Trend Micro Facebook TrendLabs Twitter Malware Blog RSS Feed You Tube - Trend Micro
Search our blog:

  • Recent Posts

  • Calendar

    February 2012
    S M T W T F S
    « Jan    
     1234
    567891011
    12131415161718
    19202122232425
    26272829  
  • About Us
    Malware Blog > Cory Aquino’s Death Used to Spread Another FAKEAV

    coryblogIt has only been a few days since former Philippine president Corazon Aquino died of cardio-respiratory arrest last Saturday (August 1). Cybercriminals are already well on their way to use this event for their own selfish gains.

    Cybercriminals use popular and high interest events to further their cause—in this case, spreading fake antivirus software detected by Trend Micro as TROJ_FAKEALRT.FK.

    Trend Micro threat analyst Joseph Pacamarra found that searching for details on the former president’s death with the words “corazon aquino’s death” led users to the following malicious sites:

    • http://{BLOCKED}-gonzales.redxhost.com/corazon-aquino-death.html
    • http://{BLOCKED}sa.20x.cc/corazon-aquino-death.html
    • http://{BLOCKED}rank.0adz/corazon-aquino-death.html
    • http://{BLOCKED}-1.0adz.com/corazon-aquino-died.html

    The cybercriminals used the same .php page (1.php) to redirect users who click the links above. However, this page was hosted on different domains, possibly to avoid detection. The redirections from the above links eventually led to the download of a fake antivirus from the following sites:

    • http://{BLOCKED}-pro-antivirus-scan.com/download.php?id=2022
    • http://{BLOCKED}-pro-antivirus-scan.com/download/Install-6a1e7ce_2022.exe
    • http://{BLOCKED}-pro-antivirus-scan.com/download/Install-74f10_2022.exe
    • http://{BLOCKED}-pro-antivirus-scan.com/download/Install-6a75f_2022.exe
    Click Click

    This is not the first time that news was used to launch blackhat SEO attacks:

    Users are advised to rely on legitimate and reputable news sites to avoid being infected. Trend Micro product users are advised to update to the latest CPR version 6.338.03 to stay protected.


    Updated on 05 August 2009 10:57 PM (UTC-7)

    After further analysis, the file corazon-aquino-died.html1, which may be downloaded from the sites mentioned earlier, is now detected as HTML_REDIR.ECT. This is consequently blocked by Trend Micro’s Smart Protection Network.


    Updated on 14 August 2009 12:45 AM (UTC-7)

    After a recent reanalysis of TROJ_FAKEALRT.FK, Trend Micro threat analyst Kathleen Notario discovered that the sample (“Personal Antivirus”) does not exhibit FAKEAV behaviors. It does not, for instance, display a FAKEAV graphical user interface (GUI) nor causes system modifications. It has been found to be missing a main installer component.

    However, the Trojan may access the following domains to download possibly malicious files or install other FAKEAVs:

    • http://{BLOCKED}ne-sachs.com
    • http://{BLOCKED}erbaseupdatesv2.com
    • http://{BLOCKED}twareupdatev2.com
    • http://{BLOCKED}ben.cn
    • http://{BLOCKED}-updatesv5.com




    Share this article
    Get the latest on malware protection from TrendLabs
    Email this story to a friend   Technorati   NewsVine   MySpace   Google   Live   del.icio.us   StumbleUpon




    7 Responses to “Cory Aquino’s Death Used to Spread Another FAKEAV”

    1. b,rivera Says:

      we love you President Cory Aquino
      your memories will remain to us…..

    2. Miray Lozada (Technical Communications) Says:

      Yes, she will always be remembered and loved.

    Trackbacks

    1. TrendMicro (TrendMicro)
    2. _third (third marquez)
    3. bluebaby98 (PJ)
    4. Menardconnect (Menard Osena)
    5. Cory Aquino’s Death Used to Spread Another FAKEAV – by Trendmicro | Tech Pinoy Support


     

    © Copyright 2011 Trend Micro Inc. All rights reserved. Legal Notice