Page 5 of 6

Re: Rogue Antimalware (FakeAV, 2014 year)

PostPosted:Mon Nov 03, 2014 11:11 pm
by Xylitol
Ramtadryla wrote:Hi, maybe someone has a sample of "Spyware Defender" (or "System Defender") fake av (hxxp://spyware-defender.com)?
System Defender
• dns: 1 ›› ip: 212.7.218.11 - adress: SPYWARE-DEFENDER.COM
---
https://www.virustotal.com/en/file/4efb ... 415056336/

Image

Re: Rogue Antimalware (FakeAV, 2014 year)

PostPosted:Wed Nov 05, 2014 1:41 pm
by Ramtadryla
Hi, thanks for the previous sample ("System Defender"). If possible could anyone attach a sample of "Rango Antivirus 2014"? Should be something similar to Braviax/FakeRean sample posted before by Xylitol. Domain - hxxp://ssmorf1.com/ MD5 - cbc15ca34a62d409b99726b6a2c47a93 (according to ThreatTrack - http://www.threattracksecurity.com/it-b ... kerean.pdf)

Re: Rogue Antimalware (FakeAV, 2014 year)

PostPosted:Thu Nov 06, 2014 9:53 am
by Xylitol
In attach.
Code: Select all
htxp://horisma77.com/X-l2ijw00hmmmvS4DbSBAJIGmN8KKOlT6fLjK8GVmKOeCUHtUq4xfCDkvHjLrO0H3rIH

Re: Rogue Antimalware (FakeAV, 2014 year)

PostPosted:Tue Nov 11, 2014 12:28 pm
by karolis
Hey guys. Maybe someone has this new variation "Windows Antivirus Adviser" sample?

http://siri-urz.blogspot.com/2014/11/wi ... viser.html

Re: Rogue Antimalware (FakeAV, 2014 year)

PostPosted:Tue Nov 11, 2014 1:18 pm
by Xylitol
Have it too, but not for you.
This is not a malware request thread and i suggest you to read the rules before doing something stupid.

Re: Rogue Antimalware (FakeAV, 2014 year)

PostPosted:Wed Nov 12, 2014 12:49 pm
by karolis
Attaching a sample of Windows AntiVirus Adviser.

Re: Rogue Antimalware (FakeAV, 2014 year)

PostPosted:Wed Nov 12, 2014 10:03 pm
by Grinler
Latest Braviax called Sirius <os name> Antivirus|Protection 2014. List of GUI titles are:

Sirius XP Antivirus 2014
Sirius XP Protection 2014 (couldn't confirm this one)
Sirius Vista Antivirus 2014
Sirius Win 7 Antivirus 2014
Sirius Win 8 Antivirus 2014
Sirius XP Protection 2014
Sirius Vista Protection 2014
Sirius Win 7 Protection 2014
Sirius Win 8 Protection 2014

Password: infected.

FakeVimes - Windows AntiBreach Module

PostPosted:Fri Nov 21, 2014 3:57 pm
by TK_
New FakeVimes Rogue - Windows AntiBreach Module

Re: FakeVimes - Windows AntiBreach Module

PostPosted:Sun Nov 23, 2014 3:20 am
by tg1489
Please use a password for it.

Re: Rogue Antimalware (FakeAV, 2014 year)

PostPosted:Thu Nov 27, 2014 9:44 am
by Ramtadryla
Updated FakeRean/Braviax fakeav - uses a name of A-Secure 2015 for all Windows versions. Domains (hxxp://fscurat20.com - 146.185.239.111; hxxp://fscurat21.com - 146.185.239.111)