Preocupado com os recentes CVEs do PAN-OS e de outros firewalls/VPNs? Aproveite a oferta especial da Zscaler hoje mesmo

Blog da Zscaler

Receba as últimas atualizações do blog da Zscaler na sua caixa de entrada

Pesquisa de segurança

New PPI Campaign

septiembre 01, 2010 - 1 Min. de leitura

PPI being pay-per-install ...

This morning I saw some interesting transactions to:

where ### are numbers, for example, "519".

MD5: 1568edcd29629f577207d7396646b741

VirusTotal results 8/43 (report), detected as (among other names):

Turns out this is being spread through spammers, SEOers, etc. being financed in a PPI model, something that I have discussed before in the past. This time I have a screenshot to share related directly to the finance aspect of this particular PPI:

This post was created today. We can see from the PPI ad that those engaging in this particular campaign stand to make between $500 and $800 per 1000 installs (< $1 per install). The numbers in the executable, like "519" correspond to the account for the spammer/SEOer that is monetizing this. Domain: Whois billing contact shows likely Russian affiliation: ImageHere is the actual Affiliate Network setup by this guy:

ImageDomain: (private/masked Whois)
(note the RU nameservers)
ImageSource of the page actual reveals that the Affiliate website is loaded from
ImageNo surprise that the contact details are bogus, but the email address is legit, here's a past domain registered with these email credentials:
ImageRobtex shows these other domains (all likely other PPI sites) on (Sagade Ltd. <- not a surprise for some) in Latvia, hosting Image

form submtited
Obrigado por ler

Esta postagem foi útil??

dots pattern

Receba as últimas atualizações do blog da Zscaler na sua caixa de entrada

Ao enviar o formulário, você concorda com nossa política de privacidade.