<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>MRG Effitas</title>
	<atom:link href="http://malwareresearchgroup.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://malwareresearchgroup.com</link>
	<description></description>
	<lastBuildDate>Sat, 04 Feb 2012 17:31:29 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=172</generator>
		<item>
		<title>MRG Effitas Online Banking Test Featured on BBC Click</title>
		<link>http://malwareresearchgroup.com/2012/02/04/mrg-effitas-online-banking-test-featured-in-bbc-click/</link>
		<comments>http://malwareresearchgroup.com/2012/02/04/mrg-effitas-online-banking-test-featured-in-bbc-click/#comments</comments>
		<pubDate>Sat, 04 Feb 2012 17:30:15 +0000</pubDate>
		<dc:creator>Sveta</dc:creator>
				<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://malwareresearchgroup.com/?p=4193</guid>
		<description><![CDATA[http://www.youtube.com/watch?v=EUGTlVSefeo]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.youtube.com/watch?v=EUGTlVSefeo">http://www.youtube.com/watch?v=EUGTlVSefeo</a></p>
]]></content:encoded>
			<wfw:commentRss>http://malwareresearchgroup.com/2012/02/04/mrg-effitas-online-banking-test-featured-in-bbc-click/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>BBC bases TV programme on MRG Effitas Online Banking Browser Security tests</title>
		<link>http://malwareresearchgroup.com/2012/02/02/bbc-bases-tv-programme-on-mrg-effitas-online-banking-browser-security-tests/</link>
		<comments>http://malwareresearchgroup.com/2012/02/02/bbc-bases-tv-programme-on-mrg-effitas-online-banking-browser-security-tests/#comments</comments>
		<pubDate>Thu, 02 Feb 2012 22:26:37 +0000</pubDate>
		<dc:creator>Sveta</dc:creator>
				<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://malwareresearchgroup.com/?p=4186</guid>
		<description><![CDATA[MRG Effitas has been working with the BBC on a programme which investigates and analyses the impact of financial malware on online banking security. http://www.bbc.co.uk/news/technology-16812064 Chris Pickard, Methodology &#38; Research director of MRG Effitas and CEO of the Effitas Group has &#8230; <a href="http://malwareresearchgroup.com/2012/02/02/bbc-bases-tv-programme-on-mrg-effitas-online-banking-browser-security-tests/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>MRG Effitas has been working with the BBC on a programme which investigates and analyses the impact of financial malware on online banking security.</p>
<p><strong><a href="http://www.bbc.co.uk/news/technology-16812064">http://www.bbc.co.uk/news/technology-16812064</a></strong></p>
<p>Chris Pickard, Methodology &amp; Research director of MRG Effitas and CEO of the Effitas Group has worked with Spencer Kelly, presenter of BBC Click in creating the programme which is to be broadcast worldwide on the BBC News channel on Seturday the 4<sup>th</sup> of February.</p>
<p>The programme features a test by MRG Effitas demonstrating that a custom piece of crimeware is able to bypass a range of security suites and capture the username and password entered in to a banking website.</p>
<p>You can hear Spencer Kelly discussing the upcoming programme here:</p>
<p><strong><a href="http://news.bbc.co.uk/1/hi/programmes/click_online/9692312.stm">http://news.bbc.co.uk/1/hi/programmes/click_online/9692312.stm</a></strong></p>
<p>We will be publishing a follow up report on Saturday to coincide with the broadcast of the programme.</p>
]]></content:encoded>
			<wfw:commentRss>http://malwareresearchgroup.com/2012/02/02/bbc-bases-tv-programme-on-mrg-effitas-online-banking-browser-security-tests/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Single Product Flash Test – IKARUS virus.utilities, January 2012</title>
		<link>http://malwareresearchgroup.com/2012/01/26/single-product-flash-test-ikarus-virus-utilities-january-2012/</link>
		<comments>http://malwareresearchgroup.com/2012/01/26/single-product-flash-test-ikarus-virus-utilities-january-2012/#comments</comments>
		<pubDate>Thu, 26 Jan 2012 10:11:19 +0000</pubDate>
		<dc:creator>Sveta</dc:creator>
				<category><![CDATA[MRG Product Comparison]]></category>

		<guid isPermaLink="false">http://malwareresearchgroup.com/?p=4177</guid>
		<description><![CDATA[Single Product Flash Test Product: IKARUS virus.utilities Product Version: 2.0.74 Operating System: Windows 7 32-Bit Amount of samples used: 50 Results Table: &#160; Trojans Set 1 Trojans Set 2 Backdoors Spy/PWS Other Harig Jorik Poison Adramax AutoRun Midgare Vilsel Bifrose &#8230; <a href="http://malwareresearchgroup.com/2012/01/26/single-product-flash-test-ikarus-virus-utilities-january-2012/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p><strong>Single Product Flash Test</strong></p>
