<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>InfoSecPodcast.com &#187; Viruses &amp; Worms</title>
	<atom:link href="http://www.infosecpodcast.com/category/security/viruses-worms/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.infosecpodcast.com</link>
	<description>Information Security related news, opinions and ramblings</description>
	<lastBuildDate>Sun, 25 Jul 2010 13:04:23 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Cell phone virus writer arrested in Spain</title>
		<link>http://www.infosecpodcast.com/2007/06/cell-phone-virus-writer-arrested-in-spain/</link>
		<comments>http://www.infosecpodcast.com/2007/06/cell-phone-virus-writer-arrested-in-spain/#comments</comments>
		<pubDate>Tue, 26 Jun 2007 13:30:35 +0000</pubDate>
		<dc:creator>Chris Harrington</dc:creator>
				<category><![CDATA[Viruses & Worms]]></category>
<category>cell phone</category><category>commwarrior</category><category>darwin</category><category>malware</category><category>viruses</category><category>virus cabir</category>
		<guid isPermaLink="false">http://www.infosecpodcast.com/viruses-worms/2007/06/cell-phone-virus-writer-arrested-in-spain/</guid>
		<description><![CDATA[Spanish police arrested a 28 year old man for writing several variants of the Cabir and Commwarrior viruses. These viruses targeted the Symbian operating system which is a popular cell phone OS. It was spread through Bluetooth connections. They are reporting that over 115,000 phones were infected. How did they catch him? He put his [...]]]></description>
			<content:encoded><![CDATA[<p>Spanish police arrested a 28 year old man for writing several variants of the Cabir and Commwarrior viruses. These viruses targeted the Symbian operating system which is a popular cell phone OS. It was spread through Bluetooth connections. They are reporting that over 115,000 phones were infected. How did they catch him?</p>
<p>He put his fiance&#8217;s name in the source code. When will malware authors stop putting personally identifiable information in their malware? I hope never&#8230;..Darwin was right.</p>
<p><a href="http://www.whitedust.net/speaks/3905/Spanish%20police%20pinch%20cell%20phone%20hacker/" title="http://www.whitedust.net/speaks/3905/Spanish%20police%20pinch%20cell%20phone%20hacker/" target="_blank">www.whitedust.net/speaks/3905/Spanish%20police%20pinch%20cell%20phone%20hacker/</a></p>
<p>&#8211;Chris</p>
<p>Technorati Tags: <a href="http://technorati.com/tag/cell+phone" rel="tag"> cell phone</a>, <a href="http://technorati.com/tag/virus" rel="tag"> virus</a>, <a href="http://technorati.com/tag/Cabir" rel="tag"> Cabir</a>, <a href="http://technorati.com/tag/Commwarroir" rel="tag"> Commwarroir</a>, <a href="http://technorati.com/tag/29a" rel="tag"> 29a</a>, <a href="http://technorati.com/tag/malware" rel="tag"> malware </a></p>
<div id="crp_related"><h2>Related Posts:</h2><ul><li><a href="http://www.infosecpodcast.com/2007/07/declassified-window-film-stops-wireless-cell-signals/" rel="bookmark" class="crp_title">Declassified window film stops wireless / cell signals</a></li><li><a href="http://www.infosecpodcast.com/2006/07/mcafee-blames-open-source-models-for-rise-in-bots/" rel="bookmark" class="crp_title">McAfee blames Open Source models for rise in &#8216;Bots</a></li><li><a href="http://www.infosecpodcast.com/2006/07/virus-targets-antivirus-researchers-sort-of/" rel="bookmark" class="crp_title">Virus targets AntiVirus researchers, sort of.</a></li><li>Powered by <a href="http://ajaydsouza.com/wordpress/plugins/contextual-related-posts/">Contextual Related Posts</a></li></ul></div><img src="http://www.infosecpodcast.com/?ak_action=api_record_view&id=104&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://www.infosecpodcast.com/2007/06/cell-phone-virus-writer-arrested-in-spain/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ESET&#8217;s NOD32 Antivirus</title>
