CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

XP Antivirus 2008 - Anatomy of a malware SCAM

 
Post new topic   Reply to topic       All -> FavForums -> Security [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
AplusWebMaster

General
General


Joined: Mar 14, 2004
Posts: 4840
Location: USA

PostPosted: Sat Aug 23, 2008 11:06 am    Post subject: XP Antivirus 2008 - Anatomy of a malware SCAM
Reply with quote

FYI...

- CastleCops Link/t225847-XP_Antivirus_2008_Anatomy_of_a_malware_SCAM.html


Exclamation


_________________
AplusWebMaster
~ Are you up to date or vulnerable to Hackers? ...or both?
.
Back to top
View users profile Send private message Visit posters website
AplusWebMaster

General
General


Joined: Mar 14, 2004
Posts: 4840
Location: USA

PostPosted: Tue Aug 26, 2008 9:44 pm    Post subject:
Reply with quote

More of same...

Phish that bites back
- http://www.secureworks.com/research/blog/index.php/2008/08/25/the-phish-that-bites-back/
August 25th, 2008 - "We all get phishing emails. Some of us more than others, so it’s no surprise that sometimes people take out their frustrations on the phishing form, letting the phisher know just what they think of him or her... While it might make you feel better, it isn’t always a good idea. For instance, if you were to do this on a phishing page hosted by the Asprox botnet, you might get more than you bargained for. The Asprox phishing form backend has a bit of extra logic added to it. If the form looks like it has been filled out with legitimate data, you get redirected to the main page of the bank website. However, fill it out incompletely or use certain words like “phish” or NSFWUYAS (Not Safe For Work Unless You’re a Sailor) language, and your browser will be subjected to a number of exploits. If you are running Windows and haven’t recently installed your security updates and patched all your browser plugins/ActiveX controls, you might find yourself infected with your very own copy of Asprox. Not only do you then get the opportunity to unknowingly send phishing emails on behalf of the botnet, you will likely get some extra goodies, since Asprox is also a downloader trojan. You won’t notice it running, but you might notice some of the things it downloads and installs. For instance, you might find your desktop wallpaper changed to a “spyware alert” type of message, and now all your screensaver shows is scary blue-screens-of-death. Of course, if you’re familiar with the Windows desktop properties dialog, you can change all that back, right? Oops. the rogue antivirus program has removed that functionality for you... you’ll notice the lack of a “I disagree” or even a “close window” button at the top of the dialog (which can’t be minimized, and stays on top of all your other windows). So there’s no easy way to continue using your computer without clicking on the “Agree and install” button. But don’t worry, Antivirus XP 08 has already installed itself, whether you click through the license agreement or not... Of course, you’re not infected with everything this program says you are - it’s scareware, designed to get you to fork over $50 or $100 in order to clean your system of all these nasty threats. But it doesn’t actually detect or clean anything, especially not the Asprox bot you’re hosting now. And at any time, Asprox might deliver another malicious payload and install it for you - and it could be much worse: we’ve seen the Zbot banking trojan installed by Asprox in the past. So instead of a dealing with a nuisance program, you might be silently sending your banking and credit card information to the botnet owners. Something to think about before venting your frustrations on the bad guys. Sometimes phish bite back."

(Screenshots available at the URL above.)

Evil or Very Mad Evil or Very Mad


_________________
AplusWebMaster
~ Are you up to date or vulnerable to Hackers? ...or both?
.
Back to top
View users profile Send private message Visit posters website
AplusWebMaster

General
General


Joined: Mar 14, 2004
Posts: 4840
Location: USA

PostPosted: Wed Aug 27, 2008 10:55 pm    Post subject: XP Antivirus 2008 - now with exploits...
Reply with quote

FYI...

XP Antivirus 2008 now with sploits, Google Adwords affected
- http://sunbeltblog.blogspot.com/2008/08/xp-antivirus-2008-now-with-sploits.html
August 27, 2008 - "...problem of Google Adwords pushing Antivirus XP Antivirus 2008. The situation is still ongoing. However, it’s taken a turn for the worse, as these XP Antivirus pages are pushing exploits to install malware on the users system. This will also affect the many syndicators of Google Adwords... There are a variety of exploits being used, including setslice and an AOL IM exploit. Unusually, an exploit framework is not being used. Fully patched systems will not be affected by these exploits. The exploit attempts to install the following malicious file: huytegygle com/bin/ file.exe..."

(Screenshots available at the URL above.)

Exclamation


_________________
AplusWebMaster
~ Are you up to date or vulnerable to Hackers? ...or both?
.
Back to top
View users profile Send private message Visit posters website
AplusWebMaster

General
General


Joined: Mar 14, 2004
Posts: 4840
Location: USA

PostPosted: Fri Aug 29, 2008 11:18 am    Post subject:
Reply with quote

FYI...

