Showing posts with label fake av. Show all posts
Showing posts with label fake av. Show all posts

Friday, June 15, 2018

Fake Malware Pop-up Example

I don't believe I've ever done a video blog, but I wanted to show you what it looks like when we look at a fake malware pop-up.  While I was prepping a lecture for a class I'm teaching by looking at something on Encyclopedia Britannica, I experienced a fake malware popup.

Here's what I saw:

"Serifed.Stream" malicious pop-up
The best way to explain this is to show it to you.  To do so, I've saved a little video of the what we saw.


In that walk through, you can see that the advertisement that led to the pop-up goes through a series of hops:

westerndigitalmeasure.com (192.241.254.144)  was the first site I hit, which had me do a POST to /j/pcl.php

(By the way, Westerndigitalmeasure.com is hosted at Cloudflare)

That PHP code sent me to "orgeles-hantests.com" (52.72.0.63) which immediately did a meta refresh to another page on orgeles-hantests.com which had a "redirect?target=(very long string here)"

That sent me to the host "redirect.orgeles-hantests.com" (54.89.11.221) which did another meta refresh to the site "server3.divinedessert.info" (67.207.82.78).

And divinedessert forwarded me to "serifed.stream" which is where we saw the fake Microsoft malware warning, which, by the way, captured and passed on my Internet service provider name and my home IP address in the URL.

We asked the URL scanner at VirusTotal check out "serifed.stream" and "serifed.stream/live/" but got the same result both ways.   0 of 68 URL reputation engines believe the site to be malicious.

Don't Worry, Be Happy, says 68 different URL Reputation Services

When we look by IP address, things aren't much better.  Of the hundreds of ".stream" addresses hosted on that same IP address, 185.44.65.141, which, by the way, is hosted in Iran, almost NOBODY found them to be malicious:



That last one shown, with 5 of 68 URL reputation services saying it might be bad, could also be interpreted as 63 out of 68 URL reputation services would have let your users see the bad content.  HOPEFULLY, they might have blocked a redirector somewhere in between, but honestly, I don't know . . . (this is the part where all of them will complain VirusTotal doesn't capture the totality of their user experience.  Yeah, yeah, yeah, cry me a river. I'm running AV and it happened to me!  Did you see the video?)



How to conclude?  I don't know.  Perhaps by just saying "the criminals are still ahead of us in this game, and this is why we can't have nice things."




Friday, November 08, 2013

Tempting Photo Attachments Lead to Fake AV

One of today's largest malicious spam campaigns continued an occasional theme we've been seeing for a few weeks. A subject line, followed by a single "emoticon" email, with an attachment that promises to be a picture.

The emails had a wide variety of subjects and were coming in fast and furious around 4:00 this morning:

A query in the Malcovery Spam Data Mine shows the variety of subjects used in the campaign:

