<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://pandalabs.pandasecurity.com/utility/FeedStylesheets/atom.xsl" media="screen"?><feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en"><title type="html">PandaLabs</title><subtitle type="html">, everything you need to know about Internet threats </subtitle><id>http://pandalabs.pandasecurity.com/atom.aspx</id><link rel="alternate" type="text/html" href="http://pandalabs.pandasecurity.com/default.aspx" /><link rel="self" type="application/atom+xml" href="http://pandalabs.pandasecurity.com/atom.aspx" /><generator uri="http://communityserver.org" version="2.1.61120.2">Community Server</generator><updated>2008-12-04T11:22:00Z</updated><entry><title>Annual Report PandaLabs 2008</title><link rel="alternate" type="text/html" href="http://pandalabs.pandasecurity.com/archive/Annual-Report-PandaLabs-2008.aspx" /><id>http://pandalabs.pandasecurity.com/archive/Annual-Report-PandaLabs-2008.aspx</id><published>2008-12-31T11:24:00Z</published><updated>2008-12-31T11:24:00Z</updated><content type="html">&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;We have just published the Annual report PandaLabs 2008. There, you can find statistics and information about the current situation of malware.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;In advance, regarding malware in the end of last Quarterly in 2008, Trojans continue being the most relevant category of malware, at 77.49%.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;&lt;img alt="Q4" height="290" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/12/31/Q4IDs.JPG" style="width:482px;height:290px;" title="Q4" width="482" /&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;Also you will find an other interesting article in this report like, rogue antimalware, spam levels, vulnerabilities, banking trojan, and others&amp;hellip;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;You can download it in English or in Spanish .&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/12/31/Annual_Report_Pandalabs_2008_ENG.pdf" target="_blank"&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;&lt;img alt="ENG" height="89" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/12/31/Portada_2008_eng.gif" style="width:71px;height:89px;" title="ENG" width="71" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/font&gt;&lt;a href="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/12/31/Annual_Report_Pandalabs_2008_ESP.pdf" target="_blank"&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;&lt;img alt="ESP" height="89" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/12/31/Portada_2008_esp.gif" style="width:71px;height:89px;" title="ESP" width="71" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;Enjoy it! And from all the team, we wish you a happy -and malware free ;-) new year!&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=945" width="1" height="1"&gt;</content><author><name>xfrancisco</name><uri>http://pandalabs.pandasecurity.com/members/xfrancisco.aspx</uri></author><category term="Security Reports" scheme="http://pandalabs.pandasecurity.com/archive/tags/Security+Reports/default.aspx" /><category term="PandaLabs" scheme="http://pandalabs.pandasecurity.com/archive/tags/PandaLabs/default.aspx" /></entry><entry><title>The cybercriminals wish us a Merry Christmas, And a Happy New Year</title><link rel="alternate" type="text/html" href="http://pandalabs.pandasecurity.com/archive/The-cybercriminals-wish-us-a-Happy-Christmas-and-a-happy-new-year.aspx" /><id>http://pandalabs.pandasecurity.com/archive/The-cybercriminals-wish-us-a-Happy-Christmas-and-a-happy-new-year.aspx</id><published>2008-12-31T10:20:00Z</published><updated>2008-12-31T10:20:00Z</updated><content type="html">&lt;p&gt;Today it is the last day of the year 2008 and all those cybercriminals who have a &amp;quot;great heart&amp;quot; want to wish us happy Christmas and a happy new year.&lt;/p&gt;&lt;p&gt;&lt;img height="436" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/12/31/1.jpg" style="width:498px;height:436px;" width="498" /&gt;&lt;/p&gt;&lt;p&gt;So they are sending us a funny Christmas postcard in flash, which you can to enjoy across the following &lt;a href="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/12/31/Windows%20XP%20Professional%20Ingles%20Movie.avi" title="video" target="_blank"&gt;video&lt;/a&gt; (~20 Mb). The file name is MerryChristmas.exe and once you run it, you only see the video... but the cybercriminals are taking the chance to steal your confidential information.