<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://pandalabs.pandasecurity.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>PandaLabs</title><link>http://pandalabs.pandasecurity.com/default.aspx</link><description>, everything you need to know about Internet threats </description><dc:language>en</dc:language><generator>CommunityServer 2.1 SP2 (Build: 61120.2)</generator><item><title>Quarterly Report April-June 2008</title><link>http://pandalabs.pandasecurity.com/archive/Quarterly-Report-April_2D00_June-2008.aspx</link><pubDate>Mon, 07 Jul 2008 06:38:00 GMT</pubDate><guid isPermaLink="false">b262f9bf-63e5-46e5-8a14-4069a6997bc7:892</guid><dc:creator>Luis Corrons</dc:creator><slash:comments>0</slash:comments><comments>http://pandalabs.pandasecurity.com/comments/892.aspx</comments><wfw:commentRss>http://pandalabs.pandasecurity.com/commentrss.aspx?PostID=892</wfw:commentRss><description>&lt;p&gt;It&amp;rsquo;s time to see what has happened in the last three months and what we can expect for the second half of the year. We have been taking a look at the countries with most active malware:&lt;/p&gt;&lt;p&gt;&lt;img alt="Active malware per Country" height="422" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/07/07/Q2%20Active%20malware%20per%20Country.jpg" style="width:634px;height:422px;" title="Active malware per Country" width="634" /&gt;&lt;/p&gt;&lt;p&gt;When we talk about active malware we mean computers that have malware processes running in memory. Yes, it is scary, isn&amp;rsquo;t it? &lt;/p&gt;&lt;p&gt;We also make a review of the main banking Trojan families and their distribution throughout the first half of 2008:&lt;/p&gt;&lt;p&gt;&lt;img alt="Q1+Q2 Distribution of Banking Trojan Families" height="371" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/07/07/Q1+Q2%20Distribution%20of%20Banking%20Trojan%20Families.JPG" style="width:596px;height:371px;" title="Q1+Q2 Distribution of Banking Trojan Families" width="596" /&gt;&lt;/p&gt;&lt;p&gt;Additionally, you can also be informed of the last massive infections via websites, spam evolution, phishing kits, vulnerabilities appeared during these months... Enjoy it!&lt;/p&gt;&lt;p&gt;English:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Spanish:&lt;/p&gt;&lt;p&gt;&lt;a href="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/07/07/Quartely_Report_Q2_PandaLabs_2008.pdf" target="_blank"&gt;&lt;img alt="Q2 Report" height="89" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/07/07/portada_en.gif" title="Q2 Report" width="72" /&gt;&lt;/a&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;a href="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/07/07/Informe_Trimestral_T2_PandaLabs_2008.pdf" target="_blank"&gt;&lt;img height="89" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/07/07/portada_es.gif" style="width:76px;height:89px;" width="76" /&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=892" width="1" height="1"&gt;</description></item><item><title>Independence Day's Worm</title><link>http://pandalabs.pandasecurity.com/archive/Independence-Day_2700_s-Worm.aspx</link><pubDate>Fri, 04 Jul 2008 10:05:00 GMT</pubDate><guid isPermaLink="false">b262f9bf-63e5-46e5-8a14-4069a6997bc7:891</guid><dc:creator>Xabier Francisco</dc:creator><slash:comments>0</slash:comments><comments>http://pandalabs.pandasecurity.com/comments/891.aspx</comments><wfw:commentRss>http://pandalabs.pandasecurity.com/commentrss.aspx?PostID=891</wfw:commentRss><description>&lt;p&gt;&lt;font color="#000000" face="tahoma,arial,helvetica,sans-serif"&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font color="#000000" face="tahoma,arial,helvetica,sans-serif"&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;&lt;font color="#000000"&gt;&lt;span style="font-size:10pt;color:navy;font-family:Arial;"&gt;&lt;font color="#000000"&gt;Once again the Stormworm as in many other special dates reaches our mailboxes in order to infect our computers with malware.&lt;/font&gt;&amp;nbsp;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font color="#000000" face="tahoma,arial,helvetica,sans-serif"&gt;&lt;img alt="Email" height="110" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/07/04/01.Email.JPG" style="width:528px;height:110px;" title="Email" width="528" /&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font color="#000000" face="tahoma,arial,helvetica,sans-serif"&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;&lt;font color="#000000"&gt;&lt;span style="font-size:10pt;color:navy;font-family:Tahoma;"&gt;&lt;font color="#000000"&gt;This time it is related to a very special day in the United States:&lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;&lt;font color="#000000"&gt;&lt;span style="font-size:10pt;color:navy;font-family:Tahoma;"&gt;&lt;font color="#000000"&gt;&lt;em&gt;Independence Day firework broke all records&lt;/em&gt;&lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;&lt;font color="#000000"&gt;&lt;span style="font-size:10pt;color:navy;font-family:Tahoma;"&gt;&lt;font color="#000000"&gt;&lt;em&gt;Amazing Independence Day show&lt;/em&gt;&lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;&lt;font color="#000000"&gt;&lt;span style="font-size:10pt;color:navy;font-family:Tahoma;"&gt;&lt;font color="#000000"&gt;&lt;em&gt;Celebrating the Glory of our Nation&lt;/em&gt;&lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;&lt;font color="#000000"&gt;&lt;span style="font-size:10pt;color:navy;font-family:Tahoma;"&gt;&lt;font color="#000000"&gt;&lt;em&gt;Celebrating 4th of July&lt;/em&gt;&lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;&lt;font color="#000000"&gt;&lt;span style="font-size:10pt;color:navy;font-family:Tahoma;"&gt;&lt;font color="#000000"&gt;&lt;em&gt;Super 4th!&lt;/em&gt;&lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;&lt;font color="#000000"&gt;&lt;span style="font-size:10pt;color:navy;font-family:Tahoma;"&gt;&lt;font color="#000000"&gt;&lt;em&gt;Etc&amp;hellip;&lt;/em&gt;&lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;&lt;font color="#000000"&gt;&lt;span style="font-size:10pt;color:navy;font-family:Tahoma;"&gt;&lt;font color="#000000"&gt;&lt;p&gt;This is what we will view in the web after clicking the link included in these emails:&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;&lt;font color="#000000"&gt;&amp;nbsp;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;&lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;p&gt;&lt;font color="#000000" face="tahoma,arial,helvetica,sans-serif"&gt;&lt;img alt="WWW" height="477" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/07/04/02.WWW.JPG" style="width:552px;height:477px;" title="WWW" width="552" /&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-size:10pt;color:black;font-family:Tahoma;"&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;&lt;font color="#000000"&gt;Evidently, as in many other occasions, it is not an embedded video, so while we are seeing this website, our browser will be trying to install W32/Nurech.BG.worm in our computer.&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-size:10pt;color:black;font-family:Tahoma;"&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;&lt;font color="#000000"&gt;The cases we have seen up to now follow the same pattern, the links point to different websites whose IPs are located in the United States and a malicious file will be downloaded &amp;ldquo;http://xxx.xxx.xxx.xxx/fireworks.exe &amp;rdquo;.&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;font color="#000000" face="tahoma,arial,helvetica,sans-serif"&gt;&lt;img alt="IPs" height="398" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/07/04/03.IPs.JPG" style="width:277px;height:398px;" title="IPs" width="277" /&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=891" width="1" height="1"&gt;</description></item><item><title>World of Authentication</title><link>http://pandalabs.pandasecurity.com/archive/World-of-Authentication.aspx</link><pubDate>Wed, 02 Jul 2008 06:24:00 GMT</pubDate><guid isPermaLink="false">b262f9bf-63e5-46e5-8a14-4069a6997bc7:890</guid><dc:creator>Luis Corrons</dc:creator><slash:comments>0</slash:comments><comments>http://pandalabs.pandasecurity.com/comments/890.aspx</comments><wfw:commentRss>http://pandalabs.pandasecurity.com/commentrss.aspx?PostID=890</wfw:commentRss><description>&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;Those hardcore gamers already know that last weekend the 2008 Blizzard Entertainment Worldwide Invitational took place in Paris. There were very important announcements, as the development of Diablo III. But there was something that did not receive that much publicity, even though IMO it is very important: &lt;a href="http://us.blizzard.com/support/article.xml?articleId=24660&amp;amp;rhtml=true" title="Blizzard Authentication" target="_blank"&gt;Blizzard Authenticator&lt;/a&gt;. &lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="Tahoma"&gt;&lt;img alt="Blizzard Authenticator" height="163" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/07/02/ht.JPG" style="width:175px;height:163px;" title="Blizzard