count |                  subject                   
-------+--------------------------------------------
    90 | Someone showed me your picture
    86 | I love your picture!
    85 | This is the funniest picture ever!
    85 | What you think of this picture?
    84 | You look so beautiful on this picture
    80 | Tell me what you think of this picture
    78 | You should take a look at this picture
    78 | Take a look at my new picture please
    75 | Is this you??
    69 | Someone told me it's your picture
    66 | Should I upload this picture on facebook?
    62 | Picture of you??
    50 | Your friends won't be happy about that
    48 | My private picture only for you
    47 | Private
    46 | Your picture is all over the web now
    44 | Keep it secret
    43 | Keep it private
    43 | Could you explain please?
    43 | Do you think I'm attractive?
    41 | Photo of you naked??
    40 | Do you think I'm 'pretty or ugly?
    40 | My private photo for you
    39 | Do you think she is hot?
    37 | Hey check out this picture
    37 | I just can't belive this
    35 | You look terrible on this photo
    35 | I found this picture of you
    35 | My private picture
    35 | To show how much I love you
    35 | Please rate my picture
    35 | Your wife won't be happy about that
    34 | How do you think she looks?
    34 | Please tell me this is your photo
    33 | Shame on you
    31 | Your opinion needed
    30 | Check out my photo but keep it private
    26 | I love you so much please check my photo
    22 | My private photo
    11 | What you think about my halloween costume
     7 | Your wife wont like this picture
     7 | Happy Halloween
     6 | Check this out!!
     6 | Best halloween costume
     6 | Your wife will be shoked
     6 | Worst picture ever!
     5 | Private picture of you?
     5 | Biggest pumpkin lol
     5 | Halloween costume
     4 | You are fucking ugly
     4 | Biggest fail of the month
     4 | Best halloween costume ever
     4 | You are so sexy
     3 | Are you crazy??
     3 | Naked picture of you
     3 | You like my halloween costume??
     3 | WTF?
     3 | Busted you naked
     3 | WOW WTF is this???
     2 | Please explain??
     2 | Let me know if this is really your picture
     2 | Check out my halloween costume
     2 | Seen this shit before??
     2 | LOL
     1 | Spam: My private photo
     1 | Can't belive this!
(66 rows)
The campaign was further confused by the fact that every email attachment had a unique MD5 hash (one of the tricks we use to cluster emails is to look for them to have the same attachment).

I won't go into the technical details of how it works, but the ZIP file contained an SCR file -- an old filetype that used to be a common way for people to share "Screen Saver" files. Trying to "view" the Image file from inside the .ZIP actually results in the .SCR file being executed, and downloading and executing the file "soft.exe" from the website at 91.216.163.208 as you can see from this code-dump of the SCR file.

The file failed to run in our default analysis Sandbox so we had to break out the Raw Iron ... since the malware was being so paranoid, I used a camera to document what came next rather than taking screenshots in the program.

The Fake AV was called "AntiVirus Security Pro" and popped up in the typical fashion to run a "Full Scan" of my system:

While it was running a pulled a running process name and found that the malware had copied itself to my "Local Settings\Temp" directory and was running from there with the name "dnn9d9n39dn93nd39b9d393d3bdb.exe" (as you can see in the CMD window behind the scan above.) That file was 569,344 bytes in size.

After the scan completed, I went ahead and told it to Repair All of the threats it had found.

Unfortunately, it failed to repair some of the infections, because I was running a "limited version" of Antivirus Security Pro.

But there is HOPE! Even though "Not all threats have been eliminated." I could "Buy Full Edition" to fix the remaining 19 threats! What a relief!

When I chose not to do that right away, the Fake AV popped up occasional helpful HINTs that said "We strongly recommend activating full edition of your antivirus software for repairing threats."

Pretty darn expensive Fake AV! To the authors - please note that you are more likely to get the $99.99 for a LIFETIME license as opposed to six months. Nobody is going to pay $59.99 for a 30 days license, but we also aren't going to pay $99.99 for only 6 months! Maybe you could try 1 year, 2 year, 5 year?

Sadly, my credit card didn't clear. I'm shocked. I tried really hard to make up a valid card number! The good news is that the "Antivirus Tech Support" link on my desktop would take me back to the shop anytime I wanted to try again by visiting "techprotectorltd.com":

Fake AV IS A CRIME! REPORT IT!

Were you a victim of this scam? Whether you paid for the Fake AV or not, I would strongly encourage you to report your experience to the Internet Crime and Complaint Center by visiting: IC3.gov and using the "File a Complaint" button!

Friday, September 20, 2013

Fake AV Malware Hits the Android

Mobile Defender - the last line of protection

Having studied malware delivered by spam for the past seven years, it is a fairly rare event for me to be amazed by something new, but that is exactly what happened today thanks to a new finding by Brendan Griffin, the lead author of Malcovery's Today's Top Threats report.

