<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://pandalabs.pandasecurity.com/utility/FeedStylesheets/atom.xsl" media="screen"?><feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en"><title type="html">PandaLabs</title><subtitle type="html">, everything you need to know about Internet threats </subtitle><id>http://pandalabs.pandasecurity.com/atom.aspx</id><link rel="alternate" type="text/html" href="http://pandalabs.pandasecurity.com/default.aspx" /><link rel="self" type="application/atom+xml" href="http://pandalabs.pandasecurity.com/atom.aspx" /><generator uri="http://communityserver.org" version="2.1.61120.2">Community Server</generator><updated>2009-09-21T21:43:00Z</updated><entry><title>Black(hat) Friday</title><link rel="alternate" type="text/html" href="http://pandalabs.pandasecurity.com/archive/Black_2800_hat_2900_-Friday.aspx" /><id>http://pandalabs.pandasecurity.com/archive/Black_2800_hat_2900_-Friday.aspx</id><published>2009-11-20T21:01:00Z</published><updated>2009-11-20T21:01:00Z</updated><content type="html">&lt;span&gt;&lt;p align="left" dir="ltr"&gt;If you plan on shopping online for &amp;quot;Black Friday&amp;quot;, or &amp;quot;Cyber Monday&amp;quot;, you might be in for more than you bargained for.　 Cyber criminals behind the Rogueware epidemic have their &lt;a href="http://pandalabs.pandasecurity.com/archive/tags/SEO/default.aspx"&gt;blackhat SEO&lt;/a&gt; campaigns optimized to take advantage of deal seekers looking for advertisements online.　 One misstep and you just might find yourself staring at a scareware site designed to trick you into believing that your computer is infected.&amp;nbsp; &lt;/p&gt;&lt;strong&gt;&lt;p align="left" dir="ltr"&gt;Google Search:&lt;/p&gt;&lt;/strong&gt;&lt;/span&gt;&lt;p align="left" dir="ltr"&gt;&lt;a href="http://www.flickr.com/photos/lithium-/4120742406/sizes/o/" title="Blackhat SEO - Black Friday Campaign"&gt;&lt;img border="0" src="http://farm3.static.flickr.com/2530/4120742406_09f89d01b8_d.jpg" /&gt;&lt;/a&gt;&lt;/p&gt;&lt;font face="Calibri" size="3"&gt;&lt;font face="Calibri" size="3"&gt;&lt;span&gt;&lt;p align="left" dir="ltr"&gt;&lt;strong&gt;Fake Antivirus Page:&lt;/strong&gt;&lt;/p&gt;&lt;p align="left" dir="ltr"&gt;&lt;strong&gt;&amp;nbsp;&lt;/strong&gt;&lt;a href="http://www.flickr.com/photos/lithium-/4120742422/sizes/o/" title="Fake Antivirus"&gt;&lt;strong&gt;&lt;img alt="Black Friday - Rogueware Page" border="0" src="http://farm3.static.flickr.com/2762/4120742422_753882db2d_d.jpg" title="Black Friday - Rogueware Page" /&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&lt;p align="left" dir="ltr"&gt;We are constantly monitoring this and other Blackhat SEO campaigns to protect our customers against the latest malware attacks on the Internet.&amp;nbsp; If you are not a customer yet,&amp;nbsp;we recommend at least&amp;nbsp;installing&amp;nbsp;our free&amp;nbsp;&lt;a href="http://download.cnet.com/Panda-Cloud-Antivirus-Free-Edition/3000-2239_4-10914099.html?tag=mncol" title="Cloud Antivirus Download" target="_blank"&gt;Cloud Antivirus&lt;/a&gt;&amp;nbsp;protection. We also recommend adding an extra layer of browsing protection&amp;nbsp;with safer browsing technology, such as the community driven system provided by our partner, &lt;a href="http://www.pandasecurity.com/homeusers/downloads/WOT/" title="Web of Trust" target="_blank"&gt;Web Of Trust&lt;/a&gt;. &lt;/p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=1049" width="1" height="1"&gt;</content><author><name>Sean-Paul Correll</name><uri>http://pandalabs.pandasecurity.com/members/Sean-Paul+Correll.aspx</uri></author><category