Last seven days
- First activity
- Aug 12, 2026
- Last activity
- Aug 12, 2026
- Feed role
- C2
- Host form
- 2 IP / 4 hostnames
SpySheriff is a Windows rogue anti-spyware/fraudware family that masqueraded as legitimate security software and used fake scans and false security alerts to coerce users into paying for removal of non-existent threats.
Profile source: Mallory opens in a new tabSpySheriff
SpySheriff is a Windows rogue anti-spyware/fraudware family that masqueraded as legitimate security software and used fake scans and false security alerts to coerce users into paying for removal of non-existent threats. It was also distributed under aliases including BraveSentry 2.0, Pest Trap, SpyDawn, Alpha Cleaner, SpywareBot, and SpyBouncer. The content attributes it to Innovative Marketing Inc. (also referred to as Innovagest 2000). Behavior described in the source includes displaying fabricated detections such as misleading "Trojan VX ..." alerts, replacing the desktop background with a fake Blue Screen of Death-style warning, blocking web browsing so that spy-sheriff.com was the only accessible site, interfering with or preventing System Restore, reinstalling itself after removal attempts, hiding components in System Restore folders, terminating some antivirus and antispyware processes, and disabling Task Manager and Registry Editor. Attempts to uninstall it via Add or Remove Programs could fail or trigger an unexpected reboot; users sometimes bypassed its blocking of taskmgr.exe and regedit.exe by renaming those executables. SpySheriff was hosted on www.spysheriff.com and www.spy-sheriff.com from 2005 until shutdown in 2008, with similarly named sites also distributing it. Vendor detections cited in the content include Symantec Adware.SpySheriff, F-Secure Rogue:W32/SpySheriff and Rogue:W32/BraveSentry, Fortiguard Adware/SpySheriff, McAfee Adware-SpySheriff, and Trend Micro ADW_SPYSHERIFF, DOWNLOADER_SPYSHERIFF, FREELOADER_SPYSHERIFF, VBS_SENTRY, ADW_BRAVESEN, and ADW_PESTTRAP.
C2 tracking
Derp observations, rolling seven-day window
Samples
087278f0e188cec163e46643aaba758e23f2a2afc30e1b8bd8b52d470f5dd49a 091d3fe111479c7b0aac73c4ee4ddd44bdf4141845ce518a5c890a6fcb969eee 1d9f54468adf66b58a809212e851a42d2696475f2a6a66cdd763e554a0739c4d 2803b74d5466845e4dc9063bd516f3679aa2a3f70a30d9e93976c212e87f6e87 29f281e0e9ebc9cc7b54af08535509feac1930a60d3d2e2fe9528f77711f04a8 2de7b97cbe137ac78f56e99ce644070cf7c129fca414c2ef26e9e4f30f0b52a6 add6c6ec77f6103f5eef91fe5d4c7a22d7c54e167c94758a685f85653ee31386 d3e610613091895831f26fd6768e41da249d0a5f4a920645aa21143e914d4b86 dbee15d75e4bfc40a0091878009dedf0cca795f224554c91ad776710eb3a76a9 ddab933a1c95e0911257dd469ced51e6647a4f0904433f660cf4aa7a7c7a2f39 MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.