Thursday, March 12, 2009

SecuredPaymentSystem.com - antivirus360-protection.com - Antivirus360 - Rogue_Antivirus

antivirusplus2009.net, securedpaymentsystem.com
Rogue_Antivirus- Antivirus360



Hosted on:

94.247.2.215 (hs.2-215.zlkon.lv)
215.2.247.94.in-addr.arpa IN PTR hs.2-215.zlkon.lv

whois details

"DATORU EXPRESS SERVISS" Ltd.
94.247.0.0/21

ZlKon HostMaster
94.247.2.0 - 94.247.3.255

Latvia
Kirovohrad Oblast
ns6.public-ns.com
ns5.public-ns.com
AD5952-RIPE


Site in conjunction with securedpaymentsystem. com

allsoftwarepayments. com
antispywareupdateservice. com
basicsconsumersupport. cn
devinepromotions. cn
fastuploadserver. com
internetupdatesystem. com
liveupdateprotection. com
livesoftwareupdates. com
live-pc-update. com
noonelivesforever. cn
onlinesoftwareupdate. com
pc-defence-update. com
powerfullantivirusproduct. com
privateupdatesystem. com
privaetprotectedupdates. com
professionalinternetupdates. com
professionalsoftwareupdates. com
prosecurityupdates. com
prosoftwareupdates. com
protectedsecurityaudit. cn
protectedprivacyupdate. com
protectedsecurityaudit. cn
protectionsoftwarecheck. com
protectionsystemcheck. com
proupdatessoftware. com
rapidsoftwareupdates. com
royalsoftwareupdate. com
securedosupdates. cn
secure.securedpaymentsystem. com
securedpaymentsystem. com
securedprosoftwareupdate. cn
securedprostatsupdates. cn
securedsoftwareproupdate. cn
securedsoftwareupdate. cn
securedupdateslive. cn
securedwindowsupdate. cn
securitysoftwarecheck. com
softwareupdatessystem. com
softwaresecurityupdates. com
thankyou4check. com
updatepcsecuritycenter. com
updateprotectioncenter. com
updatesoftwarecenter. com
windowssecurityupdates. cn

Some domain to block

Same template:

approved-payments. com  
central-scan. comCryp_FakeAV-9 Familyfull.exe
pc-software-payments. com  
securedsoftwarepayments. com  
paymentsystemonline. com   
webscannertools. com  
world-trusted-payments. com   
   

By IP

********************
*********************

72.233.64.102ThreatExpert
  
 f9671292f66f96dcb23d12929e4f0c74
 
hxxp://internetupdatesystem. com/download/security.bmp
 

83.133.126.201ThreatExpert
  
84e641b88eb256ee4979f6eaeadbc53b
 71c6b265c6ee68e2dde825d96b4575b9
 
hxxp://internetupdatesystem. com/download/security.bmp
 

83.133.126.201ThreatExpert
  
 84e641b88eb256ee4979f6eaeadbc53b
 
hxxp://windowssecurityupdates. cn/order_xp.php?ver=1
 
72.233.64.102
71c6b265c6ee68e2dde825d96b4575b9
 
hxxp://internetupdatesystem. com/download/security.bmp
 

78.47.91.153ThreatExpert
  
 a31ae007e5b722a93f083e5c47b5e350
 bf143d7b12b59fe6faf20c6fdaa4b4b9
 bf307ed85749900ffcf7ab3fb4deae48
 d091b93cd6f8d6aef7ff839e37db1c72
 1c9f11956c5edf0a8c87e0e3598eceed
 230c7ad29294771b81d835abb842919e
 4561cee1e10687756c2a327df89c066d
 798b4ee1141e547bb9093a11514f777b
 9aad9308ce5ea47878df717f2413cb8d
 
hxxp://securedupdateslive. cn/order_xp.php?ver=1
 
89.149.208.212
 
hxxp://proupdatessoftware. com/download/security.bmp
 

212.117.165.126ThreatExpert
  
 a3937b9d3ee029a420260081eba4c0f6
 
hxxp://updatesoftwarecenter. com/download/security.bmp
hxxp://thankyou4check. com/order_xp.php?ver=1
 

78.47.248.113ThreatExpert
  
 11bd6f30f886ee61ed6abbed0b5398ad
 17613df8694a83a40052c1009aee31f8
 356e297ca6633b6cc3be9cfa3b1f0fef
 
hxxp://securedsoftwareupdate. cn/order_xp.php?ver=1
hxxp://powerfullantivirusproduct. com/order_av.php?ver=1
hxxp://secure.securedpaymentsystem. com/psbill/?ver=1
 
