<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://pandalabs.pandasecurity.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>PandaLabs : Malware</title><link>http://pandalabs.pandasecurity.com/archive/tags/Malware/default.aspx</link><description>Tags: Malware</description><dc:language>en</dc:language><generator>CommunityServer 2.1 SP2 (Build: 61120.2)</generator><item><title>Zero day in MSVIDCTL.DLL</title><link>http://pandalabs.pandasecurity.com/archive/Zero-day-in-MSVIDCTL.DLL.aspx</link><pubDate>Wed, 08 Jul 2009 07:21:00 GMT</pubDate><guid isPermaLink="false">b262f9bf-63e5-46e5-8a14-4069a6997bc7:1014</guid><dc:creator>Luis Corrons</dc:creator><slash:comments>0</slash:comments><comments>http://pandalabs.pandasecurity.com/comments/1014.aspx</comments><wfw:commentRss>http://pandalabs.pandasecurity.com/commentrss.aspx?PostID=1014</wfw:commentRss><description>&lt;p&gt;A couple of days ago we started spotting a new vulnerability affecting Microsoft Video ActiveX Control. Even though it&amp;#39;s been said there are thousands of web sites affected, they are only a&amp;nbsp;few dozens and most of them are in China: Anyway, it is a matter of time to see this attack expanding worldwide. We&amp;#39;ve seen this zero day installing a Lineage Trojan, but this could change and cybercriminals could install any kind of malware. &lt;/p&gt;&lt;p&gt;Microsoft has published an &lt;a href="http://www.microsoft.com/technet/security/advisory/972890.mspx" target="_blank"&gt;advisory&lt;/a&gt; with a workaround while they prepare a final solution. An important message to everyone: please apply this workaround ASAP. &lt;/p&gt;&lt;p&gt;If you are a Panda user with TruPrevent Technologies, then you are not in a hurry, as it is proactively stopping it. The best thing is that you don&amp;#39;t need to install some kind of beta or technology preview, it just works in all of our consumer and corporate products as long as they have enabled TruPrevent. No matter which version you have installed, it covers not only the brand new 2010 products but any old version with TruPrevent. &lt;/p&gt;&lt;p&gt;Sean-Paul shows you here why and how you are protected:&lt;/p&gt;&lt;p&gt;&lt;a href="http://vimeo.com/5500638" target="_blank"&gt;&lt;img height="377" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2009/07/08/TruPrevent.jpg" width="505" /&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=1014" width="1" height="1"&gt;</description><category domain="http://pandalabs.pandasecurity.com/archive/tags/Vulnerabilities+_2600_amp_3B00_+Exploits/default.aspx">Vulnerabilities &amp;amp; Exploits</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Malware/default.aspx">Malware</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Video/default.aspx">Video</category></item><item><title>New Storm Worm: Waledacs</title><link>http://pandalabs.pandasecurity.com/archive/New-Storm-Worm_3A00_-Waledacs.aspx</link><pubDate>Mon, 06 Jul 2009 07:53:00 GMT</pubDate><guid isPermaLink="false">b262f9bf-63e5-46e5-8a14-4069a6997bc7:1011</guid><dc:creator>Asier Martínez</dc:creator><slash:comments>0</slash:comments><comments>http://pandalabs.pandasecurity.com/comments/1011.aspx</comments><wfw:commentRss>http://pandalabs.pandasecurity.com/commentrss.aspx?PostID=1011</wfw:commentRss><description>&lt;p&gt;After several months of calm, a new Waledac campaign has just started. This time a significant date has been used as social engineering: the Independence Day celebrated on 4th of July.&lt;/p&gt;&lt;p&gt;&lt;br /&gt;Nearly 30 domains are being used to spread this malware using the following interface:&lt;/p&gt;&lt;p&gt;&lt;img alt="Waledacs" height="527" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2009/07/06/waledacs.PNG" title="Waledacs" width="610" /&gt;&lt;/p&gt;&lt;p&gt;After clicking the video, a message will be displayed to download an executable file. The name it uses are the following: fireworks.exe, video.exe, install.exe, patch.exe, setup.exe and run.exe.&lt;br /&gt;&lt;br /&gt;The affected computer sends spam messages like this: &lt;/p&gt;&lt;p&gt;&lt;img height="431" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2009/07/06/email.png" width="405" /&gt;&amp;nbsp;&lt;br /&gt;&lt;/p&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=1011" width="1" height="1"&gt;</description><category domain="http://pandalabs.pandasecurity.com/archive/tags/Malware/default.aspx">Malware</category></item><item><title>HAMLET. "Something is rotten in the state of Malware"</title><link>http://pandalabs.pandasecurity.com/archive/HAMLET.