Page 8 of 46

Re: Rogue antimalware (FakeAV, FakeAlert)

PostPosted:Wed Feb 29, 2012 1:15 pm
by rkhunter
Fresh 6 samples of Smart Fortress 2012

3341269077BD332526B1617EA00CD843
3517006A962798E4A8A72F32F2EEC645
54850B4618FB6BD4B9960C8E7A2ED01E
5E2469F07950B290BE060A2D199D24C3
B2458121622535CC37EA13A3CEA0CFAE
915C42511C7C8C24B1DAF1580A4B254C

Re: Rogue antimalware (FakeAV, FakeAlert)

PostPosted:Fri Mar 02, 2012 8:15 am
by rkhunter

Re: Rogue antimalware (FakeAV, FakeAlert)

PostPosted:Fri Mar 02, 2012 8:37 am
by rkhunter
Security Shield returned, 3 fresh droppers in archive.

Re: Rogue antimalware (FakeAV, FakeAlert)

PostPosted:Sun Mar 04, 2012 12:40 pm
by BachMinuetInG
Landing

URL Landing:
hxxp://www2.powerausoft.de.gg/vyyv2184g?u4g1g=mZXck6TR6Ozd5sib6NjKsaxa15rLraKdxtTD57C3s7eboNpumaGgndTlnuzppozW3pikk8az1%2BnU38ab5t3Y1rKd0J3f2dbsi9XEssa2jN3lcZhinZ6grJOpmqOkp5ya6KjIpdzjrJ3c28WyqqSemumo027NoZ%2BsxqaTpaqimJrpp6RimqOfr5umkqyslcrj4pXQn6Tn5u6ZoNHa5eLV4tag1ZTf2JzbytjG4%2BbUlNfkoY2h19HR26Ljz97j0oo%3D

hxxp://www2.powerausoft.de.gg/qur5?hwartqkn=jN%2Fa6rHSzuDV3diL58rZsKaM5NHbnqWa0s3Q4qy%2FsrWH4easl6SfndDlsejhpZbR4Mmvw9S219jj1dyH6%2BHZ2uGt3Ojb6dHc15XJ16XKqJjd4aifoaWllqePrKydl6yendTm1eXg4a2V7s7Wnqyop4zo3OOe2KWhoM%2BkoaecpZOb5%2BKjpZuqkaqqpZ6iopXb1N%2FC3uGs3evfq4%2Fi2ePe3d7Q49PV2d2g08vazeXU16LU2tuW2%2BHQ1M%2By3tjR5M%2FZhQ%3D%3D

hxxp://www4.personalncxh-defense.com/?5ptgv=WeXdy7O

Re: Rogue antimalware (FakeAV, FakeAlert)

PostPosted:Sun Mar 04, 2012 6:03 pm
by rkhunter
27 fresh Winwebsec

Re: Rogue antimalware (FakeAV, FakeAlert)

PostPosted:Mon Mar 05, 2012 12:31 pm
by Striker
Windows Trojans Sleuth

Image

Serial: 0W000-000B0-00T00-E0020

Re: Rogue antimalware (FakeAV, FakeAlert)

PostPosted:Mon Mar 05, 2012 12:48 pm
by BachMinuetInG
Have 2 samples, one Home malware cleaner and Windows trojans sleuth with both landings and program files. Unable to upload.

Re: Rogue antimalware (FakeAV, FakeAlert)

PostPosted:Tue Mar 06, 2012 11:29 am
by rkhunter
FakePAV - "Windows Personal Detective"

MD5: 8984A4BB2DB2986CFC427CAD5934B102
FUD - 0/43

Image

Re: Rogue antimalware (FakeAV, FakeAlert)

PostPosted:Tue Mar 06, 2012 1:40 pm
by Striker
Antimalware PC Safety

Image


Packed with UPX.
Serial: U2FD-S2LA-H4KA-UEPB

in attach: Downloader + dropped files + unpacked exe

Re: Rogue antimalware (FakeAV, FakeAlert)

PostPosted:Tue Mar 06, 2012 5:33 pm
by ISergey256
Antimalware PC Safety
fixed VBox