term="Rogueware" scheme="http://pandalabs.pandasecurity.com/archive/tags/Rogueware/default.aspx" /><category term="Blackhat SEO" scheme="http://pandalabs.pandasecurity.com/archive/tags/Blackhat+SEO/default.aspx" /></entry><entry><title>See how the Rick Astley iPhone hack attack works</title><link rel="alternate" type="text/html" href="http://pandalabs.pandasecurity.com/archive/This-way-works-the-worm-for-iPhone.aspx" /><id>http://pandalabs.pandasecurity.com/archive/This-way-works-the-worm-for-iPhone.aspx</id><published>2009-11-12T17:44:00Z</published><updated>2009-11-12T17:44:00Z</updated><content type="html">
&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;We have created a video on how the iPhone/Eeki worm targeting iPhones works. &lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;You can see it here:&lt;br /&gt;&lt;br /&gt; &lt;a href="http://www.youtube.com/v/RBINaCWgA58" title="Video" target="_blank"&gt;&lt;img src="http://farm3.static.flickr.com/2551/4099231786_5dfa5d22be_o.png" /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;/font&gt;&lt;/p&gt;
&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;&lt;/font&gt;
&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;As you can see in the video, this malware first checks it is not already running on the device. To do so, it checks whether the following file exists:&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;&lt;font style="background-color:#cc3300;"&gt;/var/lock/bbot.lock&lt;/font&gt; &lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;This may help you know if you are infected; if the information is in your device, it means the worm is there.&lt;br /&gt;
Next, it changes the device host and stops the SSH daemon.&lt;br /&gt;
It then tries to spread on the subnet the phone is connected to and tries to create a random IP range. It tries pre-established ranges corresponding to certain companies&amp;rsquo; IP addresses:&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;&lt;img alt="IPs" height="175" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2009/11/12/IPs.JPG" style="width:269px;height:175px;" title="IPs" width="269" /&gt;&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;Once the IP address is created, it remotely accesses the jailbroken iPhone device, establishing an SSH connection and using the default root key, included in all iPhoneOS devices (1G, 2G and 3G Iphone and ipod touch devices). If access is denied, it tries to create a random IP again and repeats the process until it obtains a valid IP from a vulnerable victim.&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;Once the victim is found with the previous credentials, it obtains a remote session and copies itself to the affected phone, adding:&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif" style="background-color:#cc3300;"&gt;/System/Library/LaunchDaemons/com.saurik.Cydia.Startup.plist&lt;br /&gt;
/System/Library/LaunchDaemons/com.ikey.bbot.plist&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;to run on restart. &lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;It stops the SSH service that has caused the infection. Finally, it copies a photo of Rick Astley and uses the image as the device wallpaper.&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;&lt;img alt="WallPaper" height="485" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2009/11/12/WallPaper.JPG" style="width:326px;height:485px;" title="WallPaper" width="326" /&gt;&amp;nbsp;&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;&amp;ldquo;Thanks to Gorka Ram&amp;iacute;rez and Francisco Berenguer for the information and the video&amp;rdquo;.&lt;br /&gt;