In yesterday's report, Malcovery customers were informed of a prevalent spam email that used the subject lines:

  • Voice Message Notification
  • 1 New Voicemail(s)
  • 2 New Voicemail(s)
  • 3 New Voicemail(s)
  • 4 New Voicemail(s)
  • 5 New Voicemail(s)
  • 6 New Voicemail(s)
When the spam messages from this campaign are rendered in an HTML mail viewer, the received message looks like this:

For a Windows user who clicks on the link, the malware calculates a location and drops a .zip file to the visitor with a name appropriate for thier location. For example, in yesterday's T3 Report, Brendan documented the behavior of a file he received from "bhaktapurtravel.com.np" that was named "VoiceMail_Birmingham_(205)4581400.zip".

At the time of Brendan's review, only 6 of 48 Antivirus vendors detected the .zip file as malicious according to this VirusTotal Report for zip.

The unpacked file, which used an icon displaying a musical note on a sheet of paper, fared little better, with only 7 of 48 detections as shown in this Virus Total Report for exe.

Twenty-four hours later, that detection is up to 21 of 48 detections, with several vendors (AntiVir, DrWeb, Microsoft) calling the malware "Kuluoz" while BitDefender, EmSoft, and F-Secure prefer the name "Symmi".

Android Version?

Given that the email message was claiming to be from an Android application called "WhatsApp", Brendan revisited the link, using a User-Agent string that would be commonly associated with an Android-based browser.

Instead of receiving an .exe file, when using the Android emulation mode, Malcovery received *AND INSTALLED* a file called "WhatsApp.apk". Examining the code, Brendan found bilingual messages in Russian and English that seemed to be indicating that various malware packages had been found on his phone. Here's one example, that seems to claim the presence of Downad/Conficker:

The Android malware, which had the MD5: 5290df867914473426b82233567c03af, was much better detected by AV engines ...

At first glance, that seems quite encouraging! But think about it more. What possible good does it do you to have AVG, ESET, F-Secure, Kaspersky, and Trend Micro telling you that this APK file is hostile? You certainly aren't running any of their Anti-virus products on your Android phone, are you?

Brendan decided it was time to put this malware into a true Android phone, and received some shocking results, shown below!

First, the Android App pretends to scan your phone for malware . . .

And then, it asks you for your credit card information in order to buy the "Mobile Defender" application to protect your phone!

We were amused by the "Lifetime Software License" which offers a 60% discount. I wonder how many years they expect us to live to calculate that discount! Hopefully they are referring to the lifetime of their malware, rather than us or our phone!

Historical FakeAV Scams

We certainly have been talking about Fake AV for a long time! Here are some of our previous articles on the subject, dating all the way back to 2008 -- but this Fake AV on Android Phones was a first for us, especially in such a prominent spam campaign!

FTC Moves against Fake AntiVirus ScareWare Companies - Dec 2008
Conficker Fears Spread Fake AV - April 2009
Fake Twitter, Linked In, and ScribD pages lead to Fake AV - June 2009
Fake AV in the News - April 2010
MasterCard Spam leads to Fake AV - July 2011

Sites seen in spam with either "info.php" or "app.php" malware links

Each of the sites below was found in spam in the Malcovery Spam Data Mine, either with an "app.php" path, such as "/app.php?message=7nof02WSsCV044njNqRS+F1mNBPcaaHD7u7VE/2vY7c=" or an "info.php" path such as "/app.php?message=NaZNY1tYTjYL5u0C/rimmNLlnDKRleqTEBJme/hthH4="

We believe that each of the sites below was compromised to allow the criminals to insert the "app.php" or "info.php" file on their system.

