English
The Internet threat alert status is currently normal. At present, no major epidemics or other serious incidents have been recorded by Kaspersky Lab’s monitoring service. Internet threat level: 1

Choose your preferred Fake AV

Dmitry Bestuzhev
Kaspersky Lab Expert
Posted November 29, 14:48  GMT
Tags: Rogue Security Solutions, Malware Technologies
0.1
 

    Isn’t it great when your forecasts come true? Well, sometimes. But maybe not this time. Today I found a malicious site specially designed to fake three antivirus brands. Kaspersky is top of the list. So, what does it look like?

In the past we’ve seen Rogue AV websites using fake screenshots made with templates but without any real interaction with the user PC. These fakes didn’t claim to find any infections – the victim was simply ripped off after paying for a useless product. Now, though, we’ve found a new version where the Fake AV simulates the results of a malware search.

So, how does the infection happen? There is a dropper (Trojan.Win32.Scar.fdiz) which downloads the Fake GUI required by the scam. The query is built with this rule:

http://X.X.X.X/fakeav/interface.php?av=[Anti-Virus GUI name]&lang=en

Here is the list of the files / brands on this Fake AV server:


Comments

If you would like to comment on this article you must first
login


Bookmark and Share
Share

Analysis

Blog