Page 1 of 2

Rogue Antimalware (FakeAV, 2015 year)

PostPosted:Thu Feb 19, 2015 9:33 am
by Blaze
remark start

2010 year FakeAV
2011 year FakeAV
2012 year FakeAV
2013 year FakeAV
2014 year FakeAV

remark end

New year, new roguewares.

This one is:

Malware Defender 2015
Image

Image

Re: Rogue Antimalware (FakeAV, 2015 year)

PostPosted:Sat Feb 21, 2015 4:04 pm
by S!Ri
From the same family:
Antivirus Defender 2015
(72.14 KiB) Downloaded 147 times
Spyware Defender (2014)
(40.97 KiB) Downloaded 102 times

Re: Rogue Antimalware (FakeAV, 2015 year)

PostPosted:Wed Mar 25, 2015 8:25 pm
by r3shl4k1sh
Security Defender (Defender PRO 2015)

Image

Re: Rogue Antimalware (FakeAV, 2015 year)

PostPosted:Wed Apr 22, 2015 7:21 pm
by Blaze
Antivirus Pro 2015

Image

Re: Rogue Antimalware (FakeAV, 2015 year)

PostPosted:Wed Apr 22, 2015 8:39 pm
by Grinler
Thanks Blaze! Been looking for this sample.

Re: Rogue Antimalware (FakeAV, 2015 year)

PostPosted:Wed Apr 22, 2015 10:50 pm
by EP_X0FF
@Blaze

Such a hello from the past :)

http://www.kernelmode.info/forum/viewto ... 4712#p4712

Re: Rogue Antimalware (FakeAV, 2015 year)

PostPosted:Wed Apr 22, 2015 11:19 pm
by Grinler
EP_X0FF wrote:@Blaze

Such a hello from the past :)

http://www.kernelmode.info/forum/viewto ... 4712#p4712
Here is the list of rogues in this family: http://www.bleepingcomputer.com/virus-r ... cdefender/

Yup, last one we saw from this family was AntiVirus Plus 2014 from 12/06/13. This was never a prolific family, with only about 11-12 variants released over a 4 year period.

Image

Re: Rogue Antimalware (FakeAV, 2015 year)

PostPosted:Mon May 25, 2015 9:09 pm
by Xylitol
Antivirus Pro 2017
Image Image Image

Original: https://www.virustotal.com/en/file/312f ... 432579379/ > 26/57
Unpacked: https://www.virustotal.com/en/file/5187 ... 432579640/ > 15/56

Fraudulent payment processor for fake Antivirus: secure.billingauto.com ⚫ 194.54.83.82
FakeAV call home: twinkcam.net ⚫ 74.86.20.50
Fake site: securerem.com ⚫ 194.54.83.83

Persistance: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\AntiVirus Pro 2017
Fake Antivirus can be unistalled by using the argument: -uninstall
Image
Unlock key: Y65RAW-T87FS1-U2VQF7A
Vidya: https://www.youtube.com/watch?v=Z_pLtVUCz8c

Thanks to siri for the sample.

Re: Rogue Antimalware (FakeAV, 2015 year)

PostPosted:Wed Sep 16, 2015 5:06 pm
by Xylitol
Security Defender
ImageImageImage
Open random visa/xhamster/paypal websites and flash (epilepsy warning).

Network activity:
Code: Select all
95.213.186.51:81/purchase.php?a=0&v=1005&u=3c48680fa1def47c7406eff698ef4a67&bgload=1
VT: 6/52

Re: Rogue Antimalware (FakeAV, 2015 year)

PostPosted:Wed Sep 16, 2015 6:32 pm
by Grinler
Thanks Xylitol. This is a new campaign?

If so they stopped being creative as this was released previously:

http://www.bleepstatic.com/swr-guides/s ... screen.jpg