Authenticator" width="175" /&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;Basically, this is a hardware authentication token for World of Warcraft. Two-factor authentication based on hardware generated tokens is not new, but as far as I know it is the first time used in a MMORPG, even in any kind of game. Some banks have been using this kind of security measures for years, while others don&amp;rsquo;t even have two-factor authentication. Just imagine the amount of money that is handled in this game and the real risk that it implies so that Blizzard is offering this solution to the users of World of Warcraft. In the last two years we have seen a huge increase of banking Trojans, as well as malware targetting online games, basically for the two most popular: World of Warcraft and Lineage. &lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;It is very comforting to see that Wizzard is getting involved in their user&amp;acute;s security; many companies should follow Blizzard&amp;#39;s footsteps.&lt;/font&gt;&lt;/p&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=890" width="1" height="1"&gt;</description></item><item><title>Mine is bigger than yours!</title><link>http://pandalabs.pandasecurity.com/archive/Mine-is-bigger-than-yours_2100_.aspx</link><pubDate>Tue, 24 Jun 2008 12:19:00 GMT</pubDate><guid isPermaLink="false">b262f9bf-63e5-46e5-8a14-4069a6997bc7:889</guid><dc:creator>Luis Corrons</dc:creator><slash:comments>0</slash:comments><comments>http://pandalabs.pandasecurity.com/comments/889.aspx</comments><wfw:commentRss>http://pandalabs.pandasecurity.com/commentrss.aspx?PostID=889</wfw:commentRss><description>&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;In the latest months, there have been some discussions about malware figures. My colleague Stuart wrote in the SophosLabs blog a &lt;/font&gt;&lt;a href="http://www.sophos.com/security/blog/2008/04/1291.html" target="_blank"&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;post&lt;/font&gt;&lt;/a&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt; about this, as well as our colleagues at McAfee &lt;/font&gt;&lt;a href="http://www.avertlabs.com/research/blog/index.php/2008/06/19/i-say-we-are-detecting-between-400-000-and-10-000-000-malware/" target="_blank"&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;did&lt;/font&gt;&lt;/a&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;. Today I&amp;rsquo;ve seen a press release from F-Secure, where they &lt;/font&gt;&lt;a href="http://www.f-secure.com/f-secure/pressroom/news/fsnews_20080624_1_eng.html" target="_blank"&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;announce&lt;/font&gt;&lt;/a&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt; the publication of their 2008 first half data security summary (I have to talk to Mikko to see how they can summarize something that hasn&amp;rsquo;t finished yet ;-) &lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;So now we have a small ranking, listed in alphabetical order:&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;F-Secure 900,000&lt;br /&gt;McAfee 400,000 &amp;ndash; 10,000,000&lt;br /&gt;Sophos 4,600,000&lt;br /&gt;Symantec 1,122,311&lt;br /&gt;Panda 13,225,535&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;Q&amp;amp;A:&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;Does this mean that we detect more than they do?&lt;br /&gt;No, it doesn&amp;rsquo;t mean that. It is like comparing apples and oranges.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;So are you detecting less than the others?&lt;br /&gt;No, as said before you shouldn&amp;rsquo;t compare apples and oranges.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;Why some are apples and the other oranges?&lt;br /&gt;You can be counting just files or detections. With one good detection you can detect thousands of malicious files.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;The more signatures a product has, the best the product is?