At this time, we are unsure whether the "localization" seen on the Windows version of this malware is based on geolocation of the infected computer's IP address, or whether the parameter passed in the URL contains an encoding of the user's location. Every URL observed had a unique string in the "message=" portion.

countmachine
countmachinecountmachine
24 babytoysbaby.com4 coffsdentalcentre.com.au
22 bhaktapurtravel.com.np4 admingo.ru
22 tsypa.ru4 5100429.ru
19 manchesterbuddhistcentre.org.uk4 skupina-lira.si
18 koshergiftsuk.com4 planeta-avtomat.ru
17 casperscomputers.com4 personalcarephysio.ca
17 mywebby.ru4 iperidrosi.org
16 ifuneral.it4 dxixisport.com
16 tk-galaktika.ru4 guru27.ru
15 mdou321.ru4 holenefesh.com
14 thaiecom.net4 zag.com.ua
14 thenewdabbs.com4 yildizotel.com.tr
14 locweld.com4 shinyvsem.ru
14 gourmetschlitten.com4 dr-nonna.ru
14 sadafmirza.com4 niessing-gladbeck.de
14 serov1.com4 uwes-futterkiste.de
14 growlerscraftbeerandales.com4 boat-plastic.ru
13 globalpeat.com4 morterablanca.com
13 dj220w.ru4 co-co-mail.net
12 improvisera.net4 vizazh.zp.ua
12 www.raspinawin.com4 verfassungsschutz-bw.de
12 srivivekananda.com4 darkmatta.com
12 amicidelcuore.info4 www.kip26.ru
12 shop-rakushki.ru3 veerbootkobus.nl
11 rkbtservice.ru3 fehoozy.com
11 djvakcina.com3 juhatanninen.com
11 muzikosfabrikas.lt3 artedangi.com
10 ikarplus.com3 truesouthmanagement.com
10 katrinfil.ru3 paternocalabro.it
10 ladwig-gmbh.de3 tennissimo.be
10 profnastil-sm.ru3 westsaitama.com
10 cateringjaipur.com3 venoras.com
10 clockcards.ie3 netbook.com.ua
10 lichtenauer-fv.de3 einstalacje.pl
10 mrsergio.com3 kovka1.ru
10 gseo.it3 piotrkozak.com
10 mirvshkatulke.ru3 momks.org
10 albecoperu.com3 tcpredatorsbaseball.com
9 dimater.com3 autovaza.net
9 dezibelmusik.de3 surya.org
9 goldnart.ru3 fiskr.ru
9 rickhelpt.nl3 piediplomacy.com
9 designmakers.kz3 dis-travel.ru
9 crazyparty.com.pl3 sportsbettingonlineusa.net
9 tc.CastineLLC.com3 dmitriy-vasilchuk.com
9 gustavblome.de3 craftyfolks.net
9 autopialighting.com3 cityglobal.ru
9 eckkaluga.ru3 isuzu.loader.com.ua
9 redmangoindo.com3 isa-scouts.de
9 olimpodelbenessere.it3 www.michael-roos.net
9 mazdaparts.su3 www.ninja-ninja.com
9 lexbox.am3 net2day.tk
8 pennerimperium.de3 maov.info
8 yakitoriya-mo.ru3 elmetsystem.pl
8 dush80-svao.ru3 tischlerei-klemm.de
8 mastersonpr.com3 such-spinne.de
8 slocis.com3 pts.kovrov.ru
8 art52.ru3 thundermistpowerboats.com
8 tva.ru3 sungatov.ru
8 frescomeble.pl3 harald-rupp.com
8 darkstudio.net3 shermes.biz
8 orbitmotion.com3 auronzo.it
8 cam.shaksha.ru3 yakrus.com
8 www.chelyabreduktor.com3 gogreenbravo.com
8 everyday24h.de3 tengritel.kz
8 www.auxtribusindiennes.com3 sewretro.com
7 dialoguetrust.net3 oilhelp.info
7 magavilla.com3 bdlmachines.com
7 structuredsettlementsannuities.com3 cypresshomecareinc.com
7 brainseal.com3 yalublutebyazhizn.ru
7 bareli.co.il3 specialistdental.com.au
7 colorpaco.com3 trivenidigital.com
7 kasutin.ru3 englishteam.ru
7 www.myinnerpc.com2 e-nt.de
7 fasthotel.ru2 cargor.net
7 whiteys.co.uk2 ingredientspring.com
7 smsa.pt2 cthmail.de
7 granitderi.com.tr2 corpstroy.ru
7 ntsysteme.de2 heartwood.com
7 artisan-co.ru2 na-derevnu-dedu.ru
7 mosobladvokatura.ru2 swanseacity.co.uk
7 gamez.com.ua2 mdou104.ru
