Fake AV 3 Years Later: Still There, Still Not Blocked
ID: 2a661f9b-624e-5f89-8f2a-7a1172939870
STIX ID: report--2a661f9b-624e-5f89-8f2a-7a1172939870
Feed Name: Zscaler Security Research Blog
Threat Score
This blog describes a 2013 Fake AV campaign: malicious webpages present fake antivirus scans that trick users into installing executables (e.g., freescan_2013.exe, data.exe) which disable AV/firewall, register a persistent fake AV (shown as XP Antivirus 2011), wrap executables via bap.exe, and phone home to C2 infrastructure (notably 109.206.174.62); the report lists multiple affiliate-driven domains and IOCs and notes low detection rates by antivirus engines.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
