New Defru Scareware Blocks Connection to More than 300 Websites

Jack

Administrator
Thread author
Verified
Staff Member
Well-known
Jan 24, 2011
9,378
New-Defru-Scareware-Blocks-Connection-To-More-Than-300-Websites-455871-2.jpg

A recently detected scareware runs browser-based security scanning that shows bogus malware activity on the system, in an effort to deceive users into purchasing fake security products.


Dubbed Defru by Microsoft (detected as Win32/Defru), notable about it is the fact that it has the ability to modify the hosts file on the affected computer in order to manipulate web navigation. The result is blocking access to more than 300 legitimate websites, according to Daniel Chipiristeanu from Microsoft.

Basically, trying to reach any of the websites on the list leads to loading a page designed by the cyber crooks for promoting the fake products they want to sell.

The page, pcdefender[.]co[.]vu, offers a bogus security solutions named Windows Security and Windows Defender.

A scan that appears to be in progress, shows that malicious files are present on the computer; this is intended to make the potential victim believe that the computer is infected and download the false malware removal solution, for a fee.

"Win32/Defru is targeting Russian speaking users, mostly from Russia, Ukraine, and Kazakhstan," Chipiristeanu said.

According to telemetry information from Microsoft, most of the users falling victim to Defru are from Russia, but the United States comes second and Kazakhstan takes the third place.

The payment for the product can be done by credit card, at Payeer.com, a Russian payment service that also facilitates currency exchange operations.

Read more: http://news.softpedia.com/news/New-...ection-To-More-Than-300-Websites-455871.shtml
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top