-_2200_Something-is-rotten-in-the-state-of-Malware_2200_.aspx</link><pubDate>Thu, 23 Apr 2009 17:54:00 GMT</pubDate><guid isPermaLink="false">b262f9bf-63e5-46e5-8a14-4069a6997bc7:995</guid><dc:creator>Luis Corrons</dc:creator><slash:comments>0</slash:comments><comments>http://pandalabs.pandasecurity.com/comments/995.aspx</comments><wfw:commentRss>http://pandalabs.pandasecurity.com/commentrss.aspx?PostID=995</wfw:commentRss><description>&lt;p&gt;Written on behalf of Jos&amp;eacute; Julio Ruiz de Loizaga.&amp;nbsp;&lt;/p&gt;&lt;p&gt;Today being the birthday of William Shakespeare, I felt the urge to write this post.&amp;nbsp; When reversing files, one is prepared to find anything - well, almost anything. I was analyzing a dll and was surprised to find passages from Hamlet.&amp;nbsp; At first I thought &amp;quot;My God, a trojan that promotes literacy, how odd.&amp;quot; My surprise increased when the next files, two additional dlls, also contained fragments of The Bard&amp;#39;s prose.&lt;/p&gt;&lt;p&gt;&lt;img height="138" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2009/04/23/Hamlet1.png" width="633" /&gt;&lt;br /&gt;First dll.&lt;/p&gt;&lt;p&gt;It was clear that these three files were related.&amp;nbsp; There were two possibilities, either the malware author was a fan of sixteenth century renaissance literature, or that the text was used to make detection more difficult.&lt;/p&gt;&lt;p&gt;This method has been seen before in phishing emails.&amp;nbsp; Anti-phishing engines look at keywords in the body of a message.&amp;nbsp; When these words are found, they are correlated to the length of the message.&amp;nbsp; In other words, a keyword has greater weight the more times it is repeated in a short message, which is why it is not unusual to find phishing emails with some literary text rendered white, so as to be invisible to the reader.&amp;nbsp; Although the recipient does not see the extra words, the anti-phishing engine is fooled by the additional words.&lt;/p&gt;&lt;p&gt;&lt;img height="165" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2009/04/23/Hamlet2.png" style="width:637px;height:165px;" width="637" /&gt;&amp;nbsp;&lt;br /&gt;Second dll.&lt;/p&gt;&lt;p&gt;This technique isn&amp;#39;t exactly the same, but it has the same goal; to trick the antivirus.&amp;nbsp; In this case, the signature file engine is the target.&amp;nbsp; The additional text is inserted with the intention of changing the file&amp;#39;s signature, thereby avoiding detection.&amp;nbsp; The truth is that this is an interesting and educational way of doing so.&lt;/p&gt;&lt;p&gt;&lt;img height="73" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2009/04/23/Hamlet3.png" style="width:629px;height:73px;" width="629" /&gt;&amp;nbsp;&lt;br /&gt;Third dll.&lt;/p&gt;&lt;p&gt;P.S., I would have personally chosen &amp;quot;100 Years of Solitude&amp;quot;, but well, &amp;quot;Hamlet&amp;quot; is not bad either.&lt;/p&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=995" width="1" height="1"&gt;</description><category domain="http://pandalabs.pandasecurity.com/archive/tags/Malware/default.aspx">Malware</category></item><item><title>New waledac's campaign</title><link>http://pandalabs.pandasecurity.com/archive/New-waledac_2700_s-campaign.aspx</link><pubDate>Thu, 16 Apr 2009 08:00:00 GMT</pubDate><guid isPermaLink="false">b262f9bf-63e5-46e5-8a14-4069a6997bc7:992</guid><dc:creator>Asier Martínez</dc:creator><slash:comments>0</slash:comments><comments>http://pandalabs.pandasecurity.com/comments/992.aspx</comments><wfw:commentRss>http://pandalabs.pandasecurity.com/commentrss.aspx?PostID=992</wfw:commentRss><description>
&lt;p&gt;Waledac family activity has increased during the last months. The malware creators have been using several social engineering techniques to spread these samples: important dates like Christmas and Valentine&amp;rsquo;s Day, important events such as the appointment of Barack Obama as president of the United States or fake news.&lt;/p&gt;

