPlayer.exe
power-dvd-player.ivefound.com

unknown_html

1st-movies.org

unknown_html

208.98.41.113

unknown_html

208.98.41.94

unknown_html

74.55.47.101

unknown_html

bestvideoonlinepornosexsite.info

unknown_html

bid.openx.net

unknown_html

cdn.streamlike.com

unknown_html

core3023.onlinevideochanel.com

unknown_html

cute-tv

unknown_html

directvirus.com

unknown_html

freewarezsoft.com

unknown_html

gpwg.ws

unknown_html

holaamerica.tv

unknown_html

hotxxxtubevideo.com

unknown_html

movies.freeddns.com

unknown_html

ocsp.entrust.net

unknown_html

quotidiennokoue.com

unknown_html

s0.tochka.net

unknown_html

simonelliafi.it

unknown_html

soft.9ptv.org

unknown_html

thedh.info

unknown_html

theinternetdad.com

unknown_html

travel-videos.com

unknown_html

tvlistings4.zap2it.com

unknown_html

video.mature-land.com

unknown_html

www.celebritycashrocks.com

unknown_html

www.novustvnet.com

unknown_html

www.ttver.com

unknown_html_google_malware

a.release.51edm.net

unknown_html_google_malware

after40vids.com

unknown_html_google_malware

bunnyclub.tv

unknown_html_google_malware

cfteam.net

unknown_html_google_malware

dl.targetsaver.com

unknown_html_google_malware

extralargevideos.com

unknown_html_google_malware

greatladymovies.com

unknown_html_google_malware

ieshow.co.kr

unknown_html_google_malware

release.51edm.net

unknown_html_google_malware

teenbestmovie.com

unknown_html_google_malware

thefuckingvideos.com

unknown_html_google_malware

www.ccanlitv.com

unknown_html_google_malware

www.filmforum.org

unknown_html_google_malware

xmaturevids.net

unknown_html_google_malware

xmoviesday.com

unknown_html_RFI

artvanprogram.org

unknown_html_RFI

dvdshrink-hq.com

unknown_html_RFI

easyipodmovies.com

unknown_html_RFI

hafeyot.co.il

unknown_html_RFI

mostvaluablemajors.com

unknown_html_RFI

moviemaze.us

unknown_html_RFI

ottaviocasalini.com

unknown_html_RFI

palestraenergia.com

unknown_html_RFI

riverstoneimmobiliare.it

unknown_html_RFI

sampeipesca.it

unknown_html_RFI

themusicofabba.com

unknown_html_RFI

thex-perience.com

unknown_html_RFI

tvpc-now.com

unknown_html_RFI

tvprocessing.com

unknown_html_RFI

werme.nu

unknown_html_RFI

www.flashgames.de

unknown_html_RFI

www.sntv.it
unknown_html_RFI
www.streammoviesonlinenow.com

unknown_html_RFI

www.videolinksonline.com

unknown_html_RFI_eval

91.151.208.65

unknown_html_RFI_eval

corepoweryoga.com

unknown_html_RFI_eval

dogsonacid.trackitdown.net

unknown_html_RFI_eval

downloads.dogsonacid.com

unknown_html_RFI_eval

hairbasket.com

unknown_html_RFI_eval

tuporno.tv

unknown_html_RFI_eval

www.buienradar.nl

unknown_html_RFI_eval

www.whatsonindia.com

unknown_html_RFI_eval

xpornmovies.net

unknown_html_RFI_php

freetvbar.com

unknown_html_RFI_php

malirstvikt.cz

unknown_html_RFI_php

tvi33.com

unknown_html_RFI_php

u7.search-on.co.kr

unknown_html_RFI_php

updator.funtvi.kr

unknown_html_RFI_php

www.stvsoft.com

unknown_html_RFI_shell

geppettosworld.co.za

unknown_html_RFI_shell

kbcontract.cz

unknown_html_RFI_shell

maturevideoanarchy.com

unknown_html_RFI_shell

provisiontransport.com

unknown_html_RFI_shell

thekompany.com.au

unknown_html_RFI_shell

veerle-frank.be

unknown_html_RFI_shell

videos.sapo.pt

unknown_html_RFI_shell

videozonli.net

unknown_html_RFI_shell

vision-systems.gr

unknown_html_RFI_shell

www.celebritycashrocks.com

unknown_html_RFI_shell

www.dvd-cloner.com

unknown_html_RFI_shell

www.neatmovies.com

unknown_html_RFI_shell

xxsmovies.com

unknown_html_RFI_shell

youngsvideo.com

Virus.PHP.Pbot%21IK

andresexoo.justfree.com

Virus.Win32.Hupigon.KPH%21IK

movietoolbox.net
W32%2FFakeAlert.FT.gen%21Eldorado
free-porn-video.co.tv
W32%2FFakeAlert.FT.gen%21Eldorado
getnewfreeporn.in

W32%2FVirut.A

cfteam.net

Win32%2FRenos.D%21generic

thegoodfiles.com

Win32%3AMalOb-BL

bestmediastar.com

Win32%3AMalOb-BL

solopornvideos.in

Win32%3AMalOb-BL

todaypornstars.in

Win32%3AMalware-gen

ienilulupehyjom.servebbs.org

Win32.Packed.Krap.w.4

a3xbeerrr.co.cc

Win32.Packed.Krap.w.4

bestofpornmovies.in

Win32.Packed.Krap.w.4

free-porn-video.co.tv

Win32.Packed.Krap.w.4

quicklinemultimedia.com

Win32.Packed.Krap.w.4

todayporntube.in

WORM%2FAutorun.bno

cfteam.net

WS.Reputation.1

down.nzell.com