Last seven days
- First activity
- Sep 23, 2026
- Last activity
- Sep 23, 2026
- Feed role
- C2
- Host form
- 0 IP / 3 hostnames
SpySheriff is a Windows rogue anti-spyware/fraudware family that masqueraded as legitimate security software and used fake scans and false security alerts to coerce users into paying for removal of non-existent threats.
Profile source: Mallory opens in a new tabSpySheriff
SpySheriff is a Windows rogue anti-spyware/fraudware family that masqueraded as legitimate security software and used fake scans and false security alerts to coerce users into paying for removal of non-existent threats. It was also distributed under aliases including BraveSentry 2.0, Pest Trap, SpyDawn, Alpha Cleaner, SpywareBot, and SpyBouncer. The content attributes it to Innovative Marketing Inc. (also referred to as Innovagest 2000). Behavior described in the source includes displaying fabricated detections such as misleading "Trojan VX ..." alerts, replacing the desktop background with a fake Blue Screen of Death-style warning, blocking web browsing so that spy-sheriff.com was the only accessible site, interfering with or preventing System Restore, reinstalling itself after removal attempts, hiding components in System Restore folders, terminating some antivirus and antispyware processes, and disabling Task Manager and Registry Editor. Attempts to uninstall it via Add or Remove Programs could fail or trigger an unexpected reboot; users sometimes bypassed its blocking of taskmgr.exe and regedit.exe by renaming those executables. SpySheriff was hosted on www.spysheriff.com and www.spy-sheriff.com from 2005 until shutdown in 2008, with similarly named sites also distributing it. Vendor detections cited in the content include Symantec Adware.SpySheriff, F-Secure Rogue:W32/SpySheriff and Rogue:W32/BraveSentry, Fortiguard Adware/SpySheriff, McAfee Adware-SpySheriff, and Trend Micro ADW_SPYSHERIFF, DOWNLOADER_SPYSHERIFF, FREELOADER_SPYSHERIFF, VBS_SENTRY, ADW_BRAVESEN, and ADW_PESTTRAP.
C2 tracking
Derp observations, rolling seven-day window
Samples
1693a05c9f97b3a88108964a3109cf4e899313cac64e54267ad3610403adac97 1bf3b15578ce19eff12aa2cc52b734d0d96ad3290308bcdea97805016a66a77d 61c6fce75d948ebe81c61c73d47c0ed794dede15d996aabbe371eaebf3284d06 6d95085efbad4bce16e989bd5afffa081e4d3746a3ffbaa8c69a1eaafaebfff5 e41a9dbb86dba2009578a2ca18eb7257db729626afe4c0a33eaaf02be3c08626 f280cf140a3f472080888207026d6c0e9f5ca0665f2fc48d5d2e3ad31b115d94 f36a286c7994c6110ecb4cdbc9bf57bbc695bcadb0c6c3dd6ea6c1b08c55dd65 MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.