Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: Fake AV Bingo SANS ISC InfoSec Forums

Watch ISC TV. Great for NOCs, SOCs and Living Rooms: https://isctv.sans.edu

Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!
Fake AV Bingo

 

Can you guess which domains the crooks behind the Fake Anti-Virus Scam are going to use next ? Well, neither can we. But for several weeks now, they are hosting a lot of their bad stuff out of 91.213.29.66, geo-located in lovely Russia (where else?).

A passive DNS collector like BFK/RUS-CERT can help to turn this IP address back into the domain names currently in use.  Here's an excerpt from the resulting list, all in all 165 domains of badness.

List of Fake AV Domains retrieved from RUS-CERT passive DNS

Several of these domains were "found" by our readers via the poisoned Google image searches that we reported earlier this month, and also via malicious advertisements embedded in perfectly benign web pages.

If you Apple Mac users now feel all safe, think again! As we mentioned earlier, Fake AV has made its appearance on Macs, where naive automatic download-and-run default settings in browsers still are common, and where "MacDefender" and its expected numerous successors and variants are likely to become as "successful" for the bad guys as their Windows version has been for years.

Fake AV Bingo?  The only winning move is not to play.

 

Daniel

367 Posts
ISC Handler
May 19th 2011
MacProtector, one of the rouge Mac Anti Virus going to 91 213 217 30.

I've been taking the Mac stuff apart and going to release a report but here are some interesting things so far which has plenty to do with the Russia bump and run. I think the coder is Russia, reviewing Ivan Krsul paper from 94 Coast Project. Have thoughts.

MacDefender and Protector-Both installers have the "ru.lproj" indicating the developer spoke Russian.

Xcode build for both was 10M2518, Xcode 3.2.6 / iOS SDK 4.3 gm which include Russian and English.

The build machine which created both was running OSX seed 10J869, 10.6.7. Found plenty of both in all over.

We also did some other traces which we think are just large sets of spammers, pirates and content thieves from Dmitry Filin network fun house.

drStrangeP0rk

11 Posts
fyi
66.96.248.69 is part of the game as well, geo-located in lovely US (where else?) ;-). some domain names shared with 91.213.29.66 plus new ones
-> http://www.bfk.de/bfk_dnslogger_de.html?query=66.96.248.69
Alex

13 Posts
War Games! ;)
voltron88x

1 Posts
I know this is asking for trouble, but I work at a university with a large Mac base. We want to see how Macprotector/Macdefender works to be sure we're covered here on campus. Does anyone have a confirmed URL for this stuff? I've tried the domains listed above, but most are shut down already.

We can email offline.
voltron88x
1 Posts

Sign Up for Free or Log In to start participating in the conversation!