06
Sep

new rogueware domains

New rogueware domains are spreading fast around the web. Today I found a lot of websites, and some are offering a different product:
One is for Antivirus live, another one for Security Suite, and yet another website is designed for System Guard 2009. Antivirus Live even has an interface that differs from their other page.
They all seem to be very professional, with quotes copied from legit antivirus companies or security websites.

Note: none of these pages trigger a “scan” of your computer.


Whois record for avcruiser.com

Registrant Contact:
Name: Aydar Zykoev
Address: Volhonka 73
City: Moskow
Country: Russia

hxxp://avcruiser.com
Result: 5/17 (29 %)
Domain Hash: a1ba5a9028f0086c1f6f5145d569c4b6
URLVoid


Whois record for antispyfond.com

Registrant Contact:
Name: Ghilbert Fither
Address: Fither inc 1st 54/5
City: New York
Country: United States

hxxp://antispyfond.com
Result: 1/17 (6 %)
Domain Hash: 6f0d7edf587a531e78e051e1b2e9ed5a
URLVoid


Whois record for antispyclass.com

Registrant Contact:
Name: Coordination Center for TLD RU
Address: Krasnopresnenskaya nab.
City: Moscow
Country: Russia

hxxp://antispyclass.com
Result: 1/17 (6 %)
Domain Hash: 048a9c79940a686af6d5d685ef1bf1f2
URLVoid


Related domains:
hxxp://antispyware-global.net
hxxp://antispyjob.com
hxxp://Antivira2010.com
hxxp://antivirlock.com
hxxp://antivirreality.com
hxxp://antispywaresimple.com
hxxp://antivirbase.net
hxxp://antispyware-tools.net
hxxp://antivirtools.net
hxxp://anitvirustool2010.com
hxxp://antivirbest.com
hxxp://antispy-defender.com
hxxp://antivir-protect.com
hxxp://antispylock.com
hxxp://antispywarebase.net
hxxp://Antispydelta.com
hxxp://Antispydog.com
hxxp://Antispydogma.com
hxxp://Antispyextra.com
hxxp://Antispywareactual.com
hxxp://Antispywaresimple.com
hxxp://antivirdelivery.com
hxxp://antivirone.com
hxxp://antivirdom.com
hxxp://Antivirreality.com
hxxp://Antivirworld.com
hxxp://Avcleaner.com
hxxp://av-downloadcenter.com
hxxp://Claronav.com
hxxp://Cremix.net
hxxp://Doublesavior.com
hxxp://Edefender-pro.com
hxxp://Great-eusing.com
hxxp://Reddragonav.com
hxxp://sings-soft.com
hxxp://Superspyremover.com
hxxp://Taskbar-hide.com
hxxp://Viruscleanersoft.com


Screenshot examples:

Antivirus Live home page
Antivirus Live home page

Antivirus Live home page
Antivirus Live home page #2


Security Suite home page
Security Suite home page


System Guard 2009 home page
System Guard 2009 home page

24
Aug

new rogue domain: desktopsecuritysoft2010.com

Whois record for desktopsecuritysoft2010.com

Registrant Contact:
Name: Proxy Private Registration
Address: 27 Old Gloucester street
City: London WC1N 3AX
Country: United Kingdom

hxxp://desktopsecuritysoft2010.com
Result: 8/16 (50 %)
Domain 41e3eca6d25ca75d2d335708b554d8e8
URLVoid
Note: this page does not trigger a “scan” of your computer.

Some related domains:

hxxp://desktopsecuritytech2010.com
hxxp://desktopsecurity2010new.com
hxxp://desktopsecurityorg.com
hxxp://desktopsecuritylab.com

The following file was downloaded:
security.exe
Result: 31/42 (73.8%)
MD5: 48ad4454db79f34d2ed0e6be365d92fd
VirusTotal
Anubis Report
ThreatExpert Report

Screenshot examples:

Desktop Security 2010 home page
Desktop Security 2010 home page

When executing the file (security.exe):
Desktop Security 2010 installation Wizard

21
Aug

new rogue domain: makeptotect73.co.cc

If you’re looking for the latest news about Honda, you might get surprised by finding a rogueware called MySecuritySield popping up.