&lt;/font&gt;&lt;/p&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=1048" width="1" height="1"&gt;</content><author><name>xfrancisco</name><uri>http://pandalabs.pandasecurity.com/members/xfrancisco.aspx</uri></author></entry><entry><title>Blackhat SEO Aggressively Targets Halloween Related Keywords</title><link rel="alternate" type="text/html" href="http://pandalabs.pandasecurity.com/archive/Blackhat-SEO-Aggressively-Targets-Halloween-Related-Keywords.aspx" /><id>http://pandalabs.pandasecurity.com/archive/Blackhat-SEO-Aggressively-Targets-Halloween-Related-Keywords.aspx</id><published>2009-10-28T00:00:00Z</published><updated>2009-10-28T00:00:00Z</updated><content type="html">&lt;p&gt;Cyber criminals behind the Rogueware epidemic have been hard at work in poisoning search results to increase traffic to their campaign sites. Today, we identified a new Blackhat SEO campaign, which is currently targeting Halloween related keywords aggressively. While studying the campaign, I noticed that the most commonly targeted keywords were classic costume favorites, such as the Cat woman costume, vampire costume, and various adult costumes. In addition to costumes, the BHSEO campaign also targets Halloween related food recipes, haunted house directions, Halloween parties, and the movie Halloween. &lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tainted search results:&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;img alt="Blackhat SEO - Search Results" src="http://farm3.static.flickr.com/2486/4051474252_b5e88bf078_o.png" /&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Fake Antivirus site:&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.flickr.com/photos/lithium-/4051474234/sizes/o/in/photostream/"&gt;&lt;img alt="Rogueware Site" border="0" height="362" src="http://farm3.static.flickr.com/2797/4051474234_a601e7762a.jpg" width="500" /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tag cloud of targeted search terms:&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;img alt="BHSEO Tagcloud" height="416" src="http://farm3.static.flickr.com/2638/4051474274_bf1bf97f33_o.png" width="574" /&gt;&lt;/p&gt;&lt;p&gt;As we have &lt;a href="http://pandalabs.pandasecurity.com/archive/Targeted-Blackhat-SEO-Attack-against-Ford-Motor-Co_2E00_.aspx"&gt;documented&lt;/a&gt; &lt;a href="http://pandalabs.pandasecurity.com/archive/New-Blackhat-SEO-attack-exploits-vulnerabilities-in-Wordpress-to-distribute-rogue-antivirus-software.aspx"&gt;in&lt;/a&gt; &lt;a href="http://pandalabs.pandasecurity.com/archive/Swin-flu-and-the-Blackhat-SEO-techniques.aspx"&gt;prior&lt;/a&gt; &lt;a href="http://pandalabs.pandasecurity.com/archive/Blackhat-SEO-continues-to-ravage-search-results.aspx"&gt;blog&lt;/a&gt; &lt;a href="http://pandalabs.pandasecurity.com/search.aspx?q=blackhat+seo&amp;amp;p=1"&gt;posts&lt;/a&gt;, Blackhat SEO continues to be one of the most prevalent and pervasive attack vectors on the Internet today. As users, we tend to trust search engines to provide safe and accurate search results, but the reality is that today, search engines are becoming the most dangerous way to browse the Internet. &lt;/p&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=1047" width="1" height="1"&gt;</content><author><name>Sean-Paul Correll</name><uri>http://pandalabs.pandasecurity.com/members/Sean-Paul+Correll.aspx</uri></author><category