1644 posts
Windows Vista spotted in-the-wild
I just read an interesting post by Alex about adoption of Windows Vista. We recently finished a three month research study to discover infection rates…
Automatic classification of malware
Last year we posted an article about graphic representations of malware, in which we commented that it's possible to automatically identify and classify malware into…
Do AV companies create viruses?
As someone working in the lab of an antivirus company, I've often been asked if we are the ones that create viruses. Not only the…
Back from Virus Bulletin 2007
We had a really great time at VB2007 in Vienna. Not only were the talks extremely useful and interesting, but meeting many people from other…
JavaScript de-obfuscation with Rhino
Last Friday, I received a URL which used several exploits to spread malware. As always, I started to investigate it. As you may know, these sites use javascript…
XRumer
As we commented in Spam in PHP forums and in Spam in PHP forums (II), it has become more and more usual to see websites (forums,…
More about Mpack (II)
Today I have come across a server hosting an Mpack that has 292 different websites with iframes that make reference to it. Most of…