BleepingComputer.com: 180 Solutions and CDT take the train to Bittorrent land

Jump to content

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

180 Solutions and CDT take the train to Bittorrent land

#1 User is offline   TeMerc 

  • Countermeasures Team Leader
  • PipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 214
  • Joined: 15-August 04
  • Location:PHX., AZ.

Posted 08 July 2005 - 01:02 AM

"Paperghost" said:

Yes, that's right - 180 Solutions thought it'd be a great idea to not only pursue Bittorrent installer bundles,but kind of mess up on the "this is what's included" front. Hmm....because the last coverage of this kind of thing generated so much good publicity, right?

Same old, same old? Blame the affiliates? Bore us all to death with a "whoops, we got them" and a "same time next month"?

You bet. So come with me and check out the latest great bit of kit in Bittorrent land...


Full Read @ Vital Security.org
Posted Image
Calendar of Updates
Malware Advisor Blog
HijackThis! Trusted Advisor
Ultimate Countermeasures Page
TeMerc Internet Countermeasures
Remember, you can NEVER be OVERPROTECTED!!!
Proud Member of the Alliance of Security Analysis Professionals
Posted Image

#2 User is offline   TeMerc 

  • Countermeasures Team Leader
  • PipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 214
  • Joined: 15-August 04
  • Location:PHX., AZ.

Posted 08 July 2005 - 01:25 AM

From Dave Methvin of PCPitstop:

"Dave" said:

They're doing it again!
More BitTorrent fireworks went off over the July 4th holiday. After the last episode it was inevitable that the pests would come crawling back, but so soon? I plucked two files and installed them to get the details, but I saw at least a dozen more files that are likely to have the same installer. Here's what I found out so far.

Different company, same scam. This time, the supposed distributor is Media Decompressor Company, or at least that's the name in the license. A user downloads one of their files using BitTorrent; often the content is an adult-oriented video. Running the file brings up a dialog with soothing legalese on the first screen; clicking "I Agree" rewards the user with the content and the adware bundle. If the user scrolls down in the license, they will see that this program installs the 180Search Assistant from 180Solutions, Golden Retriever from ShopAtHomeSelect, and Internet Optimizer from Avenue Media. The license text shown to the user only has links to the 180Solutions license; for the others it just mentions that they are installed but says nothing about their license terms.

CDT rides again, with 180Solutions in tow. Several pieces of 180Solutions adware are installed by the bundle. 180Solutions purchased a company named CDT in March 2005. The payload for this latest bundle is immediately retrieved from servers under the control of CDT and/or 180Solutions, from domains owned by the same companies: public.windupdates.com, static.flingstone.com, bis.180solutions.com, and downloads.180solutions.com. If the "Media Compressor Company" exists at all, it delegates responsibility to CDT/180Solutions very early in the install process.


Full Read @ PCPitstop
Posted Image
Calendar of Updates
Malware Advisor Blog
HijackThis! Trusted Advisor
Ultimate Countermeasures Page
TeMerc Internet Countermeasures
Remember, you can NEVER be OVERPROTECTED!!!
Proud Member of the Alliance of Security Analysis Professionals
Posted Image

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users