Author Topic: Rogue - Fake AV  (Read 36021 times)

0 Members and 1 Guest are viewing this topic.


February 23, 2010, 07:50:27 pm
Reply #151

SysAdMini

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 3310
Seems to be random php files (not an expert on this behavior)

http://173[.]212[.]228[.]196/8_82ed2e[.]php


attached decoded sample.

pw: infected
Ruining the bad guy's day

February 25, 2010, 02:09:44 pm
Reply #152

doomrainer

  • Newbie

  • Offline
  • *

  • 9

March 23, 2010, 05:33:06 pm
Reply #153

S!Ri

  • Special Members
  • Jr. Member

  • Offline
  • *

  • 21
Virus Protector pr0n + setup

http://tubess.twilightparadox.com/land/?n=teen&id=1
http://tubess.twilightparadox.com/land/adobe-91633/adobeflashplayerv10.0.45.2.exe

March 23, 2010, 06:33:28 pm
Reply #154

S!Ri

  • Special Members
  • Jr. Member

  • Offline
  • *

  • 21
Personal Security
http://c3872131.time-defender9.com/download/Setup_28.exe

March 23, 2010, 09:34:39 pm
Reply #155

S!Ri

  • Special Members
  • Jr. Member

  • Offline
  • *

  • 21
Antivirus 7
http://91.212.127.3/download/ASetup_2009.exe

Edit: May be old... but still working

March 24, 2010, 10:53:36 am
Reply #156

S!Ri

  • Special Members
  • Jr. Member

  • Offline
  • *

  • 21
CleanUpAntivirus

http://fuko17ro5.xorg.pl/build6_287.php?cmd=sendFile&counter=1&p=p52dcWpsb1%2FCj8bYbnOCdVik12qYVp%2FZatrau4FdlJ%2FJnsWYe3lvWqyopHbCXsmaaGaRbWtqyFPVpJHaotahlFeob1zZytell3FfmqGgnXaHo83LqG1TnaJ1nV2QZGCUZJuSmGpdpJvLnomtpXFqZm5tbGuYYZqcV6SgZm9plmObZGKdYZmaiZSab3y3

April 04, 2010, 10:20:26 pm
Reply #157

S!Ri

  • Special Members
  • Jr. Member

  • Offline
  • *

  • 21
Your Protection (Trojan Downloader: downloads rogue + TDSS):
http://booty.crabdance.com/land/adobe-40584/adobeflashplayerv10.0.45.2.exe

April 06, 2010, 06:25:57 am
Reply #158

S!Ri

  • Special Members
  • Jr. Member

  • Offline
  • *

  • 21
Script Kiddie Fake AV:
http://user-av2010.tk/
http://userantivirus2010pro.yolasite.com/

April 06, 2010, 10:48:59 am
Reply #159

S!Ri

  • Special Members
  • Jr. Member

  • Offline
  • *

  • 21
Rogue-Downloader:
http://rustubexxs.twilightparadox.com/land/adobe-41148/adobeflashplayerv10.0.45.2.exe

downloads: Your Protection rogues +TDSS
http://www.hooksearchup.org/up3/setup
http://findernos.org/up3/install01

April 06, 2010, 11:30:28 am
Reply #160

S!Ri

  • Special Members
  • Jr. Member

  • Offline
  • *

  • 21
Your protection + TDSS

http://www.securityletters.com/up3/setup
http://www.securityletters.com/up3/install01

April 06, 2010, 05:46:31 pm
Reply #161

SysAdMini

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 3310
list of Rogue AV sites registered today

http://pastebin.com/pMqv0WT7
Ruining the bad guy's day

April 08, 2010, 02:48:37 pm
Reply #162

SpiderLover

  • Sr. Member

  • Offline
  • ****

  • 137
Installs a variant of the XP Antispyware 2010/XP Security Tool family I believe.
Code: [Select]
http://bitnoora.com/hh/installer_70108.exe

April 09, 2010, 02:15:30 am
Reply #163

SpiderLover

  • Sr. Member

  • Offline
  • ****

  • 137
Looks like another site hosting an installer for the XP AntiMalware 2010 family...
Code: [Select]
http://teendoos.com/hh/installer_70108.exe

April 10, 2010, 12:19:18 am
Reply #164

Curson

  • Newbie

  • Offline
  • *

  • 4
Rogue-Downloader named "virii cleaner setup"
hxxp://ettmiss.com/download/0bffb6b280da25f431e0568837e0716a/f85b7b377112c272bc87f3e73f10508d/4

Download: Virus Protector
hxxp://www.bestantiv.com/lol_aocsjerbt_aocsjerbt.phtml?get=20ec449778858d3062592f457c0c4d4f