Potentially Painful Programs Promising Pirated Products
ID: 5e936b25-3b31-5e5a-b390-e6c8df143d5e
STIX ID: report--5e936b25-3b31-5e5a-b390-e6c8df143d5e
Feed Name: Zscaler Security Research Blog
This report describes a widespread adware/spyware campaign that distributes OutBrowse and MultiPlug by luring users with fake installers and pirated-content filenames. It lists sample malicious filenames, numerous .info domains and known beacons (e.g., srv.dmdataserver.com, static.revenyou.com), common persistence locations (Temp, C:\WINDOWS\Tasks, BHO entries), observed secondary bundleware dropped (LightningDownloader, SeekerFoobar, WeatherBug), and recommends removal steps (Control Panel uninstall, checking autostart and BHOs with tools like HiJackThis).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