		<link>http://www.infosecpodcast.com/2007/03/esets-nod32-antivirus/</link>
		<comments>http://www.infosecpodcast.com/2007/03/esets-nod32-antivirus/#comments</comments>
		<pubDate>Tue, 20 Mar 2007 02:10:23 +0000</pubDate>
		<dc:creator>Chris Harrington</dc:creator>
				<category><![CDATA[Viruses & Worms]]></category>

		<guid isPermaLink="false">http://www.infosecpodcast.com/viruses-worms/2007/03/esets-nod32-antivirus/</guid>
		<description><![CDATA[I try not to write about or endorse products as a rule. Every now and then I come across a product that warrants a post. I&#8217;ve been a long time Symantec antivirus user, much of it a holdover from the Symantec System Center days. The latest versions, from Symantec and others like Trend Micro, seem [...]]]></description>
			<content:encoded><![CDATA[<p>I try not to write about or endorse products as a rule. Every now and then I come across a product that warrants a post. I&#8217;ve been a long time <a href="http://www.symantec.com" target="_blank">Symantec</a> antivirus user, much of it a holdover from the Symantec System Center days. The latest versions, from Symantec and others like Trend Micro,  seem to have everything but the kitchen sink. Take a look at running processes and you will likely find several hogging more than their share of memory. They seem to be approaching bloatware status.</p>
<p>For a while now I have been using <a href="http://www.eset.com/products/index.php" target="_blank">NOD32</a> from <a href="http://www.eset.com" target="_blank">Eset</a>. A good friend who is Information Security Analyst at a local college here in NH turned me on to NOD32. It&#8217;s lightweight, fast and accurate.  They have scored 100% on the <a href="http://http://www.virusbtn.com/vb100/index" target="_blank">Virus Bulletin</a> detection tests a total of 41 out of 43 times. The next closest competitor was Symantec at 35 out of 38 attempts.</p>
<p>If you are thinking about trying a different AV, give NOD32 a try. I&#8217;ve had great luck with it. You can get a free trial at <a href="http://www.eset.com/download/index.php" title="http://www.eset.com/download/index.php" target="_blank">www.eset.com/download/index.php</a></p>
<p>&#8211;Chris</p>
<p>Technorati Tags: <a href="http://technorati.com/tag/Antivirus" rel="tag"> Antivirus</a>, <a href="http://technorati.com/tag/ESET" rel="tag"> ESET</a>, <a href="http://technorati.com/tag/NOD32" rel="tag"> NOD32  </a></p>
<div id="crp_related"><h2>Related Posts:</h2><ul><li><a href="http://www.infosecpodcast.com/2006/10/im-presenting-at-nercomp-on-ips/" rel="bookmark" class="crp_title">I&#8217;m presenting at NERCOMP on IPS</a></li><li><a href="http://www.infosecpodcast.com/2006/07/virus-targets-antivirus-researchers-sort-of/" rel="bookmark" class="crp_title">Virus targets AntiVirus researchers, sort of.</a></li><li><a href="http://www.infosecpodcast.com/2006/07/0-day-exploit-for-powerpoint-snort-sigs-to-block-ppt/" rel="bookmark" class="crp_title">&#8220;0-Day&#8221; exploit for PowerPoint, Snort sigs to block .ppt files</a></li><li>Powered by <a href="http://ajaydsouza.com/wordpress/plugins/contextual-related-posts/">Contextual Related Posts</a></li></ul></div><img src="http://www.infosecpodcast.com/?ak_action=api_record_view&id=100&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://www.infosecpodcast.com/2007/03/esets-nod32-antivirus/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Worm articles &amp; presentations</title>
