Details of a "new" Fake AV page

Prorootect

Level 69
Thread author
Verified
Nov 5, 2011
5,855
Details of a "new" Fake AV page here ..

Details of a "new" Fake AV page : on ZScaler.com research blog: http://research.zscaler.com/2012/04/details-of-fake-av-page.html

'The first thing you notice in the source code is that there is no obfuscation at all. The attacker is not trying to hide anything: CSS is inline, plain-text JavaScript (no obfuscation, no minification or packing) is inline, etc. That makes the pages very easy to track and block. Or it should....however, antivirus vendors are still not able to block the Fake AV executable with an acceptable level of accuracy. As you can see in the video, only 5 out of 42 antivirus engines find anything suspicious.' ..
 

jamescv7

Level 85
Verified
Honorary Member
Mar 15, 2011
13,070
Definitely for first time users they may convince about aggressive result and believes that they have viruses on their system. And mostly the vector came from search results.
 

McLovin

Level 78
Verified
Honorary Member
Malware Hunter
Apr 17, 2011
9,228
They are getting better at hiding it, but it won't fool me :p
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top