More fake PornTube malware

I have posted many examples of these fake PornTube sites that serve up malware (Trojan.Zlob/Codec) ... "privacy-kit" has gone from a "Rogue Security Program" (March 2007) to serving up malware via a software program (YTFakeCreator) that creates fake "YouTube" style pages. There are now thousands of these type fake PornTube sites.

What's interesting in the above, is the fake Internet Explorer Information Bar (highlighted in red) sadly the download "MediaPlayerUpdate-28-i386.exe" was not detected when submitted to VirusTotal.

So why do we see so many of these type sites? ... in my opinion it's due to the malware authors being unable to successfully exploit an "updated" Windows Vista machine. I have yet to find a site that I have visited that was able to invade my system ... and believe me I visit thousands each week, which are mainly malware related.

Sure the "social-engineering" aspects do trick many unsuspecting people ... but this method only works when users are fooled into clicking on malicious downloads or allowing installs from untrusted sources ...

Published Thu, Oct 2 2008 22:53 by winhelp2002