89.149.217.205
 
hxxp://softwaresecurityupdates. com/download/security.bmp
 

78.47.248.113ThreatExpert
  
 2815f8982342fd53e1d8ae645a7f3611
 36a181bbdff14a7a1585df5b9655eaa7
 7cc901c53f2f209350cbd9fcc84c1cbf
 
hxxp://securedsoftwareupdate. cn/order_xp.php?ver=1
 
89.149.217.205
 
hxxp://softwaresecurityupdates. com/download/security.bmp
 
 

94.247.3.40ThreatExpert
  
 26b2d11ac1b65ad89b91b000e51eb584
 2c4447e1b7f4b91c5ec394e6576237f9
 32164301e17e954949df09687374b347
 e2ab58cf0017f39f4cc692e41d5015ec
 
hxxp://softwareupdatessystem. com/download/security.bmp
hxxp://securedwindowsupdate. cn/order_xp.php?ver=1
 
78.47.91.153
 
hxxp://thankyou4check. com/order_xp.php?ver=1
 
 

212.117.165.126ThreatExpert
  
 ce355dfe8bce2d60187662f444b21d45
 
hxxp://updatesoftwarecenter. com/download/security.bmp
 
78.47.91.153
 
hxxp://thankyou4check. com/order_xp.php?ver=1
 

78.47.172.66ThreatExpert
  
 c42ff11a1046a865260a5bc4d8eff699
 
hxxp://securedsoftwareproupdate. cn/order_xp.php?ver=1
 
89.149.227.225
 
hxxp://livesoftwareupdates. com/download/security.bmp
 

83.133.126.201ThreatExpert
  
 b2d165288d4847f9b8f5658ab083ea91
 d8734930cd824eb949bc29b07a4a32d0
 
hxxp://privateupdatesystem. com/order_xp.php?ver=1
 
217.117.165.127
 
hxxp://rapidsoftwareupdates. com/download/av_360glof.exe
 
Timeout
 
hxxp://basicsconsumersupport. cn/zsa360/winsystems.dll
hxxp://fastuploadserver. com/zsa360/winsystems.dll
 

83.133.126.201ThreatExpert
  
 6765845b4b09edd8d77fdc47824263d0
 
hxxp://privateupdatesystem. com/firstrun.php?product=A36&aff=&update=2601/360beta13
&crypt=g&time=11:08:59 AM
 
Timeout
 
hxxp://fastuploadserver. com/zsa360/zs880000.exe
 

83.133.126.201ThreatExpert
  
 28859a27ecff105b7f8328c039be1942
 
hxxp://privateupdatesystem. com/order_xp.php?ver=1
 
212.117.165.127
 
hxxp://rapidsoftwareupdates. com/download/av_360glof.exe
 
Time out:
 
hxxp://fastuploadserver. com/zsa360/zs880000.exe
hxxp://fastuploadserver. com/zsa360/winsystems.dll
 
 

83.133.126.201ThreatExpert
  
 3ee5d7b00ba9e56f4749b185c53bd0fa
 3182e5f7f334e89a7c7a34542b84c81e
 9cf80b3a896886c74128eb781ed6752c
 d540d5f317cd1bcd33da5b7ff39980c4
 d9009cd6634c4735aa5bcb5ea404b713
 
hxxp://privateupdatesystem. com/order_xp.php?ver=1
 
212.117.165.127
 
hxxp://rapidsoftwareupdates. com/download/security.bmp
 

78.47.172.66ThreatExpert
  
 4c5ee3323071a4939131c6d1bfa1e0b
 
hxxp://protectionsoftwarecheck. com/order_xp.php?ver=1
 
89.149.227.225
File not found
 
hxxp://updateprotectioncenter. com/download/av_360new.exe
hxxp://fastuploadserver. com/zsa360/winconfig.dll
 

78.47.172.66ThreatExpert
  
 9ec07cf8472b49fd5d03e6e31cd998d2
 
hxxp://protectionsoftwarecheck. com/order_xp.php?ver=1
 
89.149.227.225
File not found
 
hxxp://updateprotectioncenter. com/download/av_360glof.exe
hxxp://fastuploadserver. com/zsa360/zs880000.exe
hxxp://fastuploadserver. com/zsa360/winsystems.dll
 

