CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

New Scam Strategy

 
Post new topic   Reply to topic       All -> FavForums -> Web Malware Links [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
sparsha

Trooper
Trooper


Joined: Nov 06, 2007
Posts: 31
Location: India

PostPosted: Sun Dec 30, 2007 4:01 pm    Post subject: New Scam Strategy
Reply with quote

hxxp://search-rc.org

displays the same tricky error message informing the user to install codec to view a particular Image, When the user tries to download the codec, Boom the user will get a installer for AntiSpywareBot (a junk scanner).

info @ http://bharath-m-narayan.blogspot.com/2007/12/new-scam-strategy.html

cheers,
Sparsha

Back to top
View users profile Send private message
tetak

MIRT Team Lead
Premium Member

Joined: Jan 19, 2007
Posts: 5878

MIRT Premium

PostPosted: Sun Dec 30, 2007 4:45 pm    Post subject:
Reply with quote

When I visited the site it tried to send me to

Code:
http://surfonline.2squared01.hop.clickbank.net/?mode=download&tid=cfkj
which is down for me.


_________________
Got Windows XP? Help protect your PC from malware with Microsofts anti-spyware program Windows Defender.

Download it for free from http://www.microsoft.com/athome/security/spyware/software/default.mspx
Back to top
View users profile Send private message
brewt

SIRT Handler
Premium Member

Joined: May 29, 2007
Posts: 792
Location: USA
MIRT Premium

PostPosted: Sun Dec 30, 2007 5:24 pm    Post subject:
Reply with quote

it redirects to hxxp://download.antispywarebot.com/setup.exe for the download anyway.

File setup.exe received on 12.30.2007 17:42:34 (CET)
Result: 1/32 (3.13%)
Prevx1 V2 2007.12.30 Heuristic: Suspicious Self Modifying File
File size: 3354488 bytes
MD5: 8fd7155e68e2a7e3b92bd401944485b6
SHA1: edf851901f069dfec30a58b58d9f515eed929ff2
http://www.virustotal.com/resultado.html?3532b2682d32b68c53618b54c495fc59

McAfee SiteAdvisor also rates it as Green. -_-
http://www.siteadvisor.com/sites/antispywarebot.com/downloads/

Back to top
View users profile Send private message
MAPKOBKA

Lieutenant
Lieutenant
Premium Member

Joined: Jul 04, 2007
Posts: 163

Premium

PostPosted: Sun Dec 30, 2007 5:27 pm    Post subject:
Reply with quote

http://www.virustotal.com/analisis/fb786f4d82aec976bfd58bb88aebd509


Attached to my post.

Setup.exe


When run, usual eula stuff....


adds itself to autostart

HKEY_USERS\user\current\Software\Microsoft\Windows\CurrentVersion\Run

Value: AntiSpywareBot

New data(Unicode null-terminated string):
"C:\Program Files\AntiSpywareBot\AntiSpywareBot.exe" -boot (and does this every time it is launched to keep itself there)

Also drops a scheduled task into C:\windows\tasks\

And the executables are dropped into C:\program files\antispywarebot\

(launcher.exe, antispywarebot.exe, unins000.exe and others)


When run, it finds some imaginary infections

[img]http://i201.photobucket.com/albums/aa269/kaspersky_labs/bs2.jpg[/img]



And obviously, it will not let you do anything until you "register"

[img]http://i201.photobucket.com/albums/aa269/kaspersky_labs/bs1.jpg[/img]

here hxxp://www.antispywarebot.com/register.php

Plus you get the added scare popups in between.

Back to top
View users profile Send private message Visit posters website
tetak

MIRT Team Lead
Premium Member

Joined: Jan 19, 2007
Posts: 5878

MIRT Premium

PostPosted: Sun Dec 30, 2007 7:36 pm    Post subject:
Reply with quote

Kaspersky have confirmed that this file is malware.

not-a-virus:FraudTool.Win32.AntiSpyware.c (Kaspersky)


_________________
Got Windows XP? Help protect your PC from malware with Microsofts anti-spyware program Windows Defender.

Download it for free from http://www.microsoft.com/athome/security/spyware/software/default.mspx
Back to top
View users profile Send private message
brewt

SIRT Handler
Premium Member

Joined: May 29, 2007
Posts: 792
Location: USA
MIRT Premium

PostPosted: Mon Dec 31, 2007 10:24 am    Post subject:
Reply with quote

can't add much to kaspersky's verdict, but this finally came through from threatexpert.
http://www.threatexpert.com/report.aspx?uid=e0e817d1-86b8-4ad2-854e-dd6d6442ae5b

Back to top
View users profile Send private message
MAPKOBKA

Lieutenant
Lieutenant
Premium Member

Joined: Jul 04, 2007
Posts: 163

Premium

PostPosted: Mon Dec 31, 2007 7:53 pm    Post subject:
Reply with quote

Someone from their company has replied on siteadvisor, anyone got questions for them?

"Hi, Antispywarebot has nothing to do with search-rc .org We are working to get links to our site blocked from search-rc. We did test the site and there are no trojans being used to point to the site. Based on the traffic comming from the link (none), and the fact the person who posted the complaint here (bharath, known here as "sparsha") left our company on bad terms, we are investigating the situation closely."

http://www.siteadvisor.com/sites/antispywarebot.com


_________________
Kaspersky Lab Forum Moderator
KL Cert PSP
Virusinfo.info External Specialist
Alliance of Security Analysis Professionals Member
http://malwarecrawler.com - honeypot@malwarecrawler.com
Back to top
View users profile Send private message Visit posters website
brewt

SIRT Handler
Premium Member

Joined: May 29, 2007
Posts: 792
Location: USA
MIRT Premium

PostPosted: Mon Dec 31, 2007 8:30 pm    Post subject:
Reply with quote

what about dean's comment?

Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Web Malware Links All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You cannot download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer