<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: avsystemcare]]></title>
    <link>http://securityratty.com/tag/avsystemcare</link>
    <description></description>
    <pubDate>Fri, 07 Dec 2007 12:16:07 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Localized Fake Security Software]]></title>
      <link>http://securityratty.com/article/9c5cb4449d66fbad44e6fe61693c2485</link>
      <guid>http://securityratty.com/article/9c5cb4449d66fbad44e6fe61693c2485</guid>
      <description><![CDATA[Would you believe that in times when top tier antivirus vendors are feeling the heat from the malware authors' DoS attacks on their honeyfarms, and literally cannot keep up with their releases,...]]></description>
      <content:encoded><![CDATA[<a href="http://bp3.blogger.com/_wICHhTiQmrA/SANRxWORGRI/AAAAAAAABjY/GHkfMuLT9Z4/s1600-h/localized_fake1.jpg"><img id="BLOGGER_PHOTO_ID_5189081103881804050" style="margin: 0px 10px 10px 0px; float: left;" alt="" src="http://bp3.blogger.com/_wICHhTiQmrA/SANRxWORGRI/AAAAAAAABjY/GHkfMuLT9Z4/s200/localized_fake1.jpg" border="0" /></a>Would you believe that in times when top tier antivirus vendors are feeling the heat from the malware authors' DoS attacks on their honeyfarms, and literally cannot keep up with their releases, someone out there is using an antivirus scanner that doesn't really exist? It's one thing to <a href="http://ddanchev.blogspot.com/2008/03/cybersquatting-security-vendors-for.html">promote fake security software</a> in a <a href="http://ddanchev.blogspot.com/2007/12/diverse-portfolio-of-fake-security.html">one-to-many communication channel</a> by using a single language in a combination with <a href="http://ddanchev.blogspot.com/2008/04/cybersquatting-symantecs-norton.html">cybersquatted domains</a>, and <a href="http://ddanchev.blogspot.com/2007/10/rbns-fake-security-software.html">entirely another</a> to do the same in different languages. <a href="http://ddanchev.blogspot.com/2008/02/localizing-cybercrime-cultural.html">Localization for anything malicious</a> is already <a href="http://ddanchev.blogspot.com/2007/11/lonely-polinas-secret.html">taking place</a>, as <a href="http://ddanchev.blogspot.com/2007/10/mpack-and-icepack-localized-to-chinese.html">ori</a><a href="http://ddanchev.blogspot.com/2007/10/mpack-and-icepack-localized-to-chinese.html">ginally</a> anticipated <a href="http://ddanchev.blogspot.com/2008/03/localized-bankers-malware-campaign.html">as an</a> emerging trend back in 2006. The following currently active fake security software scams are promoted in Dutch, French, German, Italian, and you don't get to download them until you hand out your credit card details, and once you do so, you'll end up in the same situation just like many other people did in the past. Some sample fake brands :<br /><br /><div><p><em><a href="http://bp3.blogger.com/_wICHhTiQmrA/SANSqWORGSI/AAAAAAAABjg/7oehv4kc52w/s1600-h/localized_fake2.jpg"><img id="BLOGGER_PHOTO_ID_5189082083134347554" style="margin: 0px 10px 10px 0px; float: left;" alt="" src="http://bp3.blogger.com/_wICHhTiQmrA/SANSqWORGSI/AAAAAAAABjg/7oehv4kc52w/s200/localized_fake2.jpg" border="0" /></a>SpyGuardPro; PCSecureSystem; AntiWorm2008; WinSecureAv; MenaceRescue; PCVirusless; LifeLongPC; NoChanceForVirus; MenaceMonitor; TrojansFilter; TrojansFilter; LongLifePC; KnowHowProtection; Bestseller</em><em>Antivirus; PCVirusS</em><em>weeper; AVSystemCare; AVSecurityPlus; AVSecurityPlus; PCAssertor; PoseidonAntivir</em><em>us; TrustedAntivirus; PCBoosterPro; DefensiveSystem; GoldenAntiSpy; AntiS</em><em>pywareSuite; AntiMalwareShield; AntivirusPCSuite; AntivirusForAll; TrustedProtection; NoWayVirus; AntiSpywareConductor; AntiSpywareMaster; TurnkeyAntiVirus; YourSystemGuard;</em><br /></p><span style="font-weight: bold;">Portfolio one :</span><br /><br />alfaantivirus.com<br />antivirusalmassimo.com<br />farrevirus.com<br />fomputervagt.com<br />figitalerschutz.com<br />flmejorcuidado.com<br />ferramentantivirus.com<br />filterprogram.com<br />filtredevirus.com<br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp3.blogger.com/_wICHhTiQmrA/SANUGWORGTI/AAAAAAAABjo/XtgmolMIp4c/s1600-h/localized_fake_security_software.jpg"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp3.blogger.com/_wICHhTiQmrA/SANUGWORGTI/AAAAAAAABjo/XtgmolMIp4c/s200/localized_fake_security_software.jpg" alt="" id="BLOGGER_PHOTO_ID_5189083663682312498" border="0" /></a>geeninfectie.com<br />harddrivefilter.com<br />keineinfektionen.com<br />longueviepc.com<br />maseg.net<br />nonstopantivirus.com<br />pcantivirenloesung.com<br />pcsystemschutz.com<br />plutoantivirus.com<br />psbeveiligingssysteem.com<br />riendevirus.com<br />securepcguard.com<br />sekyuritikojo.com<br />sistemadedefensa.com<br />sumejorantivirus.com<br />totaltrygghet.com<br />viruscontrolleuer.com<br />viruswacht.com<br />votremeilleurantivirus.com<br />zeusantivirus.com<br /><br /><span style="font-weight: bold;">Portfolio two :</span><br /><br />advancedcleaner.com<br />alltiettantivirus.com<br />antispionage.com<br />antispionagepro.com<br />antispypremium.com<br />antispywarecontrol.com<br />antispywaresuite.com<br />antiver2008.com<br />antivirusaskeladd.com<br />antivirusfiable.com<br />antivirusforall.com<br />antivirusforalla.com<br />antivirusfueralle.com<br />antivirusgenial.com<br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp0.blogger.com/_wICHhTiQmrA/SANUQmORGUI/AAAAAAAABjw/GvJbhJxaCtU/s1600-h/localized_fake_security_software2.jpg"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp0.blogger.com/_wICHhTiQmrA/SANUQmORGUI/AAAAAAAABjw/GvJbhJxaCtU/s200/localized_fake_security_software2.jpg" alt="" id="BLOGGER_PHOTO_ID_5189083839775971650" border="0" /></a>antivirusmagique.com<br />antivirusordi.com<br />antivirusparatodos.com<br />antiviruspcpakke.com<br />antiviruspcsuite.com<br />antiviruspertutti.com<br />antivirusscherm.com<br />antiworm2008.com<br />antiwurm2008.com<br />archivoprotector.com<br />avsystemcare.com<br />avsystemshield.com<br />barrevirus.com<br />bastioneantivirus.com<br />bestsellerantivirus.com<br />bortmedvirus.com<br />cerovirus.com<br />debellaworm2008.com<br />defensaantimalware.com<br />defensaantivirus.com<br />drivedefender.com<br />exterminadordevirus.com<br />fiksdinpc.com<br />mijnantivirus.com<br />mobileantiviruspro.com<br />norwayvirus.com<br />nowayvirus.com<br />pcantivirenloesung.com<br />plutoantivirus.com<br />viruscontrolleuer.com<br />zebraantivirus.com<br />zeusantivirus.com<br /><br /><span style="font-weight: bold;">Portfolio three :</span><br /><br />pcsecuresystem.com<br />antiworm2008.com<br />winsecureav.com<br />menacerescue.com<br />pcvirusless.com<br />lifelongpc.com<br />nochanceforvirus.com<br />menacemonitor.com<br />trojansfilter.com<br />longlifepc.com<br />knowhowprotection.com<br />bestsellerantivirus.com<br />pcvirussweeper.com<br />antiespiadorado.com<br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp2.blogger.com/_wICHhTiQmrA/SANUbGORGVI/AAAAAAAABj4/t41ue-tbIUo/s1600-h/localized_fake_security_software3.jpg"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp2.blogger.com/_wICHhTiQmrA/SANUbGORGVI/AAAAAAAABj4/t41ue-tbIUo/s200/localized_fake_security_software3.jpg" alt="" id="BLOGGER_PHOTO_ID_5189084020164598098" border="0" /></a>avsecurityplus.com<br />apolloantivirus.com<br />pcassertor.com<br />menacesecure.com<br />poseidonantivirus.com<br />trustedantivirus.net<br />pcboosterpro.com<br />defensivesystem.com<br />goldenantispy.com<br />avsystemcare.com<br />trustedantivirus.com<br />antimalwareshield.com<br />avsystemcare.com<br />antiviruspcsuite.com<br />antivirusforall.com<br />trustedprotection.com<br />nowayvirus.com<br />pcantiviruspro.com<br />antispywareconductor.com<br />antispywaremaster.com<br />turnkeyantivirus.com<br />yoursystemguard.com<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp0.blogger.com/_wICHhTiQmrA/SANWOmORGWI/AAAAAAAABkA/ycww_NQ09sc/s1600-h/localized_fake3.jpg"><img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp0.blogger.com/_wICHhTiQmrA/SANWOmORGWI/AAAAAAAABkA/ycww_NQ09sc/s200/localized_fake3.jpg" alt="" id="BLOGGER_PHOTO_ID_5189086004439488866" border="0" /></a>Just like a previous <a href="http://ddanchev.blogspot.com/2008/03/portfolio-of-fake-video-codecs.html">proactive incident response</a> where I pointed out that these fake security applications are starting to appear as the final output in malicious campaigns injected<br />at high profile sites, ensuring that your customers or infrastructure cannot connect to these, will render current and upcoming massive IFRAME injected or embedded attacks pointless at least from the perspective of serving the rogue software.<br /></div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Yl9ksZG"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Yl9ksZG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=JDY5fZG"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=JDY5fZG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=UEaJdPg"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=UEaJdPg" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=yV8JnOg"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=yV8JnOg" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=tHiFAtG"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=tHiFAtG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ZwlY9XG"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ZwlY9XG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=7pK2Scg"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=7pK2Scg" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/269996668" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 14 Apr 2008 04:04:53 +0000</pubDate>
      <category domain="http://securityratty.com/tag/avsystemcare">avsystemcare</category>
      <category domain="http://securityratty.com/tag/antiworm2008">antiworm2008</category>
      <category domain="http://securityratty.com/tag/malicious">malicious</category>
      <category domain="http://securityratty.com/tag/fake security applications">fake security applications</category>
      <category domain="http://securityratty.com/tag/portfolio">portfolio</category>
      <category domain="http://securityratty.com/tag/malicious campaigns">malicious campaigns</category>
      <category domain="http://securityratty.com/tag/sample fake brands">sample fake brands</category>
      <category domain="http://securityratty.com/tag/antivirusforall">antivirusforall</category>
      <category domain="http://securityratty.com/tag/one-to-many communication channel">one-to-many communication channel</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/269996668/localized-fake-security-software.html">Localized Fake Security Software</source>
    </item>
    <item>
      <title><![CDATA[A Diverse Portfolio of Fake Security Software]]></title>
      <link>http://securityratty.com/article/9cb7b9731273f3926636a1326ee71a35</link>
      <guid>http://securityratty.com/article/9cb7b9731273f3926636a1326ee71a35</guid>
      <description><![CDATA[The recently exposed RBN's fake security software was literally just the tip of the iceberg in this ongoing practice of distributing spyware and malware under the shadow of software that's positioned...]]></description>
      <content:encoded><![CDATA[<a href="http://bp2.blogger.com/_wICHhTiQmrA/R1i5e6ehXnI/AAAAAAAABNU/OAoFVYtGWtg/s1600-h/bestsellerantivirus.jpg"><img id="BLOGGER_PHOTO_ID_5141062915387907698" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="" src="http://bp2.blogger.com/_wICHhTiQmrA/R1i5e6ehXnI/AAAAAAAABNU/OAoFVYtGWtg/s200/bestsellerantivirus.jpg" border="0" /></a>The recently exposed <a href="http://ddanchev.blogspot.com/2007/10/rbns-fake-security-software.html">RBN's fake security software</a> was literally just the tip of the iceberg in this ongoing practice of distributing spyware and malware under the shadow of software that's positioned as <a href="http://ddanchev.blogspot.com/2007/11/but-of-course-im-infected-with-spyware_18.html">anti-spyware and anti-malware one</a>. The domain farm of fake security software which I'll assess in this post is worth discussing due to the size of its portfolio, how they've spread the <a href="http://ddanchev.blogspot.com/2007/11/scammy-ecosystem.html">scammy ecosystem</a> on different networks, as well as the directory structure they take advantage of, one whose predictability makes it faily easy to efficiency obtain all the fake applications. This particular case is also a great example of the typical for a <a href="http://ddanchev.blogspot.com/2007/09/209-host-locked.html">Rock Phish</a> kit <a href="http://ddanchev.blogspot.com/2007/11/661-host-locked.html">efficiency</a> vs quality <a href="http://ddanchev.blogspot.com/2007/10/assessing-rock-phish-campaign.html">trade off</a>, namely, all the binaries dispersed through the different domains are actually hosted on a single IP, and are identical.<br /><br /><strong>Who's hosting the malware and what directory structure per campaign do they use?</strong><br /><br />It seems as <strong>content.onerateld.com</strong> (<strong>87.248.197.26</strong>) which is hosted at Limelight Networks is used in all the domains as the central download location. The directory structure is as follows :<br /><br />content.onerateld.com/antiworm2008.com/AntiWorm2008/install_en.exe<br />content.onerateld.com/avsystemcare.com/AVSystemCare/install_en.exe<br />content.onerateld.com/winsecureav.com/WinSecureAv/install_en.exe<br />content.onerateld.com/goldenantispy.com/GoldenAntiSpy/install_en.exe<br />content.onerateld.com/menacerescue.com/MenaceRescue/install_en.exe<br />content.onerateld.com/antispywaresuite.com/AntiSpywareSuite/install_en.exe<br />content.onerateld.com/trojansfilter.com/TrojansFilter/install_en.exe<br />content.onerateld.com/bestsellerantivirus.com/BestsellerAntivirus/install_en.exe<br /><br />Therefore, if you have secureyourpc.com the directory structure would be <strong>/SecureYourPC.com/SecureYourPC/install_en.exe</strong><br /><br /><strong>Sample domains portfolio of digitally alike samples of each of these :</strong><br /><br />antivirusfiable.com<br />antivirusmagique.com<br />bastioneantivirus.com<br />gubbishremover.com<br />pchealthkeeper.com<br />securepccleaner.com<br />storageprotector.com<br />trustedprotection.com<br />yourprivacyguard.com<br /><br /><strong>DNS servers further expanding the domains portfolio :</strong><br /><br />ns1.bestsellerantivirus.com<br />ns2.bestsellerantivirus.com<br />ns3.bestsellerantivirus.com<br />ns4.bestsellerantivirus.com<br />ns1.onerateld.com<br />ns2.onerateld.com<br /><br /><strong>Main portfolio domain farm IPs :</strong><br /><br />- <a href="http://img225.imageshack.us/img225/9795/portfolio01xp0.png">87.117.252.11</a><br />- <a href="http://img225.imageshack.us/img225/7826/portfolio02ib8.png">85.12.60.22</a><br />- <a href="http://img225.imageshack.us/img225/4622/portfolio03sw6.png">85.12.60.11</a><br />- <a href="http://img225.imageshack.us/img225/7940/portfolio04di6.png">85.12.60.30</a><br /><br />Laziness on behalf of the malicious parties in this campaign, leads to better detection rate, thus, they didn't hedge the risks of having their releases detected by diversifying not just the domains portfolio, but the actual binaries themselves.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=csaQZYC"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=csaQZYC" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=nr7jvBC"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=nr7jvBC" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=fzK9zmc"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=fzK9zmc" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=z5DLIsc"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=z5DLIsc" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=wIaBthC"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=wIaBthC" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ebRbmFC"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ebRbmFC" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=UMJ1PIc"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=UMJ1PIc" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/196841968" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 07 Dec 2007 12:16:07 +0000</pubDate>
      <category domain="http://securityratty.com/tag/domains portfolio">domains portfolio</category>
      <category domain="http://securityratty.com/tag/domains">domains</category>
      <category domain="http://securityratty.com/tag/portfolio">portfolio</category>
      <category domain="http://securityratty.com/tag/sample domains portfolio">sample domains portfolio</category>
      <category domain="http://securityratty.com/tag/fake security software">fake security software</category>
      <category domain="http://securityratty.com/tag/software">software</category>
      <category domain="http://securityratty.com/tag/onerateld">onerateld</category>
      <category domain="http://securityratty.com/tag/content">content</category>
      <category domain="http://securityratty.com/tag/exe">exe</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/196841968/diverse-portfolio-of-fake-security.html">A Diverse Portfolio of Fake Security Software</source>
    </item>
  </channel>
</rss>