78.47.172.66ThreatExpert
  
 7353f458765d693c9dfb4bcfc9f89062
 
hxxp://protectionsoftwarecheck. com/order_xp.php?ver=1
 
89.149.227.225
File not found
 
hxxp://updateprotectioncenter. com/download/security.bmp
 

212.117.165.127ThreatExpert
  
 65d416509d176828a882710b4202af95
 
hxxp://rapidsoftwareupdates. com/download/av_360glof.exe x
 
Time out:
 
hxxp://fastuploadserver. com/zsa360/zs880000.exe
hxxp://fastuploadserver. com/zsa360/winsystems.dll
 
http://safeweb.norton.com/report/show?name=fastuploadserver.com
 

http://www.threatexpert.com/report.aspx?md5=bdea23128f041ca9cd20c463688687c8
http://www.threatexpert.com/report.aspx?md5=f0934910ddfd047fe2f83599a93d55c8
http://www.threatexpert.com/report.aspx?md5=f1cb4306c32a15ffa12db1d3923486a4
http://www.threatexpert.com/report.aspx?md5=315b52cc49d67b96b5ac0c14bab5b5cd
http://www.threatexpert.com/report.aspx?md5=34ae55b638d3ecff94f078771d3fe41c
http://www.threatexpert.com/report.aspx?md5=3535fa8f1f8221b566f4df75b558673b
http://www.threatexpert.com/report.aspx?md5=532b662c3bc9dae22286836662ef4c9a
http://www.threatexpert.com/report.aspx?md5=801ea9a66f1e11fd65bcc776b42756db
http://www.threatexpert.com/report.aspx?md5=8939f7e107d0c243bbbef31a375dc5f3

83.133.126.201
hxxp://securedosupdates.cn/order_xp.php?ver=1

72.233.64.102
hxxp://prosoftwareupdates. com/download/security.bmp

************************
83.133.126.201
hxxp://windowssecurityupdates. cn/order_xp.php?ver=1
hxxp://allsoftwarepayments. com/order_av.php?ver=1

************************
78.47.91.153
hxxp://thankyou4check. com/order_xp.php?ver=1
hxxp://protectionsystemcheck. com/order_av.php?ver=1

************************
http://www.threatexpert.com/report.aspx?md5=2b93fc94d615ba74cd40ec850b971634
hxxp://proupdatessoftware. com/download/security.bmp

************************
http://www.threatexpert.com/report.aspx?md5=183dc3ed230ecd0d09a23522b4d88567
hxxp://fastuploadserver. com/zsa360/winsystems.dll

************************
http://www.threatexpert.com/report.aspx?md5=84adfc43d1b44243a5396062c799aa56
hxxp://proupdatessoftware. com/download/security.bmp

************************
http://www.threatexpert.com/report.aspx?md5=210777b875accb0592235169beff513d
hxxp://proupdatessoftware. com/download/security.bmp

************************
http://www.threatexpert.com/report.aspx?md5=edfc0fe6b7bb16178c2fbb1d0a561f88
hxxp://updateprotectioncenter. com/download/security.bmp

************************
http://www.threatexpert.com/report.aspx?md5=4311231c0eab3b353c21b2bf730266dd

78.47.91.153
hxxp://securedupdateslive. cn/firstrun.php?product=A36&aff=&update=2302/360&c
rypt=g&time=6:44:30 PM

78.46.216.233
hxxp://onlinesoftwareupdate. com/zsa360/winconfig.dll

www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_FAKEAV.AJK&VSect=T

************************
http://www.threatexpert.com/report.aspx?md5=d2cc9741618e4456990a580a43b22ddf

78.47.248.113
hxxp://securitysoftwarecheck. com/firstrun.php?product=A36&aff=&update=2601/360
beta13&crypt=g&time=2:22:41 PM

Time out
hxxp://fastuploadserver. com/zsa360/zs880000.exe
hxxp://fastuploadserver. com/zsa360/winsystems.dll

Analysis:

http://safeweb.norton.com/report/show?name=fastuploadserver.com

************************
http://www.threatexpert.com/report.aspx?md5=85dcd9b6fb374eab383360fc57b9ab50
http://www.threatexpert.com/report.aspx?md5=dc1da98f1fa936e3998ef57273aafe9f

78.47.248.113
hxxp://securitysoftwarecheck. com/order_xp.php?ver=1

89.149.217.205
hxxp://updatepcsecuritycenter. com/download/av_360glof.exe

************************
http://www.threatexpert.com/report.aspx?md5=3e8fa7b6f15501deb73400af48bbc07d

213.239.210.54
hxxp://protectedsecurityaudit. cn/order_xp.php?ver=77001116

Time Out
hxxp://protectedprivacyupdate. com/download/av_360glof.exe
hxxp://privaetprotectedupdates. com/zsa360/winsystems.dll

hxxps://secure.securedpaymentsystem. com/psbill/?ver=77001116

************************
http://www.threatexpert.com/report.aspx?md5=694e2510f569e7450182428764f3a5fb

83.133.126.201
hxxp://privateupdatesystem. com/firstrun.php?product=A36&aff=&update=2401/360
beta13&crypt=g&time=2:24:54 PM