&lt;br /&gt;No. Product A could have X signatures, and product B could have X/2 and detect more than product A. &lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;Finally, when AV companies are talking about this kind of figures, they are referred as detections, malware files or similar. So no proactive technologies are involved in those figures&amp;hellip; and that&amp;rsquo;s part of the solution &amp;ndash; as well as the signatures- for the ever growing malware landscape that we have. Last week, Eva Chen, Trend&amp;rsquo;s Micro CEO said that &lt;/font&gt;&lt;a href="http://www.channelregister.co.uk/2008/06/22/trend_micro_eva_chen/" target="_blank"&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;&amp;lsquo;AV Industry sucks&amp;rsquo;&lt;/font&gt;&lt;/a&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;. Even though I know what she meant and I do agree, I would have used different words. But what I want to point out about this is a different thing --&amp;gt; scanning &amp;quot;in the cloud&amp;quot;. I&amp;rsquo;m really happy to see that we have created a &lt;em&gt;trend&lt;/em&gt; and that now &lt;em&gt;Trend&lt;/em&gt; Micro is following us. I really think that this is the best AV companies can do right now, and I hope the others will follow us too. We &lt;/font&gt;&lt;a href="http://research.pandasecurity.com/archive/Technology-Paper_3A00_-From-AV-to-Collective-Intelligence.aspx" target="_blank"&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;published&lt;/font&gt;&lt;/a&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt; almost one year ago a paper about this, we released a proof of concept of that technology within a memory online scan engine called Nanoscan. Later we applied some of this technology in our 2008 products, and it is completely integrated in our 2009 products, which are right now on &lt;/font&gt;&lt;a href="http://research.pandasecurity.com/archive/Panda-Internet-Security-2009-BETA.aspx" target="_blank"&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;public beta&lt;/font&gt;&lt;/a&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;. Let&amp;rsquo;s see if we can build a safer world!&lt;/font&gt;&lt;/p&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=889" width="1" height="1"&gt;</description></item><item><title>Malicious Spam Related to False Porntube Page</title><link>http://pandalabs.pandasecurity.com/archive/Malicious-Spam-Related-to-False-Porntube-Page.aspx</link><pubDate>Fri, 20 Jun 2008 12:04:00 GMT</pubDate><guid isPermaLink="false">b262f9bf-63e5-46e5-8a14-4069a6997bc7:888</guid><dc:creator>Xabier Francisco</dc:creator><slash:comments>0</slash:comments><comments>http://pandalabs.pandasecurity.com/comments/888.aspx</comments><wfw:commentRss>http://pandalabs.pandasecurity.com/commentrss.aspx?PostID=888</wfw:commentRss><description>&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;It seems that the activity of this type of spamtraps has increased since the first time we detected it last week.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;Like every spam message with malicious intentions, it tries to attract the user&amp;rsquo;s attention with interesting subjects so that they visit the attached link.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;&lt;img height="150" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/06/20/01.JPG" style="width:704px;height:150px;" width="704" /&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;Below we can see some of the subjects used:&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;em&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;&amp;quot;Eiffel Tower suffers structural damage, collapse possible?&amp;quot;&lt;br /&gt;&amp;quot;London rocked by gas attack, army on high alert?&amp;quot;&lt;br /&gt;Britney found hanged in locker room?&lt;br /&gt;Celtics disqualified from NBA title?&lt;br /&gt;China Earthquake claims 1 million lives?&lt;br /&gt;Dan Brown&amp;#39;s latest novel?&lt;br /&gt;Nokia unveils revolutionary new phone design?&lt;br /&gt;Obama withdraws from elections?&lt;/font&gt;&lt;/em&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;The attached links can be different regarding their domain, though those we have seen up to this moment make reference to a file /r.html, which is a fake website of Porntube.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;Once there, an error message will be displayed indicating the user that they need to install a component of Video ActiveX, which will install the file ideo.exe detected as Trj/Exchanger.G&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;&lt;img height="457" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/06/20/02.JPG" style="width:665px;height:457px;" width="665" /&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;Although the malware is hosted in the same domains to which the link of the spam makes reference, it connects to an IP address located in Beijing [ CHINA ] from which the creator probably view the statistics of the infected computers.