&lt;p&gt;&lt;img align="middle" alt="Waledacs" height="584" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2009/04/16/waledacs.png" style="width:600px;height:584px;" title="Waledacs" width="600" /&gt;&lt;/p&gt;

&lt;p&gt;Currently, the technique is to offer a service that allows someone to read the sms received in a certain phone number. Obviously, it is a completely fake service and it could even be described as illegal and immoral. After accessing the website, downloading and running the software, the computer is infected and immediately starts hosting the infection website and executable on the victims computer.&lt;/p&gt;

&lt;p&gt;&amp;nbsp;&lt;strong&gt;Visualization&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;Snapshot of the Waledac Network:&lt;br /&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="http://support.us.pandasecurity.com/blog/waledac_au.png"&gt;&lt;img alt="Waledac.AU Snapshot" border="0" src="http://support.us.pandasecurity.com/blog/waledac_au_small.png" /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;/p&gt;

&lt;p&gt;The main function of the Waledac family, besides its own propagation, is to send spam messages to the email accounts obtained from the infected computer. Additionally, it can carry out other malicious actions, such as downloading malware, opening ports in order to receive instructions (acting as a botnet) and stealing passwords which are then sent to remote URLs.&lt;/p&gt;

&lt;p&gt;&lt;img alt="Emails" height="584" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2009/04/16/emails2.png" style="width:600px;height:584px;" title="Emails" width="600" /&gt;&lt;/p&gt;

&lt;p&gt;The following graph represents the evolution of the files detected as Waledac received in our inboxes during the last three months:&lt;/p&gt;

&lt;p&gt;&lt;img alt="Evolution" height="291" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2009/04/16/evolucion.png" style="width:483px;height:291px;" title="Evolution" width="483" /&gt;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Taking into account the data regarding the first two weeks of April, there has been an increase of almost 200% comparing with February&amp;#39;s figures.&lt;/p&gt;

