View Single Post
  #1 (permalink)  
Old 20th February 2012
TheDrive TheDrive is offline
Junior Member
BS.Player Newbie
 
Join Date: Feb 2012
Age: 53
Posts: 1
Rep Power: 0
TheDrive is on a distinguished road
Default BSPlayer Ads used to spread trojans!!!

I just got BSPlayer Lite installed on my Adnroid Tablet/PDA and immediately
got ads claiming (in Russian) I should immediately update Skype. Same ads appears when I watch videos etc.

Being an experianced PC service engineer I have explored suspicious ads and links and found that final link points to generic SMS pay trojan which are widely spreaded in Russia (because of total corruption trojan owners, cellular carriers and police here are in deal). Such trojans send SMS messages to special short numbers so your account becomes immediately empty.

As I said ad claim in Russian that I should update Skype
I've especially taped ad to open page. Then explored links from Android device and from PC.
As you tap ad BSPlayer opens browser and goes to:
ht___tp://govori-besplatno.net/?a=x244y244z403x4u2w4v2t2t2y3s2x444x2z2941394t284x 2c4
This link is just redirect to:
ht___tp://skype3me.net/?a=1394x2a4z403x4u2w4x2t2t2y3q2x444v22384v2d4v2d4w 2e4
On this stage fake Skype page opens which claims in Russian that
critical update for Skype is available.
If you tap Download Skype link at the bottom JavaScript performes and opens:
ht___tp://skype3me.net/d.php?a=1394x2a4z403x4u2w4x2t2t2y3q2x444v22384v2d4 v2d4w2e4&nb
This one is redirected to direct download URL:
ht___tp://free44files.net/midlets/9589_315503664/skype93.apk
for Android or
ht___tp://free44files.net/midlets/9589_315862915/skype93.jar
for PC, depending on that is "User Agent" field of your browser

As I understand ads are region specific so it may be necessary to use Russian proxy and/or OS regional settings to see that ad from other regions.

Please perform actions to stop such a dangerous ads ASAP!!!
Thank you!
Reply With Quote
 

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20