<p>Product: <strong>IKARUS virus.utilities<br />
</strong></p>
<p>Product Version: <strong>2.0.74</strong></p>
<p>Operating System: Windows <strong>7 32-Bit</strong></p>
<p>Amount of samples used: <strong>50</strong></p>
<p>Results Table:</p>
<p>&nbsp;</p>
<table width="400" border="1" cellspacing="0" cellpadding="5">
<tbody>
<tr>
<td valign="top" width="80"><strong>Trojans</strong><br />
<strong>Set 1</strong></td>
<td valign="top" width="80"><strong>Trojans</strong><br />
<strong>Set 2</strong></td>
<td valign="top" width="80"><strong>Backdoors</strong></td>
<td valign="top" width="80"><strong>Spy/PWS</strong></td>
<td valign="top" width="80"><strong>Other</strong></td>
</tr>
<tr>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Harig</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Jorik</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Poison</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Adramax</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>AutoRun</strong></span></td>
</tr>
<tr>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Midgare</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Vilsel</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Bifrose</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Zeus</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>FakeAV</strong></span></td>
</tr>
<tr>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Zmunik</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Swisyn</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Sdbot</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Lmir</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>TDSS</strong></span></td>
</tr>
<tr>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Cosmu</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Sasfis</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Kbot</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Banker</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Ngrbot</strong></span></td>
</tr>
<tr>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Autoit</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Pincav</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Shark</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Papras</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>PornoAsset</strong></span></td>
</tr>
<tr>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Refroso</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Buzus</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Hupigon</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>QQShou</strong></span></td>
<td valign="top" width="80">
<h5><strong><span style="color: #00ff00;">Cerohar</span><br />
</strong></h5>
</td>
</tr>
<tr>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Inject</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Liac</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>DsBot</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Dybalom</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>LockScreen</strong></span></td>
</tr>
<tr>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Cidox</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Diple</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Zegost</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Usteal</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Krap</strong></span></td>
</tr>
<tr>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>StartPage</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Yakes</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Turkojan</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>SpyEye</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Vobfus</strong></span></td>
</tr>
<tr>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Vapsup</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>FakeSysdef</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Gbot</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>LdPinch</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Gimemo</strong></span></td>
</tr>
</tbody>
</table>
<p>&nbsp;</p>
<p>System Status: <span style="color: #00ff00;"><strong>Secure</strong></span></p>
<p>Legend:</p>
<p><span style="color: #00ff00;"><strong>Green</strong></span> – Passed</p>
<p><span style="color: #ff0000;"><strong>Red</strong></span> – Failed</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://malwareresearchgroup.com/2012/01/26/single-product-flash-test-ikarus-virus-utilities-january-2012/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Largest Cyber Attack Ever?</title>
