« False Positives are NEVER a good thing
Michael Jackson Malware (cont.) »

Large cluster of fake AV

June 26th, 2009

This is a pretty large number of domains on the same IP address delivering scareware programs.

fake

The IP is 209.44.126.241

besecurityguardian.com

bestyourtrust.com

bitsecuritycenter.com

brasll.com

fullpcvirusscan.com

fullsecurityaction.com

gisecurityshield.com

godsecurityarchive.com

hortshieldpc.com

hupersecuritydot.com

intellectsecfind.com

intellectsecurityshield.com

libecoolsites.com

libertysecuritytool.com

mail.allowedwebsurfing.com

mail.godsecurityarchive.com

mail.hupersecuritydot.com

mail.intellectsecurityshield.com

mail.libecoolsites.com

mail.moregreatsites.com

mail.souptotalsecurity.com

mail.uniqtrustedweb.com

mail.upsecurityscanned.com

moregreatsites.com

mx241.brasll.com

ns1.godsecurityarchive.com

ns1.hupersecuritydot.com

ns1.libecoolsites.com

ns1.moregreatsites.com

ns1.souptotalsecurity.com

ns1.truesecuredpcs.com

ns1.uniqtrustedweb.com

resecurityaction.com

scanpcsecurity.com

scantrustsecurity.com

securetopshield.com

securexdetect.com

securityfastscan.com

securityshieldcenter.com

securityuniqscan.com

sidewebvirusscan.com

souptotalsecurity.com

thefirstupper.com

todaysecuritytop.com

totalsitesarchive.com

totalvirusshield.com

uniqtrustedweb.com

upsecurityscanned.com

virusdestroyerboost.com

www.allowedwebsurfing.com

www.bestwebscantools.com

www.fullsecurityaction.com

www.fullvirusprotection.com

www.hupersecuritydot.com

www.intellectsecurityshield.com

www.moregreatsites.com

www.truevirusshield.com

xvirusdescan.com

Also shown in this graph:

20944126241as

I downloaded one of the files and detection on VirusTotal is fairly low (8/41)

fake2

Just out of curiosity, I checked it against our Zheng heuristic system and we proactively detect it already :-)

zheng1

Jerome Segura

Malware ID: bb2de997ea9d38c1895b6e115e16407b.zip

    This entry was posted on Friday, June 26th, 2009 at 3:08 pm and is filed under Rogue software. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

    Comments:

    • (0) comments
    • |
    • Add your comments




RSS feed to this site Twitter Linkedin YouTube Channel

 

RSS feed to this site Jerome Segura is a Security Analyst working at ParetoLogic.

You can contact him at:
MalwareDiaries Email

 

Pages

  • Live Malware Map
  • VB2009 pictures
  • Zheng™ Technology
  • About
  • Contact Us



Security Software

  • XoftSpySE Anti-Spyware
  • Anti-Virus PLUS
  • Privacy Controls



Malware Top 10

  • Koobface Worm
  • DNS Changer Trojan
  • Fake Alert Trojan
  • Windows System Suite
  • Smart Protector
  • Home Antivirus 2010
  • PC Antispyware 2010
  • System Security
  • AVCare
  • Perfect Defender 2009



Archives

  • November 2009
  • October 2009
  • September 2009
  • August 2009
  • July 2009
  • June 2009
  • May 2009
  • April 2009
  • March 2009
  • February 2009
  • January 2009
  • December 2008
  • November 2008
  • October 2008
  • September 2008
  • August 2008
  • July 2008
  • June 2008
  • May 2008
  • April 2008
  • March 2008



Categories

  • Adware (1)
  • Banker Trojans (3)
  • Botnets (2)
  • Conferences (4)
  • DDos (1)
  • Exploits (32)
  • Fake codecs (30)
  • IM threats (1)
  • Interviews (5)
  • Keyloggers (1)
  • Mac security (14)
  • Malware Trends (67)
  • Phishing (7)
  • Podcast (1)
  • ransomware (1)
  • Research (33)
  • Rogue software (47)
  • Rootkits (2)
  • scams (3)
  • Social Networking (4)
  • Uncategorized (104)
  • Wireless Security (1)
  • world map (1)



 
 
 

© 2009 ParetoLogic Inc.