How do Criminals Sell Fake Anti-virus Software? | Scam Alert Network
| Together we can fight Crime, Scams and Spam
Thursday February 23rd 2012
Multilayer Website Security Solution

Hot News Flash

Along with rogue anti-malware, fake anti-piracy utilities are now also being distributed. Many Internet users download music and other media from the net, while being infected by malware from hacked or rogue websites. These Trojans issue fake copyright warning messages to scare the public - They are advised to take their chances in court, or skip the heavy fines and possible jail time by opting for a ‘pre-trial settlement’. They are then directed via hacked websites to another malware site where computers are further infected and where fake financial ‘settlements’ are solicited, and where banking details are provided to criminals.

How do Criminals Sell Fake Anti-virus Software?

It is easy for criminals to deceive even those who are informed about online hazards; that is why it is so important to avoid Internet crime spots.  The following is a good example of what is presented when a site wants to infect your machine with a fake Anti-Virus.

Two websites are involved in this incident:
sosgt.com hosted by Leaseweb
secureonlinestore.net hosted by Hetzner

First the malware website sosgt.com encourages visitors to scan their computers for viruses.

Obviously the website will report a few viruses.

In this case the criminal wants payment for infecting the visitor’s computer.  That way he can also gain access to payment information.  The visitor is presented with a purchase page for a “Professional online repair Service”.

Clicking to proceed to the checkout, takes you to the next malware website with the deceptive name of ‘secureonlinestore.net’.

In case you’re wondering, this is actually just a frame that loads.  The SSL certificate for secureonlinestore.net itself is provided by RapidSSL.

It is easy to see how many people can be deceived by these legitimate looking websites with security certificates and all.  Few people will actually check the credentials of these businesses and websites before trusting the software and entrusting their banking information to these criminals.  Therefore it is always advisable to check the track record of the applicable companies and their hosting providers.  With an appropriate anti-virus and Internet gateway installed, both websites triggered a danger warning.  Fake security and anti-virus websites appear every day, so rather do a little homework when it involve your security; and go for companies and software with a proven track record.

Example of a Danger Warning

MORE INFORMATION ABOUT THE APPLICABLE WEBSITES

sosgt.com
IP: 94.75.233.51
IP PTR: vpn5.vzihostmz.com
ASN: 16265 94.75.192.0/18 Leaseweb Leaseweb AS
Registered to: Alen Aniston, 31alenaniston[@]gmail.com, Gaikar 22, Prague, CZ 21991, Czech Republic, CZ
Phone: +42-0-249-5614, Fax: +42-0-249-5614

secureonlinestore.net
IP: 213.133.101.29
IP PTR: 213-133-101-29.clients.your-server.de
ASN: 24940 213.133.96.0/19 Hetzner-AS Hetzner Online AG RZ
Registered to: Andrew Bradley, abradley[@]asia.com, 53/54, Latviu Street, Vilnius, LI 2600, Lithuania, LT
Phone: +37-05-272-5555, Fax: +37-05-272-5555

OTHER REFERENCE

MysteryFCM – Fake scanner that DOESN’T lead to a fake AV


VN:F [1.9.11_1134]
Rating: 8.5/10 (2 votes cast)
VN:F [1.9.11_1134]
Rating: +2 (from 2 votes)
How do Criminals Sell Fake Anti-virus Software?, 8.5 out of 10 based on 2 ratings
Share this with Friends:
  • del.icio.us
  • Google Bookmarks
  • Blogosphere News
  • FriendFeed
  • Internetmedia
  • laaik.it
  • LinkedIn
  • Linkter
  • Live
  • MySpace
  • Ping.fm
  • Propeller
  • Reddit
  • RSS
  • Socialogs
  • StumbleUpon
  • Technorati
  • Yahoo! Buzz
  • Yahoo! Bookmarks
  • Netvibes
  • Tumblr
  • BlinkList
  • Add to favorites
  • blogmarks
  • Blogplay
  • Current
  • Digg
  • Diigo
  • DotNetKicks
  • DZone
  • eKudos
  • Facebook
  • Fark
  • Faves
  • Fleck
  • FSDaily
  • Global Grind
  • Gwar
  • HackerNews
  • HelloTxt
  • Hyves
  • LinkaGoGo
  • LinkArena
  • Meneame
  • MisterWong
  • MSN Reporter
  • MyShare
  • Netvouz
  • NewsVine
  • PDF
  • Segnalo
  • SheToldMe
  • Simpy
  • Slashdot
  • SphereIt
  • Sphinn
  • Tipd
  • Twitter
  • Upnews
  • Webnews.de
  • Webride
  • Wikio
  • Wykop
  • Xerpi
  • Yigg
  • Suggest to Techmeme via Twitter

Related posts:

  1. Rogue Anti-Malware Programs
  2. Internet Security while in the Crossfire of Cybercrime and Cyberwar
  3. Dutch National Crime Squad Announces Takedown of Dangerous Bredolab Botnet

Leave a Reply

You must be logged in to post a comment.