The standardization through template-ization of bogus codec/flash player/video pages, taking place during the past two years, has exponentially increased the efficiency levels of malware campaigns relying exclusively on social engineering.
Just like phishing pages being commodity, these commodity spoofs of legitimate software/plugins relying on “visual social engineering” represent a market segment by themselves, one that some cybercriminals have been attempting to monetize for a while.

These very same modules represent the dominant social engineering attack vector on the Internet due to the quality of the spoofs and the end users’ gullibility while self-infecting themselves. For the time being, the author appears to be an opportunist rather than someone interested in setting new benchmarks for standardization social engineering by using the efficiency and delivery methods offered by a web malware exploitation kit.

Meanwhile, the recent blackhat SEO campaign which attempted to hijack ‘Harry Potter and the Half-Blood Prince‘ related traffic is a good example on how despite the magnitude of the campaign — hundreds of thousands of indexed and malware serving pages — due to the manual campaign management, its centralized nature makes it easier to shut down.

the-blue-tube .com – Email: malccrome@gmail.com
onlysteeltube.com – Email: briashou@gmail.com
thecooltube .com – Email: malccrome@gmail.com
etesttube .com – Email: katschezz@gmail.com
thegrouttube .com – Email: katschezz@gmail.com
fllcorp .com
95.211.8.20
exefiledata .com – Email: robeshur@gmail.com
exereload .com – Email: robeshur@gmail.com
load-exe-world .com – Email: robeshur@gmail.com
cool-exe-file .com – Email: robeshur@gmail.com
last-home-exe .com – Email: robeshur@gmail.com
exefreefiles .com – Email: case0ns@gmail.com
boardexefiles .com – Email: case0ns@gmail.com
exeloadsite .com – Email: j0cqware@gmail.com
The gang maintains another domain portfolio with pretty descriptive nature for phone back, direct fake codec serving purposes:
agro-files-archive .com
alkbbs-files .com
all-tube-world .com
best-light-search .com
besttubetech .com
chamitron .com
cheappharmaad .com
dipexe .com
downloadnativeexe .com
ebooks-archive .org
etesttube .com
exedownloadfull .com
exefiledata .com
exe-paste .com
exe-soft-development .com
exe-xxx-file .com
eyeexe .com
go-exe-go .com
greattubeamp .com
green-tube-site .com
hotexedownload .com
hot-exe-load .com
imagescopybetween .com
isyouimageshere .com
labsmedcom .com
last-exe-portal .com
lost-exe-site .com
lyy-exe .com
main-exe-home .com
mchedlishvili .name
metro-tube .net
my-exe-load .com
newfileexe .com
protectionimage .com
robo-exe .com
rube-exe .com
securetaxexe .com
sk1project .org
softportal-extrafiles .com
softportal-files .com
storeyourimagehere .com
super0tube .com
super-exe-home .com
supertubetop .com
sysreport1 .com
sysreport2 .com
testtubefilms .com
texasimages2009 .com
the-blue-tube.com
thecooltube .com
thegrouttube .com
thetubeamps .com
thetubesmovie .com
tiaexe .com
tube-best-4free .com
tube-collection .com
tvtesttube .com
yourtubetop .com
This post has been reproduced from Dancho Danchev’s blog.