Zlob and Vundo team up!
Recently, noticed few rogue websites that are pushing both Zlob fake codec and Vundo trojan. Usually, Vundo trojans spread in the form of keygens or cracks. However, the gang behind Vundo seems to be collaborating with Zlob gang to spread malware in the form of fake codecs!
Here's one such website,
aaibberlinoschlosschn.com.cn (220.127.116.11), hosting both Vundo and Zlob. A Zlob installer is offered for download if
"Continue"button is clicked, and a Vundo dropper is delivered when
"Download free player"link is clicked.
VirusTotal scan results for Zlob and Vundo droppers are available here and here respectively.