See: http://zulu.zscaler.com/submission/show/224defddd018d6423972460c577a6787-1340268464
& https://www.virustotal.com/file/3f87d1a741bd6a9594d7f092a42f34c1efd325f81cf579718e60adf292cc1046/analysis/
reported to virus AT avast dot com
polonus
See: http://zulu.zscaler.com/submission/show/224defddd018d6423972460c577a6787-1340268464
& https://www.virustotal.com/file/3f87d1a741bd6a9594d7f092a42f34c1efd325f81cf579718e60adf292cc1046/analysis/
reported to virus AT avast dot com
polonus
nice find! looks like the reveton ransom malware in HTML…
Hey! look i found their e-mail address in the HTML data …see screenshots…looks like we can harvest them ;D
Man you are genius,what are you doing here?Fill an application for NASA,they will accept you for sure.Do i need to mention that they give their E-mail on their own?Just look at the picture saying : If an error occurs ,send the codes to the adress surcharge@cyber-metropolitan-police.uk .
See: http://urlquery.net/report.php?id=72958
Looks more like a scam then trying to harm the user. Are these ransom pages used in FakeAVs?
scareware
http://www.2-viruses.com/remove-police-central-ecrime-unit
http://www.cio.co.uk/news/3336896/malicious-software-impersonates-police-e-crime-unit/
and you find lots more if you google it…
Hi Pondus,
When there is one, more to follow, I guess,
pol
there is always more…this will never stop…
gives us something to play with…and essexboy busy
Hello all.
This is Tobfy
See: https://www.botnets.fr/index.php/Tobfy
(a new version is arriving with Camera feature). (see my post here : http://malware.dontneedcoffee.com/2012/06/ransomware-keep-smiling-youre-still-on.html )
And for the sample getting this page :
https://www.virustotal.com/file/21c0601f225087fa6d36ed951e0328bcbd2138bcea6a413162d1a8e17b0cb179/analysis/
https://www.virustotal.com/file/5686a29474da547dafb1163d6f07cb7a78b4695f52c17bb17132e642dbe8d7f6/analysis/
https://www.virustotal.com/file/2724128492fa9ea83c80caec9110e3f06006f72e4d04707b3ac9f00013aa160b/analysis/
For other landing search Tobfy on VT. I used to tagged what i found.
Hi Kafeine,
Thanks for the heads-up. By the way where the second link is concerned: Is your rel canonical tag pointing to another domain?
polonus
I am very pleased to see you here,i found your Blog VIA Xylit0l’s friend list.Welcome,welcome.
It is evident that such threats are widespread,mainly because they are being distributed by Black hole exploit kit.