&lt;/p&gt;&lt;p&gt;In order to do it, when you execute the file MerryChristmas.exe it will install two pieces of malware: Trj/PasswordStealer.BJ&amp;nbsp;and Rootkit/HidePort.TO. These two work as a team so the rootkit is hiding the Trojan while it gets all your confidential information.&lt;/p&gt;&lt;p&gt;Thanks to Ulises for the video.&lt;/p&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=944" width="1" height="1"&gt;</content><author><name>Oscar Cavada</name><uri>http://pandalabs.pandasecurity.com/members/Oscar+Cavada.aspx</uri></author></entry><entry><title>Sony's Home hacked</title><link rel="alternate" type="text/html" href="http://pandalabs.pandasecurity.com/archive/Sony_2700_s-Home-hacked.aspx" /><id>http://pandalabs.pandasecurity.com/archive/Sony_2700_s-Home-hacked.aspx</id><published>2008-12-19T12:37:00Z</published><updated>2008-12-19T12:37:00Z</updated><content type="html">&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;It is not that someone has hacked Sony CEO&amp;#39;s house, we are talking about the Sony Playstation Home:&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;img height="332" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/12/19/playstation-home-logo.jpg" style="width:397px;height:332px;" width="397" /&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://en.wikipedia.org/wiki/PlayStation_Home" title="Home in Wikipedia" target="_blank"&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;Home&lt;/font&gt;&lt;/a&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt; is&amp;nbsp;a virtual world for PlayStation 3 users, where they can interact with other gamers, create their own avatars, etc.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;We&amp;#39;ve seen it &lt;/font&gt;&lt;a href="http://www.telegraph.co.uk/scienceandtechnology/technology/technologynews/3793715/PlayStation-Home-hacked.html" title="PlayStation Home hacked" target="_blank"&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;here&lt;/font&gt;&lt;/a&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;&amp;nbsp;and this opens a totally new world for cybercrooks, as it could lead to identity theft and malware spreading.&amp;nbsp;A user could even upload, download&amp;nbsp;or delete any file within the Home server (!)&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=943" width="1" height="1"&gt;</content><author><name>lcorrons</name><uri>http://pandalabs.pandasecurity.com/members/lcorrons.aspx</uri></author><category term="Vulnerabilities &amp;amp; Exploits" scheme="http://pandalabs.pandasecurity.com/archive/tags/Vulnerabilities+_2600_amp_3B00_+Exploits/default.aspx" /></entry><entry><title>Critical updated of Microsoft Security Bulletin MS08-078</title><link rel="alternate" type="text/html" href="http://pandalabs.pandasecurity.com/archive/Critical-updated-of-Microsoft-Security-Bulletin-MS08_2D00_078.aspx" /><id>http://pandalabs.pandasecurity.com/archive/Critical-updated-of-Microsoft-Security-Bulletin-MS08_2D00_078.aspx</id><published>2008-12-18T11:01:00Z</published><updated>2008-12-18T11:01:00Z</updated><content type="html">&lt;font size="2"&gt;&lt;p&gt;Today is not the second Tuesday of December, so we didn&amp;rsquo;t expect that Microsoft was going to publish any security bulletins until 2009. But given the circumstances and the severity of this vulnerability, Microsoft had no choice but to release once again a bulletin, called MS08-078, out of the usual date.&lt;/p&gt;&lt;p&gt;&lt;img align="middle" height="277" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/12/18/1.jpg" style="width:405px;height:277px;" width="405" /&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;If this vulnerability is exploited, it allows remote code to be executed without the user&amp;rsquo;s consent. &lt;/p&gt;&lt;p&gt;This vulnerability affects all the Internet Explorer versions from 5.01.&lt;/p&gt;&lt;p&gt;&lt;img height="473" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/12/18/2.png" style="width:700px;height:473px;" width="700" /&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;To sum up, it is a critical vulnerability as it is very easy to exploit and affects from Windows 2000 to Windows Server 2008 computers and all the versions of Internet Explorer. In fact, it can be stated that more than 6.000 URL are currently being used to exploit this vulnerability and distribute malware. &lt;/p&gt;&lt;p&gt;We strongly recommend you to install this patch immediately by following this link &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms08-078.mspx" title="MS08-078" target="_blank"&gt;MS08-078&lt;/a&gt;. &lt;/p&gt;&lt;p&gt;In spite of the latest patches published out of the usual date, let&amp;rsquo;s hope that in the future these updates continue being released the second Tuesdays of the month.