term="Rogueware" scheme="http://pandalabs.pandasecurity.com/archive/tags/Rogueware/default.aspx" /><category term="Blackhat SEO" scheme="http://pandalabs.pandasecurity.com/archive/tags/Blackhat+SEO/default.aspx" /></entry><entry><title>Blackhat SEO Campaign Targets 2009 Nobel Prize Winner</title><link rel="alternate" type="text/html" href="http://pandalabs.pandasecurity.com/archive/Blackhat-SEO-Campaign-Targets-2009-Nobel-Prize-Winner.aspx" /><id>http://pandalabs.pandasecurity.com/archive/Blackhat-SEO-Campaign-Targets-2009-Nobel-Prize-Winner.aspx</id><published>2009-10-09T12:20:00Z</published><updated>2009-10-09T12:20:00Z</updated><content type="html">&lt;p&gt;&amp;nbsp;We&amp;rsquo;ve identified a new Blackhat SEO campaign today which  targets President Obama as the 2009 Nobel Peace  Prize winner among a thousand or so other search terms.&amp;nbsp;&amp;nbsp; Clicking on a malicious search result yields  the typical Rogueware campaign.&amp;nbsp; 

&lt;/p&gt;&lt;p&gt;&lt;br /&gt;
  &lt;strong&gt;Search result&lt;/strong&gt;:&lt;br /&gt;
  &lt;img alt="Nobel Peace Prize Winner 2009 - Obama Blackhat SEO" height="107" src="http://farm3.static.flickr.com/2481/3994744083_33696b8a90_o.png" width="669" /&gt;&lt;br /&gt;
  &lt;br /&gt;
  &lt;strong&gt;Rogueware site&lt;/strong&gt;:&lt;br /&gt;
  &lt;img alt="Windows Performance Center Rogueware" height="439" src="http://farm4.static.flickr.com/3535/3995502608_1e92824bd1_o.png" width="603" /&gt;&lt;/p&gt;

&lt;p&gt;The complete list of targeted search terms can be found &lt;a href="http://dl.getdropbox.com/u/1301849/BlackhatSEO4.txt"&gt;here&lt;/a&gt;.&amp;nbsp; &amp;nbsp;&lt;/p&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=1046" width="1" height="1"&gt;</content><author><name>Sean-Paul Correll</name><uri>http://pandalabs.pandasecurity.com/members/Sean-Paul+Correll.aspx</uri></author><category term="Rogueware" scheme="http://pandalabs.pandasecurity.com/archive/tags/Rogueware/default.aspx" /><category term="Blackhat SEO" scheme="http://pandalabs.pandasecurity.com/archive/tags/Blackhat+SEO/default.aspx" /></entry><entry><title>Rogueware with new Ransomware Technology™</title><link rel="alternate" type="text/html" href="http://pandalabs.pandasecurity.com/archive/Rogueware-with-new-Ransomware-Technology_2221_.aspx" /><id>http://pandalabs.pandasecurity.com/archive/Rogueware-with-new-Ransomware-Technology_2221_.aspx</id><published>2009-10-08T11:05:00Z</published><updated>2009-10-08T11:05:00Z</updated><content type="html">&lt;p&gt;The criminals behind &lt;a href="http://www.pandasecurity.com/img/enc/The%20Business%20of%20Rogueware.pdf"&gt;Rogueware&lt;/a&gt; attacks are becoming increasingly aggressive in their approach to make money.  We recently stumbled across a sample (&lt;a href="http://www.pandasecurity.com/homeusers/security-info/212529/information/TotalSecurity2009"&gt;Adware/TotalSecurity2009&lt;/a&gt;) which uses a &lt;a href="http://pandalabs.pandasecurity.com/archive/Ransomware-Reloaded.aspx"&gt;ransomware&lt;/a&gt; technique to improve its sales. Once the computer becomes infected, Total Security forces the victim to purchase it before it will allow any files from being accessed  on the system.&amp;nbsp; When attempting to open a file, a message pops up in the notification area claiming that the application was blocked due to infection.&amp;nbsp; The pop up recommends activating the &amp;quot;antivirus&amp;quot; software, which costs $79.95.&amp;nbsp; &lt;br /&gt;
&lt;br /&gt;
&lt;img alt="Notification Area - Notepad.exe blocked" height="69" src="http://farm3.static.flickr.com/2642/3993133972_af6917dbf6_m.jpg" title="Notification Area - Notepad.exe blocked" width="240" /&gt; &lt;br /&gt;
