February 2007 - Posts

How to infect + 40.000 computers in 1 second?

Posted by Luis Corrons at  28 February 07 04:44     Yes, I know we should talk about how to protect computers, not about how to infect them, but... aren't you curious? We found a server managed by a hacker that controls more than 40.000 computers. Only yesterday, he created a new trojan and sent a command

Read More...


2006 PandaLabs Annual Report

Posted by Luis Corrons at  27 February 07 04:58     We have just published the brand new 2006 PandaLabs Annual Report, you can download it from here . Enjoy it!

Read More...


A curious technique of social engineering

Posted by Vicente Martinez at  22 February 07 03:41     We have recently detected many infections of Trj/Abox.A. This high number of infections is due to the curious technique of social engineering that it uses in order to deceive users. This malware sends email messages with an asx file attached. The code

Read More...


Malware, Banks & Google Maps (II)

Posted by Luis Corrons at  21 February 07 11:06     It seems that this hacker is pretty active, the Trojan tries to update itself, and then downloads some SSL v.2 crypted packages, which seem to be the message body and e-mail addresses. Today we have intercepted phishing being sent out, and right now it

Read More...


Malware, Banks & Google Maps

Posted by Luis Corrons at  20 February 07 12:30     Yesterday, we detected a downloader that focused media attention because it was spammed using some "curious" subjects: # "Current Australia’s Prime Minister survived a hear attack" # "Prime Minister survived a heard attack"

Read More...


More fakecodecs!!!

Posted by Vicente Martinez at  19 February 07 05:04     Lately we have noticed an increase in the detection of fake codecs. They are supposed to be codecs that allow users to watch certain videos, usually for adults, but in fact they only register a key in the computer in order to check if they had been previously

Read More...


MS deny the execution of IE7 if the executable file name isn't iexplore.exe

Posted by Ismael Briones at  15 February 07 12:26     Some days ago, while we were doing some of our research, we discovered a strange IE 7 behavior or "feature". We were trying to execute a renamed IE 7 executable, but we noticed that it was always ended without any system notification. After

Read More...


Wifi comments ( Update )

Posted by Sergio Piñeiro at  14 February 07 10:12     We have received some comments, on our last post. There we said " 2.- Use encription WEP/WPA, something is better than nothing, although we know that this encription systems can't stop an attack for more than 5 minutes, at least, you make it

Read More...


Wifi comments

Posted by Sergio Piñeiro at  09 February 07 08:51     Not long ago, one of my colleagues told me a story which was quite funny. He was at home, and one of his neighbours, called him. He asked if he was having problems with his internet connection. My colleague told him, that everything was working for him,

Read More...


Skype rumours

Posted by Sergio Piñeiro at  08 February 07 05:42     Recently an article has been published, that suggests that Skype, the so famous VOIP client, may be collecting some information from the users PC. To be more specific, some details about the BIOS and the motherboard's serial numbe. Read it for full

Read More...


January Spyware List

Posted by Sergio Piñeiro at  07 February 07 10:27     Today we are going to review our top spyware list. 1: Adware/Gator(=) 2: Adware/Lop (Up from 8th) 3: Application/MyWebSearch (Up from 5th) 4: Application/Winantivirus2006 (Down from 2nd) 5: Adware/Wupd (Down from 4th) So not many changes this month, but

Read More...


Nurech.A.worm Alert II ( UPDATE )

Posted by Sergio Piñeiro at  06 February 07 06:46     We have compiled more information on this alert. Here you have a graph of the continuous arrival of messages to the lab related to this specific variant in the last 90 hours. Today it reached the second place on the ranking of total number of infections

Read More...

Attachment(s): Nurech_a_evolution2.JPGf


Windows Vista

Posted by Sergio Piñeiro at  06 February 07 05:19     So finally Vista has arrived, we have started to see ads on the newspapers, and even on TV. There is one question regarding Vista that is still unanswered. Are you ready for Vista? A couple of days ago I was wondering if I was ready for Vista. So I decided

Read More...


Nurech.A.worm Alert ( UPDATE )

Posted by Sergio Piñeiro at  05 February 07 09:52     This weekend we have seen a lot of activity from a new worm. It is called Nurech.A. In the last 48 hours it got more than 60% of all the messages received in PandaLabs. At some points it was massively spammed. Here is a graph of the evolution in the last

Read More...

Attachment(s): Nurech_a_evolution.JPGf


Spam in PHP forums (II)

Posted by Sergio Piñeiro at  02 February 07 07:58     One reader has pointed that although requiring a user to register is a good idea, some bots are able to do so, and has sent some "tricks" that administrators should use to prevent bots from registering in the forums. First you should use security

Read More...

Attachment(s): obsfuscatedkey.JPGf