Zscaler Blog

Get the latest Zscaler blog updates in your inbox

Security Research

Fake AV Moving From .co.cc To .cz.cc

September 23, 2010 - 1 min read

I've mentioned before that most of the fake AV sites were hosted on the sub-domain of co.cc which offers free DNS services.

It is certainly true that the domain is still hosting most of the fake AV sites, however, they are also doing a lot of cleanup. All the malicious sites we have reported to them have been removed within 24 hours. Many sites I've checked recently have been taken down.

Fake AV domain was taken down

While we're still seing new co.cc fake AV sites, we've seen an increase of such sites hosted on cz.cc. They offer free sub-domains, and free hosting as well.



Attackers take advantage of free hosting services

Attackers will keep changing providers to find a more hospitable home, a place where they are not shut down quickly. It took several months for co.cc registrars to first take actions against attackers abusing their service, certainly enough time to infect plenty of unaware users and we expect the same for cz.cc.

-- Julien



Explore more Zscaler blogs

A cyber criminal shopping for malware
Agniane Stealer: Dark Web’s Crypto Threat
Read Post
Business people walking through a city
The Impact of the SEC’s New Cybersecurity Policies
Read Post
Digital cloud illuminated in blue
Security Advisory: Remote Code Execution Vulnerability (CVE-2023-3519)
Read Post
The TOITOIN Trojan: Analyzing a New Multi-Stage Attack Targeting LATAM Region
Read Post
01 / 02
dots pattern

Get the latest Zscaler blog updates in your inbox

By submitting the form, you are agreeing to our privacy policy.