Time Out
hxxp://basicsconsumersupport. cn/zsa360/zs880000.exe

************************
http://www.threatexpert.com/report.aspx?md5=210777b875accb0592235169beff513d
http://www.threatexpert.com/report.aspx?md5=b4f0eec7b06252d57ebc2818c93f4aa2

Filesize: 172,032 bytes

94.247.3.40 hs.3-40.zlkon.lv

hxxp://professionalsoftwareupdates. com/download/security.bmp

************************
http://www.threatexpert.com/report.aspx?md5=0b63ebb55ea0ccdfcb69f796cf4e0865
http://www.threatexpert.com/report.aspx?md5=fd31effec02bae459d106aa97822e55a

78.47.172.66
hxxp://securedpowerupdates. cn/order_xp.php?ver=1

212.117.165.126
hxxp://prosecurityupdates. com/download/security.bmp

************************
http://www.threatexpert.com/report.aspx?md5=048a431eafa602f3810652aa5f10cdc2
http://www.threatexpert.com/report.aspx?md5=e0a95e9d7c4436dabc9c45fbde591c25
http://www.threatexpert.com/report.aspx?md5=e8eda76798358970d0f6912a3ea31615
http://www.threatexpert.com/report.aspx?md5=3ec09f1f143b2f83aae78ac6152d8a2b
http://www.threatexpert.com/report.aspx?md5=540a3d4621f2ddc46a8389b669d0ef3b
http://www.threatexpert.com/report.aspx?md5=919647058036ee4b9ca968fec35912d3
http://www.threatexpert.com/report.aspx?md5=dc844fdcb35befd6a3c0c8f84732bc86

83.133.126.201
hxxp://securedprostatsupdates. cn/order_xp.php?ver=1

212.117.165.127
hxxp://liveupdatesoftware. com/download/security.bmp

************************
http://www.threatexpert.com/report.aspx?md5=f66483379e2aa700b0cb0067609013c0
http://www.threatexpert.com/report.aspx?md5=66577af25af8a1f244fe1dbddbd6f569
http://www.threatexpert.com/report.aspx?md5=86ccd41c5386c98989e460dddc60ca54
http://www.threatexpert.com/report.aspx?md5=9a10b2fb3f67e1f1af367cbda7e59586

Time out
91.211.64.68
hxxp://noonelivesforever. cn/order_xp.php?ver=1

94.247.3.40 hs.3-40.zlkon.lv
hxxp://professionalsoftwareupdates. com/download/security.bmp

************************
http://www.threatexpert.com/report.aspx?md5=b18e7e19d31289abca8fb24e4f723f87
http://www.threatexpert.com/report.aspx?md5=cab8d6846885ef8135645b0ae4e6a46a
http://www.threatexpert.com/report.aspx?md5=c0136fa0494d61afef171cfb55f5d7f1
http://www.threatexpert.com/report.aspx?md5=c46810c83bb566f792baf3817db6a76e
http://www.threatexpert.com/report.aspx?md5=d64bd5ebed1c92d72d77595a7f73368b
http://www.threatexpert.com/report.aspx?md5=00a602c95bdb5d2a10305b00120306b8
http://www.threatexpert.com/report.aspx?md5=496ea11d3646969ea16d144e47d7c029
http://www.threatexpert.com/report.aspx?md5=6afa6679a007f4b8120d0f5626ad6281
http://www.threatexpert.com/report.aspx?md5=87348a2e6d637218999290462142289d

Time out
78.47.91.153
hxxp://devinepromotions. cn/order_xp.php?ver=1

212.117.165.126
hxxp://royalsoftwareupdate. com/download/security.bmp

************************
http://www.threatexpert.com/report.aspx?md5=4feb2883a00a4ac67753e8911923b581

78.47.248.113
hxxp://thankyouforinstall. cn/order_xp.php?ver=1

78.47.248.113
hxxp://powerfullantivirusproduct. com/order_av.php?ver=1

78.47.248.115
hxxps://secure.securedpaymentsystem. com/psbill/?ver=1

89.149.217.205
hxxp://antispywareupdateservice. com/download/security.bmp
************************
http://www.threatexpert.com/report.aspx?md5=015835865c30eea3cfa45a53fcfb3648
http://www.threatexpert.com/report.aspx?md5=262eb47abc021b0fe24ea649008de250
http://www.threatexpert.com/report.aspx?md5=366ab787fce44cb116c1e0fcf7804c3a
http://www.threatexpert.com/report.aspx?md5=41fc7f1c23f3ad4aaa302b8c725fdf72
http://www.threatexpert.com/report.aspx?md5=821178fdfba76c1244eb0b92791033fe
http://www.threatexpert.com/report.aspx?md5=f9ec9a2dcf7d9eda8b981587caebc534

