<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://pandalabs.pandasecurity.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>PandaLabs : Video</title><link>http://pandalabs.pandasecurity.com/archive/tags/Video/default.aspx</link><description>Tags: Video</description><dc:language>en</dc:language><generator>CommunityServer 2.1 SP2 (Build: 61120.2)</generator><item><title>Rogueware with new Ransomware Technology™</title><link>http://pandalabs.pandasecurity.com/archive/Rogueware-with-new-Ransomware-Technology_2221_.aspx</link><pubDate>Thu, 08 Oct 2009 11:05:00 GMT</pubDate><guid isPermaLink="false">b262f9bf-63e5-46e5-8a14-4069a6997bc7:1045</guid><dc:creator>Sean-Paul Correll</dc:creator><slash:comments>0</slash:comments><comments>http://pandalabs.pandasecurity.com/comments/1045.aspx</comments><wfw:commentRss>http://pandalabs.pandasecurity.com/commentrss.aspx?PostID=1045</wfw:commentRss><description>&lt;p&gt;The criminals behind &lt;a href="http://www.pandasecurity.com/img/enc/The%20Business%20of%20Rogueware.pdf"&gt;Rogueware&lt;/a&gt; attacks are becoming increasingly aggressive in their approach to make money.  We recently stumbled across a sample (&lt;a href="http://www.pandasecurity.com/homeusers/security-info/212529/information/TotalSecurity2009"&gt;Adware/TotalSecurity2009&lt;/a&gt;) which uses a &lt;a href="http://pandalabs.pandasecurity.com/archive/Ransomware-Reloaded.aspx"&gt;ransomware&lt;/a&gt; technique to improve its sales. Once the computer becomes infected, Total Security forces the victim to purchase it before it will allow any files from being accessed  on the system.&amp;nbsp; When attempting to open a file, a message pops up in the notification area claiming that the application was blocked due to infection.&amp;nbsp; The pop up recommends activating the &amp;quot;antivirus&amp;quot; software, which costs $79.95.&amp;nbsp; &lt;br /&gt;
&lt;br /&gt;
&lt;img alt="Notification Area - Notepad.exe blocked" height="69" src="http://farm3.static.flickr.com/2642/3993133972_af6917dbf6_m.jpg" title="Notification Area - Notepad.exe blocked" width="240" /&gt; &lt;br /&gt;
&lt;/p&gt;
&lt;p&gt;  This would be a devistating blow to any user and would likely force the victim to purchase it, so we went ahead and cracked the sample to reveal all of the valid serial numbers.  We&amp;#39;re hoping that&amp;nbsp; victims can find this blog post before shelling out any hard earned cash to these criminals. &lt;br /&gt;
&lt;/p&gt;

&lt;p&gt;Watch the video to see it in action:&amp;nbsp; &lt;br /&gt;
&lt;/p&gt;

&lt;p&gt;&lt;a href="http://vimeo.com/6949998"&gt;&lt;img border="0" src="http://farm4.static.flickr.com/3419/3992052465_98a09ebb8d_o.png" /&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Valid serials for &lt;a href="http://www.pandasecurity.com/homeusers/security-info/212529/information/TotalSecurity2009"&gt;Adware/TotalSecurity2009&lt;/a&gt;:&lt;/p&gt;

