February 2008 - Posts

Multi AVs Scanners

Posted by Xabier Francisco at  27 February 08 01:37     From the point of view of a malware developer, one of the main goals when developing a new creation is to avoid antivirus detections, via signature or heuristic technologies. There are different ways to do it, such as using free on-line scanners offered

Read More...


Not all phishing is about banking

Posted by Luis Corrons at  25 February 08 01:51     When we think about phishing, we think about e-mails that try to get information from online banks, eBay or PayPal accounts. While in most of the cases this is true, it must be noted that the aim of the guys behind these attacks is the money. So, wherever

Read More...


Yet Another Web Attack Toolkit --> Exploit Multipackage 0.2

Posted by Xabier Francisco at  25 February 08 09:59     Last week we received an email message written in German which advertised a casino called Lux Imperial Casino. However, this message was not just spam but also included a malicious link to a toolkit called Exploit Multipackage. The URL infection, which

Read More...


Sensation.New Video - make haste to look!!!

Posted by Xabier Francisco at  19 February 08 03:50     Since last week we have been noticing a significant increase in certain spam messages, which have several features in common. The subject of all of them is “Sensation.New Video - make haste to look!!!”, and as a social engineering technique

Read More...


Phishing Ecosystem

Posted by Luis Corrons at  18 February 08 11:11     Taking a look at one of the thousands of malware samples we are processing everyday, we have found a Trojan that was looking for e-mail addresses, apparently nothing special. Unlike other Trojans, it was not looking for e-mail addresses in every location,

Read More...


FirePack for the winter

Posted by Luis Corrons at  14 February 08 04:03     Do you remember IcePack ? It seems that some kits for installing malware are somehow “seasonal”, as we found IcePack in summer, and in late 2007 we found yet another one that suits better for winter, called FirePack: Anyway it is not as advanced

Read More...


Microsoft Updates for February

Posted by Ismael Briones at  13 February 08 09:48     This month Microsoft has released 11 security bulletins (from MS08-03 to MS08-013) . Six of them are rated as critical and five are Important. We recommend you to update your systems ASAP, as most of the vulnerabilities allow remote code execution. Last

Read More...


Happy Saint Valentine!

Posted by Xabier Francisco at  12 February 08 04:39     As Saint Valentine’s Day is approaching, we start to observe how this special day is used as an effective bait in order to spread malware. In the last hours, we have noticed how the malicious files called “withlove.exe” which we saw

Read More...


Playboy TV Spam

Posted by Xabier Francisco at  08 February 08 11:40     I suppose we are in a way getting accustomed to see unwanted messages in our inbox, either advertising rolex watches at reasonable prices or Viagra, “miraculous” beauty products, among many others. That’s nothing new and the figures

Read More...


January Adware/Spyware List

Posted by Xabier Francisco at  05 February 08 05:29     In January, the first position has not changed with regard to the previous month. However, Savenow and Virtumonde interchange their positions, making Virtumonde obtain the second position. The 4th and 5th positions remain unchanged but Adware/ActiveSearch

Read More...


AntiMalware Testing Standards Organization (AMTSO)

Posted by Luis Corrons at  04 February 08 09:01     Two weeks ago we had a really interesting meeting in Bilbao. It was about something that started in Iceland, in the International Antivirus Testing Workshop in May 2007. I had a meeting with some of the AV industry people that were there, talking about

Read More...


Active malware wave

Posted by Xabier Francisco at  01 February 08 02:05     In the last 3 days, we have seen a lot of activity in this Trojan, detected as Trj/Nabload.CXU, which downloads another 2 Trojans: Trj/Banker.KKQ and Trj/Banker.KKU. At certain hours of the day, it has represented up to 21% of all messages received in

Read More...


Mortgage spam!

Posted by ocavada at  01 February 08 09:00     Are you looking for the ideal mortgage for your home? Which is the best choice? Where can you find it? What a dilemma! It’s really easy, you only have to take a look at the Inbox of your email account, concretely in the spam folder. There has been

Read More...