&lt;p&gt;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Which will be the next subject used by the malware creators to spread this worm?&amp;nbsp; We&amp;rsquo;ll know it soon&amp;hellip;&lt;/p&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=992" width="1" height="1"&gt;</description><category domain="http://pandalabs.pandasecurity.com/archive/tags/Malware/default.aspx">Malware</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/SMS/default.aspx">SMS</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Fast-flux/default.aspx">Fast-flux</category></item><item><title>Chapter 2. The Conficker countdown melodrama.</title><link>http://pandalabs.pandasecurity.com/archive/Chapter-2.-The-Conficker-countdown-melodrama_2E00_.aspx</link><pubDate>Tue, 31 Mar 2009 15:27:00 GMT</pubDate><guid isPermaLink="false">b262f9bf-63e5-46e5-8a14-4069a6997bc7:988</guid><dc:creator>Luis Corrons</dc:creator><slash:comments>0</slash:comments><comments>http://pandalabs.pandasecurity.com/comments/988.aspx</comments><wfw:commentRss>http://pandalabs.pandasecurity.com/commentrss.aspx?PostID=988</wfw:commentRss><description>&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;The melodramatic Conficker countdown is starting to resemble one of those never-ending TV soap operas; everyone is talking about it, but it never draws to an end. Well, at last the countdown is in the final straight, because if not we could end up with mass hysteria.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;So let&amp;#39;s see what new information there is about Conficker. It would seem that some opportunists are taking advantage of the notoriety of Conficker, downloading malware onto computers from domains that are ranked highly in Google searches for the name of this virus. It&amp;rsquo;s not surprising, when you see how widely the news is being reported.&amp;nbsp; Google Trends illustrates the point:&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;&lt;img height="260" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2009/03/31/Google1.png" width="580" /&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;What is most interesting is the ranking of countries where this information is being most widely reported, and where most people are searching for this information. Bearing in mind the number of domains that are downloading malware by exploiting the interest in Conficker, without actually having any connection with it, it is likely that although people in these countries may escape the wrath of Conficker, there may still be users who have downloaded other Trojans simply by searching for news about Conficker&amp;hellip; Ironic really. Perhaps on April 2 we will be talking about another epidemic in Indonesia or Austria&amp;hellip;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;&lt;img height="287" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2009/03/31/Google2.png" style="width:339px;height:287px;" width="339" /&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;What new information is there about Conficker? Absolutely none, other than everyone is waiting with baited breath to see when the apocalypse starts. This all takes me back to when, in the laboratory, we had a calendar for marking the payload dates of notorious viruses such as Friday 13 or Barrotes. So does this mean we are returning to the days of epidemics with payloads and countdowns? &lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;Paradoxically, while we are all waiting to see what happens tomorrow, who knows what is actually going on in the background, and how many people are lining their pockets thanks to Conficker. And to get back to soap operas, what are the odds on a happy ending to the Conficker saga?&lt;/font&gt;&lt;/p&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=988" width="1" height="1"&gt;</description><category domain="http://pandalabs.pandasecurity.com/archive/tags/Malware/default.aspx">Malware</category></item><item><title>Facebook Malware Refocusing on Bank of America </title><link>http://pandalabs.pandasecurity.com/archive/Facebook-Malware-Refocusing-on-Bank-of-America-.aspx</link><pubDate>Sat, 14 Mar 2009 00:32:00 GMT</pubDate><guid isPermaLink="false">b262f9bf-63e5-46e5-8a14-4069a6997bc7:983</guid><dc:creator>Sean-Paul Correll</dc:creator><slash:comments>0</slash:comments><comments>http://pandalabs.pandasecurity.com/comments/983.aspx</comments><wfw:commentRss>http://pandalabs.pandasecurity.com/commentrss.aspx?PostID=983</wfw:commentRss><description>
&lt;p&gt;The perpetrators behind the &lt;a href="http://pandalabs.pandasecurity.com/archive/Malware-Impersonates-Classmates-and-Facebook-to-Deliver-Password-Stealing-Trojan.aspx"&gt;recent  Classmates and Facebook Malware incident&lt;/a&gt; are now refocusing their attack on  Bank of America customers.&amp;nbsp; The new  website is designed to look like a Bank of America Help page and reads:&lt;br /&gt;
&amp;ldquo;You have not been permitted to access the Bank of America  Direct&amp;reg; login page because your browser did not provide a valid digital  certificate. In order to access Bank of America Direct, you must have a  valid Digital Certificate installed on your PC.&amp;nbsp;  For help, please select from the help links below.&amp;rdquo;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://support.us.pandasecurity.com/blog/bofabig.png"&gt;&lt;img alt="Bank of America Malware Site" border="0" height="599" src="http://support.us.pandasecurity.com/blog/bofasmall.png" width="516" /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
  The page includes a fake video which is labeled as an  &amp;ldquo;Installation Demo&amp;rdquo; but points to a Malicious Executable named  Adobeflashplayer.exe, which we detect as &lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?lst=vis&amp;amp;idvirus=206993&amp;amp;sitepanda=particulares" title="Trj/Spyforms.BZ" target="_blank"&gt;Trj/Spyforms.BZ&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Trj/Spyforms.BZ is primarily distributed through links in  spam e-mails and the Trojan is designed to monitor network traffic and steal  ftp, icq, pop3, and imap passwords.&amp;nbsp; The stolen  data is then sent back to a server located in Hong Kong.&amp;nbsp; &lt;br /&gt;
&lt;/p&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=983" width="1" height="1"&gt;</description><category domain="http://pandalabs.pandasecurity.com/archive/tags/Malware/default.aspx">Malware</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Hostfresh/default.aspx">Hostfresh</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Spyforms/default.aspx">Spyforms</category></item><item><title>ID Theft Malware is Infecting Computers at Alarming Rates</title><link>http://pandalabs.pandasecurity.com/archive/ID-Theft-Malware-is-Infecting-Computers-at-Alarming-Rates.aspx</link><pubDate>Mon, 09 Mar 2009 21:54:00 GMT</pubDate><guid isPermaLink="false">b262f9bf-63e5-46e5-8a14-4069a6997bc7:980</guid><dc:creator>Sean-Paul Correll</dc:creator><slash:comments>0</slash:comments><comments>http://pandalabs.pandasecurity.com/comments/980.aspx</comments><wfw:commentRss>http://pandalabs.pandasecurity.com/commentrss.aspx?PostID=980</wfw:commentRss><description>Today
we&amp;#39;re announcing results of a study that analyzed 67 million computers in 2008
and revealed that 1.1 percent of the worldwide population of Internet users
have been actively exposed to identity theft malware. We predict that the
infection rate will increase by an additional 336 percent per month throughout
2009, based on the trend of the previous 14 months.


