Showing posts with label Rogue-Security-Product-As-A-Service. Show all posts
Showing posts with label Rogue-Security-Product-As-A-Service. Show all posts

Sunday, 19 June 2011

Tracking Cyber Crime: Gagarincash AV Affiliate

Another Fake AV affiliate infiltrated: Gagarincash AV
My friend ScriptKiddieSec gived me a ICQ number for contact these guys, and get access


Gagarincash AV site (nb: The man on background is Yuri Gagarin):


Contrary to the BestAV network who was very professional and closed, Gagarincash have a very simple interface and new account can be created if you have an invitation, and for get invitation, you need to pose as bad guys :þ



When connected, all is grouped on the same page:

Statistics, FakeAV download and three invitation keys, if you want invite someone.
The text before statistics is interesting: Обновляйте exe раз в 5-10 минут. Теперь будет чище гораздо.
It's mean the FakeAV Exe is repacked every 5-10 minutes. (Like BestAV and many others)

According to VirusTotal, repacked FakeAV are detected by 11 Antivirus


Finally it's time to test their FakeAV, and it's: Security Shield 2011, named 'pack.exe' on their download page.


 i'm sure you know it too ;)


 Fake gate:

You can edit your details on Gagarincash, and something i've noticed directly: your current password appear in plaintext on the input password. (i guess account infos are not encrypted on the database)


Contrary to common beliefs, peoples who make FakeAV are not some alone guys who do that for them.
Generaly behind a fakeAV there is a affiliate network who product a huge trafic, don't take them slightly.

The unpack of their FakeAV is boring like this:



Have a nice day.
PS: For those who menace me on irc, who you will call, hitman ?
haha, fags.

Gagarincash related ~
Tracking Cyber Crime: Inside the FakeAV Business (14 Jun 2k11)
Security Shield 2011 (11 Jun 2k11)
Essential Cleaner (18 May 2k11)
MS Removal Tool (29 Mar 2k11)
Security Shield (9 Dec 2k10)
System Tool (12 Dec 2k10)
Security Tool (10 Aug 2k10)

Tuesday, 14 June 2011

Tracking Cyber Crime: Inside the FakeAV Business

Few days ago, a friend mention me about his new article.


For those who don't have access you can see the article here:


I've already see alots of FakeAV samples who got a filename like 'BestAV.exe'
Man, you have definitely intrigued me with your post :)
And like that, i've started to hunt these 'BestAV' guys.

After alot of coffee, i finally come inside the network.
You will see, it's nicely organized, they are responsible for the MS Removal Tool plague.

The main site is named BestAV2, you'll see only this:


WHOIS:
nicline.com's WHOIS database is only for information purposes,
this information consists on domain name registration records.
nicline.com does not guarantee the accuracy of the information
contained in the WHOIS. nicline.com allows the use of the
information only for lawful purposes, under no circumstances this data
will be use for: (a) allow, enable, or otherwise support the transmission
by e-mail, telephone, or facsimile of mass unsolicited, commercial
advertising or solicitations to entities other than the data recipient's
own existing customers; or (b) enable high volume, automated,
electronic processes that send queries or data to the systems of
Registry Operator or any ICANN-Accredited Registrar, except as
reasonably necessary to register domain names or modify existing
registrations.



Service provided by First Ukrainian Internet-Registrar LLC
Hosting solutions and domain registration service.

Domain name: bestavsoft2.com

Registrant:
Ivan Shlesko (SROW-1714932)

audiodius@hotmail.com
ordinskaya 23
Kiev none
827123 UA
+3 80993362121

Administrative contact:
Ivan Shlesko (SRCO-2727745)
Ivan Shlesko
audiodius@hotmail.com
ordinskaya 23
Kiev none
827123 UA
+3 80993362121

Technical contact:
Vyacheslav Cherkashyn (SRCO-101023)
First Ukrainian Internet-Registrar LLC
info@forward.com.ua
134-4-100 Nab Pobeda
Dnepropetrovsk Dnepropetrovsk
49106 UA
+38 0563705242 fax:+38 0563705242

Domain servers in listed order:
ns3.prohosting.com.ua 213.186.192.137
netname.com.ua 91.207.44.31

Created: 02 Dec 2010 00:53:48:930 UTC
Expires: 01 Dec 2011 00:00:00:000 UTC
Last updated: 02 Dec 2010 00:53:48:930 UTC

Like the ripped announce on the ScriptKiddieSec blog says: it's a FakeAV Service, that explain why we see a big amounts of samples like MS Removal Tool, Security Tool, etc.. every day.
Anyone who have money can buy his own MS Removal Tool copy and make money by infecting peoples
The benefit system work like that: 50% for the customer and 50% for the site owner (BestAV team).


Statistic of the customer FakeAV:

I've hidden the stats here, but if you want an example:
(Yeah, easy money.)

FakeAV download:

Testing the downloaded FakeAV:

I guess you know it:

The famous fake payement gate:

BestAv sample found in the wild:

And that even include a system for know wich AntiVirus detect actualy the malware:

Like he says: These guys has a very good cryptor support:

Public download link:

 The customer can manual encrypt the malware:

Can use also a public API

Domains:

Redirector:

News pages, about campaigns, downtime etc...

Condition of use (what a joke):

Escrow support:

What's your mind now about FakeAV ?

BestAV related ~
Security Shield 2011 (11 Jun 2k11)
Essential Cleaner (18 May 2k11)
MS Removal Tool (29 Mar 2k11)
Security Shield (9 Dec 2k10)
System Tool (12 Dec 2k10)
Security Tool (10 Aug 2k10)