Showing posts with label PC Defender Plus. Show all posts
Showing posts with label PC Defender Plus. Show all posts

Thursday, 18 July 2013

FakeAV abandoned affiliate

Appeared also recently on vx.vault: http://vxvault.siri-urz.net/ViriList.php?IP=31.184.244.2
https://www.virustotal.com/en/ip-address/31.184.244.2/information/

hxxp://topqweb.org/content/scc
hxxp://rowline.org/api/ping?stage=1&uid=5cda27721bcbf14da53e8aad2fc722c2&id=35&subid=1&os=1&avf=0
hxxp://rowline.org/api/ping?stage=2&uid=5cda27721bcbf14da53e8aad2fc722c2&success=1
hxxp://rowline.org/load/?uid=5cda27721bcbf14da53e8aad2fc722c2
hxxp://rowline.org/html/viruslist/?uid=5cda27721bcbf14da53e8aad2fc722c2
hxxps://secure.9billing.com/html/billing/?uid=5cda27721bcbf14da53e8aad2fc722c2


Antivirus System is from the same familly as PC Defender Plus and Multirogue Defender
Unlock code xOxZxLxWxIxTxFxQxCxNxYxKxVxHxSxE still work for manual registration.

Main:
Geo:
Subacc:
Get EXE:
Profile:

A code mistake allow you to view the stats without being logged if you know the good token:
hxxp://dapav.net/subacc/?type=lol&token=da01a28ac6bbbf228ba9dc52c98ea1b0
hxxp://dapav.net/geo/?type=lol&token=da01a28ac6bbbf228ba9dc52c98ea1b0

400 installs