Archive for the ‘Uncategorized’ Category

« Previous Entries

Follow me on Twitter

July 3rd, 2009

If you don’t already know it, I am on Twitter. Get the latest security updates on there!

twitt

Jerome Segura

  • Posted in Uncategorized
  • |
  • (0) comments
  • |
  • Add your comments

Happy Canada Day!

June 30th, 2009

Tomorrow is Canada Day. It is our national holiday.

It was 8 years ago that I first came to Canada for a visit to Halifax, N.S. That’s at the same time I met my future wife.

Years have passed and I am still loving this country.

canadaday

Jerome Segura

  • Posted in Uncategorized
  • |
  • (0) comments
  • |
  • Add your comments

False Positives are NEVER a good thing

June 26th, 2009

We discovered that one of our products, Paretologic Antivirus Plus is being flagged as malware.

It started with two vendors, and it is now at seven!

Interesting to note that the names that are coming up look pretty much identical… So, does that mean one AV vendor makes a mistake and all the rest of them blindly follow?

We are contacting the approriate people.

http://www.virustotal.com/analisis/affded445cf330a224ed8cf3d9bc14dc480b54fdb24fec3789fbe83ae3a907a1-1246046818

vt

Jerome Segura

  • Posted in Uncategorized
  • |
  • (0) comments
  • |
  • Add your comments

Another fake codec Mac and PC

June 22nd, 2009

As I was just finished with the fake Brazzers site, my investigation took me to another very interesting path.

The following IP: 61.235.117.88 from China, hosts malware:

caaaqjnn

The domain celebnudestars.net pushes PC and Mac Trojans:

brazzers021

The Mac sample is yet again totally undetected:

brazzers03

The PC sample will change your Desktop wallpaper to this:

brazzers04

and install a rogue, System Security:

brazzers05

Stay clear off those sites!

Jerome Segura

  • Posted in Uncategorized
  • |
  • (0) comments
  • |
  • Add your comments

Fake Brazzers site leads to Malware

June 22nd, 2009

This is a look alike of Brazzers.com:

brazzers00

All the download links are malware files, detected as:

brazzers01

Jerome Segura

  • Posted in Uncategorized
  • |
  • (0) comments
  • |
  • Add your comments

More Mac malware

June 18th, 2009

UPDATE:

Totally undetected variant found:

dmg06

From the following site:

dmg05

The Windows version is detected, but not by many vendors:

dmg07

——————————–

As I was browsing different crack sites with a spoofed user agent (Safari) I came across another Jahlav OSX Trojan:

dmg01

See the extension at the bottom of the previous snapshot is for an “.exe” but when I click on the link it converts it into a “.dmg”

dmg02

Very few vendors are detecting this variant:

dmg03

I did some background check on the original crack site. All bad stuff!

IP: 213.182.197.8

IP Country:   Latvia

This IP address resolves to mxs.newhostgroup.ru

34 Hosts on this IP

Number Domain / Host Functions

1. prowarezsite.com

2. prolinesoft.com

3. studiaweb.com

4. inspirationsbymicco.com

5. prosserpianoca.com

6. seexxxfree.info

7. djstevyvee.com

8. topsecretwarez.com

9. therogueelement.net

10. uniquexsoftware.com

11. yourcrackkey.com

12. premieracs.com

13. yoursoftonline.com

14. unix-service.com

15. 2008bloggger.com

16. lyutsifer.ru

17. vipwarezz.com

18. arws.org

19. prava-center.ru

20. zoosexvideo.net

21. kostenlosie.net

22. giveprava.ru

23. dwlsoft.com

24. paysitesmag.com

25. watch-video.info

26. sihuirading.com

27. warezfans.com

28. hacker-pro.net

29. index938.com

30. www.arws.org

31. appz-blog.com

32. klasoft.com

33. warezter.com

34. www.sihuirading.com

More fake codecs from faretransy.com:

dmg04

I will keep monitoring those links and pass on the information to other security folks.