7 sentabilisim.com2 assistantinukraine.com
7 tufts.biz2 wowbestservers.com
6 angelomasotti.it2 arsenalyar.ru
6 tripdogs.com2 velvet-sound.ru
6 ciarko.by2 intimdosug38.ru
6 big-cock.biz2 supertouch.co.in
6 softrace.no2 chemycards.com
6 haugesund-toppidrettsgymnas.no2 cebuhomesville.com
6 samedaystationery.co.uk2 leaderscenter.com
6 tadaphotography.com2 rolandward.co.uk
6 dyffryn.org2 ignologics.com
6 hochseilgarten-springe.de2 zarco-sic.com
6 bagnaradiromagna.net2 etarlo.ru
6 sitallsmolensk.ru2 bigpk.ru
6 humtata.de2 ofis-v-nikolaeve.com
6 tiarahlds.com2 ravolna.ru
6 allpress.biz2 pyora68.net
6 zdrowieonly.ovh.org2 poster.ua
6 webasto-ufa.ru2 scottishtaxifinance.co.uk
6 custers.ru2 formularmaker.com
6 hansobermeier.de2 ais-stroi.ru
6 ziehdichauskunft.com2 bluereefwatersports.com
6 venetamalaysia.com2 fundigital.org
6 cathedralcityestates.co.uk2 avminho.pt
6 paminklaizidiniai.lt2 pechatiboom.ru
6 mbuhgalter.ru2 filtrum-safari.ru
6 shilvi.com2 aquatechperu.com
6 orderschering.com2 butik-koles.ru
5 mouvsoch185.ru2 visumconsulting.com
5 zenxual.com2 warehouseboxing.com
5 michael-roos.net2 elviras-tischdeko.de
5 easywebmexico.com2 homemoney.ru
5 agapy.com2 mar-kant.nl
5 marsperformance.ru2 eeesolution.com
5 muzacikunovice.cz2 microfi.co.uk
5 andyxator.ru1 neps.ru
5 bahfuture.org1 christel-gekeler.de
5 cfgb.fr1 open-63.ru
5 golazvezda.ru1 hardmetalunderground.com
5 mapradio.org1 nickparton.com
5 therabrands.com1 dieschrauba.at
5 goetzke-krottelbach.de1 gardi.eu
5 paleorecip.es1 vivasan-forum.ru
5 rus-futbolka.ru1 aki-kowalstwo.pl
5 lcc.org.au1 dotmatt.com
5 stolk.de1 wesselinkgmbh.de
5 mikemetcalfe.ca1 turfirma-yaroslavl.ru
5 nbvf.nl1 positivelynaked.com
5 juszczyn.eu1 barkersofwindsor.co.uk
5 izumrudny.org1 assignmentwriting.co.uk
5 myinnerpc.com1 manfred-konrad.de
5 burtonbrothers.net1 frenken-adviesburo.nl
5 asesoriacontableperu.com1 alumdeco.ru
5 dustycatwriter.com1 pawsathome.ca
5 coolpcgames.co.uk1 demonic3d.com
5 wallmountainweb.com1 computing4schools.co.uk
5 airspill.com1 visibus.ru
5 schweitzers.com1 nazike.com
5 cond.ru1 vitapool.ru
5 trimeducation.com1 eventlocation-kiel.de
5 bfphotography.eu1 radio-kabyle.com
5 meter-online.info1 stkiliansnsmullagh.ie
5 organocontinuo.com1 spentec.ca
5 damsit.com1 gsp35.ru
5 ahkrc.org1 shkolaimperatritsy.ru
5 tc.castinellc.com1 cdrv.ru
5 muralzbyjean.com1 altaicompass.com
5 gubo.com1 pototype.com
4 paulhughestransport.com1 line-message.net
4 koo-doo.ru1 sad-natali.ru
4 louisedenson.com1 gie-expo.com
4 mcmillandefense.com1 lkmining.com
4 avionstudio.com1 sonyfoto.com.pt
4 permanentmakeup-soest.de1 schulezorneding.de
4 rogerclarkejohnson.com1 angelkeeper.ru
4 solovy.ru1 enlightenpro.com
4 simoneliebst.de1 burim.by
4 georgysphoto.ru1 pp73.ru
4 initsiativa.com1 avitrade.ru
4 mephics.co.tz1 centik.de
4 pax-sancta.de1 nevertoolatebook.com
4 physiotherapie-kies.de1 alyes.nl
4 idollighting.com1 romchik.com
4 semeylib.kz1 towi69.de
4 foundationforhealthaction.org1 eplater.co.uk
4 ekimenko.net1 intal.net.ua
4 mikroeta.lt1 radio-germanija.de
4 contact.com.vn1 manjitubhi.com
4 yu7.ru1 carrahar.co.uk
4 srmarketers.com1 arenda-t.ru
4 supercarsofmoscow.ru1 torbeta.com
4 greaterbaycomputer.com1 ventoz.ru
1 babysun-volga.ru