78.47.248.113
hxxp://securedprosoftwareupdate. cn/order_xp.php?ver=1

78.47.248.113
hxxp://powerfullantivirusproduct. com/order_av.php?ver=1

78.47.248.115
hxxps://secure.securedpaymentsystem. com/psbill/?ver=1

89.149.217.205
hxxp://professionalinternetupdates. com/download/security.bmp
************************
http://www.threatexpert.com/report.aspx?md5=13addbdc9ce34c437353c9ca57e8c0da1

212.117.165.126
hxxp://royalsoftwareupdate. com/download/security.bmp
************************
http://www.threatexpert.com/report.aspx?md5=88925f04b85d32e66ec94d61866355b5

Time out
hxxp://pc-defence-update. com/firstrun.php?product=A36&aff=&update=1512/360beta4
&crypt=g&time=6:44:30 PM
************************
http://www.threatexpert.com/report.aspx?md5=6ef9a7e4657e59da0d0edf543c656ecf

213.239.210.54
hxxp://protectedsecurityaudit. cn/firstrun.php?product=A36&aff=&update=360beta&
crypt=g&time=9:19:44 PM
************************
http://www.threatexpert.com/report.aspx?md5=6ef9a7e4657e59da0d0edf543c656ecf

Time out
hxxp://live-pc-update. com/firstrun.php?product=A36&aff=&update=1712/360beta7&
crypt=g&time=8:48:41 AM
************************
http://www.threatexpert.com/report.aspx?md5=7c4f33dab4302a98da8d2e0998689a8d

Time out
hxxp://liveupdateprotection. com/firstrun.php?product=A36&aff=&update=1112/360
beta3&crypt=g&time=12:07:38 PM
************************
http://www.threatexpert.com/report.aspx?md5=cd55adb19380a413c88fdb2815ab3e39

78.47.248.113
hxxp://securitysoftwarecheck. com/firstrun.php?product=A36&aff=&update=0202/360
&crypt=g&time=2:22:29 PM

Time out
hxxp://fastuploadserver. com/zsa360/winconfig.dll
************************


 


Size of malware: 2,711,552 Bytes

Alias:
InternetAntivirus [Symantec]
FakeAlert-AB.gen.e [McAfee]
TROJ_FAKEAV.AKO [TrendMicro]

ThreatExpert Analysis

Topic related:

BlueTack
Antivirus 2009 /2010 / 360 Redirects

Site associated :
 The following domain have the same template and same
location for the payload

hxxp://approved-payments. com
hxxp://pc-software-payments. com
hxxp://securedsoftwarepayments. com
hxxp://paymentsystemonline. com
hxxp://webscannertools. com
hxxp://world-trusted-payments.com

The spyware is located on:

hxxp://central-scan.com (212.117.165.126)
File Analysis:
 




Filename: full.exe
File size: 1597440 bytes
MD5...: 6f2d8bcf1bff87a82e0f88259597b7fb
SHA1..: 532e1dbc668ff41373e959e20454be99bbcbd8c2

TrID..: File type identification
Win32 Executable Generic (42.3%)
Win32 Dynamic Link Library (generic) (37.6%)
Generic Win/DOS Executable (9.9%)
DOS Executable Generic (9.9%)
VXD Driver (0.1%)

Alias:

Win32.FraudTool.Antivirus2009
FraudTool.Win32.Antivirus2009
Trojan.FakeAntivirus
Generic Dropper.bw
a variant of Win32/Kryptik.EJ
Mal/FakeAV-I
Antivirus 2009
Cryp_FakeAV-9

***

Virustotal Result
25/39 (64.10%)

***

ThreatExpert Result

***

Packed.Generic.187 [Symantec]
FraudTool.Win32.Antivirus2009.fs [Kaspersky Lab]
Generic Dropper.bw [McAfee]
Mal/FakeVirPk-A, Mal/FakeAV-I [Sophos]
Trojan.FakeAntivirus [Ikarus]

***

Trend Micro Virus Description / Statistics
Cryp_FakeAV-9 Family

***

Sunbelt Software™ CWSandbox Report
Malware Report for ID: 6897949