		<link>http://malwareresearchgroup.com/2012/01/20/largest-cyber-attack-ever/</link>
		<comments>http://malwareresearchgroup.com/2012/01/20/largest-cyber-attack-ever/#comments</comments>
		<pubDate>Fri, 20 Jan 2012 16:23:05 +0000</pubDate>
		<dc:creator>Sveta</dc:creator>
				<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://malwareresearchgroup.com/?p=4174</guid>
		<description><![CDATA[Targets: U.S. Department of Justice, FBI, U.S. Copyright Office, RIAA, Universal Music, Broadcast Music Inc, Motion Picture Association of America&#8230; Damage: Unknown Attacker(s): Hacktivist Group Anonymous]]></description>
			<content:encoded><![CDATA[<p>Targets: <strong>U.S. Department of Justice, FBI, U.S. Copyright Office, RIAA, Universal Music, Broadcast Music Inc, Motion Picture Association of America&#8230;</strong></p>
<p>Damage: <strong>Unknown</strong></p>
<p>Attacker(s): <strong>Hacktivist Group Anonymous</strong></p>
]]></content:encoded>
			<wfw:commentRss>http://malwareresearchgroup.com/2012/01/20/largest-cyber-attack-ever/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Carberp Hits Facebook Users</title>
		<link>http://malwareresearchgroup.com/2012/01/19/carberp-hits-facebook-users/</link>
		<comments>http://malwareresearchgroup.com/2012/01/19/carberp-hits-facebook-users/#comments</comments>
		<pubDate>Thu, 19 Jan 2012 17:13:46 +0000</pubDate>
		<dc:creator>Sveta</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://malwareresearchgroup.com/?p=4168</guid>
		<description><![CDATA[Facebook users are being targeted in a new man-in-the-browser (MitB) attack that attempts to steal money by duping the user into redeeming an e-cash voucher. The malware is a new configuration of the Carberp Trojan, according to security firm Trusteer. &#8230; <a href="http://malwareresearchgroup.com/2012/01/19/carberp-hits-facebook-users/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p><a href="http://malwareresearchgroup.com/wp-content/uploads/2012/01/facebook_logo.png"><img class="alignleft  wp-image-4169" title="facebook_logo" src="http://malwareresearchgroup.com/wp-content/uploads/2012/01/facebook_logo-300x300.png" alt="" width="210" height="210" /></a>Facebook users are being targeted in a new man-in-the-browser (MitB) attack that attempts to steal money by duping the user into redeeming an e-cash voucher.</p>
<p>The malware is a new configuration of the Carberp Trojan, according to security firm Trusteer. Carberp replaces any Facebook page the user navigates to with a fake page notifying the victim that his or her Facebook account is “temporarily locked”.</p>
<p>The user is then asked to enter their name, email address, date of birth and password, followed by the number of a €20 Ukash voucher to “confirm verification” of their identity and unlock the account. Ukash is an e-money network that allows customers to anonymously exchange cash for vouchers that can be spent online.<span id="more-4168"></span></p>
<p>The page claims the cash voucher will be “added to the user’s main Facebook account balance”. However, the credit is instead transferred to the Carberp bot master, who is able to use it as a cash equivalent.</p>
<p>”This clever man-in-the-browser (MitB) attack exploits the trust users have with the Facebook website and the anonymity of e-cash vouchers,” said Trusteer’s CTO Amit Klein.</p>
<p>“Unlike attacks against online banking applications that require transferring money to another account which creates an auditable trail, this new Carberp attack allows fraudsters to use or sell the e-cash vouchers immediately anywhere they are accepted on the internet.”</p>
<p>Klein told Techworld that Trusteer does not have a concrete idea of how many users have been affected. “However, we&#8217;ve seen botnets ranging in size from thousands to millions, so it&#8217;s safe to say it&#8217;s somewhere in between,” he said.</p>
<p>With the growing adoption of e-cash on the internet, Trusteer expects to see an increasing number of these types of attack, and social networks like Facebook provide cybercriminals with a large pool of victims that can be fairly easily tricked into divulging confidential account information.</p>
<p>Like card-not-present fraud, where cybercriminals use stolen debit and credit card information to make illegal online purchases, e-cash fraud is a low risk form of crime, explains Trusteer. With e-cash, however, it is the account holder who assumes liability for fraudulent transactions, rather than the financial institution.</p>
<p>Klein recommends using browser-based security tools that can secure communication between the computer and target website to block MitB attack methods like HTML injection, and prevent keylogging from grabbing data.</p>
