Archive
Mac OS X: 2007 Year Ender for Zlob
Then, it was last year when this trojan stand-out to the crowd of other competing malwares. A new variant arrived to users via email employing social engineering tactics to attract users in clicking the link to video. However, the video does not play successfully without installing the required codec. This tricky behavior persuades the user to install the fake codec – unknowingly, the user has just installed the malware!
The spurs of shares, free downloads, blogs and social websites has become a perfect time for Zlob to infiltrate networks. Evidently, the increasing domain names and clicks have been utility for Zlob to stay visible in search engines.
Yes, all of this works in Windows until late this year (November), this trojan crosses over to Mac specifically OS X. Suddenly, a list of domain names is capable to download installers both for Windows and Mac users. Domain names hosting Zlob fake codec for Mac user does not sleep, it stays online 24×7 and it’s increasing in numbers. It’s out there in-the-wild!
These sites are smart enough to check if you are running in Windows or Mac. Then, it gives you the right installer either in Windows Executable (EXE) or Disk Image (DMG) for Mac.
Who’s behind Zlob? Let’s investigate its network connection …
:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
Web Site: http://codecdemo.com
A–>64.28.184.189–PTR->64.28.184.189-rev.cernel.net
NS–>ns1.codecdemo.com—A–>64.28.181.226–PTR->64-28-181-226-rev.cernel.net
NS–>ns2.codecdemo.com—-A–>64.28.181.227–PTR->64-28-181-227-rev.cernel.net
MX–>10mail.codecdemo.com–A–>64.28.184.164–PTR->64-28-184-164-rev.cernel.net
NET —-> gw1.cernel.net [ 64.28.176.1]–> AS27595
:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::







Recent Comments