&lt;/p&gt;&lt;/font&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=942" width="1" height="1"&gt;</content><author><name>Oscar Cavada</name><uri>http://pandalabs.pandasecurity.com/members/Oscar+Cavada.aspx</uri></author></entry><entry><title>Santa gets 0wned</title><link rel="alternate" type="text/html" href="http://pandalabs.pandasecurity.com/archive/Santa-gets-0wned.aspx" /><id>http://pandalabs.pandasecurity.com/archive/Santa-gets-0wned.aspx</id><published>2008-12-15T08:55:00Z</published><updated>2008-12-15T08:55:00Z</updated><content type="html">&lt;p&gt;A couple of weeks ago, I was sent this screenshot, and it is something I&amp;nbsp;want to share with you as Christmas time is so close. As you can see, Santa&amp;#39;s Inbox is not&amp;nbsp;so uncommon: you can see spam, scams, though the senders are somehow relevant people, going from God to Oprah:&lt;/p&gt;&lt;p&gt;&lt;img alt="Santa&amp;#39;s Inbox" height="532" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/12/15/santa.jpg" style="width:700px;height:532px;" title="Santa&amp;#39;s Inbox" width="700" /&gt;&lt;/p&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=941" width="1" height="1"&gt;</content><author><name>lcorrons</name><uri>http://pandalabs.pandasecurity.com/members/lcorrons.aspx</uri></author><category term="Off Topic" scheme="http://pandalabs.pandasecurity.com/archive/tags/Off+Topic/default.aspx" /></entry><entry><title>AVAR 2008</title><link rel="alternate" type="text/html" href="http://pandalabs.pandasecurity.com/archive/AVAR-2008.aspx" /><id>http://pandalabs.pandasecurity.com/archive/AVAR-2008.aspx</id><published>2008-12-11T16:59:00Z</published><updated>2008-12-11T16:59:00Z</updated><content type="html">&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;The anual conference organized by the Association of antiVirus Researchers (&lt;/font&gt;&lt;a href="http://pandalabs.pandasecurity.com/ControlPanel/Blogs/www.aavar.org" target="_blank"&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;AVAR&lt;/font&gt;&lt;/a&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;) is taking place this week in New Delhi, India. Even though some people cancelled the trip due to the recent terrorist attack in Mumbai, there are still a number of great professionals from all around the world. As this is the first time that AVAR takes place in India, it is also a pleasure to meet some really skilled people from this country that we do not usually have the chance to meet.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;The presentations are being really great until now, which are mainly related to the fight against malware and cybercrime. These are some of which we have already enjoyed:&lt;/font&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;Fighting International Organized Online Crime&lt;/font&gt;&lt;/li&gt;&lt;li&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;Understanding and teaching Bots and Botnets&lt;/font&gt;&lt;/li&gt;&lt;li&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;Exploiting Anti-virtualization Techniques to Prevent Running of Malware&lt;/font&gt;&lt;/li&gt;&lt;li&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;Propagation of Malware Through Compromised Websites: Attack Trends and Countermeasures&lt;/font&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;And we still have many of them to enjoy, those to which I&amp;#39;m specially looking forward are:&lt;/font&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;Darwin inside the machines: malware evolution and the consequences for computer security&lt;/font&gt;&lt;/li&gt;&lt;li&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;Use of Statistic Methods for Fighting Malware&lt;/font&gt;&lt;/li&gt;&lt;li&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;Cyber Terrorism&lt;/font&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;In the picture you can see our colleague Mikko during his keynote:&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;&lt;img height="267" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/12/11/AVAR_IMG_0024.jpg" style="width:200px;height:267px;" width="200" /&gt;&lt;/font&gt;&lt;/p&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=940" width="1" height="1"&gt;</content><author><name>lcorrons</name><uri>http://pandalabs.pandasecurity.com/members/lcorrons.aspx</uri></author></entry><entry><title>Microsoft Updates for December</title><link