<p>Carberp was first discovered in October 2010 by several security companies and noted for its ability to steal a range of data, as well as disguise itself as legitimate Windows files and remove antivirus software. It has been billed as a rival to Zeus, another well-known piece of malware.</p>
<p>Context Information Security warned yesterday that financial malware of this kind is becoming increasingly difficult to detect and eliminate, as it uses multiple layers of obfuscation and encryption to remain hidden and prevent analysis.</p>
<p>- <strong><em>TechWorld</em></strong></p>
]]></content:encoded>
			<wfw:commentRss>http://malwareresearchgroup.com/2012/01/19/carberp-hits-facebook-users/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cyber Crime Diary , January 2012</title>
		<link>http://malwareresearchgroup.com/2012/01/19/cyber-crime-diary-january-2012/</link>
		<comments>http://malwareresearchgroup.com/2012/01/19/cyber-crime-diary-january-2012/#comments</comments>
		<pubDate>Thu, 19 Jan 2012 13:00:40 +0000</pubDate>
		<dc:creator>Sveta</dc:creator>
				<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://malwareresearchgroup.com/?p=4156</guid>
		<description><![CDATA[1. Target: Symantec corp. Damage: Surce code stolen Attacker(s): Dharmaraja group (India) 2. Target: South African Postbank Damage: $6.7 million Attacker(s): Unknown 3. Target: Zappos.com Damage: 24 million customer details compromised Attacker(s): Unknown 4. Target: Japanese Space Agency Damage: Login &#8230; <a href="http://malwareresearchgroup.com/2012/01/19/cyber-crime-diary-january-2012/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p style="text-align: left;"><strong></strong><em><strong>1.</strong> Target:</em> <strong>Symantec corp.</strong><em></em></p>
<p style="text-align: left;"><em>Damage:</em> <strong>Surce code stolen</strong><em></em></p>
<p style="text-align: left;"><em> Attacker(s):</em> <strong>Dharmaraja group</strong> (India)</p>
<p style="text-align: left;"><strong></strong><em><strong>2.</strong> Target:</em> <strong>South African Postbank</strong></p>
<p style="text-align: left;"><em>Damage:</em> <strong>$6.7 million</strong></p>
<p style="text-align: left;"><em>Attacker(s):</em> <strong>Unknown</strong></p>
<p style="text-align: left;"><em><strong>3.</strong> Target:</em> <strong>Zappos.com</strong></p>
<p style="text-align: left;"><em>Damage:</em> <strong>24 million customer details compromised</strong></p>
<p style="text-align: left;"><em>Attacker(s):</em> <strong>Unknown</strong></p>
<p style="text-align: left;"><strong></strong><em><strong>4.</strong> Target:</em> <strong>Japanese Space Agency</strong></p>
<p style="text-align: left;"><em>Damage:</em> <strong>Login information to gain access to a cargo shuttle that carries food and equipment to the International Space Station (ISS) has been stolen</strong><em></em></p>
<p style="text-align: left;"><em> Attacker(s):</em> <strong>Unknown</strong></p>
]]></content:encoded>
			<wfw:commentRss>http://malwareresearchgroup.com/2012/01/19/cyber-crime-diary-january-2012/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Single Product Flash Test – Symantec Norton Antivirus, January 2012</title>
		<link>http://malwareresearchgroup.com/2012/01/16/single-product-flash-test-symantec-norton-antivirus-january-2012/</link>
		<comments>http://malwareresearchgroup.com/2012/01/16/single-product-flash-test-symantec-norton-antivirus-january-2012/#comments</comments>
		<pubDate>Mon, 16 Jan 2012 21:21:02 +0000</pubDate>
		<dc:creator>Sveta</dc:creator>
				<category><![CDATA[MRG Product Comparison]]></category>

		<guid isPermaLink="false">http://malwareresearchgroup.com/?p=4151</guid>
		<description><![CDATA[Single Product Flash Test Product: Symantec Norton Antivirus 2012 Product Version: 19.2.0.10 Operating System: Windows 7 32-Bit Amount of samples used: 50 Results Table: &#160; Trojans Set 1 Trojans Set 2 Backdoors Spy/PWS Other Rammit Diple DsBot LdPinch Krap Inject Menti &#8230; <a href="http://malwareresearchgroup.com/2012/01/16/single-product-flash-test-symantec-norton-antivirus-january-2012/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p><strong>Single Product Flash Test</strong></p>
<p>Product: <strong>Symantec Norton Antivirus 2012<br />
</strong></p>
<p>Product Version: <strong>19.2.0.10</strong></p>
<p>Operating System: Windows <strong>7 32-Bit</strong></p>
<p>Amount of samples used: <strong>50</strong></p>
<p>Results Table:</p>
<p>&nbsp;</p>
<table width="400" border="1" cellspacing="0" cellpadding="5">
<tbody>
<tr>
<td valign="top" width="80"><strong>Trojans</strong><br />
<strong>Set 1</strong></td>