&lt;/p&gt;
&lt;p&gt;  This would be a devistating blow to any user and would likely force the victim to purchase it, so we went ahead and cracked the sample to reveal all of the valid serial numbers.  We&amp;#39;re hoping that&amp;nbsp; victims can find this blog post before shelling out any hard earned cash to these criminals. &lt;br /&gt;
&lt;/p&gt;

&lt;p&gt;Watch the video to see it in action:&amp;nbsp; &lt;br /&gt;
&lt;/p&gt;

&lt;p&gt;&lt;a href="http://vimeo.com/6949998"&gt;&lt;img border="0" src="http://farm4.static.flickr.com/3419/3992052465_98a09ebb8d_o.png" /&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Valid serials for &lt;a href="http://www.pandasecurity.com/homeusers/security-info/212529/information/TotalSecurity2009"&gt;Adware/TotalSecurity2009&lt;/a&gt;:&lt;/p&gt;

&lt;p&gt;WNDS-TGN15-RFF29-AASDJ-ASD65&lt;br /&gt;
  WNDS-U94KO-LF4G4-1V8S1-2CRFE&lt;br /&gt;
  WNDS-6W954-FX65B-41VDF-8G4JI&lt;br /&gt;
  WNDS-G84H6-S854F-79ZA8-W4ERS&lt;br /&gt;
  WNDS-TTUYJ-7UO54-G561H-J1D6F&lt;br /&gt;
  WNDS-A1SDF-6AS4D-RF5RE-79G84&lt;br /&gt;
  WNDS-A1SDF-RY4E8-7U98D-F1GB2&lt;br /&gt;
  WNDS-5SRTS-AEHUF-YA54S-D6F35&lt;br /&gt;
  WNDS-P9685-4H41A-DSW3A-2R64T&lt;br /&gt;
  WNDS-2AE32-1VFC2-B6894-G67YU&lt;br /&gt;
  WNDS-4TS8R-D6F5D-4JH8T-U4JK5&lt;br /&gt;
  WNDS-FGS5D-649RG-4S53D-412SF&lt;br /&gt;
  WNDS-452S3-ER00F-TSE35-S8FSD&lt;br /&gt;
  WNDS-SERFH-2642S-F04SD-64FG1&lt;br /&gt;
  WNDS-F40SA-1ER5H-4FG5D-F8412&lt;br /&gt;
  WNDS-5D1V2-XB0D5-JT1TY-97DS3&lt;br /&gt;
  WNDS-4BGY2-JY4KO-IT98Y-7HJ43&lt;br /&gt;
  WNDS-G8FB6-1V87S-DRT1S-63SRG&lt;br /&gt;
  WNDS-HFVDR-9844O-U54DA-5TBSC&lt;br /&gt;
  WNDS-89OF7-7324R-5SAD4-TG68U&lt;br /&gt;
  WNDS-JUYH3-24GHJ-HGKSH-FKLSD&lt;/p&gt;&lt;p&gt;You can &lt;a href="http://www.pandasecurity.com/usa/homeusers/downloads/register?Tipo=1&amp;amp;CodigoProducto=60&amp;amp;Idioma=2&amp;amp;TipoUsuario=12&amp;amp;Country=US&amp;amp;TipoLead=2&amp;amp;Ref=WWUS-GP10-DWN" title="Global Protection 2010 Trial" target="_blank"&gt;download a free trial&lt;/a&gt; to completely remove the infection once the ransomware feature is removed.&lt;/p&gt;&lt;p&gt;&lt;br /&gt;Special thanks to Sherab Giovannini for extracting the serials.&amp;nbsp; &lt;br /&gt;&lt;/p&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=1045" width="1" height="1"&gt;</content><author><name>Sean-Paul Correll</name><uri>http://pandalabs.pandasecurity.com/members/Sean-Paul+Correll.aspx</uri></author><category term="Rogueware" scheme="http://pandalabs.pandasecurity.com/archive/tags/Rogueware/default.aspx" /><category term="Video" scheme="http://pandalabs.pandasecurity.com/archive/tags/Video/default.aspx" /><category term="Ransomware" scheme="http://pandalabs.pandasecurity.com/archive/tags/Ransomware/default.aspx" /><category term="Total Security" scheme="http://pandalabs.pandasecurity.com/archive/tags/Total+Security/default.aspx" /></entry><entry><title>Rogueware distributors use Skype</title><link rel="alternate" type="text/html" href="http://pandalabs.pandasecurity.com/archive/Rogueware-distributors-use-Skype.aspx" /><id>http://pandalabs.pandasecurity.com/archive/Rogueware-distributors-use-Skype.aspx</id><published>2009-10-05T10:41:00Z</published><updated>2009-10-05T10:41:00Z</updated><content type="html">&lt;p&gt;Rogueware distributors are like the cockroaches of the  Internet; they&amp;rsquo;re everywhere. &amp;nbsp;&amp;nbsp;Malicious  search results, online advertisements, and iframe hijacked sites are the  typical distribution methods, but every once in a while we come across an interesting approach.&lt;br /&gt;