Some of the affected search terms:
honda recall 2010 list
honda recall 2010

Whois record for makeptotect73.co.cc

Registrant Contact:
Name: JONG SUNG, KIM
Address: 864-2, JANGHANGDONG, ILSAN
City: GOYANG,GYEOUNGGI
Country: South-Korea

hxxp://makeptotect73.co.cc
Result: 2/16 (13 %)
Domain Hash: 4546911ccc95e03d4290f0a5209c0077
URLVoid

The following file was dropped:
packupdate8_195.exe
Result: 7/39 (17.9%)
MD5: 64c63db4f9bb57a85120b822fbd4dfb0
VirusTotal
Anubis Report
ThreatExpert Report

Related domain:
hxxp://get-download41.co.cc

Screenshot examples:

Fake scan page Windows XP style
Fake scan page Windows XP style

Fake scan page Windows 7 style
Fake scan page Windows 7 style

17
Aug

new rogue domain: pcsecurityshield.com

Whois record for pcsecurityshield.com

Registrant Contact:
Name: Frischman, Arthur
Address: 601 N Congress Avenue
City: Delray Beach, Florida 33445
Country: United States

hxxp://pcsecurityshield.com
Result: 3/19 (16 %)
Domain Hash: 3a4c1b0c128468d2390ddf1e5ba86f98
URLVoid
Note: this page does not trigger a “scan” of your computer.

Some related domains and roguevertising pages:

hxxp://pc-security.net
hxxp://www.topsofts.com/pop/anti-spyware/shield-deluxe-2009-user-comments.html
hxxp://shielddeluxe.com-shareware.com/
hxxp://anti-virus-software-review.toptenreviews.com/v2/the-shield-antivirus-software.html
hxxp://www.securemost.com/antivir/shieldpro.htm

Screenshot example:

PC
PC Security Shield home page

14
Jul

new rogue domain: antivirmore.com

Whois record for antivirmore.com

Registrant Contact:
Name: Youriy Lens
Address: 15 avenue 45-13
City: New York,NY
Country: United States

hxxp://antivirmore.com
Result: 1/17 (6 %)
Domain Hash: 361a40e6b3b2a635b6924e5c5aaceb6d
URLVoid
Note: this page does not trigger a “scan” of your computer.

Some related domains:

hxxp://Antispy-defender.com
hxxp://Antispywork.com
hxxp://Antivir-product.com
hxxp://Antivirglass.com
hxxp://Antivirprime.com
hxxp://Antivirstat.com
hxxp://Av-look.com

Screenshot example:

AV Security Suite home page
AV Security Suite home page

06
Jul

new rogue domain: oksave9.co.cc

Whois record for oksave9.co.cc

Registrant Contact:
Name: Jong Sung, Kim
Address: 864-2, Janghangdong, Ilsan
City: Goyang, Gyeonggi-do
Country: South Korea

packupdate107_195.exe
Result: 7/41 (17.07%)
MD5: 08a2ad37c6920b640615d7a1d6c3bbec
VirusTotal
Anubis Report
ThreatExpert Report

Rogueware Page: hxxp://www1.oksave9.co.cc
Result: 2/17 (12 %)
Domain Hash: 9b83d635ed7bf5be568e9cbae3b97935
URLVoid
Note: this rogueware page triggers a “scan” of your computer if redirected by a search engine.

This rogue is called Security Master AV.