<td valign="top" width="80"><strong>Trojans</strong><br />
<strong>Set 2</strong></td>
<td valign="top" width="80"><strong>Backdoors</strong></td>
<td valign="top" width="80"><strong>Spy/PWS</strong></td>
<td valign="top" width="80"><strong>Other</strong></td>
</tr>
<tr>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Rammit</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Diple</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>DsBot</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>LdPinch</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Krap</strong></span></td>
</tr>
<tr>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Inject</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Menti</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Cycbot</strong></span></td>
<td valign="top" width="80"><span style="color: #ff0000;"><strong>Banbra</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>FakeAV</strong></span></td>
</tr>
<tr>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Rozena</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Cidox</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Zegost</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Zeus</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Alureon</strong></span></td>
</tr>
<tr>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Vilsel</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Lampa</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Havar</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Chekafev</strong></span></td>
<td valign="top" width="80"><span style="color: #ff0000;"><strong>Digitala</strong></span></td>
</tr>
<tr>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Injector</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Rimecud</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Agobot</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Adramax</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Vobfus</strong></span></td>
</tr>
<tr>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Buzus</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Midgare</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Shiz</strong></span></td>
<td valign="top" width="80"><strong><span style="color: #ff0000;">Lmir</span></strong></td>
<td valign="top" width="80">
<h5><strong><span style="color: #00ff00;">Pdfka</span><br />
</strong></h5>
</td>
</tr>
<tr>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Refroso</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Pakes</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Hupigon</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>SpyEye</strong></span></td>
<td valign="top" width="80"><span style="color: #ff0000;"><strong>Ransom</strong></span></td>
</tr>
<tr>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Liac</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Small</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Simda</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Bjlog</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>AutoRun</strong></span></td>
</tr>
<tr>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Renos</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Chifrax</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Wuca</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Kykymber</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>VBNA</strong></span></td>
</tr>
<tr>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Scar</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Otran</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Simbot</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>QQLogger</strong></span></td>
<td valign="top" width="80"><strong><span style="color: #00ff00;">ZAccess</span></strong></td>
</tr>
</tbody>
</table>
<p>&nbsp;</p>
<p>System Status: <span style="color: #ff0000;"><strong>Compromised</strong></span></p>
<p>Legend:</p>
<p><span style="color: #00ff00;"><strong>Green</strong></span> – Passed</p>
<p><span style="color: #ff0000;"><strong>Red</strong></span> – Failed</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://malwareresearchgroup.com/2012/01/16/single-product-flash-test-symantec-norton-antivirus-january-2012/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Modern Warfare 2012</title>
		<link>http://malwareresearchgroup.com/2012/01/02/the-war-is-on/</link>
		<comments>http://malwareresearchgroup.com/2012/01/02/the-war-is-on/#comments</comments>
		<pubDate>Mon, 02 Jan 2012 18:03:44 +0000</pubDate>
		<dc:creator>Sveta</dc:creator>
				<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://malwareresearchgroup.com/?p=4136</guid>