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;&lt;img height="41" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/06/20/03.JPG" style="width:539px;height:41px;" width="539" /&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;&lt;img height="478" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/06/20/04.JPG" style="width:625px;height:478px;" width="625" /&gt;&lt;/font&gt;&lt;/p&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=888" width="1" height="1"&gt;</description></item><item><title>T2W --&gt; Trojan to Worm</title><link>http://pandalabs.pandasecurity.com/archive/T2W-_2D002D003E00_-Trojan-to-Worm.aspx</link><pubDate>Tue, 17 Jun 2008 16:04:00 GMT</pubDate><guid isPermaLink="false">b262f9bf-63e5-46e5-8a14-4069a6997bc7:887</guid><dc:creator>ocavada</dc:creator><slash:comments>0</slash:comments><comments>http://pandalabs.pandasecurity.com/comments/887.aspx</comments><wfw:commentRss>http://pandalabs.pandasecurity.com/commentrss.aspx?PostID=887</wfw:commentRss><description>&lt;p&gt;We have detected an application whose main function is to turn an executable file into a worm, giving it the capacity to spread itself. Even though it&amp;rsquo;s aim is to give a Trojan the spread capability of&amp;nbsp; a worm, it works with any executable file.&lt;/p&gt;&lt;p&gt;As you can see in the image below, &lt;strong&gt;Constructor/Wormer&lt;/strong&gt; is an eye-catching tool and very easy to use. By checking different flags, you can design a worm with different functionalities, such as compress it with UPX, enable MuteX, select icons, etc.&lt;/p&gt;&lt;p&gt;&lt;img height="601" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/06/17/control_panel.JPG" style="width:703px;height:601px;" width="703" /&gt;&lt;/p&gt;&lt;p&gt;It also has advanced options to select a certain infection date, disable different options of the operating system, such as the Task Manager, the Windows Registry Editor, Folder Options, and different browsers such as Internet Explorer, Firefox or Opera. Additionally, the worms can be configured to display a message when they are run or activate themselves when Windows is started.&lt;/p&gt;&lt;p&gt;One curious option is that you can avoid the infection of removable drives, such as PenDrives, indicating the username and the name of the drive.&lt;/p&gt;&lt;p&gt;The tool seems to have been created in Spain. You can switch the language of the tool to English, Spanish, Portuguese and Catalan. As you can see, nowadays there are tools that allow any user, no matter their technical knowledge, to create malware very easily.&lt;/p&gt;&lt;p&gt;Thanks to Oscar Anduiza for the information.&lt;/p&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=887" width="1" height="1"&gt;</description></item><item><title>Malicious use of Akihabara's killer news</title><link>http://pandalabs.pandasecurity.com/archive/Malicious-use-of-Akihabara_2700_s-killer-news.aspx</link><pubDate>Wed, 11 Jun 2008 10:31:00 GMT</pubDate><guid isPermaLink="false">b262f9bf-63e5-46e5-8a14-4069a6997bc7:886</guid><dc:creator>Xabier Francisco</dc:creator><slash:comments>0</slash:comments><comments>http://pandalabs.pandasecurity.com/comments/886.aspx</comments><wfw:commentRss>http://pandalabs.pandasecurity.com/commentrss.aspx?PostID=886</wfw:commentRss><description>&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;It is surprising how fast the cyber-crooks take advantage of any eye-catching news to distribute malware. Less than two days after the tragic event that took place in Tokyo &amp;ldquo;Tomohiro Kato - Akihabara Killer&amp;rdquo;, we detected an email that used this news as a bait to deceive users.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;The email seemed to come from an address belonging to the RPP news (Radio Programas del Per&amp;uacute;) in order to pass itself as a trustworthy source. However, you can check in the following &lt;/font&gt;&lt;a href="http://www.rpp.com.pe/2008/06/08/siete_muertos_y_diez_heridos_apu&amp;ntilde;alados_por_un_hombre_en_el_centro_de_tokio/nid_127227.html" target="_blank"&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;URL&lt;/font&gt;&lt;/a&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;, which makes reference to the official news published by RPP, that it is totally different to the news included in the malicious email message, where after a brief description of the event, users are enticed to download and see a video regarding this news. However, what they actually download and install in the system is the Trojan QHost.IH.