





Outbreak Alert
Most Active New Threats
| Name | Type | Discovered |
| W32.Ramnit.B!gen2 | Virus | 02/21/2012 |
| Trojan.Zeroaccess!gen9 | Trojan | 02/17/2012 |
| Packed.Generic.350 | Trojan | 02/15/2012 |
| Bloodhound.Gampass.E | Trojan | 02/15/2012 |
| Trojan.Sefnit!gen4 | Trojan | 02/14/2012 |
| Backdoor.Pihar!gen1 | Trojan | 02/14/2012 |
| Bloodhound.Exploit.448 | Trojan Virus | 02/14/2012 |
| Infostealer.Shiz!gen | Trojan | 02/09/2012 |
| W32.Pilleuz!gen31 | Worm | 02/08/2012 |
| Backdoor.Cycbot!gen10 | Trojan | 02/08/2012 |
Internet Threat Meter
The Internet Threat Meter provides a quick visual indicator of how likely each common online activities is likely to encounter some form of threat from a malicious attacker.
- Hover over each activity for a short explanation of the current risk level
- Click on an activity to visit a page with more detail on that activity and the risk level

Email
MEDIUM RISK:
Use Extra Caution
On February 15, 2012, Adobe released a patch for a cross-site scripting (XSS) vulnerability that is being exploited in the wild through links in emails (CVE-2011-0767, BID 52040). User interaction is required to click on the malicious link.
Web Activities
MEDIUM RISK:
Use Extra Caution
Microsoft Updates for February 2012 have been released. Please ensure that latest updates are applied.
Instant Messaging
LOW RISK:
Use Basic Caution
Currently there are no widespread outbreaks of malicious code circulating via instant messaging. In the past, however, some malicious code did take advantage of IM. Always use normal security precautions whenever you use IM.
File Sharing
LOW RISK:
Use Basic Caution
Although attackers often use this medium to distribute trojan applications and malicious code, no high-profile threats are currently affecting the medium. Always use caution when downloading files, especially from sources you don’t know or trust.
Security Response Blog
Zeusbot/Spyeye P2P Updated, Fortifying the Botnet
Andrea Lelli @ Tue, 21 Feb 2012 22:44:03We blogged about a parallel Zeusbot/Spyeye build near the end of last year that introduced some ...
PDF Malware Writers Keep Targeting Vulnerability
Jason Zhang @ Tue, 21 Feb 2012 20:49:19We keep seeing new waves of PDF file-based attacks that exploit the Adobe Acrobat and Reader ...
Airline Booking Confirmation Phish
Sean Butler @ Tue, 21 Feb 2012 08:55:45Recently I came across an airline booking confirmation phishing email. Whilst this is not necessarily a ...
Масленица Началась, And So Is Spam!
Samir Patil @ Tue, 21 Feb 2012 07:24:14Thanks to Poonam Keluskar for their assistance with this research. read more ...
Malware to Mourn Whitney Houston
Samir Patil @ Fri, 17 Feb 2012 03:43:08Thanks to Anand Muralidharan for their assistance with this research. read more ...
Microsoft Patch Tuesday - February 2012
Robert Keith @ Tue, 14 Feb 2012 11:40:31Hello, welcome to this month’s blog on the Microsoft patch release. This is a larger month—the ...
Twitter Feed





Threat Spotlight: Trojan.Zeroaccess
Trojan.Zeroaccess is a Trojan horse that uses an advanced rootkit to hide itself. It is often installed through drive-by-download attacks from sites hosting the Blackhole exploit kit. The Trojan can also create an encrypted, hidden file system, download more malware, and open a back door on the compromised computer.
The Trojan is called ZeroAccess due to a string found in the kernel driver code that is pointing to the original project folder called ZeroAccess. It is also known as max++ as it creates a new kernel device object called __max++>.
More information on Trojan.Zeroaccess is available in the Trojan.Zeroaccess writeup.