		<description><![CDATA[Rootkit, Bootkit, Adware, Backdoor, BHO, Downloader, Email Worm, Exploit, Flooder, Hack Tool, Hoax, Script, HTML, VB, JS, Bat, Fat, Net Worm, P2P Worm, Packed, Constructor , Packer, SQL, IM Worm, PWS, Spy, Dropper, Banker, Clicker, Proxy, SMS, GameThief, Ransom, Virus, &#8230; <a href="http://malwareresearchgroup.com/2012/01/02/the-war-is-on/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<h1><strong><span style="color: #000000;">Rootkit, Bootkit, Adware, Backdoor, BHO, Downloader, Email Worm, Exploit, Flooder, Hack Tool, Hoax, Script, HTML, VB, JS, Bat, Fat, Net Worm, P2P Worm, Packed, Constructor , Packer, SQL, IM Worm, PWS, Spy, Dropper, Banker, Clicker, Proxy, SMS, GameThief, Ransom, Virus, Worm, Spyware, Fake AV, Fraud, Win32, Win64, Android&#8230;.</span></strong></h1>
<p>&nbsp;</p>
<p><em>Above is a list detailing just some of the malware categories MRG Effitas processes in its labs. Each individual category of malware may have tens or hundreds of thousands of variants. Each and every day, each category will spawn tens of thousands more variants.</em></p>
<p style="text-align: center;"><em>The war is on, let’s work smart and join forces and win it!</em></p>
<p><em><a href="http://malwareresearchgroup.com/wp-content/uploads/2012/01/shake-hands.jpg"><img class="aligncenter size-full wp-image-4146" title="Modern Warfare 2012" src="http://malwareresearchgroup.com/wp-content/uploads/2012/01/shake-hands.jpg" alt="" width="300" height="225" /></a><br />
</em></p>
<p style="text-align: center;"><strong>MRG Effitas Team.</strong></p>
]]></content:encoded>
			<wfw:commentRss>http://malwareresearchgroup.com/2012/01/02/the-war-is-on/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Single Product Flash Test – Sourcefire Immunet Plus, December 2011</title>
		<link>http://malwareresearchgroup.com/2011/12/19/single-product-flash-test-sourcefire-immunet-plus-december-2011/</link>
		<comments>http://malwareresearchgroup.com/2011/12/19/single-product-flash-test-sourcefire-immunet-plus-december-2011/#comments</comments>
		<pubDate>Mon, 19 Dec 2011 09:55:54 +0000</pubDate>
		<dc:creator>Sveta</dc:creator>
				<category><![CDATA[MRG Product Comparison]]></category>

		<guid isPermaLink="false">http://malwareresearchgroup.com/?p=4133</guid>
		<description><![CDATA[Single Product Flash Test Product: Sourcefire Immunet Plus Product Version: 3.0.5.7688 Operating System: Windows 7 32-Bit Amount of samples used: 50 Results Table: &#160; Trojans Set 1 Trojans Set 2 Backdoors Spy/PWS Other Cidox Mudrop Bifrose Zeus TDSS Rimecud Hiloti &#8230; <a href="http://malwareresearchgroup.com/2011/12/19/single-product-flash-test-sourcefire-immunet-plus-december-2011/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p><strong>Single Product Flash Test</strong></p>
<p>Product: <strong>Sourcefire Immunet Plus</strong></p>
<p>Product Version: <strong>3.0.5.7688</strong></p>
<p>Operating System: Windows <strong>7 32-Bit</strong></p>
<p>Amount of samples used: <strong>50</strong></p>
<p><span style="text-decoration: underline;">Results Table:</span></p>
<p>&nbsp;</p>
<table width="400" border="1" cellspacing="0" cellpadding="5">
<tbody>
<tr>
<td valign="top" width="80"><strong>Trojans</strong><br />
<strong>Set 1</strong></td>
<td valign="top" width="80"><strong>Trojans</strong><br />
<strong>Set 2</strong></td>
<td valign="top" width="80"><strong>Backdoors</strong></td>
<td valign="top" width="80"><strong>Spy/PWS</strong></td>
<td valign="top" width="80"><strong>Other</strong></td>
</tr>
<tr>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Cidox</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Mudrop</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Bifrose</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Zeus</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>TDSS</strong></span></td>
</tr>
<tr>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Rimecud</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Hiloti</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Ursap</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Qbot</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Obfuscated</strong></span></td>
</tr>
<tr>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Cosmu</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Ramnit</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Dsbot</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Banker</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Ransom</strong></span></td>
</tr>
