Skip to content

SpySheriff

SpySheriff is a Windows rogue anti-spyware/fraudware family that masqueraded as legitimate security software and used fake scans and false security alerts to coerce users into paying for removal of non-existent threats.

Profile source: Mallory opens in a new tab

SpySheriff

Family profile

SpySheriff is a Windows rogue anti-spyware/fraudware family that masqueraded as legitimate security software and used fake scans and false security alerts to coerce users into paying for removal of non-existent threats. It was also distributed under aliases including BraveSentry 2.0, Pest Trap, SpyDawn, Alpha Cleaner, SpywareBot, and SpyBouncer. The content attributes it to Innovative Marketing Inc. (also referred to as Innovagest 2000). Behavior described in the source includes displaying fabricated detections such as misleading "Trojan VX ..." alerts, replacing the desktop background with a fake Blue Screen of Death-style warning, blocking web browsing so that spy-sheriff.com was the only accessible site, interfering with or preventing System Restore, reinstalling itself after removal attempts, hiding components in System Restore folders, terminating some antivirus and antispyware processes, and disabling Task Manager and Registry Editor. Attempts to uninstall it via Add or Remove Programs could fail or trigger an unexpected reboot; users sometimes bypassed its blocking of taskmgr.exe and regedit.exe by renaming those executables. SpySheriff was hosted on www.spysheriff.com and www.spy-sheriff.com from 2005 until shutdown in 2008, with similarly named sites also distributing it. Vendor detections cited in the content include Symantec Adware.SpySheriff, F-Secure Rogue:W32/SpySheriff and Rogue:W32/BraveSentry, Fortiguard Adware/SpySheriff, McAfee Adware-SpySheriff, and Trend Micro ADW_SPYSHERIFF, DOWNLOADER_SPYSHERIFF, FREELOADER_SPYSHERIFF, VBS_SENTRY, ADW_BRAVESEN, and ADW_PESTTRAP.

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 12, 2026
Last activity
Aug 12, 2026
Feed role
C2
Host form
2 IP / 4 hostnames

Leading locations

  • DE3
  • US2
  • RU1

Leading providers

  • Cloudflare, Inc.2
  • FEMO IT SOLUTIONS LIMITED2
  • DDOS-GUARD LTD1
  • Melbikomas UAB1

Infrastructure traits

  • Hosting 6
  • Anycast 3

Samples

Recent associated samples

MITRE ATT&CK

SpySheriff in ATT&CK

5 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.