Monday, September 14, 2009

In Brief: The New York Times fake anti-virus redirect

Several people have emailed asking if the fake anti-virus products I mentioned in today's blog article, US Open and VMAs top rogue anti-virus efforts, was the same fake anti-virus that was reported as being launched from advertisements at the New York Times website over the weekend. The truth is, I didn't know! So I looked into it.

The New York Times fessed up that they were having problems in This note on September 13th:

Some NYTimes.com readers have seen a pop-up box warning them about a virus and directing them to a site that claims to offer antivirus software. We believe this was generated by an unauthorized advertisement and are working to prevent the problem from recurring. If you see such a warning, we suggest that you not click on it. Instead, quit and restart your Web browser. Questions and comments can be sent to webeditor@nytimes.com.


A second NYT story today tells only SLIGHTLY more information:
http://bits.blogs.nytimes.com/2009/09/14/times-site-was-victim-of-a-malicious-ad-swap/?hpw, see also: http://gadgetwise.blogs.nytimes.com/2009/09/14/what-to-do-if-you-saw-an-antivirus-pop-up-ad/


A new advertising network that fed ads to the NYT ran "normal" ads for about a week, then suddenly started advertising malware sites over the weekend. An ad, that at least part of the time redirected to russell-brand.cn, contained hostile javascript, which redirected to the actual fake AV site.

Some of the domains involved included:

protection-check07.com which resolved to IP address 88.198.107.25. That IP was also used by:

antivirusonlinescan03.com
antispywarescanner07.com
antispywarescanner08.com
best-antivirus03.com
best-spyware-scan01.com
best-spyware-scan03.com
intellectual-vir-scan08.com
intellectual-vir-scan09.com
malwareinternetscanner03.com
online-antivir-scan09.com
protection-check07.com
quick-virus-scanner01.com
quick-virus-scanner02.com
quick-virus-scanner08.com
reliable-scanner02.com
reliable-scanner05.com


These actually were shared across several IPs, including:

78.46.251.43 - Berlin, Germany, "your-server.de"
88.198.107.25 - Sweden, - "your-server.de"
88.198.120.177 - your-server.de
91.212.107.5 - Cyprus - Ricomm
91.212.127.200 - UK - Telos Solutions
94.102.51.26 - Netherlands - Ecatel

As I was not a first-hand witness, I'm going to wrap this up short as promised by pointing to a few other blogs:

http://ddanchev.blogspot.com/2009/09/ukrainian-fan-club-features.html


http://troy.yort.com/anatomy-of-a-malware-ad-on-nytimes-com

US Open and Video Music Awards top rogue anti-virus efforts

This summary is not available. Please click here to view the post.