Those links are dangerous, so proceed with caution.

Jerome Segura

  • Posted in Uncategorized
  • |
  • (0) comments
  • |
  • Add your comments

Mac users from Germany

June 16th, 2009

The Jahlav-C Mac Trojan has generated a lot of buzz in the Mac community.

Normally, this blog does not get a single visit from Mac users. After all, most things I talk about  here are related to PC security.

After I discovered this new Trojan and blogged about it, we saw a spike in traffic coming from Mac users:

mac

Mac users, daily visits prior and after the blog post.

Other thing that I noticed, most Mac users seem to come from Germany:

germany

In fact, Germany is the second country, after the USA that accounts for the most visits to MalwareDiaries.

This reminds me that this blog should be about security in general, not just Windows security.

Jerome Segura

  • Posted in Uncategorized
  • |
  • (0) comments
  • |
  • Add your comments

Money talks

June 11th, 2009

I have been using this free Firefox add-on called Fast Video Download for a while to save videos from YouTube.

It was really nice and easy to use, all you had to do was click on a iconflv3 on the current page, and it would save your video.

I was quite disappointed when I saw this message:

flv1

Here comes the Ask Toolbar again.

flv2

Suffice to say, I am not longer using this product and I found a better one for free (without the catch).

Jerome Segura

  • Posted in Uncategorized
  • |
  • (0) comments
  • |
  • Add your comments

Zheng technology overview

June 8th, 2009

I just made a little video on YouTube that shows our latest free online file scan service.

Check it out here :-)

Jerome Segura

  • Posted in Uncategorized
  • |
  • (0) comments
  • |
  • Add your comments

Hot day chasing malware away

June 4th, 2009

Today is pretty hot for Victoria BC flirting with 30 degrees Celsius.

vic

But in our office, the temperature is nice and cool at about 22 C.

I am busy finding new malware, preparing a PowerPoint preso, and writing down some new ideas.

We had an excellent lunch today, from of one our SWAT guys, Josh. He made some Greek food :-)

This is my desk:

mydesk

Why 4 monitors you may ask? Well, the laptop is what I am currently using to write this blog post. The two silver screens are dual monitors for my AV testing box, running Ubuntu 9.04. Finally the monitor on the right is for my company’s email and other documents (SVN etc.).

Back to analyzing some stuff now.

Jerome

  • Posted in Uncategorized
  • |
  • (0) comments
  • |
  • Add your comments

« Previous Entries



Location

You are currently browsing the archives for the Uncategorized category.




RSS feed to this site Twitter Linkedin YouTube Channel

 

RSS feed to this site Jerome Segura is a Security Analyst working at ParetoLogic.

You can contact him at:
MalwareDiaries Email

 

Pages

  • Live Malware Map
  • About
  • Contact Us



Malware Top 10

  • Privacy Center
  • Pro AntiSpyware 2009
  • Antivirus XP
  • Antivirus 2009
  • Antivirus 360
  • Internet Antivirus Pro
  • Ultimate Antivirus 2008
  • Ultimate Cleaner
  • Ultimate Defender
  • Renus



Archives

  • July 2009
  • June 2009
  • May 2009
  • April 2009
  • March 2009
  • February 2009
  • January 2009
  • December 2008
  • November 2008
  • October 2008
  • September 2008
  • August 2008
  • July 2008
  • June 2008
  • May 2008
  • April 2008
  • March 2008



Categories

  • Botnets (2)
  • Exploits (14)
  • Fake codecs (14)
  • IM threats (1)
  • Keyloggers (1)
  • Mac security (4)
  • Malware Trends (64)
  • Phishing (5)
  • Research (25)
  • Rogue software (45)
  • Rootkits (2)
  • Uncategorized (66)
  • Wireless Security (1)



 
 
 

© 2009 ParetoLogic Inc.