<tr>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Yakes</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Liac</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Zegost</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Dybalom</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Bybz</strong></span></td>
</tr>
<tr>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Genome</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Midgare</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Poison</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Kykymber</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>AutoIt</strong></span></td>
</tr>
<tr>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Inject</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Banload</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Trukojan</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>LdPinch</strong></span></td>
<td valign="top" width="80">
<h5><span style="color: #00ff00;"><strong>Pdfka</strong></span></h5>
</td>
</tr>
<tr>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Delf</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Renos</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Begman</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Banbra</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>ZAccess</strong></span></td>
</tr>
<tr>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Dipel</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Pincav</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Cycbot</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>SpyEye</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Alureon</strong></span></td>
</tr>
<tr>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Menti</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>FakeSysdef</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Koutodoor</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Carberp</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Vobfus</strong></span></td>
</tr>
<tr>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Jorik</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Refroso</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Hupigon</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Pophot</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>FakeAV</strong></span></td>
</tr>
</tbody>
</table>
<p>&nbsp;</p>
<p>System Status: <span style="color: #00ff00;"><strong>Secure</strong></span></p>
<p><span style="text-decoration: underline;">Legend:</span></p>
<p><span style="color: #00ff00;"><strong>Green</strong></span> – Passed</p>
<p><span style="color: #ff0000;"><strong>Red</strong></span> – Failed</p>
]]></content:encoded>
			<wfw:commentRss>http://malwareresearchgroup.com/2011/12/19/single-product-flash-test-sourcefire-immunet-plus-december-2011/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Single Product Flash Test – SUPERAntispyware Professional, December 2011</title>
		<link>http://malwareresearchgroup.com/2011/12/16/single-product-flash-test-superantispyware-professional-december-2011/</link>
		<comments>http://malwareresearchgroup.com/2011/12/16/single-product-flash-test-superantispyware-professional-december-2011/#comments</comments>
		<pubDate>Fri, 16 Dec 2011 21:17:57 +0000</pubDate>
		<dc:creator>Sveta</dc:creator>
				<category><![CDATA[MRG Product Comparison]]></category>

		<guid isPermaLink="false">http://malwareresearchgroup.com/?p=4130</guid>
		<description><![CDATA[Single Product Flash Test Product: SUPERAntispyware Professional Product Version: 5.0.4412 Operating System: Windows 7 32-Bit Amount of samples used: 50 Results Table: &#160; Trojans Set 1 Trojans Set 2 Backdoors Spy/PWS Other Menti Delf Ruskill Usteal Alureon Inject Frijoiner Shark &#8230; <a href="http://malwareresearchgroup.com/2011/12/16/single-product-flash-test-superantispyware-professional-december-2011/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p><strong>Single Product Flash Test</strong></p>
<p>Product: <strong>SUPERAntispyware Professional</strong></p>
<p>Product Version: <strong>5.0.4412</strong></p>
<p>Operating System: <strong>Windows 7 32-Bit</strong></p>
<p>Amount of samples used:<strong> 50</strong></p>
<p><span style="text-decoration: underline;">Results Table:</span></p>
<p>&nbsp;</p>
<table width="400" border="1" cellspacing="0" cellpadding="5">
<tbody>
<tr>
<td valign="top" width="80"><strong>Trojans</strong><br />
<strong>Set 1</strong></td>
<td valign="top" width="80"><strong>Trojans</strong><br />
<strong>Set 2</strong></td>
<td valign="top" width="80"><strong>Backdoors</strong></td>
<td valign="top" width="80"><strong>Spy/PWS</strong></td>
<td valign="top" width="80"><strong>Other</strong></td>
</tr>