&lt;p&gt;WNDS-TGN15-RFF29-AASDJ-ASD65&lt;br /&gt;
  WNDS-U94KO-LF4G4-1V8S1-2CRFE&lt;br /&gt;
  WNDS-6W954-FX65B-41VDF-8G4JI&lt;br /&gt;
  WNDS-G84H6-S854F-79ZA8-W4ERS&lt;br /&gt;
  WNDS-TTUYJ-7UO54-G561H-J1D6F&lt;br /&gt;
  WNDS-A1SDF-6AS4D-RF5RE-79G84&lt;br /&gt;
  WNDS-A1SDF-RY4E8-7U98D-F1GB2&lt;br /&gt;
  WNDS-5SRTS-AEHUF-YA54S-D6F35&lt;br /&gt;
  WNDS-P9685-4H41A-DSW3A-2R64T&lt;br /&gt;
  WNDS-2AE32-1VFC2-B6894-G67YU&lt;br /&gt;
  WNDS-4TS8R-D6F5D-4JH8T-U4JK5&lt;br /&gt;
  WNDS-FGS5D-649RG-4S53D-412SF&lt;br /&gt;
  WNDS-452S3-ER00F-TSE35-S8FSD&lt;br /&gt;
  WNDS-SERFH-2642S-F04SD-64FG1&lt;br /&gt;
  WNDS-F40SA-1ER5H-4FG5D-F8412&lt;br /&gt;
  WNDS-5D1V2-XB0D5-JT1TY-97DS3&lt;br /&gt;
  WNDS-4BGY2-JY4KO-IT98Y-7HJ43&lt;br /&gt;
  WNDS-G8FB6-1V87S-DRT1S-63SRG&lt;br /&gt;
  WNDS-HFVDR-9844O-U54DA-5TBSC&lt;br /&gt;
  WNDS-89OF7-7324R-5SAD4-TG68U&lt;br /&gt;
  WNDS-JUYH3-24GHJ-HGKSH-FKLSD&lt;/p&gt;&lt;p&gt;You can &lt;a href="http://www.pandasecurity.com/usa/homeusers/downloads/register?Tipo=1&amp;amp;CodigoProducto=60&amp;amp;Idioma=2&amp;amp;TipoUsuario=12&amp;amp;Country=US&amp;amp;TipoLead=2&amp;amp;Ref=WWUS-GP10-DWN" title="Global Protection 2010 Trial" target="_blank"&gt;download a free trial&lt;/a&gt; to completely remove the infection once the ransomware feature is removed.&lt;/p&gt;&lt;p&gt;&lt;br /&gt;Special thanks to Sherab Giovannini for extracting the serials.&amp;nbsp; &lt;br /&gt;&lt;/p&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=1045" width="1" height="1"&gt;</description><category domain="http://pandalabs.pandasecurity.com/archive/tags/Rogueware/default.aspx">Rogueware</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Video/default.aspx">Video</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Ransomware/default.aspx">Ransomware</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Total+Security/default.aspx">Total Security</category></item><item><title>Live Demo: Banking Trojans</title><link>http://pandalabs.pandasecurity.com/archive/Live-Demo_3A00_-Banking-Trojans.aspx</link><pubDate>Tue, 08 Sep 2009 22:09:00 GMT</pubDate><guid isPermaLink="false">b262f9bf-63e5-46e5-8a14-4069a6997bc7:1036</guid><dc:creator>Sean-Paul Correll</dc:creator><slash:comments>0</slash:comments><comments>http://pandalabs.pandasecurity.com/comments/1036.aspx</comments><wfw:commentRss>http://pandalabs.pandasecurity.com/commentrss.aspx?PostID=1036</wfw:commentRss><description>
&lt;p&gt;Banking Trojans are one of the most prevalent Malware species in the threat landscape today.&amp;nbsp; Malware
authors aim to keep infections live and undetected long
enough so that they can get what they are really after: money. Financial
motivations lead malware developers to craft the stealthiest banking
Trojans to steal personal and financial data for further exploitation
on the black market.&amp;nbsp; Day after day &lt;a href="http://voices.washingtonpost.com/securityfix/2009/09/more_business_banking_victims.html" title="Brian Krebs - More Business Banking Trojans" target="_blank"&gt;innocent victims&lt;/a&gt; are hacked with the end result being an emptied out bank account. This video demonstrates how dangerous and stealthy
banking Trojans can be and why we must continue to raise awareness on
the issue. &lt;/p&gt;


