This is cache of http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/341345275/impersonating-stopbadwareorg-to-serve.html. Cache is the snapshot of article that we took when we index feed.
To see original page click here.
We are not affiliated with the authors of this article and not responsible for its content.
Impersonating StopBadware.org to Serve Fake Security Warnings
2008-07-21 03:30:51 by Dancho Danchev in Dancho Danchev's Blog - Mind Streams of Information Security Knowledge
 
Malware is known to have been hijacking search results, take for instance the rogue Antivirus XP 2008 as a recent example, but it's even more interesting to see other rogue security software impersonating Stopbadware.org in order to server fake security warnings that ultimately lead to fake security software.

stopbadware2008 .com (58.65.238.171) is one of these examples, where stopbadware2008 .com/antivirus.php  redirects to infectionscanner .com and attempts to trick the user into installing download.infectionscanner.com /AntvrsInstall.exe.  The message used :

"Reported Insecure Browsing: Navigation blocked. Due to insecure Internet browsing your PC can easily get infected with viruses, worms and trojans without your knowledge, and that can lead to system slowdown, freezes and crashes. Also insecure Internet activity can result in revealing your personal information. To get full advanced real-time protection for PC and Internet activity, register Antivirus 2008. We recommend you to protect your PC now and continue safe Internet browsing."

There's in fact even more rogue software using the same IP (58.65.238.171), courtesy of HostFresh :
virus-scanner-online .com
security-scanner-online .com
viruses-scanonline .com
virus-scanonline .com
antivirus-scanonline .com
download.antivirus-scanonline .com
topantivirus-scan .com
topvirusscan .com
virusbestscan .com
virus-detection-scanner .com
antivirus-scanner .com
infectionscanner .com
virusbestscanner .com
internet-security-antivirus .com


It would be interested to monitor whether or not the template for the fake security warning would start getting used on a large scale.

Related posts:
A Portfolio of Fake Video Codecs 
Fake PestPatrol Security Software
Got Your XPShield up and Running?
Localized Fake Security Software
A Diverse Portfolio of Fake Security Software
RBN's Fake Security Software
 
 
 
 
 
 
RELATED VIDEO
Expand / Minimize
SecurityRatty FAQ
Sergey Zarubin, 31yo
CISSP, CCSP
Moscow, Russia