&lt;p&gt;Here
are the highlights from our study on the evolution of online identity theft:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;-&lt;/strong&gt;Over
three million of the audited users in the U.S. and more than 10 million users
worldwide were infected with active identity theft-based malware last year&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;-&lt;/strong&gt;1.07%
of all PCs scanned in 2008 were infected with active malware (resident in
memory during the scan) related to identity theft, such as banker Trojans&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;-&lt;/strong&gt;35%
of the infected PCs had up-to-date antivirus software installed &lt;/p&gt;

&lt;p&gt;&lt;strong&gt;-&lt;/strong&gt;The
number of PCs infected with identify theft malware increased by 800 percent
from the first half of 2008 to the second half&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;-&lt;/strong&gt;Arizona, California and Florida
continue to be the states with the highest per-capita incidence of reported
identity theft&lt;/p&gt;


&lt;p&gt;Active
malware means malware that is loaded into the PC&amp;#39;s memory and actively running
as a process. For example, users of PCs infected with this type of identity
theft malware who utilize online services such as shopping, banking, and social
networking, have had their identities stolen in some fashion. According to the
Federal Trade Commission (FTC), the average time victims spend resolving identity
theft issues is &lt;a href="http://www.consumer.gov/idtheft/pdf/ftc_06.16.05.pdf"&gt;30
hours per incident&lt;/a&gt;. The cumulative cost in hours alone from identity theft
related malware based on Panda Security&amp;#39;s projected infection rate could reach
90 million hours.&amp;nbsp; &lt;/p&gt;


