Click to Enlarge
Click to Enlarge
You'll notice they missed a trick there, advertising Firefox 6 instead of the freshly minted Firefox 7. The URLs involved are hotelcrystalpark(dot)com/firefox_1 and firefox(dot)dl-labs(dot)com, with the rogue downloads being hosted at the dl-labs URL. VirusTotal score currently gives us 6/43, with VIPRE detecting this as Trojan.Win32.Kryptik.cqw (v).
Christopher Boyd (Thanks to Matthew for finding this one).


No comments:
Post a Comment