Screenshot examples:

Security Master AV fake notification
Security Master AV fake notification

Security Master AV fake scan page
Security Master AV fake scan page

When executing the file ( packupdate107_195.exe ):
Security Master AV Setup
Security Master AV Setup

22
Jun

new rogue domain: antivirus-elite.com

Whois record for antivirus-elite.com

Registrant Contact:
Name: Domains by Proxy, Inc.
Address: 15111 N. Hayden Rd., Ste 160, PMB 353
City: Scottsdale, Arizona 85260
Country: United States

setup.exe
Result: 16/41 (39.02%)
MD5: 27b002ee170c751d14e030dacbb52b9f
VirusTotal
Anubis Report
ThreatExpert Report

Rogueware Page: hxxp://www.antivirus-elite.com
Result: 6/19 (32 %)
Domain Hash : 7cd43e9333370d93ed8df0cc6a55bf7f
URLVoid
Note: this rogueware page does not trigger a “scan” of your computer.

This rogue is called Anti-Virus Elite v5.0.

Screenshot examples:

Anti-Virus Elite Website
Anti-Virus Elite Website

When executing the file ( setup.exe ):
Anti-Virus Elite Warning Message
Anti-Virus Elite Warning Message

Anti-Virus Elite Interface
Anti-Virus Elite Interface

14
Jun

Introducing: Roguevertising

Introducing: Roguevertising

A new term in the rogue industry – written by Bart Parys


Today I will be talking about a new trend that spreads itself quite quickly throughout the internet.
In this document I will try to explain what it is all about and provide additional information like screenshots and measures that can be taken to tackle these threats.

It all started when I found a new rogue domain:
hxxp://antispyware.com
antispyware.com
Antispyware2010 website

The following domains are associated with Antispyware.com:
hxxp://antispyware2009.com
hxxp://Errorsmart.com
hxxp://Registryclear.com
hxxp://Remover.org

They all introduce the same ‘product’ – to perform a scan for malware on your computer. You can even request Live Technical Support.
(No, not really, it will just refer you to the download page)

When you download their product, you can find the following setup file in your chosen download folder:
setupxv

setupxv.exe

Pending on the website you landed on, you can also download another file called setup.exe

The file setupxv.exe has currently a 53.66% detection ratio on VirusTotal. The classification most used included the name Fakealert:
VirusTotal Result
It is also possible you download a file with the same name (setupxv.exe) but with slightly changed binaries. You can find an example of this on VirusTotal:
VirusTotal Result

For more information about this rogue program and the others described down below, I refer to the end of this document, where you can find some screenshots of my findings.


Then, after performing some Google searches on fake testimonials and information taken from their website , I landed on the following rogue domain:

hxxp://againstadware.com
againstadware.com
AgainstAdware website

Unfortunately, you cannot download their product anymore, as the setup file has been removed.

The following domains are associated with Againstadware.com:

http://Fileboxx.com

http://Incredible-mail-download.com

http://Secureoneantivirus.com

http://Wincleanerpro.com


Now, why am I introducing the term roguevertising ?

You might have heard about malvertising. Malvertising (short for Malicious Advertising)  is a term used for malicious advertisements that are clicked on, and can deliver a drive-by-download or suggesting to install a certain program to clean and scan your computer.

These days I have found a lot of websites using malvertising for rogue security software. That is how the term roguevertising was born.

A few examples of these websites:

hxxp://www.hopelinenc.org/forum/anti-spyware

hxxp://www.thedietsolutionprogram.ws/weblog/anti-spyware

hxxp://www.thedietsolutionprogram.ws/rating/anti-spyware

hxxp://www.perfectoptimizer5.com/?hop=aseafood

hxxp://www.bestspywareprogram.net
antispyware.com roguevertising
Along with legit Antispyware applications, you can find “Antispyware” between the list with … an advertisement leading to the download link of the rogue. (Done through an advertising mirror)

hxxp://threats.browsetag.com/antispyware
hxxp://www.plrarticlesoftware.biz/forum/anti-spyware
hxxp://www.earth4energyoffical.com/weblog/anti-spyware
hxxp://www.earth4energyoffical.com/article/adware-alert
hxxp://www.earth4energyoffical.com/article/privacy-control
hxxp://www.theaffiliatecode.ws/weblog/anti-spyware
hxxp://www.legitonlinejobshome.com/tags/anti-spyware

Additionally, I stumbled upon the following rogue domain:
hxxp://spywareremover.com
spywareremover.com website
SpywareRemover website

When you download their product, you can find the following setup file in your chosen download folder:
SpywareRemover icon
Setupxv.exe

That’s right. Setupxv all over again, but with a different icon and again changed binaries.