<tr>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Menti</strong></span></td>
<td valign="top" width="80"><span style="color: #ff0000;"><strong>Delf</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Ruskill</strong></span></td>
<td valign="top" width="80"><span style="color: #ff0000;"><strong>Usteal</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Alureon</strong></span></td>
</tr>
<tr>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Inject</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Frijoiner</strong></span></td>
<td valign="top" width="80"><span style="color: #ff0000;"><strong>Shark</strong></span></td>
<td valign="top" width="80"><span style="color: #ff0000;"><strong>Zeus</strong></span></td>
<td valign="top" width="80"><span style="color: #ff0000;"><strong>FakeAV</strong></span></td>
</tr>
<tr>
<td valign="top" width="80"><span style="color: #ff0000;"><strong>Sasfis</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Vilsel</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Bifrose</strong></span></td>
<td valign="top" width="80"><span style="color: #ff0000;"><strong>Banker</strong></span></td>
<td valign="top" width="80"><span style="color: #ff0000;"><strong>Ransom</strong></span></td>
</tr>
<tr>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Refroso</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Dapato</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Hupigon</strong></span></td>
<td valign="top" width="80"><span style="color: #ff0000;"><strong>Bancos</strong></span></td>
<td valign="top" width="80"><span style="color: #ff0000;"><strong>Krap</strong></span></td>
</tr>
<tr>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Swisyn</strong></span></td>
<td valign="top" width="80"><span style="color: #ff0000;"><strong>Liac</strong></span></td>
<td valign="top" width="80"><span style="color: #ff0000;"><strong>Kredoor</strong></span></td>
<td valign="top" width="80"><span style="color: #ff0000;"><strong>QQPass</strong></span></td>
<td valign="top" width="80"><span style="color: #ff0000;"><strong>AutoRun</strong></span></td>
</tr>
<tr>
<td valign="top" width="80"><span style="color: #ff0000;"><strong>Pasta</strong></span></td>
<td valign="top" width="80"><span style="color: #ff0000;"><strong>Scar</strong></span></td>
<td valign="top" width="80"><span style="color: #ff0000;"><strong>DsBot</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>SpyEye</strong></span></td>
<td valign="top" width="80">
<h5><span style="color: #ff0000;"><strong>ZAccess</strong></span></h5>
</td>
</tr>
<tr>
<td valign="top" width="80"><span style="color: #ff0000;"><strong>Rbot</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Malf</strong></span></td>
<td valign="top" width="80"><span style="color: #ff0000;"><strong>AgoBot</strong></span></td>
<td valign="top" width="80"><span style="color: #ff0000;"><strong>Carberp</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>TDSS</strong></span></td>
</tr>
<tr>
<td valign="top" width="80"><span style="color: #ff0000;"><strong>Yakes</strong></span></td>
<td valign="top" width="80"><span style="color: #ff0000;"><strong>Ircbrute</strong></span></td>
<td valign="top" width="80"><span style="color: #ff0000;"><strong>Poison</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Fingotok</strong></span></td>
<td valign="top" width="80"><span style="color: #ff0000;"><strong>VBNA</strong></span></td>
</tr>
<tr>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Zmunik</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Jorik</strong></span></td>
<td valign="top" width="80"><span style="color: #ff0000;"><strong>Turkojan</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Sinowal</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Sality</strong></span></td>
</tr>
<tr>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Buzus</strong></span></td>
<td valign="top" width="80"><span style="color: #ff0000;"><strong>Small</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Optix</strong></span></td>
<td valign="top" width="80"><span style="color: #00ff00;"><strong>Ruftar</strong></span></td>
<td valign="top" width="80"><span style="color: #ff0000;"><strong>Kokab</strong></span></td>
</tr>
</tbody>
</table>
<p>&nbsp;</p>
<p>System Status: <span style="color: #ff0000;"><strong>Compromised</strong></span></p>
<p>Legend:</p>
<p><span style="color: #00ff00;"><strong>Green</strong></span> – Passed</p>
<p><span style="color: #ff0000;"><strong>Red</strong></span> – Failed</p>
]]></content:encoded>
			<wfw:commentRss>http://malwareresearchgroup.com/2011/12/16/single-product-flash-test-superantispyware-professional-december-2011/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>

