<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://pandalabs.pandasecurity.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>PandaLabs : Hostfresh</title><link>http://pandalabs.pandasecurity.com/archive/tags/Hostfresh/default.aspx</link><description>Tags: Hostfresh</description><dc:language>en</dc:language><generator>CommunityServer 2.1 SP2 (Build: 61120.2)</generator><item><title>Facebook Malware Refocusing on Bank of America </title><link>http://pandalabs.pandasecurity.com/archive/Facebook-Malware-Refocusing-on-Bank-of-America-.aspx</link><pubDate>Sat, 14 Mar 2009 00:32:00 GMT</pubDate><guid isPermaLink="false">b262f9bf-63e5-46e5-8a14-4069a6997bc7:983</guid><dc:creator>Sean-Paul Correll</dc:creator><slash:comments>0</slash:comments><comments>http://pandalabs.pandasecurity.com/comments/983.aspx</comments><wfw:commentRss>http://pandalabs.pandasecurity.com/commentrss.aspx?PostID=983</wfw:commentRss><description>
&lt;p&gt;The perpetrators behind the &lt;a href="http://pandalabs.pandasecurity.com/archive/Malware-Impersonates-Classmates-and-Facebook-to-Deliver-Password-Stealing-Trojan.aspx"&gt;recent  Classmates and Facebook Malware incident&lt;/a&gt; are now refocusing their attack on  Bank of America customers.&amp;nbsp; The new  website is designed to look like a Bank of America Help page and reads:&lt;br /&gt;
&amp;ldquo;You have not been permitted to access the Bank of America  Direct&amp;reg; login page because your browser did not provide a valid digital  certificate. In order to access Bank of America Direct, you must have a  valid Digital Certificate installed on your PC.&amp;nbsp;  For help, please select from the help links below.&amp;rdquo;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://support.us.pandasecurity.com/blog/bofabig.png"&gt;&lt;img alt="Bank of America Malware Site" border="0" height="599" src="http://support.us.pandasecurity.com/blog/bofasmall.png" width="516" /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
  The page includes a fake video which is labeled as an  &amp;ldquo;Installation Demo&amp;rdquo; but points to a Malicious Executable named  Adobeflashplayer.exe, which we detect as &lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?lst=vis&amp;amp;idvirus=206993&amp;amp;sitepanda=particulares" title="Trj/Spyforms.BZ" target="_blank"&gt;Trj/Spyforms.BZ&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Trj/Spyforms.BZ is primarily distributed through links in  spam e-mails and the Trojan is designed to monitor network traffic and steal  ftp, icq, pop3, and imap passwords.&amp;nbsp; The stolen  data is then sent back to a server located in Hong Kong.&amp;nbsp; &lt;br /&gt;
&lt;/p&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=983" width="1" height="1"&gt;</description><category domain="http://pandalabs.pandasecurity.com/archive/tags/Malware/default.aspx">Malware</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Hostfresh/default.aspx">Hostfresh</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Spyforms/default.aspx">Spyforms</category></item><item><title>Malware Impersonates Classmates and Facebook Websites to Deliver Password Stealing Trojan</title><link>http://pandalabs.pandasecurity.com/archive/Malware-Impersonates-Classmates-and-Facebook-to-Deliver-Password-Stealing-Trojan.aspx</link><pubDate>Thu, 12 Mar 2009 08:38:00 GMT</pubDate><guid isPermaLink="false">b262f9bf-63e5-46e5-8a14-4069a6997bc7:981</guid><dc:creator>Sean-Paul Correll</dc:creator><slash:comments>0</slash:comments><comments>http://pandalabs.pandasecurity.com/comments/981.aspx</comments><wfw:commentRss>http://pandalabs.pandasecurity.com/commentrss.aspx?PostID=981</wfw:commentRss><description>&lt;p&gt;&lt;br /&gt;
  Websites  designed to look like Classmates.com and Facebook are currently being used to  distribute a password stealing Trojan, which we detect as &lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?lst=vis&amp;amp;idvirus=206993&amp;amp;sitepanda=particulares"&gt;Trj/Spyforms.BZ&lt;/a&gt;. &amp;nbsp;&amp;nbsp;Some of you may remember the Spyforms Malware  family from a &lt;a href="http://pandalabs.pandasecurity.com/archive/Barack-Obama_2700_s-Spam-_2600_-Malware-Campaign.aspx"&gt;previous  incident&lt;/a&gt; involving Barack Obama spam campaigns. In this most recent  incident, the malicious web links are still primarily distributed via spam  e-mails. Once clicked, the victim is presented with a realistic looking  Classmates or Facebook website.&amp;nbsp; The website  contains a fake YouTube video, which prompts a dialog stating &amp;ldquo;Please Download  correct Flash Movie Player!&amp;nbsp;  Installation: Double-click the downloaded installer.&amp;nbsp; Follow the on-screen instructions!&amp;rdquo; and  attempts to download a file named Adobemedia10.exe or Adobemedia11.exe.&amp;nbsp; &lt;br /&gt;
  &lt;br /&gt;
  &lt;img alt="Fake Classmates.com Malware Site" border="0" height="488" src="http://support.us.pandasecurity.com/Blog/classmates.jpg" width="624" /&gt; &lt;br /&gt;
  &lt;br /&gt;
  &lt;img alt="Fake Facebook Malware Site" border="0" height="486" src="http://support.us.pandasecurity.com/Blog/facebook.jpg" width="624" /&gt;&lt;br /&gt;
  &lt;br /&gt;
Once installed, the Trojan intercepts network  traffic in order to obtain ftp, icq, pop3, and imap passwords and then sends  the data back to a server in a Hong Kong based ISP (HOSTFRESH).&amp;nbsp; You may recall the last major Malware  incident involving the Hong Kong based ISP, which was one of the providers  involved in the malware distribution operation taking place inside of the &lt;a href="http://hostexploit.com/downloads/Atrivo%20white%20paper%20082808ac.pdf"&gt;Atrivo/Intercage&lt;/a&gt; network.
&lt;/p&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=981" width="1" height="1"&gt;</description><category domain="http://pandalabs.pandasecurity.com/archive/tags/Social+Networks/default.aspx">Social Networks</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Facebook.com/default.aspx">Facebook.com</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Hostfresh/default.aspx">Hostfresh</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Spyforms/default.aspx">Spyforms</category></item></channel></rss>