PC District
Software News
| |
Search in
PC District » News Articles Reviews » Software » PandaLabs Issues New Report About Malware Developers

PandaLabs Issues New Report About Malware Developers

Category: Software
Published: 03/01/2008, 21:41
Editor: Badragan Ciprian

    According to PandaLabs, cyber-crooks are looking for ways to test their creations before distributing them. An investigation conducted by the malware analysis and detection laboratory at Panda Security, has shown that cyber-crooks are collaborating on different forums and pages to develop test-tools that replicate the scans of some of the leading security solutions. This allows hackers to check their creations will be undetected before launching them.

    "The tool is very similar to Hispasec's legitimate 'Virus Total' tool. In fact, the increasing interest in these new tools coincides
with the removal of the "do not distribute the sample" option in 'Virus Total' which allowed files to be scanned without sending the sample to security companies," explains Luis Corrons, Technical Director of PandaLabs.

    From the point of view of a malware developer, one of the main goals when developing a new creation is to avoid antivirus detections
, via signature or heuristic technologies. There are different ways to do it, such as using free on-line scanners offered by most of the vendors. But this is something tedious, as you have to go from one to another all the time. These tools represent another piece of the new malware dynamic, in which cyber-crooks no longer seek to cause widespread alerts and make the headlines, but to go unnoticed. They therefore want to check their creations are undetected by companies before launching them.

    "Even if their creations were detected by one or two companies, they could still launch them,
as they would affect all users with different security technologies," says Luis Corrons.

    When VirusTotal was born a few years ago, some people were claiming that it was being used by malware developers
to test their creations. In some cases, we knew it was true, as we have seen some advertisements in forums showing the scanning results from VirusTotal claiming that certain malware was not detected by any vendor. On January 3rd, VirusTotal decided to remove the option "Do not distribute the sample", so each and every file could be sent to any antivirus vendor.

    It uses some kind of "install & forget" philosophy. When you install it, you do not need to do anything else,
but updating it from time to time. If you take a look at the update option, you’ll see that the different signature files will be updated. Maybe its disadvantage is the limited number of engines it uses, though they are likely to improve it considerably in future versions.



Bookmark this article to:
Add 'PandaLabs Issues New Report About Malware Developers' to Del.icio.us Add 'PandaLabs Issues New Report About Malware Developers' to digg Add 'PandaLabs Issues New Report About Malware Developers' to FURL Add 'PandaLabs Issues New Report About Malware Developers' to reddit Add 'PandaLabs Issues New Report About Malware Developers' to Technorati Add 'PandaLabs Issues New Report About Malware Developers' to Yahoo My Web Add 'PandaLabs Issues New Report About Malware Developers' to Stumble Upon Add 'PandaLabs Issues New Report About Malware Developers' to Google Bookmarks Add 'PandaLabs Issues New Report About Malware Developers' to RawSugar Add 'PandaLabs Issues New Report About Malware Developers' to Squidoo Add 'PandaLabs Issues New Report About Malware Developers' to Spurl Add 'PandaLabs Issues New Report About Malware Developers' to Netvouz Add 'PandaLabs Issues New Report About Malware Developers' to Rojo Add 'PandaLabs Issues New Report About Malware Developers' to Bloglines Add 'PandaLabs Issues New Report About Malware Developers' to Tailrank
Add comment  
PC District is not responsible for the content of these User comments. The views and opinions expressed are those of the individual poster and not the PC District.
User comments (0):

There is no comment for this review.

 
Related Articles:
 

Maxtor Delivers Secure Remote Access to Your Shared Storage From Any Web Browser
 Seagate introduces at CES a free software upgrade that provides a secure and easy-to-use remote access service, empowering people to easily and securely retrieve content stored on their Maxtor Shared Storage II network attached drive through any Internet browser. This latest offering from Maxtor demonstrates the company's ongoing commitment to providing the tools people need to back up, access and share digital assets while in the office, at home or on the road. Maxtor Central Axis software will be a free software upgrade for anyone that chooses to enable the remote access capabilities of their Maxtor Shared Storage II drive.
Read More >
01/07/2008, 04:40
 

Online Advertising Analytics Platform 3.6 Released by ClearSaleing
 The release of version 3.6 to their online advertising analytics application has been announced by An online advertising analytics and technology company, ClearSaleing Inc. (http://www.clearsaleing.com).
Read More >
08/25/2008, 17:51
 

RSSCalendar Abducted By Lookout Software
 Lookout Software, LLC., a developer of Microsoft Outlook calendar sharing application for users without Exchange Server, OfficeCalendar; and a new AJAX time tracking solution for SME's, Office Timesheets; announced that it has acquired RSSCalendar, an innovative online event and calendaring syndication solution. RSS Calendar offers a free online calendar syndication solution and currently has more than 25,000 registered users, hosts more than 1 million calendar events, and garners more than 2.7 million page views per month.
Read More >
10/22/2007, 16:11
 

The Next-Generation of Embedded Solution Launched by Parasoft
 Leading provider of solutions and services that deliver quality as a continuous process throughout the Software Development Lifecycle (SDLC) for embedded and real time systems, Parasoft Embedded, today announced full support of a comprehensive, end-to-end solution for software development that supports all ARM processors and ARM debug technology, called ARM® RealView® Development Suite 3.1 (RVDS).
Read More >
04/14/2008, 14:36
 

Now Available on Yahoo!® is IDEALYST® Widget
 Now, directly from Yahoo, a desktop widget designed to keep IDEALYST participants up-to-date on the content of their brainstorming session can be downloaded!
Read More >
08/21/2008, 18:31

 My PCDistrict Login
News - Articles - Reviews
Software
Sponsored