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;&lt;img height="458" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/06/11/01.JPG" style="width:581px;height:458px;" width="581" /&gt;&amp;nbsp;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;This malware is designed to modify the hosts file by adding four fake websites of a certain banking entity. This way, if users visit any of the websites included in the hosts file, they will not be redirected to the original one but to another imitating the original website.&lt;/font&gt;&lt;/p&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=886" width="1" height="1"&gt;</description></item><item><title>Another trojan creator...</title><link>http://pandalabs.pandasecurity.com/archive/Another-trojan-creator_2E002E002E00_.aspx</link><pubDate>Mon, 09 Jun 2008 16:33:00 GMT</pubDate><guid isPermaLink="false">b262f9bf-63e5-46e5-8a14-4069a6997bc7:885</guid><dc:creator>Xabier Francisco</dc:creator><slash:comments>0</slash:comments><comments>http://pandalabs.pandasecurity.com/comments/885.aspx</comments><wfw:commentRss>http://pandalabs.pandasecurity.com/commentrss.aspx?PostID=885</wfw:commentRss><description>&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;Everybody knows that nowadays it is very easy to create malicious programs or new variants of malware generally with the help of programs like virus constructors, which are publicly released by real experts in creating malware.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;As we mentioned in a previously published &lt;/font&gt;&lt;a href="http://pandalabs.pandasecurity.com/archive/Multi-AVs-Scanners.aspx" target="_blank"&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;post&lt;/font&gt;&lt;/a&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;, these &amp;ldquo;beginners&amp;rdquo; in creating malware use different antivirus scanners with which they test their creations until they are undetectable.&amp;nbsp;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;In this case, one of these tools is Constructor/Turkojan, which offers new different functionalities with each version, currently the v4.0. &lt;/font&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;Among the options offered, the following are included: &lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;Remote Desktop / Webcam Streaming / Audio Streaming / Remote passwords / MSN Sniffer / Remote Shell / Advanced File Manager / Online &amp;amp; Offline keylogger / Information about remote computer / Etc..&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;&lt;img height="624" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/06/09/01.JPG" style="width:551px;height:624px;" width="551" /&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;You may be wondering which benefits the author gains with this tool.&amp;nbsp; Obviously, there is a financial reason behind this. Almost all users who design this type of tools offer versions with different services, which include customized support depending on the sum of money paid.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;&lt;img height="677" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/06/09/02.JPG" style="width:595px;height:677px;" width="595" /&gt;&amp;nbsp;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;This is a clear example that shows that cybercrooks are more are more professional and that there is a real organized business which looks for the profitability of their creations.&lt;br /&gt;&lt;/font&gt;&lt;/p&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=885" width="1" height="1"&gt;</description></item><item><title>Be careful with Tixcet.A</title><link>http://pandalabs.pandasecurity.com/archive/Be-careful-with-Tixcet.A.aspx</link><pubDate>Mon, 02 Jun 2008 08:45:00 GMT</pubDate><guid isPermaLink="false">b262f9bf-63e5-46e5-8a14-4069a6997bc7:884</guid><dc:creator>ocavada</dc:creator><slash:comments>0</slash:comments><comments>http://pandalabs.pandasecurity.com/comments/884.aspx</comments><wfw:commentRss>http://pandalabs.pandasecurity.com/commentrss.aspx?PostID=884</wfw:commentRss><description>&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-size:10pt;font-family:Tahoma;"&gt;PandaLabs has recently discovered the worm Tixcet.A&lt;/span&gt;&lt;span style="font-family:Tahoma;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:5pt 0cm;"&gt;&lt;span style="font-size:10pt;font-family:Tahoma;"&gt;It is a very destructive worm, as it deletes files with several extensions and replaces them with a copy of itself keeping the same name as the original files. Among the affected extensions are the following: .DOC, .PPT, .MP3, .MOV, .ZIP and .JPG. This means that we can lose our photos, songs, Word documents and other important files for us.