Archive for September 26th, 2008

26
Sep

Antivirus-Alert

Note: This site is distributing Rogue “Fake” Anti-Malware product.  Do not visit, pay, or download the software discussed below.

We found new rogue domain today.  This time we are greeted with javascript  and redirect to a 502 (Bad Gateway).

Mal Script

502 Page

You may be wondering why we see a 502 error rather than the typical incomplete template.

The redirection takes us to antivirus-scanner.com and that site is hosted by EstBoxes.  EstBoxes is a former customer of Atrivo (InterCage).  Atrivo was forced to remove EstBoxes as a customer after their last upstream provider (PIE) pulled the plug on them for ignoring abuse complaints about all of the malware and botnets on their network.

So you can thank all of the people that helped take down Atrivo in effort to remove many malicious sites from the internet.  Shoutout to the team at HostExploit!  You can read their CyberCrime USA whitepaper here.

Site: hxxp://Antivirus-Alert.com
Server Data:
IP Address:     203.117.111.47
IP Location     Singapore – Singapore – Starhubinternet
Response Code:     200
Domain Status:     Registered And Active Website

26
Sep

Update on Plimus and Antivirus Advance

It has been 48 hours since we sent our complaint to Plimus regarding their badware producing customer, Antivirus Advance. [original post]

Plimus has not made an attempt to contact us and we *know* they saw the complaint the very morning we posted it.

Plimus

We checked the site and Antivirus Advance still is being sold through the Plimus e-commerce portal.  This is unfortunate because innocent people are being had by this badware product and the only people that could help stop it from being sold will not even reply to our complaint!

I have resubmitted my complaint to Plimus.  I hope they reply to me this time! I would like to prevent further actions and resolve this issue on amicable terms.  I can be contacted directly at –>lithium@malwaredatabase.net.

**UPDATE**

Plimus has finally contacted me! :)

Plimus Response






 

September 2008
M T W T F S S
« Aug   Oct »
1234567
891011121314
15161718192021
22232425262728
2930