Having a bot is not a crime…yet

PandaLabs,

Sometimes, after reading news you may be really shocked: Techie jailed due to an IP confussion.

In this case, the information is not so deep, but we can extract a conclussion: be aware with your IP, you can be arrested (at least in Bangalore).

But if we take a look to the latest information, provided by PandaLabs, the 75% of the new samples of malware received were trojans. It means the main goal for hackers is staying in the computer waiting for something. And this something may be downloading something in your computer on behalf of the hacker. Or post something.

What happens if this download or upload is an illegal content? Will the police arrest you due to the lack of protection in your computer? Having a bot, for example, is not a crime. As today…

Special Thanks to Fernando de la Cuadra

Tags: , , ,

Posted under Malware Alerts

This post was written by Ted on November 15, 2007

Tags: , , ,

October spyware list

PandaLabs,

This month the two first positions have not changed, but Spyware/Virtumonde and Adware/Savenow gain a position each, leaving Adware/Lop in the fifth position.

Adware/VideoActiveXObject goes up from the 7th to 6th position.
It is the most active version of the known fakecodecs.

Adware/NaviPromo goes up from 15th to 14th position.
It is an adware that promotes dialers and uses rootkit techniques in order to go unnoticed. It usually comes with other programs such as MailSkinner, WebMediaplayer or InternetGameBox.

Application/Bestoffer goes down from the 22nd to 33rd position.
It is an application that displays advertising, but it will be gradually losing positions until disappearing from the list because “Best Offers” and “Direct Revenue” have given up offering their services.

Tags: , ,

Posted under Malware Alerts

This post was written by Ted on November 15, 2007

Tags: , ,

Mac Trojan: OSX/RxPlug.A

PandaLabs,

Today, we have found a Mac OS X trojan. It is usually said that only windows users should be worried by malware. As we show today, this is not true.

It all starts with a lot of porn sites:

ispfiltersporn.com

land-porn.com

lineporn.net

look-porn.com

play-porn.com

playhardmovie.com

playxvideo.com

playxxxvideo.net

porn-abc.com

porn-contact.com

porn-global.net

porn-go.net

porn-group.net

porn-party.net

porn-play.net

porn-plus.net

porn-power.net

pornissex.com

pornname.net

pornxxxfilm.com

relatedporn.net

seek-porn.net

stephieporn.com

superadultfriend.com

theadulteye.com

time-porn.net

use-porn.com

withpornstars.com

worldbestadult.com

porn-room.net

pornabout.com

porndrive.net

pornhelp.net

They all host some videos with names like: Download Sample Movie, Free movie clip, Get movie clip

This malware hides as a QuickTime plugin. When you try to download a video file, you are encouraged to download this plugin. It also, asks the user for the administrator password, in order to get installed.

Once installed, it runs a script that changes de DNS configuration, to redirect users to phishing sites of banks, eBay, or Paypal.

As always, be careful!

Thanks to Adrian and Oscar for this one.

Tags: , , , ,

Posted under Malware Alerts

This post was written by Ted on November 15, 2007

Tags: , , , ,