Last seven days
- First activity
- Sep 9, 2026
- Last activity
- Sep 9, 2026
- Feed role
- C2
- Host form
- 0 IP / 4 hostnames
SpySheriff is a Windows rogue anti-spyware/fraudware family that masqueraded as legitimate security software and used fake scans and false security alerts to coerce users into paying for removal of non-existent threats.
Profile source: Mallory opens in a new tabSpySheriff
SpySheriff is a Windows rogue anti-spyware/fraudware family that masqueraded as legitimate security software and used fake scans and false security alerts to coerce users into paying for removal of non-existent threats. It was also distributed under aliases including BraveSentry 2.0, Pest Trap, SpyDawn, Alpha Cleaner, SpywareBot, and SpyBouncer. The content attributes it to Innovative Marketing Inc. (also referred to as Innovagest 2000). Behavior described in the source includes displaying fabricated detections such as misleading "Trojan VX ..." alerts, replacing the desktop background with a fake Blue Screen of Death-style warning, blocking web browsing so that spy-sheriff.com was the only accessible site, interfering with or preventing System Restore, reinstalling itself after removal attempts, hiding components in System Restore folders, terminating some antivirus and antispyware processes, and disabling Task Manager and Registry Editor. Attempts to uninstall it via Add or Remove Programs could fail or trigger an unexpected reboot; users sometimes bypassed its blocking of taskmgr.exe and regedit.exe by renaming those executables. SpySheriff was hosted on www.spysheriff.com and www.spy-sheriff.com from 2005 until shutdown in 2008, with similarly named sites also distributing it. Vendor detections cited in the content include Symantec Adware.SpySheriff, F-Secure Rogue:W32/SpySheriff and Rogue:W32/BraveSentry, Fortiguard Adware/SpySheriff, McAfee Adware-SpySheriff, and Trend Micro ADW_SPYSHERIFF, DOWNLOADER_SPYSHERIFF, FREELOADER_SPYSHERIFF, VBS_SENTRY, ADW_BRAVESEN, and ADW_PESTTRAP.
C2 tracking
Derp observations, rolling seven-day window
Samples
29f281e0e9ebc9cc7b54af08535509feac1930a60d3d2e2fe9528f77711f04a8 4cb5aa48159039802920e727630baa8605b89fa680c8296a4220a3c431a0d7ac 6ec6204ceb39cc235927feb55c6c78a029f051b8770cd8f6823bf2eaeb9f8409 7c0dcc80d059cebeb8a803f7455f008a1561737b7f6b1bbaa249b51799ba1ca7 96d443a8f6fbb22ef7a1462d57b39591cbd465ba391a8c6e2c41fa3df7f92f0c dbee15d75e4bfc40a0091878009dedf0cca795f224554c91ad776710eb3a76a9 MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.