&lt;/span&gt;&lt;span style="font-family:Tahoma;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:5pt 0cm;"&gt;&lt;span style="font-size:10pt;font-family:Tahoma;"&gt;Additionally, it does not allow files to be copied, as it disables the option &lt;em&gt;&lt;span style="font-family:Tahoma;"&gt;Paste&lt;/span&gt;&lt;/em&gt; and contents to be copied, as the text that is copied is not the selected by the user but one selected by the worm.&lt;/span&gt;&lt;span style="font-family:Tahoma;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:5pt 0cm;"&gt;&lt;span style="font-size:10pt;font-family:Tahoma;"&gt;It reaches the computer passing itself off as a Word document in order to deceive users. &lt;/span&gt;&lt;span style="font-family:Tahoma;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:5pt 0cm;"&gt;&lt;span style="font-size:10pt;font-family:Tahoma;"&gt;It also creates several files that contain a signature of the author, like the following: &lt;/span&gt;&lt;span style="font-family:Tahoma;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;/span&gt;&lt;p class="MsoNormal" style="margin:5pt 0cm;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:5pt 0cm;"&gt;&lt;img alt="tixcet_1.jpg" height="50" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/06/02/tixcet_1.jpg" style="width:149px;height:50px;" title="tixcet_1.jpg" width="149" /&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;img height="481" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/06/02/tixcet_2.jpg" style="width:498px;height:481px;" width="498" /&gt;&lt;/p&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;p&gt;&lt;span style="font-size:10pt;font-family:Tahoma;"&gt;PandaLabs &lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?lst=det&amp;amp;idvirus=193879" title="has analysed this worm deeply" target="_blank"&gt;has analysed this worm deeply&lt;/a&gt; and has prepared an &lt;a href="http://www.pandasecurity.com/img/enc/TixcetA.wmv" title="interesting video" target="_blank"&gt;interesting video&lt;/a&gt; where we can see some of the actions it carries out in the affected computers.&lt;/span&gt;&lt;/p&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:10pt;font-family:Arial;"&gt;&lt;/span&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=884" width="1" height="1"&gt;</description></item><item><title>Lost in Translation (II)</title><link>http://pandalabs.pandasecurity.com/archive/Lost-in-Translation-_2800_II_2900_.aspx</link><pubDate>Tue, 27 May 2008 10:25:00 GMT</pubDate><guid isPermaLink="false">b262f9bf-63e5-46e5-8a14-4069a6997bc7:883</guid><dc:creator>Luis Corrons</dc:creator><slash:comments>0</slash:comments><comments>http://pandalabs.pandasecurity.com/comments/883.aspx</comments><wfw:commentRss>http://pandalabs.pandasecurity.com/commentrss.aspx?PostID=883</wfw:commentRss><description>&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;As promised, here you can see some pictures. This is the Grand Prince Hotel Akasaka, where the meeting is taking place:&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;&lt;img height="700" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/05/27/Tokyo01.jpg" style="width:525px;height:700px;" width="525" /&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;This is me inside the hotel:&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;&lt;img height="700" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/05/27/Tokyo02.jpg" style="width:525px;height:700px;" width="525" /&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;This is the Tokyo Tower, a 250-meter-high tower from which you can see the whole city:&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;&lt;img height="700" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/05/27/Tokyo03.jpg" style="width:525px;height:700px;" width="525" /&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;Finally, I recommend you to visit Japan, it&amp;rsquo;s an unforgettable experience:&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;&lt;img height="525" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/05/27/Tokyo04.jpg" style="width:700px;height:525px;" width="700" /&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;Well, this is all for the moment, you&amp;rsquo;ll hear from me soon.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;Signing off,&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;Luis&lt;/font&gt;&lt;/p&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=883" width="1" height="1"&gt;</description></item></channel></rss>