&lt;blockquote&gt;&lt;a href="http://vimeo.com/6491332"&gt;&lt;img border="0" src="http://farm3.static.flickr.com/2586/3901227423_fa8b717dba.jpg" /&gt;&lt;/a&gt;&lt;/blockquote&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=1036" width="1" height="1"&gt;</description><category domain="http://pandalabs.pandasecurity.com/archive/tags/Video/default.aspx">Video</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Demonstration/default.aspx">Demonstration</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Banking+Trojans/default.aspx">Banking Trojans</category></item><item><title>Zero day in MSVIDCTL.DLL</title><link>http://pandalabs.pandasecurity.com/archive/Zero-day-in-MSVIDCTL.DLL.aspx</link><pubDate>Wed, 08 Jul 2009 07:21:00 GMT</pubDate><guid isPermaLink="false">b262f9bf-63e5-46e5-8a14-4069a6997bc7:1014</guid><dc:creator>Luis Corrons</dc:creator><slash:comments>0</slash:comments><comments>http://pandalabs.pandasecurity.com/comments/1014.aspx</comments><wfw:commentRss>http://pandalabs.pandasecurity.com/commentrss.aspx?PostID=1014</wfw:commentRss><description>&lt;p&gt;A couple of days ago we started spotting a new vulnerability affecting Microsoft Video ActiveX Control. Even though it&amp;#39;s been said there are thousands of web sites affected, they are only a&amp;nbsp;few dozens and most of them are in China: Anyway, it is a matter of time to see this attack expanding worldwide. We&amp;#39;ve seen this zero day installing a Lineage Trojan, but this could change and cybercriminals could install any kind of malware. &lt;/p&gt;&lt;p&gt;Microsoft has published an &lt;a href="http://www.microsoft.com/technet/security/advisory/972890.mspx" target="_blank"&gt;advisory&lt;/a&gt; with a workaround while they prepare a final solution. An important message to everyone: please apply this workaround ASAP. &lt;/p&gt;&lt;p&gt;If you are a Panda user with TruPrevent Technologies, then you are not in a hurry, as it is proactively stopping it. The best thing is that you don&amp;#39;t need to install some kind of beta or technology preview, it just works in all of our consumer and corporate products as long as they have enabled TruPrevent. No matter which version you have installed, it covers not only the brand new 2010 products but any old version with TruPrevent. &lt;/p&gt;&lt;p&gt;Sean-Paul shows you here why and how you are protected:&lt;/p&gt;&lt;p&gt;&lt;a href="http://vimeo.com/5500638" target="_blank"&gt;&lt;img height="377" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2009/07/08/TruPrevent.jpg" width="505" /&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=1014" width="1" height="1"&gt;</description><category domain="http://pandalabs.pandasecurity.com/archive/tags/Vulnerabilities+_2600_amp_3B00_+Exploits/default.aspx">Vulnerabilities &amp;amp; Exploits</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Malware/default.aspx">Malware</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Video/default.aspx">Video</category></item><item><title>New Blackhat SEO attack exploits vulnerabilities in Wordpress to distribute rogue antivirus software</title><link>http://pandalabs.pandasecurity.com/archive/New-Blackhat-SEO-attack-exploits-vulnerabilities-in-Wordpress-to-distribute-rogue-antivirus-software.aspx</link><pubDate>Thu, 23 Apr 2009 16:50:00 GMT</pubDate><guid isPermaLink="false">b262f9bf-63e5-46e5-8a14-4069a6997bc7:994</guid><dc:creator>Sean-Paul Correll</dc:creator><slash:comments>0</slash:comments><comments>http://pandalabs.pandasecurity.com/comments/994.aspx</comments><wfw:commentRss>http://pandalabs.pandasecurity.com/commentrss.aspx?PostID=994</wfw:commentRss><description>
&lt;p&gt;&lt;strong&gt;&lt;/strong&gt;Over the past week we have seen a new Blackhat SEO technique  emerge to exploit vulnerabilities in the popular Wordpress blog software.&amp;nbsp; Two of the sites we identified were  TheWorkBuzz.com, a website owned and operated by Career Builder  (CareerBuilder.com), and The Center for International Media Assistance, an  initiative of the National Endowment for Democracy (NED.org). Just like last  week&amp;rsquo;s attack against &lt;a href="http://pandalabs.pandasecurity.com/archive/Targeted-Blackhat-SEO-Attack-against-Ford-Motor-Co_2E00_.aspx"&gt;Ford Motor&lt;/a&gt;, these scams work by misleading search engines  to falsely promote malicious pages to the top of the search results.&amp;nbsp;When a  user visits one of the malicious sites, they are duped into downloading fake  antivirus software.&lt;/p&gt;

