An explosive cocktail: MySecuWaloader
In this post we are going to prepare a cocktail using 4 ingredients. We’ve called it MySecuWaloader. Now you’ll find out why. First of all, put into the cocktail shaker a BlackHat SEO attack together with a sample of rogueware and see the result: If you search for any the following group of keywords related [...]
Don’t play with Natural Disasters!!
We want to warn you of an email message in Spanish we’ve received with the subject ( Urgente ) Posible Terremoto y Tsunami con un 89 % de efectividad and that is of course false. The message consists of different images and informs users about an alert of earthquake and tsunami in Chile. Besides, it [...]
Social engineering, PDFs and banking Trojans
A few days ago our colleague Oscar received an email inviting him to access a Web page by clicking on a link. This is not new. However, on clicking on the link, the following page was displayed (don’t try this at home, kids ): As you can see, the page includes a download window inviting [...]
Demonstrating the Latest IE 0-day Vulnerability
Yesterday, Microsoft issued a security advisory for an unpatched and actively exploited invalid reference pointer vulnerability in the Internet Explorer 6 and 7 web browsers. In the attack we observed, the exploit code will load the TDSS.CQ trojan, which is designed to steal personal and sensitive data. Panda customers are already protected against the threat, [...]
Fake IRS Notifications
Fake IRS notification e-mails have been in circulation on the Internet over the past few weeks. We've monitored the situation closely and have observed 30 active domain names currently spreading the Zeus trojan affiliated with the spam campaign, as well as 300 links used in the attack over the past month. The e-mail arrives as [...]
- Comments Off
Rogue ScanVirus site impersonates SaaS Anti-Virus
Today we discovered a new site using an interesting tactic to trick users into infecting themselves with malware. This time the cyber-criminals opted to pretend to be a Software as a Service (SaaS) Anti-Virus solution. The "Scan Virus" website uses several legitimate Anti-Malware logos and badges in order to gain the victims confidence. Immediately upon [...]
- Comments Off