rel="alternate" type="text/html" href="http://pandalabs.pandasecurity.com/archive/Microsoft-Updates-for-December.aspx" /><id>http://pandalabs.pandasecurity.com/archive/Microsoft-Updates-for-December.aspx</id><published>2008-12-10T13:03:00Z</published><updated>2008-12-10T13:03:00Z</updated><content type="html">&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-family:Tahoma;"&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;In this last month Microsoft have been published eight new security bulletins as part of the usual launch of &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms08-dec.mspx" target="_blank"&gt;Microsoft Updates&lt;/a&gt;, those security updates fixed different vulnerabilities affecting Windows, Office, Internet Explorer, Visual Basic Active Controls and Windows Media Player.&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Tahoma;"&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;According to Microsoft&amp;#39;s classification six of the bulletins are rated as &amp;quot;critical&amp;quot; and the other two as &amp;quot;important&amp;quot;. So we recommend you to update your system as soon as possible.&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-family:Tahoma;"&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;You can find more information about those security bulletins by clicking the following links:&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-family:Tahoma;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-family:Tahoma;"&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-family:Tahoma;"&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;&lt;a href="http://www.microsoft.com/technet/security/Bulletin/ms08-070.mspx" target="_blank"&gt;MS08-070&lt;/a&gt;: Vulnerabilities in Visual Basic 6.0 Runtime Extended Files (ActiveX Controls) Could Allow Remote Code Execution.&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-family:Tahoma;"&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;&lt;a href="http://www.microsoft.com/technet/security/Bulletin/ms08-071.mspx" target="_blank"&gt;MS08-071&lt;/a&gt;: Vulnerabilities in GDI Could Allow Remote Code Execution.&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-family:Tahoma;"&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;&lt;a href="http://www.microsoft.com/technet/security/Bulletin/ms08-072.mspx" target="_blank"&gt;MS08-072&lt;/a&gt;: Vulnerabilities in Microsoft Office Word Could Allow Remote Code Execution.&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-family:Tahoma;"&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;&lt;a href="http://www.microsoft.com/technet/security/Bulletin/ms08-073.mspx" target="_blank"&gt;MS08-073&lt;/a&gt;: Cumulative Security Update for Internet Explorer.&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-family:Tahoma;"&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;&lt;a href="http://www.microsoft.com/technet/security/Bulletin/ms08-074.mspx" target="_blank"&gt;MS08-074&lt;/a&gt;: Vulnerabilities in Microsoft Office Excel Could Allow Remote Code Execution.&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-family:Tahoma;"&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;&lt;a href="http://www.microsoft.com/technet/security/Bulletin/ms08-075.mspx" target="_blank"&gt;MS08-075&lt;/a&gt;: Vulnerabilities in Windows Search Could Allow Remote Code Execution.&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-family:Tahoma;"&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;&lt;a href="http://www.microsoft.com/technet/security/Bulletin/ms08-076.mspx" target="_blank"&gt;MS08-076&lt;/a&gt;: Vulnerabilities in Windows Media Components Could Allow Remote Code Execution.&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span style="font-family:Tahoma;"&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;&lt;a href="http://www.microsoft.com/technet/security/Bulletin/ms08-077.mspx" target="_blank"&gt;MS08-077&lt;/a&gt;: Vulnerability in Microsoft Office SharePoint Server Could Cause Elevation of Privilege.&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=939" width="1" height="1"&gt;</content><author><name>xfrancisco</name><uri>http://pandalabs.pandasecurity.com/members/xfrancisco.aspx</uri></author></entry><entry><title>Prices are higher now!</title><link rel="alternate" type="text/html" href="http://pandalabs.pandasecurity.com/archive/Prices-are-higher-now_2100_.aspx" /><id>http://pandalabs.pandasecurity.com/archive/Prices-are-higher-now_2100_.aspx</id><published>2008-12-10T10:35:00Z</published><updated>2008-12-10T10:35:00Z</updated><content type="html">&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;img height="651" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/12/10/ScreenHunter_09%20Dec.