&lt;p&gt;The
study revealed that an alarming 35 percent of the PCs infected with this type
of malware were using up-to-date antivirus software. Antivirus labs are
receiving a massive amount of new malware samples each day (22,000 new samples
per day according to PandaLabs), and antivirus vendors are continually updating
their services to keep up with the overwhelming volume of new malware surfacing
each day. AV detection labs such as PandaLabs have made advances in automated
detection and classification capabilities. These new detection methods as well
as improved surveillance and cloud-based detection techniques have reduced the
risk of individual identity theft incidents and its associated costs. Some
global banks, notably in Brazil,
have made changes to banking authentications using electronic tokens and
virtual keyboards, but these approaches have been slow to be adopted in the U.S. &lt;/p&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=980" width="1" height="1"&gt;</description><category domain="http://pandalabs.pandasecurity.com/archive/tags/Malware/default.aspx">Malware</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/identity+theft/default.aspx">identity theft</category></item><item><title>Malware in Social Media</title><link>http://pandalabs.pandasecurity.com/archive/Malware-in-Social-Media.aspx</link><pubDate>Thu, 26 Feb 2009 17:17:00 GMT</pubDate><guid isPermaLink="false">b262f9bf-63e5-46e5-8a14-4069a6997bc7:972</guid><dc:creator>Sean-Paul Correll</dc:creator><slash:comments>0</slash:comments><comments>http://pandalabs.pandasecurity.com/comments/972.aspx</comments><wfw:commentRss>http://pandalabs.pandasecurity.com/commentrss.aspx?PostID=972</wfw:commentRss><description>
&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;A few weeks ago we talked about &lt;/font&gt;&lt;a href="http://pandalabs.pandasecurity.com/archive/Have-you-ever-heard-the-term-_2200_Rickrolling_22003F00_-Malware-distributors-have_2E002E002E00_.aspx" target="_blank"&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;cyber-criminals using Digg.com to spread malware&lt;/font&gt;&lt;/a&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;. Today we see that the very same group responsible for the Digg.com incident was using the same tactic on YouTube through the use of YouTube&amp;#39;s Annotations feature. &lt;/font&gt;&lt;a href="http://www.youtube.com/t/annotations_about" target="_blank"&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;Video Annotations&lt;/font&gt;&lt;/a&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt; is a way to add interactive commentary to videos on YouTube. &lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;The following image displays a video using the annotations feature to guide users over to a malware ridden website:&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;img height="363" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2009/02/26/MWYoutube.png" style="width:700px;height:363px;" width="700" /&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;&lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;Although the YouTube description malware is not as prevalent as the Digg.com comment abuse, it does show that Social Media websites are increasingly being used to spread Malware. We expect to see plenty of new examples similar to this throughout 2009. &lt;/font&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;Thanks to &lt;a href="http://ddanchev.blogspot.com/" target="_blank"&gt;Dancho Danchev&lt;/a&gt; for the information. &lt;br /&gt;
&lt;/font&gt;&lt;/p&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=972" width="1" height="1"&gt;</description><category domain="http://pandalabs.pandasecurity.com/archive/tags/Malware/default.aspx">Malware</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Malicious+links/default.aspx">Malicious links</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Social+Media/default.aspx">Social Media</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/YouTube/default.aspx">YouTube</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/PornTube/default.aspx">PornTube</category></item><item><title>Good (?) old times</title><link>http://pandalabs.pandasecurity.com/archive/Good-_28003F002900_-old-times.aspx</link><pubDate>Tue, 17 Feb 2009 17:28:00 GMT</pubDate><guid isPermaLink="false">b262f9bf-63e5-46e5-8a14-4069a6997bc7:966</guid><dc:creator>Luis Corrons</dc:creator><slash:comments>0</slash:comments><comments>http://pandalabs.pandasecurity.com/comments/966.aspx</comments><wfw:commentRss>http://pandalabs.pandasecurity.com/commentrss.aspx?PostID=966</wfw:commentRss><description>&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;Right now we are dealing with about 25,000 new malware samples per day. From time to time we remember the old days, when we were almost fighting each other in order to disassemble the latest virus we had received in the lab. Well, what were you expecting? We&amp;#39;re freaks ;-)&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;But the real thing is that nowadays most of the malware are Trojans, rogueware, etc. We are talking mainly about non-polymorphic and non-viral malware, and the major problem we may find are some packers or similar stuff trying to avoid AV signature detections, not a big deal when you have technologies such as TruPrevent, that are watching the behaviour of the program rather than the static file itself.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;Malware evolves, and so do antimalware technologies. That&amp;rsquo;s why in our last &lt;/font&gt;&lt;a href="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/12/31/Annual_Report_Pandalabs_2008_ENG.pdf" title="2009 Annual Report" target="_blank"&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;Annual Report&lt;/font&gt;&lt;/a&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt; I was expecting that this year we would see an increase in the use of old techniques as a way to evade some of the technologies that the top AV vendors are using &amp;ndash;&amp;gt; old viruses tricks, mixing virus &amp;amp; Trojans behaviours, etc. It turns out that we have seen this change already happening. The first week of February a new virus appeared, we called it W32/Sality.AO. &lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;Why is this new variant of a well known file infector worth mentioning? Well, first it is smart enough to avoid being too promiscuous, as it will not scan the whole hard drive looking for files to infect, but&amp;nbsp;will just infect&amp;nbsp;some files upon running the malicious code and will also infect any new files that we run in our computer. Furthermore, it is using very complex techniques to infect PE files: &lt;/font&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#EPO" target="_blank"&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;EPO&lt;/font&gt;&lt;/a&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;, &lt;/font&gt;&lt;a href="http://www.pandasecurity.com/homeusers/security-info/glossary/#Cavity" target="_blank"&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;Cavity&lt;/font&gt;&lt;/a&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;, different encryption layers&amp;hellip; and not always in the same way, one sample maybe infected using EPO and 1 encryption layer, another one using EPO, cavity and 2 encryption layers, and so on.&amp;nbsp;If this wasn&amp;rsquo;t enough, it connects to an IRC server in order to receive commands. Even more, it will try to download files from the Internet in order to infect our computer with more malware. It also infects (I&amp;rsquo;d rather say &amp;quot;modifies&amp;quot;) .PHP, .ASP and .HTML files by inserting an iFrame tag into them. When visiting any of these &amp;ldquo;infected&amp;rdquo; files through our web browser, it will use an exploit in order to download and run a new file. This file is a double-malware, a Trojan&amp;nbsp;downloader infected with a virus. &lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;And here we were missing some good old polymorphic and self-replicating action. Another variant of W32/Sality just came in. Looks like we&amp;#39;re not going to get much sleep tonight.&amp;nbsp;&lt;/font&gt;&lt;/p&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=966" width="1" height="1"&gt;</description><category domain="http://pandalabs.pandasecurity.com/archive/tags/Malware/default.aspx">Malware</category></item><item><title>Rogue ScanVirus site impersonates SaaS Anti-Virus</title><link>http://pandalabs.pandasecurity.com/archive/ScanVirus-infection-site-impersonates-SaaS-Anti_2D00_Virus.aspx</link><pubDate>Tue, 03 Feb 2009 13:23:00 GMT</pubDate><guid isPermaLink="false">b262f9bf-63e5-46e5-8a14-4069a6997bc7:958</guid><dc:creator>Sean-Paul Correll</dc:creator><slash:comments>0</slash:comments><comments>http://pandalabs.pandasecurity.com/comments/958.aspx</comments><wfw:commentRss>http://pandalabs.pandasecurity.com/commentrss.aspx?PostID=958</wfw:commentRss><description>
&lt;p&gt;Today we discovered a new site using an interesting tactic  to trick users into infecting themselves with malware. This time the  cyber-criminals opted to pretend to be a Software as a Service (SaaS)  Anti-Virus solution. &lt;/p&gt;

