-
-
15:04
»
PandaLabs
One of the most interesting things in order to know how the bot behind Mariposa has been spreading is to study the geographical distribution of the infections. Unlike other cases, the Mariposa Working Group stats don’t come from scanning PCs. In order to avoid the DDP Team from controlling Mariposa, ...
-
-
2:22
»
PandaLabs
Pedro Bustamante has just published a new blog post in the Panda Research blog, about a Mariposa-like bot as special gift in a new HTC distributed by Vodafone. For the same price you can be infected with other 2 'gifts': Conficker and Lineage :(
Read the full story in Panda Research ...
-
-
15:24
»
PandaLabs
We want to inform you of a new flood of email messages that seem to contain a postcard but are actually distributing malware. Concretely, we’ve seen several thousands in a few hours.
It’s not the first time we see emails like this in circulation, as subjects like “You’ve received a postcard” ...
-
-
1:19
»
PandaLabs
In May 2009, Defence Intelligence announced the discovery of a new botnet, dubbed “Mariposa”. This discovery was followed by months of investigation, aimed at bringing down the criminal network behind what was to become one of the largest botnets on record.
Initial steps involved the creation of the Mariposa Working Group ...
-
-
11:41
»
PandaLabs
If last week we talked about a rogueware program that had deliberately imitated Microsoft’s free antimalware protection called Security Essentials, today we’re going to show you a program that imitates Panda Security’s products, site, logo, etc.
You’ll probably have ever played the Find the differences game; it consists in finding the ...
-
-
23:38
»
PandaLabs
Today our lab has detected a flood of spam messages that contain a malicious link from which malware is downloaded. We’ve seen more than 8,000 in a few hours.
These emails have the following subjects:
Fw:
FW:
Re:
RE:FW:
Re:Fw:
RE:
The content of these messages is just a link to a website. The following are some examples:
http://anonymfiles.reda.co.kr/archive0714/?id=email@domain.com
http://archivedv.kr/archive0714/?id=email@domain.com
http://filearchredb.or.kr/archive0714/?id=email@domain.com
http://files.reco.kr/archive0714/?id=email@domain.com
http://files4friends1e3eq.co.uk/archive0714/?id=email@domain.com
http://incognireda.ne.kr/archive0714/?id=email@domain.com
http://postcayrxc.kr/archive0714/?id=email@domain.com
http://secretarcredn.kr/archive0714/?id=email@domain.com
http://secretfiyrxo.co.kr/archive0714/?id=email@domain.com
http://sendspyrxs.co.kr/archive0714/?id=email@domain.com
If ...
-
23:38
»
PandaLabs
After yesterday’s epic fail (I'm still laughing) it’s time to do something about users’ education. Many times I wonder which the best approach to education is, and even though writing white papers and all that kind of serious stuff is useful, the average Joe user won’t ever read it. And ...
-
1:51
»
PandaLabs
A few days ago I came across one of the most hilarious and pitiful stories I have recently read. I couldn’t stop laughing, and still have a laugh now and then on recalling it. Let me share it with you so we can laugh together. It all began when the ...
-
-
17:00
»
PandaLabs
Today we’re going to talk about a rogueware program. To be honest, we’re fed up with seeing these programs everyday, because it’s always the same stuff, the same interfaces, the same icons, the same behaviour…and just another name.
As you know, these programs try to deceive you passing themselves off as ...
-
17:00
»
PandaLabs
We want to inform you of two different email messages we’ve been receiving lately in the lab in order to distribute malware designed to steal information.
One of them seems to have been sent by Amazon and informs you that they have received your payment and your order has been already ...