%2009%2009.04b.jpg" style="width:700px;height:651px;" width="700" /&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;A new rogueware site by Pandora Software appeared today. For those of you who do not know, Pandora Software is one of the rogue affiliate systems that produce the software for resellers to distribute.&amp;nbsp; You can see more information on how rogueware affiliate systems work in our related post entitled, &amp;ldquo;Anatomy of a Rogue Security Campaign.&amp;ldquo;&amp;nbsp; The domains involved are registered at INTERNET.BS and we have noticed that being the trend especially since ICANN yanked EstDomains in November. The MS AntiMalware rogue download is not available at the moment of our post but the merchant links are active and pointing to a shopping cart selling a &amp;ldquo;6 month license&amp;rdquo; for $37.95.&amp;nbsp; &lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;img height="735" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/12/10/ScreenHunter_10%20Dec.%2009%2009.29.jpg" style="width:632px;height:735px;" width="632" /&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;strong&gt;Payment Gateway whois&lt;/strong&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;strong&gt;Site: &lt;/strong&gt;vsoftstore.com&lt;strong&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;strong&gt;Registrar&lt;/strong&gt;: INTERNET.BS CORP.&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;strong&gt;IP&lt;/strong&gt; &lt;strong&gt;Address&lt;/strong&gt;: 209.8.25.244 &lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;strong&gt;IP&lt;/strong&gt; &lt;strong&gt;Location:&lt;/strong&gt; - District Of Columbia - Washington - Beyond The Network America Inc&lt;strong&gt;&lt;/strong&gt;&lt;/p&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=938" width="1" height="1"&gt;</content><author><name>Sean-Paul Correll</name><uri>http://pandalabs.pandasecurity.com/members/Sean-Paul+Correll.aspx</uri></author></entry><entry><title>My friend was a worm</title><link rel="alternate" type="text/html" href="http://pandalabs.pandasecurity.com/archive/My-friend-was-a-worm.aspx" /><id>http://pandalabs.pandasecurity.com/archive/My-friend-was-a-worm.aspx</id><published>2008-12-09T16:24:00Z</published><updated>2008-12-09T16:24:00Z</updated><content type="html">&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;Social networks have been an increasing way&amp;nbsp;to distribute malware in 2008. And, according to our predictions, this will go on in 2009.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;In recent days we have seen a case with a new sample, W32/Boface.J.worm, very similar to what we &lt;a href="http://pandalabs.pandasecurity.com/archive/Facebook-and-MySpace_2700_s-worm.aspx" target="_blank"&gt;discovered&lt;/a&gt; a few months ago. &lt;br /&gt;&amp;nbsp;&lt;br /&gt;A colleague from work phoned&amp;nbsp;us saying that he had received a very suspicious&amp;nbsp;email&amp;nbsp;from a friend in facebook.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;img alt="Email" height="206" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/12/09/01Email.JPG" style="width:700px;height:206px;" title="Email" width="700" /&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;When he contacted his friend to know if&amp;nbsp;it has been him, he followed the link included in the e-mail and&amp;nbsp;he discovered that it&amp;nbsp;was the typical bait:The link makes you think you&amp;#39;re going to watch a video, but before asked you to&amp;nbsp;install a video codec. This complement is, &lt;br /&gt;in fact, a copy of the worm.&amp;nbsp;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;&lt;img alt="FakeYoutube" height="338" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/12/09/02Web.JPG" style="width:700px;height:338px;" title="FakeYoutube" width="700" /&gt;&amp;nbsp;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;At the same time, the friend of our colleague said that he did not send anything and&amp;nbsp;moreover Facebook had blocked his account. He told us that he&amp;nbsp;received this mail:&amp;nbsp;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;&lt;img alt="Facebook" height="422" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/12/09/03Facebook.JPG" style="width:700px;height:422px;" title="Facebook" width="700" /&gt;&amp;nbsp;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;Facebook has been fast this time and has blocked his account and gives somes tips to him.&lt;br /&gt;&amp;nbsp;&lt;br /&gt;Thanks to Alberto&amp;nbsp;for this information.