94.247.3.232
216.240.151.112
78.159.99.52
www.newdllsolution.com (92.241.163.90)
http://brakeplayer.net (94.247.2.183)One of the site mentioned above,
http://brakeplayer.net (94.247.2.183), hosts a fake media player installer called BrakePlayer. This installer actually installs a nasty kernel mode rootkit. Following screenshot shows the kernel mode hooks installed by rootkit driver:The backdoor component of this rootkit establishes connection with a remote rogue server
85.255.112.188 (whois). VirusTotal scan results for the installer and rootkit driver files can be found here and here respectively.Update: BrakePlayer removal procedure has been posted here. Hope that helps :)
0 comments:
Post a Comment