&lt;p&gt;The &amp;quot;Scan Virus&amp;quot; website uses several legitimate  Anti-Malware logos and badges in order to gain the victims confidence.&amp;nbsp; Immediately upon loading the site a fake scan will begin and shortly
after that the site will prompt the user to download a file called
AntiVir.exe, which we detect as &lt;strong&gt;Adware/Antivirus2009&lt;/strong&gt;. The site attempts to scare users by displaying images such as,  &amp;quot;&lt;strong&gt;Your PC is infected! Sorry, standard programs cannot disinfect your PC  now&lt;/strong&gt;&amp;quot;, and &amp;quot;&lt;strong&gt;DO&lt;/strong&gt;&lt;strong&gt;WNLOAD PATCH to fix this problem&lt;/strong&gt;&amp;quot;&lt;/p&gt;

&lt;p&gt;&lt;a href="http://support.us.pandasecurity.com/blog/ScanVirus.jpg"&gt;&lt;img alt="scanvirusonline.net" border="0" height="390" src="http://support.us.pandasecurity.com/blog/ScanVirus.jpg" width="705" /&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=958" width="1" height="1"&gt;</description><category domain="http://pandalabs.pandasecurity.com/archive/tags/Malware/default.aspx">Malware</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/SaaS/default.aspx">SaaS</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Trojan/default.aspx">Trojan</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Adware/default.aspx">Adware</category></item></channel></rss>