&lt;br /&gt;&lt;/font&gt;&lt;/p&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=937" width="1" height="1"&gt;</content><author><name>xfrancisco</name><uri>http://pandalabs.pandasecurity.com/members/xfrancisco.aspx</uri></author></entry><entry><title>From Russia with Love</title><link rel="alternate" type="text/html" href="http://pandalabs.pandasecurity.com/archive/From-Russia-with-Love.aspx" /><id>http://pandalabs.pandasecurity.com/archive/From-Russia-with-Love.aspx</id><published>2008-12-04T10:22:00Z</published><updated>2008-12-04T10:22:00Z</updated><content type="html">&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;This is not the plot of one of the famous films of the &lt;/font&gt;&lt;a href="http://www.filmaffinity.com/en/film823940.html" target="_blank"&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;James Bond&lt;/font&gt;&lt;/a&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt; saga, although some scam attempts deserve an Oscar. &lt;span style="font-size:10pt;font-family:Wingdings;"&gt;&lt;span&gt;J&lt;/span&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;You have probably heard of the saying &amp;ldquo;unlucky at cards, lucky in love&amp;rdquo; and as I have never won a miserable cent in the lottery, I must be destined to live through something special. It seems that now I have become a latin lover, as in less than one month 4 women wish to meet me.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;Svetlana, Irina, Hasmik, Tatyana, all of them, come from countries of the former Soviet Union, but nobody said it was going to be easy. You may think that distance is a problem but neither they nor I see distance as a problem. Moreover, they are very interested in coming to my country to know each other in a &amp;ldquo;deeper&amp;rdquo; way.&lt;br /&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;&lt;strong&gt;Svetlana&lt;/strong&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;&lt;img alt="Svetlana" height="323" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/12/04/Svetlana.JPG" style="width:571px;height:323px;" title="Svetlana" width="571" /&gt;&lt;br /&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;&lt;strong&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Irina&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Hasmik&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Tatyana&lt;/strong&gt; &lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;&lt;img alt="Irina_Hasmik_Tatyana" height="239" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/12/04/Irina_Hasmik_Tatyana.JPG" style="width:571px;height:239px;" title="Irina_Hasmik_Tatyana" width="571" /&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;After exchanging several emails, I&amp;rsquo;m starting to become fond of them, I&amp;rsquo;m looking forward to meeting them soon&amp;hellip;but it seems that destiny hinders me again&amp;hellip;Svetlana has financial difficulties to pay the trip.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;990 USD??? Well, of course that I love you, but for that price I can buy a new laptop &amp;hellip;Moreover, I was very disappointed when I discovered that she was flirting via email with a friend of mine, what a cheeky girl! So, I don&amp;rsquo;t trust her any more.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;&lt;img alt="Email" height="409" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/12/04/Email.JPG" style="width:571px;height:409px;" title="Email" width="571" /&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;&amp;nbsp;&lt;img alt="DNI" height="378" src="http://pandalabs.pandasecurity.com/blogs/images/PandaLabs/2008/12/04/DNI.JPG" style="width:269px;height:378px;" title="DNI" width="269" /&gt;&amp;nbsp;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;Definitely love in distance is not made for me, I must be cursed. Anyway, let&amp;rsquo;s see if I&amp;rsquo;m luckier in the lottery. Well, I&amp;rsquo;m having a look at my inbox and I&amp;rsquo;ve received an email saying that I&amp;rsquo;ve won the lottery! Don&amp;acute;t you know that every cloud has a silver lining?&lt;br /&gt;&amp;nbsp;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="tahoma,arial,helvetica,sans-serif"&gt;&lt;/font&gt;&lt;/p&gt;&lt;img src="http://pandalabs.pandasecurity.com/aggbug.aspx?PostID=935" width="1" height="1"&gt;</content><author><name>xfrancisco</name><uri>http://pandalabs.pandasecurity.com/members/xfrancisco.aspx</uri></author><category term="Scam" scheme="http://pandalabs.pandasecurity.com/archive/tags/Scam/default.aspx" /></entry></feed>