The Latest in IT Security

Choose your preferred Fake AV

29
Nov
2011

??? Isn’t it great when your forecasts
come true? Well, sometimes. But maybe not this time. Today I found a
malicious site specially designed to fake three antivirus brands.
Kaspersky is top of the list. So, what does it look like?


In the past we’ve seen Rogue
AV websites
using fake screenshots made with templates but
without any real interaction with the user PC. These fakes didn’t
claim to find any infections – the victim was simply ripped off
after paying for a useless product. Now, though, we’ve found a new
version where the Fake AV simulates the results of a malware search.

So, how does the infection happen? There is a dropper (Trojan.Win32.Scar.fdiz) which
downloads the Fake GUI required by the scam. The query is built with
this rule:

http://X.X.X.X/fakeav/interface.php?av=[Anti-Virus GUI name]&lang=en

Here is the list of the files / brands on this Fake AV server:

Leave a reply


Categories

SATURDAY, APRIL 20, 2024
WHITE PAPERS

Mission-Critical Broadband – Why Governments Should Partner with Commercial Operators:
Many governments embrace mobile network operator (MNO) networks as ...

ARA at Scale: How to Choose a Solution That Grows With Your Needs:
Application release automation (ARA) tools enable best practices in...

The Multi-Model Database:
Part of the “new normal” where data and cloud applications are ...

Featured

Archives

Latest Comments