{"id":11023,"date":"2013-05-15T00:00:07","date_gmt":"2013-05-15T06:00:07","guid":{"rendered":"http:\/\/blog.webroot.com\/?p=11023"},"modified":"2018-01-30T12:21:47","modified_gmt":"2018-01-30T19:21:47","slug":"fake-free-media-player-distributed-via-rogue-adobe-flash-player-hd-advertisement","status":"publish","type":"post","link":"https://www.webroot.com/blog/2013\/05\/15\/fake-free-media-player-distributed-via-rogue-adobe-flash-player-hd-advertisement\/","title":{"rendered":"Fake &#8216;Free Media Player&#8217; distributed via rogue &#8216;Adobe Flash Player HD&#8217; advertisement"},"content":{"rendered":"<p>Our sensors just picked up a rogue advertisement served through the\u00a0Yieldmanager ad network, which exposes users to fake Adobe Flash Player HD ads, ultimately dropping a copy of the potentially unwanted application (PUA)\/adware, known as Somoto Better Installer.<\/p>\n<p>More details:<\/p>\n<p><!--more--><\/p>\n<p><strong>Sample screenshot of the actual advertisement:<\/strong><\/p>\n<p><a href=\"http:\/\/webrootblog.files.wordpress.com\/2013\/05\/fake_flash_player_hd_02_adware_somoto.png\"><img decoding=\"async\" loading=\"lazy\" class=\"aligncenter size-full wp-image-11026\" alt=\"Fake_Flash_Player_HD_02_Adware_Somoto\" src=\"http:\/\/webrootblog.files.wordpress.com\/2013\/05\/fake_flash_player_hd_02_adware_somoto.png\" width=\"299\" height=\"251\" \/><\/a><\/p>\n<p>Surprisingly, once users click, they&#8217;re presented with a rogue Free Media Player page, instead of of a Adobe Flash Player HD themed page. Users who fall victim to the social engineering scam will end up installing multiple potentially unwanted applications.<\/p>\n<p><strong>Yieldmanager ad URL:<\/strong><br \/>\n<em>hxxp:\/\/ad.yieldmanager.com\/clk?3,eJyljd1ugkAQhZ.GO0qWv7Bk04tBpEpZBbOVyN2yQkWxEt10I0.fJbS-QE8mZ07mJ5.lENygA8duhZE4uNwVxHLqwKu9qmkqAxFCHOT7VuBbXmAsH4mEZLt4z-d1MogQRqX9huUw6XO01ZQzPHoI9-Ir-92fXiib0ry33yj8Q7dd-AfVPKXREYbMN7uOueHzKhIPGoFaX1Z2WiTHDVtIyuKOtsgri48hZfFpP8TnkgFaR9u2zJ-fr4ZxlLKfOTCzY11KKZPfJe.4d6ubKa4XPf0Bx21b5Q==,<\/em><\/p>\n<p><strong>Landing domain:<\/strong><br \/>\n<em>hxxp:\/\/www.softigloo.com<\/em> &#8211; 78.138.105.151. Responding to the same IP is also the following typosquatted domain &#8211; <em>hxxp:\/\/down1oads.com<\/em><\/p>\n<p style=\"text-align:center;\"><a href=\"http:\/\/webrootblog.files.wordpress.com\/2013\/05\/fake_flash_player_hd_01_adware_somoto.png\"><img decoding=\"async\" loading=\"lazy\" class=\"aligncenter  wp-image-11028\" alt=\"Fake_Flash_Player_HD_01_Adware_Somoto\" src=\"http:\/\/webrootblog.files.wordpress.com\/2013\/05\/fake_flash_player_hd_01_adware_somoto.png\" width=\"706\" height=\"564\" \/><\/a><\/p>\n<p><strong>Detection rate for the sampled malware:<\/strong><br \/>\n<a href=\"https:\/\/www.virustotal.com\/en\/file\/826b5b15c89eb70d8459bb26a4faefdf505e3baae76bb6dd49289aa96d72217a\/analysis\/1368314633\/\"><strong>MD5: 