Sunday, March 22, 2009

SystemGuard2009 Spyware - New rogue

System Guard 2009 Spyware - Rogueware FakeAV

SystemGuard2009 is a new rogue spyware application. Same template used
with malware defender 2009.

Alias: SpywareGuard2008, SpywareGuard2008,FakeSpyGuard

Files:
MalwareDefender2009.exe
SpywareGuard2008.exe,
SystemGuard2009.exe, SystemGuard2009.exe,

Site screenshot:

System Guard 2009 Spyware FakeAV

Analysis:

 File info:SystemGuard2009.exe 
    
 File size70145 Bytes 
 MD5bf9f74546cf479c9266ace967bb2bce4 
    
    
 ThreatExpert:Report 
 VirusTotal:Report 
    
 First received03.22.2009 03:54:54 (CET) 
 ResultsResult: 6/39 (15.39%) 
    
 Alias:Trojan.Win32.FakeSpyGuard 
  Mal/FakeAV-AD [Sophos] 
    
Result when running:
 System Guard 2009 Spyware FakeAV Application

Application screenshot:
 System Guard 2009

Domain associated
 
dlsg09.com/ --> systemguard2009.com
dlsg09.com/setup.php
dlsg09.com/sysgd09/install.php?track_id=...
dlsg09.com/maldef09/install.php?track_id=...
 
dlsgd3.com/setup.php
dlsgd3.com/sysgd09/install.php?track_id=...
dlsgd3.com/maldef09/install.php?track_id=...
 
getsg09.com/setup.php
getsg09.com/sysgd09/install.php?track_id=...
getsg09.com/maldef09/install.php?track_id=...
 
getsgd3.com/setup.php?track_id=20062
getsgd3.com/sysgd09/install.php?track_id=...
getsgd3.com/maldef09/install.php?track_id=...
 
getsysgd09.com/setup.php
getsysgd09.com/sysgd09/install.php?track_id=...
getsysgd09.com/maldef09/install.php?track_id=...
 
 
Redirections:
 
http://getsgd3.com/setup.php?track_id=20062
http://84.16.243.169/setup.php?track_id=20062
http://78.159.122.156/setup.php?track_id=20062
 
http://dlsg09.com/sysgd09/install.php?track_id=...
http://84.16.243.169/sysgd09/install.php?track_id=...
 
http://dlsgd3.com/sysgd09/install.php?track_id=...
http://78.159.122.156/sysgd09/install.php?track_id=...
 
http://getsg09.com/sysgd09/install.php?track_id=...
http://78.159.122.156/sysgd09/install.php?track_id=...
 
http://getsgd3.com/sysgd09/install.php?track_id=...
http://84.16.247.29/sysgd09/install.php?track_id=...
 
http://getsysgd09.com/sysgd09/install.php?track_id=...
http://78.159.122.156/sysgd09/install.php?track_id=...
 
http://84.16.243.169/setup.php
http://78.159.122.156/setup.php
 
 
same template used with malware defender 2009
 
67.43.237.75
 
systemguard2009.com
systemguard2009.com/download/?track_id=10001
systemguard2009m.com
 
Redirections:
 
67.43.237.78
 
dlsg09.com
dlsgd3.com
getsg09.com
getsgd3.com
getsysgd09.com
gosg09.com
gosgd3.com
gosysgd09.com
 
67.43.237.77
 
gosg09.com
gosgd3.com
gosysgd09.com
 
 
URLs
 
84.16.243.169
 
http://84.16.243.169/setup.php
http://84.16.243.169/sysgd09/setup.php?track_id=10001
http://84.16.243.169/maldef09/install.php?track_id=10107
 
SpywareGuard2008.exe 2.97 MB (3,116,544 bytes)
MalwareDefender2009.exe 68.5 KB (70,149 bytes)
SystemGuard2009.exe 2.55 MB (2,675,712 bytes)
 
 
84.16.247.29
 
http://84.16.247.29/setup.php?track_id=...
http://84.16.247.29/sysgd09/install.php?track_id=...
http://84.16.247.29/maldef09/install.php?track_id=...
 
SpywareGuard2008.exe 2.97 MB (3,116,544 bytes)
SystemGuard2009.exe 68.5 KB (70,145 bytes)
MalwareDefender2009.exe 68.5 KB (70,149 bytes)
 
 
78.159.122.156
 
http://78.159.122.156/setup.php
http://78.159.122.156/sysgd09/install.php?track_id=...
http://78.159.122.156/maldef09/install.php?track_id=...
 
