Banking Trojans III

Pedro Bustamante at  02 June 08 12:24    
In previous posts Banking Trojans I and Banking Trojans II we did an overview of the main banker trojan families and their simple characteristics (files and registry entries). Let's dig a little deeper now and take a look at their infection and hiding
Read More...

Post a Comment: 4 Comments    Category: ,     


Fenomen(al) False Positives

Pedro Bustamante at  19 May 08 06:22    
One of the problems with automation of antivirus signature creation is that if a few AV vendors start detecting something as malicious, even with heuristics, "automagically" soon afterwards other AV vendors start doing the same without even
Read More...

Post a Comment: 11 Comments    Category: ,     


Banking Trojans II

Pedro Bustamante at  21 April 08 05:21    
In Banking Trojans Part I I covered some banking trojan families. Here I will list the rest of the most dangerous of these types of malicious codes. Goldun, Haxdoor, Nuclear Grabber It usually drops a DLL and a SYS file with rootkit functionality. It
Read More...

Post a Comment: 1 Comments    Category: ,     


Banking Trojans I

Pedro Bustamante at  18 April 08 12:40    
Some of the most dangerous types of threats out there today are banking trojans. These malicious trojans are very specialized and focused at stealing banking credentials. They use advanced techniques to fool users , such as injecting HTML code to ask
Read More...

Post a Comment: 2 Comments    Category: ,     


Panda ActiveScan 2.0

Pedro Bustamante at  31 March 08 05:08    
We've been working very hard over the last few months to integrate all our online scanners (ActiveScan 1.0, NanoScan & TotalScan) into a single new scanner that rules them all. The result is the new Panda ActiveScan 2.0 ( www.pandasecurity.com/activescan
Read More...

Post a Comment: 17 Comments    Category: ,     


Think you're protected? Think again

Pedro Bustamante at  17 October 07 02:02    
For many years the security industry has been saying that in order to be correctly protected, users should have an anti-malware and firewall solution installed and up-to-date with the latest signatures at all times. However malware today is really specialized
Read More...

Post a Comment: 1 Comments    Category: , ,     


Technology Paper: From AV to Collective Intelligence

Pedro Bustamante at  27 August 07 11:26    
There is more malware than ever being released in the wild, and antivirus companies relying on signatures to protect users cannot keep up with the pace of creating signatures fast enough. As a result, the current installed base of anti-malware solutions
Read More...

Post a Comment: 3 Comments    Category: , ,     


Malware-friendly countries

Pedro Bustamante at  22 May 07 05:08    
Recently there have been some studies regarding Internet hosting providers which are often used maliciously to distribute malware. As this is an interesting subject we've been tracking quite a few thousand malware samples received over the last few
Read More...

Post a Comment: 2 Comments    Category: ,     


The rise of the (http) botnet

Pedro Bustamante at  17 April 07 08:29    
We're seeing more and more http-based botnet controllers. Even though these botnets are still limited in number of infected hosts, there's also some new and interesting exploit-frameworks being used to infect and populate these http-controlled
Read More...

Post a Comment: 0 Comments    Category:     


The Long Tail: malware's business model

Pedro Bustamante at  08 January 07 04:53    
Chris Anderson first coined the term "The Long Tail" back in 2003 while explaining an interesting effect businesses on the Internet were starting to experience ( here and here ). Basically it consits on a statistical distribution which demonstrates
Read More...

Post a Comment: 1 Comments    Category: ,     


A very large malware honeynet

Pedro Bustamante at  19 December 06 01:28    
As of today approximately 4.5 million PCs are running a malware honeypot on their machines with Panda's behavioural-based Host Intrusion Prevention System (aka TruPrevent©). All these high-interaction malware honeypot nodes report to PandaLabs
Read More...

Post a Comment: 0 Comments    Category: , ,