The file setupxv.exe has currently a 39.02% detection ratio on VirusTotal. The classification most used included the name AdSpy:
VirusTotal Result


Do you surf the internet ? Does your PC run slow ? Do you get bombarded with annoying pop-up ads ?
Then you are most likely to land on the following page:
Adware Alert homepage
AdwareAlert website

Yet again, setupxv is presented to you with a nice new icon:
AdwareAlert icon

Current VirusTotal detection rate is 48.78% . The file was again changed to avoid detections by Antivirus software. (also introduces another GUI as noted at the end of this document)
VirusTotal Result

The setupxv rogueware campaign is on a roll, down below some associated domains with AdwareAlert.com:

hxxp://Cbadvance.com
hxxp://Errorkiller.com
hxxp://Evidenceeraser.com
hxxp://Malwarebot.com
hxxp://Malwareremovalbot.com
hxxp://Registrybot.com
hxxp://Registrysmart.com
hxxp://Regrecall.com
hxxp://Regsweep.com
hxxp://Spywarebot.com
hxxp://Spywarestop.com


Next rogueware domain on our list is:
hxxp://www.antispywarebotpro.com
AntiSpywarebot homepage
AntiSpywareBot website

As always your download is free as well as the malicious payload:
asbot icon
Setupxv.exe

Current VirusTotal detection rate is 48.78% .
VirusTotal Result

Related domains in this case are:

hxxp://mail.remover.org
hxxp://www.privacycontrolpro.com
hxxp://errorsweeperpro.com
hxxp://Regcleanlite.com
hxxp://www.browsetag.com/spyware/virus/threats
hxxp://support.browsetag.com/certified/antispyware
hxxp://www.spywarenuker-gary.com/blog/anti-spyware
hxxp://www.spywarenuker-gary.com/blog/adware-alert

As you might have noticed, roguevertising is appearing on these last pages. Spywarenuker Gary needs to find another name, as his directory is filled with malicious advertisements and bloatware:
spywarenuker gary directory
Part of a roguevertising directory


I have also gathered the following URLs which are also related to the setupxv rogueware campain:

hxxp://adwarealert.com
hxxp://Cbadvance.com
hxxp://Errorkiller.com
hxxp://Evidenceeraser.com
hxxp://Malwarebot.com
hxxp://Malwareremovalbot.com
hxxp://Registrybot.com
hxxp://Registrysmart.com
hxxp://Regrecall.com
hxxp://Regsweep.com
hxxp://Spywarebot.com
hxxp://Spywareremover.com
hxxp://Spywarestop.com

One of the rogues download above, again setupxv:
Setupxv.exe
Setupxv.exe

This new version of setupxv only has a 4.88% detection ratio on VirusTotal:
VirusTotal Result

… and delivers you the program RegClean
RegClean Setup Wizard
RegClean Setup Wizard


The following rogue that you might remember is Spyware Cease:

hxxp://www.spywarecease.com
SpywareCease website
SpywareCease website

SpywareCease comes in the following setup file:
spywarecease icon

It has currently a 12.20% ratio on VirusTotal:
VirusTotal Result

Associated domains and roguevertising links for Spywarecease.com:

hxxp://www.spycease.com
hxxp://www.micronichefinderhome.com/blog/spyware-cease
hxxp://entrepreneur.useoursite.com/go.php?p=SSPYKILLER
hxxp://offto.net/SpywareCease_4ee8
hxxp://viral-link-exchange.info/clickbank-supercenter/html/spyware-cease-1-converting-anti-spyware-software.htm
hxxp://www.cheapsale.org/html/spyware-cease-1-converting-anti-spyware-software.htm
hxxp://www.easyfixcomputersolutions.com/home.php
hxxp://www.easydigitalsales.com/33027/Spyware-Cease—1-Converting-Anti-Spyware-Software.html