  &lt;br /&gt;
Recently, a colleague alerted me of a spam message  coming through to his personal Skype account.&amp;nbsp;  The message appeared out of nowhere from an account labeled &amp;ldquo;Online  Notification&amp;rdquo; and made the typical claims of a found infection.&amp;nbsp; Once the victim navigates to the site, the usual fake antivirus trickery takes place.&lt;/p&gt;
&lt;blockquote&gt;&lt;a href="http://www.flickr.com/photos/lithium-/3983643398/sizes/o/"&gt;&lt;img alt="Skype Spam" height="428" src="http://farm4.static.flickr.com/3504/3983643398_8be4d7c1a2.jpg" width="500" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/blockquote&gt;&lt;p&gt;
  &lt;br /&gt;
  Skype isn&amp;rsquo;t the most reliable or innovative distribution  method, but we&amp;rsquo;ll go ahead and give them an &amp;quot;A&amp;quot; for effort.&amp;nbsp; &lt;/p&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=1044" width="1" height="1"&gt;</content><author><name>Sean-Paul Correll</name><uri>http://pandalabs.pandasecurity.com/members/Sean-Paul+Correll.aspx</uri></author><category term="Rogueware" scheme="http://pandalabs.pandasecurity.com/archive/tags/Rogueware/default.aspx" /><category term="Skype" scheme="http://pandalabs.pandasecurity.com/archive/tags/Skype/default.aspx" /></entry><entry><title>Q3 report released</title><link rel="alternate" type="text/html" href="http://pandalabs.pandasecurity.com/archive/Q3-report-released.aspx" /><id>http://pandalabs.pandasecurity.com/archive/Q3-report-released.aspx</id><published>2009-10-01T07:51:00Z</published><updated>2009-10-01T07:51:00Z</updated><content type="html">&lt;p&gt;We&amp;#39;ve just published our latest quarterly report. We&amp;#39;ll show the different figures about malware in Q3, and some interesting articles. &amp;nbsp;If you want to know what has happened in the last 3 months, which have been the most important&amp;nbsp;Blakhat SEO attackes or the latest movements of the Koobface&amp;nbsp;worm,&amp;nbsp;just download it and enjoy!&lt;/p&gt;&lt;p&gt;&amp;nbsp;English:&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.pandasecurity.com/img/enc/Quarterly_Report_Pandalabs_Q3_2009.pdf" target="_blank"&gt;&lt;img height="89" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2009/10/01/Portada_Q3_2009_en.gif" width="72" /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.pandasecurity.com/img/enc/Quarterly_Report_PandaLabs_Q2_2009.pdf"&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;Spanish:&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.pandasecurity.com/img/enc/Informe_Trimestral_Pandalabs_T3_2009.pdf" target="_blank"&gt;&lt;img height="89" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2009/10/01/Portada_Q3_2009_es.gif" width="72" /&gt;&lt;/a&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/p&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=1043" width="1" height="1"&gt;</content><author><name>lcorrons</name><uri>http://pandalabs.pandasecurity.com/members/lcorrons.aspx</uri></author></entry><entry><title>Fake IRS Notifications</title><link rel="alternate" type="text/html" href="http://pandalabs.pandasecurity.com/archive/Fake-IRS-Notifications.aspx" /><id>http://pandalabs.pandasecurity.com/archive/Fake-IRS-Notifications.aspx</id><published>2009-09-28T21:45:00Z</published><updated>2009-09-28T21:45:00Z</updated><content type="html">&lt;p&gt;Fake IRS notification e-mails have been in circulation on  the Internet over the past few weeks. We&amp;#39;ve monitored the situation closely and  have observed 30 active domain names currently spreading the Zeus trojan affiliated with the spam campaign, as  well as 300 links used in the attack over the past month. The e-mail arrives as a notice of unreported income and  directs the victim to click on a link (E.g. www.irs.gov.malwaredomain.com).&amp;nbsp; When clicked, the victim arrives at website  designed to look like an official IRS page.&amp;nbsp;  &amp;nbsp;&amp;nbsp;&lt;br /&gt;