3ee49800cc3c2ce74fa63e6174c81dff<\/strong><\/a> &#8211; detected by 8 out of 46 antivirus scanners as Somoto BetterInstaller; Adware.Somoto<br \/>\n<a href=\"https:\/\/www.virustotal.com\/en\/file\/2e0d7b543e5471f9bff7ec7f9121658d0e8fd588238f7c0b98c9e863061fc0ba\/analysis\/1368314918\/\"><strong>MD5: b57cc4b5aecd69eb57063f4de914d4dd<\/strong><\/a> &#8211; detected by 8 out of 46 antivirus scanners as 8 out of 46 antivirus scanners as Somoto BetterInstaller; TROJ_GEN.F47V0429<\/p>\n<p style=\"text-align:center;\"><a href=\"http:\/\/webrootblog.files.wordpress.com\/2013\/05\/fake_flash_player_hd_adware_somoto.png\"><img decoding=\"async\" loading=\"lazy\" class=\"aligncenter  wp-image-11029\" alt=\"Fake_Flash_Player_HD_Adware_Somoto\" src=\"http:\/\/webrootblog.files.wordpress.com\/2013\/05\/fake_flash_player_hd_adware_somoto.png\" width=\"706\" height=\"341\" \/><\/a><\/p>\n<p><strong>Once executed, MD5: b57cc4b5aecd69eb57063f4de914d4dd creates the following files on the affected hosts:<\/strong><br \/>\n<em>C:DOCUME~1&lt;USER&gt;~1LOCALS~1Tempnsh2.tmp<\/em><br \/>\n<em>C:DOCUME~1&lt;USER&gt;~1LOCALS~1Tempbiclient.exe<\/em><br \/>\n<em>C:DOCUME~1&lt;USER&gt;~1LOCALS~1Tempconfig.ini<\/em><br \/>\n<em>C:DOCUME~1&lt;USER&gt;~1LOCALS~1Tempbundlesweetimsetup.exe.0<\/em><br \/>\n<em>C:DOCUME~1&lt;USER&gt;~1LOCALS~1Tempbundlesweetimsetup.exe.2<\/em><br \/>\n<em>C:DOCUME~1&lt;USER&gt;~1LOCALS~1Tempbundlesweetimsetup.exe.5<\/em><br \/>\n<em>C:DOCUME~1&lt;USER&gt;~1LOCALS~1Tempbundlesweetimsetup.exe.4<\/em><br \/>\n<em>C:DOCUME~1&lt;USER&gt;~1LOCALS~1Tempbundlesweetimsetup.exe.3<\/em><br \/>\n<em>C:DOCUME~1&lt;USER&gt;~1LOCALS~1Tempbundlesweetimsetup.exe.6<\/em><br \/>\n<em>C:DOCUME~1&lt;USER&gt;~1LOCALS~1Tempbundlesweetimsetup.exe.7<\/em><br \/>\n<em>C:DOCUME~1&lt;USER&gt;~1LOCALS~1Tempbundlesweetimsetup.exe.1<\/em><br \/>\n<em>C:DOCUME~1&lt;USER&gt;~1LOCALS~1Tempbundlesweetimsetup.exe<\/em><br \/>\n<em>C:DOCUME~1&lt;USER&gt;~1LOCALS~1TempDeltaTB.exe.0<\/em><br \/>\n<em>C:DOCUME~1&lt;USER&gt;~1LOCALS~1TempDeltaTB.exe.1<\/em><br \/>\n<em>C:DOCUME~1&lt;USER&gt;~1LOCALS~1TempDeltaTB.exe.2<\/em><br \/>\n<em>C:DOCUME~1&lt;USER&gt;~1LOCALS~1TempDeltaTB.exe.3<\/em><br \/>\n<em>C:DOCUME~1&lt;USER&gt;~1LOCALS~1TempDeltaTB.exe.4<\/em><br \/>\n<em>C:DOCUME~1&lt;USER&gt;~1LOCALS~1TempDeltaTB.exe.5<\/em><br \/>\n<em>C:DOCUME~1&lt;USER&gt;~1LOCALS~1TempDeltaTB.exe.6<\/em><br \/>\n<em>C:DOCUME~1&lt;USER&gt;~1LOCALS~1TempDeltaTB.exe.7<\/em><br \/>\n<em>C:DOCUME~1&lt;USER&gt;~1LOCALS~1TempDeltaTB.exe<\/em><br \/>\n<em>C:DOCUME~1&lt;USER&gt;~1LOCALS~1TempLollipopInstaller_somoto_14693.exe.0<\/em><br \/>\n<em>C:DOCUME~1&lt;USER&gt;~1LOCALS~1TempLollipopInstaller_somoto_14693.exe.2<\/em><br \/>\n<em>C:DOCUME~1&lt;USER&gt;~1LOCALS~1TempLollipopInstaller_somoto_14693.exe.1<\/em><br \/>\n<em>C:DOCUME~1&lt;USER&gt;~1LOCALS~1TempLollipopInstaller_somoto_14693.exe.3<\/em><br \/>\n<em>C:DOCUME~1&lt;USER&gt;~1LOCALS~1TempLollipopInstaller_somoto_14693.exe.4<\/em><br \/>\n<em>C:DOCUME~1&lt;USER&gt;~1LOCALS~1TempLollipopInstaller_somoto_14693.exe.5<\/em><br \/>\n<em>C:DOCUME~1&lt;USER&gt;~1LOCALS~1TempLollipopInstaller_somoto_14693.exe.6<\/em><br \/>\n<em>C:DOCUME~1&lt;USER&gt;~1LOCALS~1TempLollipopInstaller_somoto_14693.exe.7<\/em><br \/>\n<em>C:DOCUME~1&lt;USER&gt;~1LOCALS~1TempLollipopInstaller_somoto_14693.exe<\/em><br \/>\n<em>C:DOCUME~1&lt;USER&gt;~1LOCALS~1TempLyricsPal.exe.2<\/em><br \/>\n<em>C:DOCUME~1&lt;USER&gt;~1LOCALS~1TempLyricsPal.exe.3<\/em><br \/>\n<em>C:DOCUME~1&lt;USER&gt;~1LOCALS~1TempLyricsPal.exe.4<\/em><br \/>\n<em>C:DOCUME~1&lt;USER&gt;~1LOCALS~1TempLyricsPal.exe.5<\/em><br \/>\n<em>C:DOCUME~1&lt;USER&gt;~1LOCALS~1TempLyricsPal.exe.0<\/em><br \/>\n<em>C:DOCUME~1&lt;USER&gt;~1LOCALS~1TempLyricsPal.exe.1<\/em><br \/>\n<em>C:DOCUME~1&lt;USER&gt;~1LOCALS~1TempLyricsPal.exe.6<\/em><br \/>\n<em>C:DOCUME~1&lt;USER&gt;~1LOCALS~1TempLyricsPal.exe.7<\/em><br \/>\n<em>C:DOCUME~1&lt;USER&gt;~1LOCALS~1TempLyricsPal.exe<\/em><br \/>\n<em>C:DOCUME~1&lt;USER&gt;~1LOCALS~1Temp7z920.exe.0<\/em><br \/>\n<em>C:DOCUME~1&lt;USER&gt;~1LOCALS~1Temp7z920.exe.1<\/em><br \/>\n<em>C:DOCUME~1&lt;USER&gt;~1LOCALS~1Temp7z920.exe.2<\/em><br \/>\n<em>C:DOCUME~1&lt;USER&gt;~1LOCALS~1Temp7z920.exe.3<\/em><br \/>\n<em>C:DOCUME~1&lt;USER&gt;~1LOCALS~1Temp7z920.exe.4<\/em><br \/>\n<em>C:DOCUME~1&lt;USER&gt;~1LOCALS~1Temp7z920.exe.7<\/em><br \/>\n<em>C:DOCUME~1&lt;USER&gt;~1LOCALS~1Temp7z920.exe.5<\/em><br \/>\n<em>C:DOCUME~1&lt;USER&gt;~1LOCALS~1Temp7z920.exe.6<\/em><br \/>\n<em>C:DOCUME~1&lt;USER&gt;~1LOCALS~1Temp7z920.exe<\/em><\/p>\n<p><strong>Creates the following Mutexes:<\/strong><br \/>\n<em>CTF.LBES.MutexDefaultS-1-5-21-1275210071-920026266-1060284298-1003<\/em><br \/>\n<em>CTF.Compart.MutexDefaultS-1-5-21-1275210071-920026266-1060284298-1003<\/em><br \/>\n<em>CTF.Asm.MutexDefaultS-1-5-21-1275210071-920026266-1060284298-1003<\/em><br \/>\n<em>CTF.Layouts.MutexDefaultS-1-5-21-1275210071-920026266-1060284298-1003<\/em><br \/>\n<em>CTF.TMD.MutexDefaultS-1-5-21-1275210071-920026266-1060284298-1003<\/em><\/p>\n<p><strong>Makes the following DNS requests:<\/strong><br \/>\n<em>bi.bisrv.com (78.138.97.8)<\/em><br \/>\n<em>installercdn.filebulldog.com (54.239.158.183)<\/em><br \/>\n<em>static.bisrv.com (78.138.97.8)<\/em><br \/>\n<em>cdn.bisrv.com (54.239.158.151)<\/em><br \/>\n<em>cdn.bispd.com (78.138.127.129)<\/em><br \/>\n<em>installercdn.betterinstaller.com (54.239.158.63)<\/em><br \/>\n<em>installer.betterinstaller.com (78.138.97.8)<\/em><br \/>\n<em>download.filesfrog.com (78.138.127.7)<\/em><\/p>\n<p><strong>And initiates the following TCP connections:<\/strong><br \/>\n<em>78.138.97.8:80<\/em><br \/>\n<em>54.239.158.55:80<\/em><br \/>\n<em>78.138.127.129:80<\/em><br \/>\n<em>54.239.158.183:80<\/em><br \/>\n<em>54.239.158.247:80<\/em><br \/>\n<em>78.138.127.7:80<\/em><\/p>\n<p>The affiliate network participant that&#8217;s abusing the Yieldmanager ad network is currently earning revenue through the Somoto&#8217;s BetterInstaller PPI (Pay-Per-Install) revenue sharing network:<\/p>\n<p style=\"text-align:center;\"><a href=\"http:\/\/webrootblog.files.wordpress.com\/2013\/05\/betterinstaller.png\"><img decoding=\"async\" loading=\"lazy\" class=\"aligncenter  wp-image-11031\" alt=\"BetterInstaller\" src=\"http:\/\/webrootblog.files.wordpress.com\/2013\/05\/betterinstaller.png\" width=\"569\" height=\"555\" \/><\/a><\/p>\n<p style=\"text-align:center;\"><a href=\"http:\/\/webrootblog.files.wordpress.com\/2013\/05\/somoto_betterinstaller.png\"><img decoding=\"async\" loading=\"lazy\" class=\"aligncenter  wp-image-11033\" alt=\"Somoto_BetterInstaller\" src=\"http:\/\/webrootblog.files.wordpress.com\/2013\/05\/somoto_betterinstaller.png\" width=\"595\" height=\"537\" \/><\/a><\/p>\n<p>We&#8217;ll be definitely keeping an eye on this PPI revenue-sharing network, especially on the deceptive advertising done on behalf of its participants.<\/p>\n<p><em>You can find more about Dancho\u00a0Danchev at his\u00a0<a href=\"http:\/\/linkedin.com\/in\/danchodanchev\"><strong>LinkedIn Profile<\/strong><\/a>. You can also\u00a0<a href=\"http:\/\/www.twitter.com\/danchodanchev\"><strong>follow him on Twitter<\/strong><\/a>.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Our sensors just picked up a rogue advertisement served through the\u00a0Yieldmanager ad network, which exposes users to fake Adobe Flash Player HD ads, ultimately dropping a copy of the potentially unwanted application (PUA)\/adware, known as Somoto Better Installer. More details:<\/p>\n","protected":false},"author":65,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[3005],"tags":[],"yst_prominent_words":[5707,5701,14433,14439,14431,9969,4985,7179,14437,3871,14441,14435,10891,7187,14447,14453,14451,14443,14449,14445],"acf":[],"_links":{"self":[{"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/posts\/11023"}],"collection":[{"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/users\/65"}],"replies":[{"embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/comments?post=11023"}],"version-history":[{"count":1,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/posts\/11023\/revisions"}],"predecessor-version":[{"id":17065,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/posts\/11023\/revisions\/17065"}],"wp:attachment":[{"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/media?parent=11023"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/categories?post=11023"},{"taxonomy":"post_tag","embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/tags?post=11023"},{"taxonomy":"yst_prominent_words","embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/yst_prominent_words?post=11023"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}