SpywareGuard2008.exe 2.97 MB 2.97 MB (3,116,544 bytes)
SystemGuard2009.exe 68.5 KB (70,145 bytes)
MalwareDefender2009.exe 68.5 KB (70,145 bytes)
 
 
78.159.122.156
 
IP Location: China Gibibits-ltd
Resolve Host: 78.159.122.156.internetserviceteam.com
netdirekt e.K.
 
 
67.43.237.75
67.43.237.77
67.43.237.78
 
IP Location: Ukraine Olexij Khrenov
Olexij Khrenov GTCOMM-394
 
 
84.16.243.169
 
IP Location: Germany Berlin Netdirekt E.k
Resolve Host: 84.16.243.169.internetserviceteam.com
netdirekt e.K.
 
 
84.16.247.29
 
IP Location: Germany Berlin Netdirekt E.k
Resolve Host: 84.16.247.29.internetserviceteam.com
netdirekt e.K.


 

Analysis
 
 File info:SpywareGuard2008.exe 
    
 File size169,740 bytes (165 KB) 
 MD5077180ac8e689bd2825821c4a69d6670 
    
 ThreatExpert:Report 
 Ikarus:Trojan.Win32.FakeSpyguard 
 VirusTotal:Report 
    
 First received03.22.2009 06:46:38 (CET) 
 ResultsResult: 12/39 (30.77%) 
    
 Alias:FraudTool.Win32.SpywareGuard2008.bw 
  Win32/FakeSpyguard 
  Win32/Adware.SpywareGuard 
    

 File info:SpywareGuard2008.exe 
    
 File size222,780 bytes (217 KB) 
 MD53214ff1bfa0fa0f11041b55d29075301 
    
 ThreatExpert:Report - Trojan:Win32/FakeSpyguard 
 VirusTotal:Report 
    
 First received03.22.2009 06:49:50 (CET) 
 ResultsResult: 12/39 (30.77%) 
    
 Alias:FraudTool.Win32.SpywareGuard2008.bw 
  Win32/FakeSpyguard 
  Win32/Adware.SpywareGuard 
    

 File info:SpywareGuard2008.exe 
    
 File size3,116,544 bytes (2.97 MB) 
 MD5347b37e967e557b4fa9e4dc9d201dcaa 
    
 ThreatExpert:Report 
 VirusTotal:Report 
    
 First received03.01.2009 13:03:23 (CET) 
 ResultsResult: 19/39 (48.72%) 
    
 Alias:FraudTool.Win32.SpywareGuard2008.bw 
  Win32/FakeSpyguard 
  Win32/Adware.SpywareGuard 
    

 File info:SystemGuard2009.exe 
    
 File size70149 bytes (68.5 KB) 
 MD575351bfd0671afb15860e05f91289cfa 
    
 ThreatExpert:Report 
 VirusTotal:Report 
    
 First received03.22.2009 06:59:42 (CET) 
 ResultsResult: 6/39 (15.39%) 
    
 Alias:Win32/Cryptor 
  Mal/FakeAV-AD [Sophos] 
  Trojan.Win32.FakeSpyGuard 
    

 File info:SystemGuard2009.exe 
    
 File size2,675,712 bytes (2.55 MB) 
 MD5c423ac1ab75e9b64a5832239fee63845 
    
 ThreatExpert:Report - RogueAntiSpyware.Sysguard 
 VirusTotal:Report 
    
 First received03.21.2009 01:05:02 (CET) 
 Results2/39 (5.13%) 
    
 Alias:Win32/Adware.SpywareGuard 
    

 File info:MalwareDefender2009.exe 
    
 File size70,149 bytes (68.5 KB) 
 MD51b7f057b660576d0bb8fdf398604f988 
    
 Prevx:Report 
 ThreatExpert:Report 
 VirusTotal:Report 
    
 First received03.22.2009 07:02:57 (CET) 
 Results13/39 (33.34%) 
    
 Alias:Win32/Cryptor 
  Rootkit.Win32.TDSS!IK 
  Trojan-Downloader.Win32.FraudLoad.dwz 
  Mal/FakeAV-AD 
  Trojan.Win32.FakeSpyGuard 
    

SpywareGuard2008.exe 165 KB (169,740 bytes)
SpywareGuard2008.exe 217 KB (222,780 bytes)
SpywareGuard2008.exe 2.97 MB (3,116,544 bytes)

SystemGuard2009.exe 68.5 KB (70,145 bytes)
SystemGuard2009.exe 2.55 MB (2,675,712 bytes)

MalwareDefender2009.exe 68.5 KB (70,149 bytes)