  &lt;br /&gt;
    &lt;a href="http://www.flickr.com/photos/lithium-/3963988680/sizes/o/"&gt;&lt;img alt="Fake IRS Notification" border="0" height="346" src="http://farm3.static.flickr.com/2621/3963988680_acb53b9b97.jpg" width="500" /&gt;&lt;br /&gt;
  &lt;/a&gt;&lt;br /&gt;
  The website attempts to legitimize itself by referencing the  receivers name in the Taxpayer ID field and in the download link. Once the  malware is accessed, the zeus trojan is silently installed on the victim&amp;rsquo;s computer and  begins to intercept communication with banking sites in order to facilitate financial  fraud.&lt;br /&gt;
&lt;/p&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=1042" width="1" height="1"&gt;</content><author><name>Sean-Paul Correll</name><uri>http://pandalabs.pandasecurity.com/members/Sean-Paul+Correll.aspx</uri></author><category term="Spam" scheme="http://pandalabs.pandasecurity.com/archive/tags/Spam/default.aspx" /><category term="Trojan" scheme="http://pandalabs.pandasecurity.com/archive/tags/Trojan/default.aspx" /></entry><entry><title>Blackhat SEO continues to ravage search results</title><link rel="alternate" type="text/html" href="http://pandalabs.pandasecurity.com/archive/Blackhat-SEO-continues-to-ravage-search-results.aspx" /><id>http://pandalabs.pandasecurity.com/archive/Blackhat-SEO-continues-to-ravage-search-results.aspx</id><published>2009-09-22T23:26:00Z</published><updated>2009-09-22T23:26:00Z</updated><content type="html">&lt;p&gt;Every day cyber criminals are exploiting search engines to  display high ranking malicious search results. Targeting hot topics allows for  cyber criminals to improve infection rates for their money making &lt;a href="http://www.pandasecurity.com/img/enc/The%20Business%20of%20Rogueware.pdf"&gt;Rogueware&lt;/a&gt;  (pdf) schemes.&amp;nbsp;Below is an example of the attack we observed today. &amp;nbsp; &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;strong&gt;Most targeted search terms:&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Dallas Cowboys&lt;/li&gt;
&lt;li&gt;NFL&lt;/li&gt;
&lt;li&gt;School&lt;/li&gt;
&lt;li&gt;Emmy Awards&lt;/li&gt;
&lt;li&gt;Autumn Equinox (Mabon)&lt;/li&gt;
&lt;li&gt;Atlanta&lt;/li&gt;
&lt;li&gt;News&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;
..The full list of targeted keywords can be  downloaded here: &lt;a href="http://dl.getdropbox.com/u/1301849/BlackhatSEO3.txt"&gt;BlackhatSEO3.txt&lt;/a&gt; &lt;br /&gt;
&lt;/p&gt;

&lt;strong&gt;Sample search result:&lt;br /&gt;
&lt;/strong&gt;&lt;br /&gt;
  &lt;a href="http://www.flickr.com/photos/lithium-/3946167610/sizes/o/"&gt;&lt;img alt="BHSEO Search Result" border="0" height="68" src="http://farm4.static.flickr.com/3500/3946167610_9827cf3c0e.jpg" width="500" /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
  &lt;strong&gt;Redirection to fake  security (Rogueware) site:&lt;/strong&gt;&lt;br /&gt;
  &lt;br /&gt;
  &lt;a href="http://www.flickr.com/photos/lithium-/3945384803/sizes/o/"&gt;&lt;img alt="Rogueware Site" border="0" height="343" src="http://farm3.static.flickr.com/2494/3945384803_4ab52b828f.jpg" width="500" /&gt;&lt;/a&gt;