&lt;p&gt;You can checkout a video demonstrating how this particular attack  works below:&lt;br /&gt;
  &lt;a href="http://vimeo.com/4288832"&gt;
  &lt;/a&gt;&lt;/p&gt;

&lt;blockquote&gt;&lt;a href="http://vimeo.com/4288832"&gt;&lt;img alt="press play" border="0" height="382" src="http://support.us.pandasecurity.com/blog/pressplay.png" width="506" /&gt;&lt;/a&gt;&lt;/blockquote&gt;

&lt;p&gt;Both attacks involve a vulnerability in an older version of  Wordpress, which allows the /wp-includes/ folder of the software to house  thousands of malicious redirectors.&amp;nbsp;&amp;nbsp;  Exact details of the specific vulnerability are not yet known, but we  have contacted both site owners and the security team at Wordpress to get  clarification.&amp;nbsp; &lt;/p&gt;

&lt;p&gt;In the first case involving the Center for International  Media Assistance website, we uncovered over 13,330 words used in the Blackhat  SEO attack.&amp;nbsp; We took all the terms and  threw them into a Tag Cloud generator to see how they were targeting the CIMA  viewers.&amp;nbsp; Here&amp;rsquo;s what we found:&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://support.us.pandasecurity.com/blog/tagcloud.jpg"&gt;&lt;img alt="Tag Cloud Thumbnail" border="0" src="http://support.us.pandasecurity.com/blog/tagcloud_small.jpg" /&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Song&lt;/strong&gt; - Appeared 1303  times &lt;br /&gt;
  &lt;strong&gt;Software &lt;/strong&gt;- Appeared 879 times&lt;br /&gt;
  &lt;strong&gt;Free &lt;/strong&gt;- Appeared 244 times&lt;br /&gt;
  &lt;strong&gt;Lyrics &lt;/strong&gt;- Appeared 210 times&lt;/p&gt;

&lt;p&gt;Cyber-criminals have chosen Rogue Anti-Malware as their  primary method of payment because it has become easier for them to make money  by affiliate systems and utilizing these types of attacks.&amp;nbsp; It&amp;rsquo;s no wonder why we have seen more Rogue  detections in the first quarter of 2009 then all of 2008. As you can see from  the chart below,&amp;nbsp; PandaLabs predicts that  incidents of rogue AV scams will grow 100 percent quarter over quarter through the  end of Q3.&amp;nbsp; &lt;/p&gt;

&lt;p&gt;&lt;img alt="Rogue AV Growth" src="http://support.us.pandasecurity.com/blog/rogueav_growth.png" /&gt;&lt;/p&gt;

&lt;p&gt;Remember, It&amp;#39;s just as important to update your web applications as it is to update your operating system. If you use Wordpress as a platform for your blog or website, then I recommend viewing the &lt;a href="http://codex.wordpress.org/Hardening_WordPress"&gt;official hardening guide.&lt;/a&gt;&lt;br /&gt;
&lt;/p&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=994" width="1" height="1"&gt;</description><category domain="http://pandalabs.pandasecurity.com/archive/tags/SEO/default.aspx">SEO</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Blackhat/default.aspx">Blackhat</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Video/default.aspx">Video</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/The+Work+Buzz/default.aspx">The Work Buzz</category><category domain="http://pandalabs.pandasecurity.com/archive/tags/Rogue+Anti-malware/default.aspx">Rogue Anti-malware</category></item></channel></rss>