March 2007 - Posts

March Spyware list

Posted by Vicente Martinez at  30 March 07 01:31     The six first positions of the March top ten are the same as the previous month: 1: Adware/Lop 2: Adware/Gator 3: Application/MyWebSearch 4: Adware/SaveNow 5: Adware/nCase 6: Application/Winantivirus2006 The version of fakecodecs that is most extended

Read More...


A "new" ANI vulnerability in the wild

Posted by Ismael Briones at  30 March 07 08:50     It's real, it's not a "deja vù". Yesterday, March 29, a new 0-day exploit with the ANI file format was discovered in the wild. This vulnerability is due to the way Microsoft Windows handles the animated cursor. Microsoft has released an advisory . Affected

Read More...


A fast and easy way to identify a system in a local network

Posted by Ismael Briones at  22 March 07 09:34     We know some tools and techniques to remote OS detection via TCP/IP Stack FingerPrinting : nmap , Queso , p0f ,... These tools use advanced techniques to identify the OS of a remote system and they are really good. But sometimes we can use an easier method

Read More...


Insecure features : should AV companies detect them?

Posted by mballano at  20 March 07 01:39     These days we have been analyzing one of the latest MySpace threats, JS/MySpace.A, which uses an interesting QuickTime feature : HREF Tracks . A deep analysis of this malware is avaliable at Didier Steven´s blog . Abusing HREF Tracks was firstly documented

Read More...


Sex in ASCII

Posted by Luis Corrons at  14 March 07 12:05     We have seen SPAM using ASCII ART in order to avoid being detected by antispam filters. Most of the times, they try to show different words (Viagra, etc.) using this technique, but this is the first time I have seen them showing a picture. It is not a

Read More...


AntiVirus Trojan?

Posted by Luis Corrons at  07 March 07 06:11     We have seen rogue antispyware for quite a long time; there is a list of these kind of "programs" in the Spywarewarrior site. We have discovered something similar but this time its aim is not to earn money, but to bother users conscientiously. It has

Read More...


February Spyware List

Posted by Vicente Martinez at  05 March 07 04:13     Today we are going to review our top spyware list. 1: Adware/Lop (Up from 2nd) 2: Adware/Gator (Down from 1st) 3: Application/MyWebSearch (=) 4: Adware/SaveNow (Up from 7th) 5: Adware/nCase (Up from 6th) It is the first time that Adware/Gator has been

Read More...