&lt;p&gt;&lt;strong&gt;Rogueware:  Adware/PCDefender&lt;/strong&gt;&lt;br /&gt;
&lt;br /&gt;
  &lt;a href="http://www.flickr.com/photos/lithium-/3946167632/sizes/o/in/photostream/"&gt;&lt;img alt="Adware/PC Defender" border="0" height="414" src="http://farm4.static.flickr.com/3498/3946167632_141197666d.jpg" width="500" /&gt;&lt;/a&gt;&lt;br /&gt;
  &lt;strong&gt;&lt;br /&gt;
Tag cloud of targeted terms:&lt;/strong&gt;&lt;br /&gt;
  &lt;a href="http://www.flickr.com/photos/lithium-/3946167600/sizes/o/"&gt;&lt;img alt="Blackhat SEO Tag Cloud" border="0" height="319" src="http://farm4.static.flickr.com/3459/3946167600_907938a5dd.jpg" width="500" /&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=1041" width="1" height="1"&gt;</content><author><name>Sean-Paul Correll</name><uri>http://pandalabs.pandasecurity.com/members/Sean-Paul+Correll.aspx</uri></author><category term="Rogueware" scheme="http://pandalabs.pandasecurity.com/archive/tags/Rogueware/default.aspx" /><category term="Blackhat SEO" scheme="http://pandalabs.pandasecurity.com/archive/tags/Blackhat+SEO/default.aspx" /></entry><entry><title>Hack MySpace, ICQ, and Vkontakte for $100 (50% discount for Russians)</title><link rel="alternate" type="text/html" href="http://pandalabs.pandasecurity.com/archive/Hack-MySpace_2C00_-ICQ_2C00_-and-Vkontakte-for-_2400_100-_2800_50_2500_-discount-for-Russians_2900_.aspx" /><id>http://pandalabs.pandasecurity.com/archive/Hack-MySpace_2C00_-ICQ_2C00_-and-Vkontakte-for-_2400_100-_2800_50_2500_-discount-for-Russians_2900_.aspx</id><published>2009-09-21T19:43:00Z</published><updated>2009-09-21T19:43:00Z</updated><content type="html">&lt;p&gt;The Ukrainian Facebook scam we blogged about on &lt;a href="http://pandalabs.pandasecurity.com/archive/Your-Facebook-account-is-worth-_2400_100.aspx"&gt;Friday&lt;/a&gt; has similar campaigns for MySpace, ICQ, and Vkontakte. All of the scam sites are identical in design and require the  payment of $100 except for the Vkontakte scam site. Vkontakte is a Russian clone of Facebook and the scam offers to hack Vkontakte profiles for 1500 rubles, which is about $50 USD. &lt;/p&gt;

&lt;p&gt;&lt;strong&gt;MySpace&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="http://www.flickr.com/photos/lithium-/3941367423/sizes/o/"&gt;&lt;img border="0" src="http://farm4.static.flickr.com/3465/3941367423_b92dc46946.jpg" /&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;ICQ&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="http://www.flickr.com/photos/lithium-/3941367317/sizes/o/"&gt;&lt;img border="0" src="http://farm4.static.flickr.com/3449/3941367317_b1f97db5d1.jpg" /&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Vkontakte &lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="http://www.flickr.com/photos/lithium-/3941367221/sizes/o/"&gt;&lt;img border="0" src="http://farm3.static.flickr.com/2452/3941367221_d13669b610.jpg" /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;What&amp;#39;s strange here is that the Ukrainian scam crew responsible for these scam sites are making a run at conning Russians, which is a tactic we don&amp;#39;t see very often in the labs.&amp;nbsp; &lt;br /&gt;&lt;/p&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=1040" width="1" height="1"&gt;</content><author><name>Sean-Paul Correll</name><uri>http://pandalabs.pandasecurity.com/members/Sean-Paul+Correll.aspx</uri></author><category term="Scam" scheme="http://pandalabs.pandasecurity.com/archive/tags/Scam/default.aspx" /></entry></feed>