We are moving on to the last roguevertising campaign, brought to you by 007 Anti-Spyware.
I stumbled upon this one while investigating the SpywareCease roguevertising campaign.
hxxp://www.007antispyware.com
Unfortunately (or luckily) this site was down at the time of writing, but I found a roguevertising domain for this one:
hxxp://007antyspyware.blogspot.com
007 Anti-Spyware website (blog)
007 Anti-Spyware website (blog)

The blog provides an ad-provided mirror for the setup file 007antipsyware.exe
007antipsyware.exe
007antipsyware.exe

The file has currently very low detection ratios on Virustotal. Only 4.88% of the scanners detect it,
namely as Adware.SpywareCease. Rings a bell somewhere…
VirusTotal Result

But the fun is not over yet. When visiting this roguevertiser’s Twitter page, you can install the Googod toolbar. Now we can add spyware on the list, since the Googod toolbar is copyrighted under
Conduit Ltd., which is renowned for its spyware activities. This toolbar is available for Internet Explorer, Mozilla Firefox and Safari.

hxxp://www.googod.ourtoolbar.com
Googod toolbar website
Googod toolbar website

2.44% on VirusTotal
VirusTotal Result


Conclusion

Although malvertising is not a new concept, roguevertising however is.
I hope that throughout this document it became a bit clearer what it is all about and how only one rogueware campaign is and will be able to infect a lot of users.
No, the rogueware will not clean nor speed up your computer.

Pushing rogueware downloads through advertisements on weblogs, bloatware websites or even on Google, will be a phenomenon we have to deal with. In this case the setupxv rogueware campaign was able to spread itself through different domains, which can attract users to actually download and install the software.

But there might be hope.In my opinion can websites like Antispyware.com be prevented by ever seeing the light: register domains that can be used for roguevertising. In this case, the setupxv creators would not have been able to register this domain, and users would get a message stating the website is under construction, for example or it is registered for the single purpose of stopping websites like this.
Another option would be for the domain linking to an AntiVirus vendor, as described below.
After all, the site Antispyware.com website sounds legit, and when you visit the site, the user will not notice anything suspicious. For example Antivirus.com is registered to TrendMicro.
When you look up Antispyware.com however, you get a 32 % dangerous rating on URLVoid:
URLVoid Result

Tools like Web Of Trust (WOT) can prevent you from landing on sites like Antispyware.com.
Other manners to prevent this can either be hostfile-based or user-based.
Examples can be MVPS Hosts or Sandboxie. Common sense however will always be the most important factor, just remember the following rule: if it looks like a rogue, it probably is !
This does of course not imply that every suspicious looking program is malicious, rather perform some checks with your favorite search engine or use URLVoid and VirusTotal as a reference.

Further rogueware screenshots are provided down below. Thank you for reading.


007 Antispyware
Setup screen
Setup screen

Shortcut icon
Shortcut icon

Interface
Interface

Adware Alert
Setup screen
Setup screen

Shortcut icon
Shortcut icon

Interface
Interface

Antispyware 2008
Setup screen
Setup screen

Shortcut icon
Shortcut icon

Interface
Interface


007 Antispyware
Setup screen
Setup screen

Shortcut icon
Shortcut icon

Interface
Interface



wordpress@djpnuemo.com tracker@djpnuemo.com trap@djpnuemo.com spam@djpnuemo.com virus@djpnuemo.com mdb@djpnuemo.com malware@djpnuemo.com


SANDBOX

SANDBOX ANALYSIS PAGE




 

September 2010
M T W T F S S
« Aug    
 12345
6789101112
13141516171819
20212223242526
27282930