Monday, July 21, 2008

Impersonating StopBadware.org to Serve Fake Security Warnings

Malware is known to have been hijacking search results, take for instance the rogue Antivirus XP 2008 as a recent example, but it's even more interesting to see other rogue security software impersonating Stopbadware.org in order to server fake security warnings that ultimately lead to fake security software.



stopbadware2008 .com (58.65.238.171) is one of these examples, where stopbadware2008 .com/antivirus.php  redirects to infectionscanner .com and attempts to trick the user into installing download.infectionscanner.com /AntvrsInstall.exe.  The message used :



"Reported Insecure Browsing: Navigation blocked. Due to insecure Internet browsing your PC can easily get infected with viruses, worms and trojans without your knowledge, and that can lead to system slowdown, freezes and crashes. Also insecure Internet activity can result in revealing your personal information. To get full advanced real-time protection for PC and Internet activity, register Antivirus 2008. We recommend you to protect your PC now and continue safe Internet browsing."



There's in fact even more rogue software using the same IP (58.65.238.171), courtesy of HostFresh :

virus-scanner-online .com

security-scanner-online .com

viruses-scanonline .com

virus-scanonline .com

antivirus-scanonline .com

download.antivirus-scanonline .com

topantivirus-scan .com

topvirusscan .com

virusbestscan .com

virus-detection-scanner .com

antivirus-scanner .com

infectionscanner .com

virusbestscanner .com

internet-security-antivirus .com




It would be interested to monitor whether or not the template for the fake security warning would start getting used on a large scale.



Related posts:

A Portfolio of Fake Video Codecs 

Fake PestPatrol Security Software

Got Your XPShield up and Running?

Localized Fake Security Software

A Diverse Portfolio of Fake Security Software

RBN's Fake Security Software

No comments:

Post a Comment