Beware of Fake PornTube Website at KUKUZHMUKU.COM Hosted in California – Part 1

anti spam






TOKYO (MacHouse) – Several hours ago, a cyber spam terrorist circulated a short spam comment involving five vBulletin websites. (See Screenshot 01.) The following is a list of the domains where forums contain at least one spam profile.





  • attc.edu.au
  • blokt.com
  • djw.hr
  • escort-czech.com
  • gopckt.com




  • attc.edu.au blokt.com djw.hr escort-czech.com gopckt.com vBulletin fake PornTube kukuzhmuku.com
    Screenshot 01 – Source: MacHouse
      attc.edu.au blokt.com djw.hr escort-czech.com gopckt.com vBulletin fake PornTube kukuzhmuku.com
    Screenshot 02 – Source: attc.edu.au
      attc.edu.au blokt.com djw.hr escort-czech.com gopckt.com vBulletin fake PornTube kukuzhmuku.com
    Screenshot 03 – Source: attc.edu.au






    Visiting the website at attc.edu.au, it looks like an education-related website for non-native-English speakers. (See Screenshot 02.) Visiting the spam profile found at http://www.attc.edu.au/forum2/member.php?u=1597, you will find a hyperlink under a sexually-explicit phrase starting with the word ‘mature.’ (See Screenshot 03.) The underlying link is http://vbestserv.org/ds/go.php?sid=1. This spam website is believed to determine your next destination, depending your geographic location, referer and other aspects. One destination is the website at videopreviewshow.com, where you will be forced to download a file titled c-setup.exe, which is delivered from http://216.240.151.112. (See Screenshot 04.) 





    attc.edu.au blokt.com djw.hr escort-czech.com gopckt.com vBulletin fake PornTube kukuzhmuku.com
    Screenshot 04 – Source: videopreviewshow.com
      attc.edu.au blokt.com djw.hr escort-czech.com gopckt.com vBulletin fake PornTube kukuzhmuku.com
    Screenshot 05 – Source: kukuzhmuku.com
      attc.edu.au blokt.com djw.hr escort-czech.com gopckt.com vBulletin fake PornTube kukuzhmuku.com
    Screenshot 06 – Source: kukuzhmuku.com






    Another destination is a fake PornTube website at kukuzhmuku.com. (See Screenshot 05.) The story is the same as other fake PornTube websites. Clicking on one of the sexually-explicit images, you will be forced to download a suspicious file, which is delivered from http://download-top-software.net. (See Screenshot 06.)

    Our preliminary analysis shows that the Watch Free Movie website found at the domain of videopreviewshow.com seems to be hosted in Ukraine. As for the fake PornTube website, it appears to be hosted in Los Angels, California, USA. We will have a more detailed report in several hours.

    This entry was posted in Internet security and tagged , . Bookmark the permalink.

    Leave a Reply

    Your email address will not be published.

    You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

    Comment spam protected by SpamBam

    Notify me of followup comments via e-mail. You can also subscribe without commenting.