<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://pandalabs.pandasecurity.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>PandaLabs : Trojan</title><link>http://pandalabs.pandasecurity.com/archive/tags/Trojan/default.aspx</link><description>Tags: Trojan</description><dc:language>en</dc:language><generator>CommunityServer 2.1 SP2 (Build: 61120.2)</generator><item><title>Fake IRS Notifications</title><link>http://pandalabs.pandasecurity.com/archive/Fake-IRS-Notifications.aspx</link><pubDate>Mon, 28 Sep 2009 21:45:00 GMT</pubDate><guid isPermaLink="false">b262f9bf-63e5-46e5-8a14-4069a6997bc7:1042</guid><dc:creator>Sean-Paul Correll</dc:creator><slash:comments>0</slash:comments><comments>http://pandalabs.pandasecurity.com/comments/1042.aspx</comments><wfw:commentRss>http://pandalabs.pandasecurity.com/commentrss.aspx?PostID=1042</wfw:commentRss><description>&lt;p&gt;Fake IRS notification e-mails have been in circulation on  the Internet over the past few weeks. We&amp;#39;ve monitored the situation closely and  have observed 30 active domain names currently spreading the Zeus trojan affiliated with the spam campaign, as  well as 300 links used in the attack over the past month. The e-mail arrives as a notice of unreported income and  directs the victim to click on a link (E.g. www.irs.gov.malwaredomain.com).&amp;nbsp; When clicked, the victim arrives at website  designed to look like an official IRS page.&amp;nbsp;  &amp;nbsp;&amp;nbsp;&lt;br /&gt;
  &lt;br /&gt;
    &lt;a href="http://www.flickr.com/photos/lithium-/3963988680/sizes/o/"&gt;&lt;img alt="Fake IRS Notification" border="0" height="346" src="http://farm3.static.flickr.com/2621/3963988680_acb53b9b97.jpg" width="500" /&gt;&lt;br /&gt;
  &lt;/a&gt;&lt;br /&gt;
  The website attempts to legitimize itself by referencing the  receivers name in the Taxpayer ID field and in the download link. Once the  malware is accessed, the zeus trojan is silently installed on the victim&amp;rsquo;s computer and  begins to intercept communication with banking sites in order to facilitate financial  fraud.&lt;br /&gt;
&lt;/p&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=1042" width="1" height="1"&gt;</description><category domain="http://pandalabs.pandasecurity.com/archive/tags/Spam/default.aspx">Spam</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Trojan/default.aspx">Trojan</category></item><item><title>Rogue ScanVirus site impersonates SaaS Anti-Virus</title><link>http://pandalabs.pandasecurity.com/archive/ScanVirus-infection-site-impersonates-SaaS-Anti_2D00_Virus.aspx</link><pubDate>Tue, 03 Feb 2009 13:23:00 GMT</pubDate><guid isPermaLink="false">b262f9bf-63e5-46e5-8a14-4069a6997bc7:958</guid><dc:creator>Sean-Paul Correll</dc:creator><slash:comments>0</slash:comments><comments>http://pandalabs.pandasecurity.com/comments/958.aspx</comments><wfw:commentRss>http://pandalabs.pandasecurity.com/commentrss.aspx?PostID=958</wfw:commentRss><description>
&lt;p&gt;Today we discovered a new site using an interesting tactic  to trick users into infecting themselves with malware. This time the  cyber-criminals opted to pretend to be a Software as a Service (SaaS)  Anti-Virus solution. &lt;/p&gt;

&lt;p&gt;The &amp;quot;Scan Virus&amp;quot; website uses several legitimate  Anti-Malware logos and badges in order to gain the victims confidence.&amp;nbsp; Immediately upon loading the site a fake scan will begin and shortly
after that the site will prompt the user to download a file called
AntiVir.exe, which we detect as &lt;strong&gt;Adware/Antivirus2009&lt;/strong&gt;. The site attempts to scare users by displaying images such as,  &amp;quot;&lt;strong&gt;Your PC is infected! Sorry, standard programs cannot disinfect your PC  now&lt;/strong&gt;&amp;quot;, and &amp;quot;&lt;strong&gt;DO&lt;/strong&gt;&lt;strong&gt;WNLOAD PATCH to fix this problem&lt;/strong&gt;&amp;quot;&lt;/p&gt;

&lt;p&gt;&lt;a href="http://support.us.pandasecurity.com/blog/ScanVirus.jpg"&gt;&lt;img alt="scanvirusonline.net" border="0" height="390" src="http://support.us.pandasecurity.com/blog/ScanVirus.jpg" width="705" /&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=958" width="1" height="1"&gt;</description><category domain="http://pandalabs.pandasecurity.com/archive/tags/Malware/default.aspx">Malware</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/SaaS/default.aspx">SaaS</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Trojan/default.aspx">Trojan</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Adware/default.aspx">Adware</category></item></channel></rss>