Spammed SWF URLs Abuse ImageShack, Lead to Rogue AV
- http://blog.trendmicro.com/spammed-swf-urls-abuse-imageshack-lead-to-rogue-av/
Aug. 28, 2008 - "We’re seeing a lot of spam right now using the now annoyingly familiar Free Update Windows XP, Vista spam template. This time though, instead of linking to an .EXE file, it is now pointing to an .SWF file. The SWF file linked via the large-font text Free Update Windows XP,Vista contains Flash ActionScript... After this a EULA window appears, and then the system proceeds to install a rogue AV software from avxp-2008.net. Note that it does this automatically from the moment the install.exe is run... The technique used in the spam has two things going for it:
1. the use of SWF instead of EXE and
2. the use of an ImageShack-hosted file, both of which may suggest to normal users that the file is possibly harmless.
So it seems the siege of rogue AV is not only not dying down, its proponents are becoming more creative in their “advertising” schemes. We detect this rogue AV as TROJ_FAKEAV.IG."

(Screenshots available at the URL above.)

Exclamation Evil or Very Mad


_________________
AplusWebMaster
~ Are you up to date or vulnerable to Hackers? ...or both?
.
Back to top
View users profile Send private message Visit posters website
AplusWebMaster

General
General


Joined: Mar 14, 2004
Posts: 4840
Location: USA

PostPosted: Tue Sep 16, 2008 11:44 am    Post subject:
Reply with quote

FYI...

Fake AV 2009 and search engine results
- http://isc.sans.org/diary.html?storyid=5042
Last Updated: 2008-09-16 01:15:04 UTC - "Web servers have been compromised and their .htaccess files have been modified. Here you can see an example of a modified .htacces
http://forums.devnetwork.net/viewtopic.php?f=6&t=85984 ...
Another site that was compromised and searches redirected is discussed here:
http://groups.google.com/group/Google_Webmaster_Help-Indexing/msg/0cd2cafd907a0380 ...
Their .htaccess is being modified to rewrite requests. Specifically they are redirecting to sites that "advertise" antivirus2008 or antivirus2009 when several search engines try to spider the original site. They redirect most of the search engines there (google, yahoo, altavista...). I believe that is how they are getting their fake av into the search engines with a HIGH hit rate. The site I was seeing in use was int3rn3t-d3f3ns3s .com Which is an "ad" for anti-virus2009... used to convince victims to load this fake-av software...
int3rn3t-d3f3ns3s .com is at 84.16.252.73 I recommend blocking that at your enterprise gateway. Prt3ctionactiv3scan .com which is mentioned in the sunbelt blog is at 78.159.118.168 blocking that at your gateway is also recommended.
There is a blog here about some of these fake av sites.
http://ddanchev.blogspot.com/2008/08/diverse-portfolio-of-fake-security.html
Microsoft mvp Harry Waldron blogged about it here.
http://msmvps.com/blogs/harrywaldron/archive/2008/08/15/antivirus-2009-avoid-these-fake-antivirus-trojan-attacks.aspx ...
Sunbelt did a good write up of it here and has been tracking the sites involved.
http://sunbeltblog.blogspot.com/2008/09/scam-sites-update-iii.html
If you need antivirus software icsa labs has a useful collection of valid links here:
https://www.icsalabs.com/icsa/topic.php?tid=cfe0$3d83e732-011a28d6$5ac9-0f77e15b "

Exclamation Evil or Very Mad Shocked


_________________
AplusWebMaster
~ Are you up to date or vulnerable to Hackers? ...or both?
.
Back to top
View users profile Send private message Visit posters website
AplusWebMaster

General
General


Joined: Mar 14, 2004
Posts: 4840
Location: USA

PostPosted: Wed Oct 01, 2008 11:39 am    Post subject: More "scareware"...
Reply with quote

FYI...

More "scareware"...
- http://www.f-secure.com/weblog/archives/00001508.html
September 30, 2008 - "WinDefender 2008 is a rogue application. Rogues are also sometimes known as scareware... Looks sort of familiar, doesn't it? Do you recognize the shape of the box? The website creators appear to have "borrowed" a few things. Let's check out the legal disclaimer... From where else we can find really legal stuff? Spyware Rogue: Antivirus XP 2008... Oh, Antivirus XP 2008. That particular rogue is a huge pain in the… neck. The guys that produce this stuff are crooks and swindlers... Here's a tip: If they claim to be REALiable — they're probably FAKE..."

(Screenshots available at the URL above.)

Evil or Very Mad


_________________
AplusWebMaster
~ Are you up to date or vulnerable to Hackers? ...or both?
.
Back to top
View users profile Send private message Visit posters website
AplusWebMaster

General
General


Joined: Mar 14, 2004
Posts: 4840
Location: USA

PostPosted: Fri Oct 10, 2008 11:38 am    Post subject:
Reply with quote

FYI...

New rogue: Antivirus 2010
- http://sunbeltblog.blogspot.com/2008/10/new-rogue-antivirus-2010.html
October 09, 2008 - "Antivirus 2010 is a new rogue security product. This rogue is a clone evolved from IEdefender that begat XP Antivirus, that begat Antivirus 2008, that then begat Antispyware 2009... The rogue application uses the same old tricks to lure users into purchasing their worthless application... Fake Windows Security Center - Fake BSOD..."

(Screenshots available at the URL above.)

Evil or Very Mad


_________________
AplusWebMaster
~ Are you up to date or vulnerable to Hackers? ...or both?
.
Back to top
View users profile Send private message Visit posters website
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Security All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer