Tag Archive for 'xp-antivirus-2008'

21
Aug

MS Antivirus 2008 morphed from XP Antivirus 2008

We detected a new XP Antivirus 2008 rogue security software site branded as “MS Antivirus 2008″. The file, MSASetup.exe comes from hxxp://msantivirusxp.com/install.php and is undetected by most AV vendors at the moment.

MS Antivirus 2008

File: MSASetup.exe
File size
: 1037918 bytes
MD5…
: 1f58d870738aaebb12ed7ece90781c6a
SHA1..: d8f030275b571dea6b8836f433e933cc5e6a1834
MDB: /lithium-malware/MSASetup.zip

We also detected other new sites pushing out rogue anti-malware product.

Antivirus 09

Site:http://antivirus-purchasing.com/
Distributes: Antivirus 09
File: None yet

Site:http://antivirusfreescan2009.com/
Distributes: Antivirus 09
File: AV2009Install_.exe
DL Link: hxxp://antivirusfreescan2009.com/2009/download/trial/AV2009Install_*.exe

Removal:

Remove this threat with MalwareBytes!

05
Aug

Sponsored Result != Safe

We have been monitoring several malware campaigns lately and we are noticing the distribution spread from just spam e-mails to social networking sites to search engine sponsored results.

A good example is the CNN Top 10 malspam campaign we exposed yesterday. The e-mail comes off as legit to the average user and leads to infection.

In a malware related google search we entered the search term “CNN Top 10 XP Antivirus” and found a sponsored result for a rogue anti-malware product, Antivirus XP 2008.

Google search with malicious results

Free online check! New Generation.

Search Results

If we click the link we are taken to a rogue anti-malware site, hxxp://antivirus-xp-2008.net. *Warning* Live malicious site! Proceed at your own risk** It’s appears legit, offers a free scan, and even sports badges from PC Magazine, Sun, Microsoft, Intel. ICSA, Checkmark, and VB100 to keep it looking like a credible site.

XP Antivirus

If we download the files we get a zip file with 2 files. The files are pretty much undetected across the board because they are so new. We have included the JoeBox Sandbox reports for you to look at.

Zip Contents

Antivirus-XP-2008.exe
-> VirusTotal: Result: 6/36 (16.67%) CDFAE03CA18BBAF307A77F9BA2BB7B38
->JoeBox Sandbox: JoeBox Sandbox Report

Update-July-2008.exe
-> VirusTotal: Result: 3/36 (8.34%) 2E3D63ED9BFF383926FBD34449513928
-> JoeBox Sandbox: JoeBox Sandbox Report

*UPDATED 835pm*

Found more sponsored links by simply searching “antivirus software” on Google. Same exact setup on a different domain name hxxp://2008antivirusxp.com.

avxp2k8ad

More results on other search engines (click image for Virustotal results)…

adwaredlad

*UPDATED 8-06-08*

Another sponsored link was found for rogue antivirus software on a different domain hxxp://xp-2008.com.  This was found by searching ‘antivirus’.  This has potential for misleading many people because also searching ‘norton antivirus’, ‘mcafee antivirus’, ‘panda antivirus’, or any other REAL software, will be presented with this advertisement.

xpav2k8ad




SANDBOX

SANDBOX ANALYSIS PAGE




 

September 2010
M T W T F S S
« Aug    
 12345
6789101112
13141516171819
20212223242526
27282930