New domains are added to the list on the first page, and corresponding abuse messages were sent.
If you have any other URL's not listed here, please add.
update 11 Jul 2011, 00:14
New domains detected.
hxxp://gutfmulti.client.jp/xxx_video.exe
hxxp://lecwovil.client.jp/xxx_video.exe
hxxp://farsioce.client.jp/xxx_video.exe
Abuse sent.
update 11 Jul 2011, 14:24
All ninja.co.jp domains deleted.
Lock'Em'All moved to other host. Abuse sent.
hxxp://fimsporn.s3.amazonaws.com/xxx_video.exe DELETED
EDIT:
hxxp://xvidcoms.s3.amazonaws.com/xxx_video.exe DELETED
EDIT2:
hxxp://zzporrno.s3.amazonaws.com/xxx_video.exe DELETED
EDIT3:
hxxp://mixntrd.s3.amazonaws.com/xxx_video.exe DELETED
EDIT4:
hxxp://llzxzt.s3.amazonaws.com/xxx_video.exe DELETED
EDIT5:
hxxp://hnkporn.s3.amazonaws.com/xxx_video.exe DELETED
EDIT6:
hxxp://qqyygf.s3.amazonaws.com/xxx_video.exe DELETED
EDIT7:
hxxp://z4porn.s3.amazonaws.com/xxx_video.exe DELETED
update 13 Jul 2011, 18:04
New domain at Amazon Web Services.
hxxp://1biporn.s3.amazonaws.com/xxx_video.exe
Lock'Em'All is now multipacked also (UPX->VBInject->UPX).
Amazon looks like a paradise for these guys :)
Original
http://www.virustotal.com/file-scan/rep ... 1310550784
Unpacked
http://www.virustotal.com/file-scan/rep ... 1310550476
update 13 Jul 2011, 20:48
The following narod.ru hosted sites have been closed.
hxxp://racviphossotu.narod.ru/
hxxp://northvalgikacen.narod.ru/
hxxp://glitiheslynchea.narod.ru/
hxxp://nievialansscharen.narod.ru/
hxxp://brazunengavi.narod.ru/
hxxp://caropesiter.narod.ru/
hxxp://penfbaddisctranev.narod.ru/
hxxp://mobejustita.narod.ru/
Hello,
Thank you for your report. The reported accounts have been closed.
--
Sincerely yours,
Yandex customer support
http://company.yandex.com/
update 15 Jul 2011, 00:58
New domain
hxxp://rim2bi.s3.amazonaws.com/xxx_video.exe DELETED
hxxp://new3porn.s3.amazonaws.com/xxx_video.exe DELETED
hxxp://w1porka.s3.amazonaws.com/xxx_video.exe DELETED
hxxp://w2yporn.s3.amazonaws.com/xxx_video.exe DELETED
hxxp://w3vporn.s3.amazonaws.com/xxx_video.exe DELETED
hxxp://us1porn.s3.amazonaws.com/xxx_video.exe DELETED
hxxp://2bioko.s3.amazonaws.com/xxx_video.exe DELETED
hxxp://gnpotk.s3.amazonaws.com/xxx_video.exe DELETED
hxxp://w3nixx.s3.amazonaws.com/xxx_video.exe DELETED
hxxp://sv2porn.s3.amazonaws.com/xxx_video.exe DELETED
hxxp://ffporm.s3.amazonaws.com/xxx_video.exe DELETED