Author Topic: Fake Anti-Malware Applications  (Read 12039 times)

0 Members and 1 Guest are viewing this topic.

iRonzel

  • Guest
Fake Anti-Malware Applications
« on: June 26, 2010, 04:55:53 AM »
Hi, I just want to help avast! in the detection of Rogues. This is a undetected Rogue by avast! called Spyware Cease. At the moment avast! is not detecting it.

This is my shared account from MediaFire where I uploaded it (and upcoming threats relate to this topic), because it size is about 27MB. All my reports will take place here.

Information and password are included in the archive (only the executable  has password).   

http://www.mediafire.com/?ezi3f2n0ii0

I hope an avast! Researcher attend this topic. Thanks


Sincerely,



iRanzel

Offline nmb

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3054
Re: Fake Anti-Malware Applications
« Reply #1 on: June 26, 2010, 06:53:47 AM »
Hi,

You can also upload it to ftp.avast.com/incoming . Name the compressed file as fakeav or something similar to that. Put a readme in that stating this topic, password and your name(userrname).

nmb

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: Fake Anti-Malware Applications
« Reply #2 on: June 26, 2010, 02:57:26 PM »
Hi iRanzel,

Do not put live links to possible malcode out here, make them non-click-through by putting hxtp or wXw.
finjan says malicious behavior detected, the file you requested contains malicious code..
Status "suspicious" here as well: http://wepawet.iseclab.org/view.php?hash=1470bb9af7b084c93e17c4963db2fed5&t=1277556752&type=js
and consider this: htxp://jsunpack.jeek.org/dec/go?report=d7271afcf77b40d8f9fce316a1e5565511fc4f1e

polonus
« Last Edit: June 26, 2010, 06:25:28 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

iRonzel

  • Guest
Re: Fake Anti-Malware Applications
« Reply #3 on: June 26, 2010, 07:17:57 PM »
Hi polonus!

Dont worry about it. The exe. file is compressed with password. So to execute the FakeAV need to be decrypted with the password provided.

Note: This link is from my MediaFire Account. So, It not malicious. The link is provided to download the zip-folder. Also, this part of my account is private and not for sharing purpose. Thanks

You are malware fighter? help this topic and me. Report all Fake antimalware here please. Thanks


Sincerely,



iRanzel

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: Fake Anti-Malware Applications
« Reply #4 on: June 27, 2010, 12:52:53 AM »
Hi iRanzel,

Coming up, here: http://wepawet.iseclab.org/domain.php?hash=3941b630b9ede4f050d0dfe287cfe0b7&type=js

And read here, the new domains registered for fake AV: http://www.malwaredomainlist.com/forums/index.php?topic=2729.120

We keep them coming to be detected,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: Fake Anti-Malware Applications
« Reply #5 on: July 08, 2010, 08:56:22 PM »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

iRonzel

  • Guest
Re: Fake Anti-Malware Applications
« Reply #6 on: August 27, 2010, 04:15:51 PM »
Ummm! I was searching for a book online that I need for Spanish class (I am college student) and found this sites that allegedly they are selling the book that I am looking for. But the site is a FAKE AV.

Check this, the is:

wXw.secureforservers.com/libreriainterponce/bookstorelist.php

and this: 

hXXp://www1.zangievsoft11pd.in/?p=p52dcWpla2yHjsbIo216h4Ve0KCfYWCdU9LXoKitiJ%2FY1cRflJ2dcZqTgX6ZU9janW1eZWVsnWWUZJGeZInX15Krp6mikomqb1qtnaygnXaHk83Slm1Tqpud22qImaCjZJWSmGFlZWuTkpxuWKaemnVarKyeXpaeY2leamdtmVPWo2KjXpWclWpoaGualomclXGJhl6roZ2eZZmW


Virutotal results:

http://www.virustotal.com/file-scan/report.html?id=9036b0d6aed67c0e72f2a6841161c130a7481dd693c6366a3c15da647b4e36d0-1282917430

Note: The problem here is only with Internet Explorer, because Crhome and Firefox is blocking the site. Also with Chrome the first site that I posted, is working fine. This is the ISBN of the book that I am searching: 1-56328-243-7
The second and third site are hosting the malware. Google the ISBN and you can see the sites.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: Fake Anti-Malware Applications
« Reply #7 on: August 28, 2010, 01:15:21 AM »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Sirmer

  • Avast team
  • Sr. Member
  • *
  • Posts: 324
Re: Fake Anti-Malware Applications
« Reply #8 on: August 28, 2010, 10:25:32 PM »
Hello,
thanks for informations.
I put these urls in black list.It will be catched in next VPS.
Best regards
Jan sirmer

iRonzel

  • Guest
Re: Fake Anti-Malware Applications
« Reply #9 on: August 29, 2010, 01:25:06 AM »
Hello,
thanks for informations.
I put these urls in black list.It will be catched in next VPS.
Best regards
Jan sirmer

Thanks! avast! is now detecting it. I will continue reporting this type of malware here. According to continue finding more specimens.

iRonzel

  • Guest
Re: Fake Anti-Malware Applications
« Reply #10 on: September 13, 2010, 12:19:20 AM »
Three more:

 abodeflash-vol51.co.cc/se/flash_plugin.exe
 scaner-acer.cz.cc/installer_m_93.exe
 188.65.74.162/fuckemall_dfljgsdhfog.exe

iRonzel

  • Guest
Re: Fake Anti-Malware Applications
« Reply #11 on: April 23, 2011, 01:56:58 AM »
Here:

htxp://cardscannerwinprotection.com/index.php?06abQDY3QUWfUWuqry413pb5fD1uNSJne10II339BlpUZcd0FCuFftY70F4kis1WF3Y=#DB452FNGM452HGFG452DGFH452GJK452


Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37532
  • Not a avast user
Re: Fake Anti-Malware Applications
« Reply #12 on: April 23, 2011, 02:05:44 AM »
Sample sendt avast   ;)


Krelnadi

  • Guest
Re: Fake Anti-Malware Applications
« Reply #14 on: April 25, 2011, 07:14:55 AM »
Got re-directed to another fake AV site, this one was for E-Set, asked to install a file called Setup.exe after the fake scan

htxp://859f3.n2l4.net/vguard/?db5a4956=wgwabmg&496f81e=mmxslashsf&04f0799=mlglsgshxa&a94f56e41=3

However i got redirected to a site IP before i went to that site:

htxp://174.36.165.28/7583/74