R3v3rs3e's Blog

Posts Tagged ‘rogue domain’

Scareware uses Fake Windows 7 Action Center

Posted by Steve Espino on December 8, 2009

Privacy Center, Privacy Components and Safety Center are some of the aliases used by this family of scareware that hide under the guise of a fake Windows 7 Action Center.

The scareware installer uses the filename win_protection_update.exe and once installed, this scareware displays fake scan results in an attempt to convince unsuspecting users into buying the fake software.

A lifetime license for this fake app amounts to a hefty $79.95 plus $19.95 for “Premium Support”.

Here are some domains related to distributing this attack:

software-scaner-online.com
scaner-online-malware.biz

PC Tools Spyware Doctor with Antivirus detects this scareware as RogueAntiSpyware.PrivacyCenter.AJ.

Posted in Rogue Apps | Tagged: , , , , , , , , , , , , , , , , , , , , , , | Leave a Comment »

Koobface on the Move, Serving Scareware

Posted by Steve Espino on September 18, 2009

The PC Tools Malware Research Centre has been seeing new movement on the koobface front Lately.

koob_fiddle

As koobface-serving domains are being taken down as early as the good guys discover them, the bad guys are at it and they respond by registering new ones. At the moment, their, C&C server is hosted in China with IP Address 61.235.117.83.

The bad guys are still using a fake facebook website, as well as posing as a fake codec, in order to distribute koobface.

fake_facebook

Clicking anywhere on the page, presents us with a file named setup.exe. Here are some of the IPs being used to distribute koobface:

koob_script

115.130.27.204
123.202.200.84
151.204.31.67
196.206.65.53
221.126.0.105
24.215.207.229
41.238.76.198
61.93.34.23
67.206.253.52
68.47.48.240
69.18.107.115
69.254.215.173
70.122.242.250
70.212.232.126
71.116.37.213
71.130.216.179
71.194.236.32
71.80.105.40
72.13.138.210
72.190.87.208
75.181.171.110
75.251.94.44
76.119.98.22
76.22.160.28
76.23.203.64
81.192.192.160
98.140.58.163
98.244.224.140
98.26.40.38
99.22.74.229

The javascript component being by used by koobface, remains bascically the same as before

And as before, koobface is still serving up scareware. From time to time, users are presented with a My Computer online scan, going through these domains:

rogue

gotrioscan(dot)com
plazec(dot)info

At some instances, we also get these warnings:

hardware_error
Internet_Antivirus_Pro

At the moment, these warnings are serving Internet Antivirus Pro.

In order to be protected against these attacks, users of PC Tools Spyware Doctor are advised to use the latest PC Tools update.

An earlier post about koobface can be found here.

Update:
Koobface has been going at it and here’s another one that spoofs youtube and serves koobface malware as a fake codec:

hxxp://71.197.170.226/d=www.marcellaburnard.com/0x3E8/view/console=yes/?go

Posted in Malicious Intent, Rogue Apps | Tagged: , , , , , , , , , , , , , , , , , , , | 4 Comments »

Rogue App: System Cleaner

Posted by Steve Espino on August 5, 2009

I visited this rogue domain:

hxxp://antivirussecurescannerv3.com

antivirussecurescannerv3.com

The website proceeded to show me that it is scanning my machine for system errors and that it is doing a very wonderful job because it found heaps of problems on my machine and it is very eager to fix it.

To give the website some kind of authentic feel, it also showed me which browser I am using, my operating system, and my IP address.

It was also offering 60% discount on the product. Isn’t that a good deal?

Now, if the dubious scanning and the overall feel of the website did not give away its real intentions, and if we are to be lulled into buying their software, well… hold on a minute!

If you notice that on my screenshot, the rogue website was giving some errors about the Windows TEMP folder, Internet Explorer temp files. But how can that be? As I mentioned on a previous post, I am not running Windows!

As usual, unsuspecting users get ripped off for a crappy software. So be careful!

Posted in Rogue Apps | Tagged: , , , , , , , | Leave a Comment »

 
Follow

Get every new post delivered to your Inbox.