		<link>http://www.infosecpodcast.com/2006/10/worm-articles-presentations/</link>
		<comments>http://www.infosecpodcast.com/2006/10/worm-articles-presentations/#comments</comments>
		<pubDate>Fri, 13 Oct 2006 15:45:16 +0000</pubDate>
		<dc:creator>Chris Harrington</dc:creator>
				<category><![CDATA[Viruses & Worms]]></category>

		<guid isPermaLink="false">http://www.infosecpodcast.com/viruses-worms/2006/10/worm-articles-presentations/</guid>
		<description><![CDATA[The JoatBlog posted links to conference materials from last years Workshop on Rapid Malcode (WORM). A lot of great material worms, bots and other nastys can be found here. &#8211;Chris Technorati Tags: worm, bot, malcode Related Posts:Martin McKeay leaving CobiaWill iPhone support Exchange?Frequent flier miles expose CIA operativesPowered by Contextual Related Posts]]></description>
			<content:encoded><![CDATA[<p>The <a target="_blank" href="http://www.757.org/~joat/cgi-bin/blosxom.cgi">JoatBlog</a> posted links to conference materials from last years <a target="_blank" href="http://www1.cs.columbia.edu/~angelos/worm05/worm-prog.html">Workshop on Rapid Malcode</a> (WORM).  A lot of great material  worms, bots and other nastys can be found <a target="_blank" href="http://www.757.org/~joat/cgi-bin/blosxom.cgi/2006/08/27#wormshop.1">here</a>.</p>
<p>&#8211;Chris</p>
<p>Technorati Tags: <a href="http://technorati.com/tag/worm" rel="tag"> worm</a>, <a href="http://technorati.com/tag/bot" rel="tag"> bot</a>, <a href="http://technorati.com/tag/malcode" rel="tag"> malcode </a></p><br />
<font><font face="arial,  helvetica" /></font></p>
<p><font> </font><font><font><font><font> </font></font></font></font></p>
<div id="crp_related"><h2>Related Posts:</h2><ul><li><a href="http://www.infosecpodcast.com/2007/07/martin-mckeay-leaving-cobia/" rel="bookmark" class="crp_title">Martin McKeay leaving Cobia</a></li><li><a href="http://www.infosecpodcast.com/2007/06/will-iphone-support-exchange/" rel="bookmark" class="crp_title">Will iPhone support Exchange?</a></li><li><a href="http://www.infosecpodcast.com/2006/07/frequent-flier-miles-expose-cia-operatives/" rel="bookmark" class="crp_title">Frequent flier miles expose CIA operatives</a></li><li>Powered by <a href="http://ajaydsouza.com/wordpress/plugins/contextual-related-posts/">Contextual Related Posts</a></li></ul></div><img src="http://www.infosecpodcast.com/?ak_action=api_record_view&id=71&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://www.infosecpodcast.com/2006/10/worm-articles-presentations/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Virus targets AntiVirus researchers, sort of.</title>
		<link>http://www.infosecpodcast.com/2006/07/virus-targets-antivirus-researchers-sort-of/</link>
		<comments>http://www.infosecpodcast.com/2006/07/virus-targets-antivirus-researchers-sort-of/#comments</comments>
		<pubDate>Thu, 13 Jul 2006 15:24:39 +0000</pubDate>
		<dc:creator>Chris Harrington</dc:creator>
				<category><![CDATA[Viruses & Worms]]></category>

		<guid isPermaLink="false">http://www.infosecpodcast.com/2006/07/13/virus-targets-antivirus-researchers-sort-of/</guid>
		<description><![CDATA[A new virus was detected in early July that reportedly targets AV researchers. The virus, know as Gatt / Gattaca, will scan an infected system for any files with the .idc extension and infect them. These .idc files are disassembler files used by Interactive Disassembler Pro, a very common tool used by AV researchers to [...]]]></description>
			<content:encoded><![CDATA[<p>A new virus was detected in early July that reportedly targets AV researchers. The virus, know as Gatt / Gattaca, will scan an infected system for any files with the .idc extension and infect them. These .idc files are disassembler files used by Interactive Disassembler Pro, a very common tool used by AV researchers to reverse engineer malware.</p>
<p>Why do I say this <strong><em>sort of</em></strong> targets AV researchers? The virus doesn&#8217;t do anything as there is <strong>no</strong> malicious payload. It just replicates it self to other .idc files. So why write something like this? I agree with Mikko from <a target="_blank" href="http://www.f-secure.com/weblog/">F-Secure</a>, &#8220;I think it  was written to just show off it can be done&#8221;. In typical hax0r tradition there is a hidden message / shout out in the file accoding to <a target="_blank" href="http://www.sophos.com/security/analyses/w32gattmana.html">this Sophos</a> analysis. For the curious I&#8217;ve added links to several AV companies analyses of the virus.</p>
<p>And for the REALLY curious, pick up a copy of Ed Skoudis&#8217; book,  <a target="_blank" href="http://www.amazon.com/exec/obidos/redirect?tag=infosecpodcas-20%26link_code=xm2%26camp=2025%26creative=165953%26path=http://www.amazon.com/gp/redirect.html%253fASIN=0131014056%2526tag=infosecpodcas-20%2526lcode=xm2%2526cID=2025%2526ccmID=165953%2526location=/o/ASIN/0131014056%25253FSubscriptionId=0EMV44A9A5YT1RVDGZ82">Malware: Fighting Malicious Code.</a> I am just finishing the book now and will post a review soon.</p>
<p>&#8211;Chris  <a target="_blank" href="http://www.symantec.com/avcenter/venc/data/w32.gatt.html" /></p>
<p><a target="_blank" href="http://www.symantec.com/avcenter/venc/data/w32.gatt.html"> </a></p>
<table width="100%" cellspacing="2" cellpadding="2" border="0" style="text-align: left">
<tr>
<td>Links to W32.Gatt / W32.Gattaca / W32.Gattmann analysis<br />
<a target="_blank" href="http://www.symantec.com/avcenter/venc/data/w32.gatt.html">Symantec</a> <a target="_blank" href="http://www.sophos.com/security/analyses/w32gattmana.html"><br />
Sophos</a> <a target="_blank" href="http://vil.nai.com/vil/content/v_140140.htm"><br />
McAfee</a> <a target="_blank" href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=PE%5FGATTMAN%2EA%2DO"><br />
Trend Micro</a></td>
<td>&nbsp;</td>
</tr>
</table>
<p><a target="_blank" href="http://www.symantec.com/avcenter/venc/data/w32.gatt.html"> </a><a target="_blank" href="http://www.symantec.com/avcenter/venc/data/w32.gatt.html"><p>Technorati Tags: <a href="http://technorati.com/tag/Virus" rel="tag">Virus</a>, <a href="http://technorati.com/tag/Malware" rel="tag"> Malware</a>, <a href="http://technorati.com/tag/Antivirus" rel="tag"> Antivirus</a></p></a></p>
<div id="crp_related"><h2>Related Posts:</h2><ul><li><a href="http://www.infosecpodcast.com/2006/07/podcast-1-july-20-2006/" rel="bookmark" class="crp_title">Podcast #1, July 20, 2006</a></li><li><a href="http://www.infosecpodcast.com/2007/03/esets-nod32-antivirus/" rel="bookmark" class="crp_title">ESET&#8217;s NOD32 Antivirus</a></li><li><a href="http://www.infosecpodcast.com/2006/07/0-day-exploit-for-powerpoint-snort-sigs-to-block-ppt/" rel="bookmark" class="crp_title">&#8220;0-Day&#8221; exploit for PowerPoint, Snort sigs to block .ppt files</a></li><li>Powered by <a href="http://ajaydsouza.com/wordpress/plugins/contextual-related-posts/">Contextual Related Posts</a></li></ul></div><img src="http://www.infosecpodcast.com/?ak_action=api_record_view&id=5&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://www.infosecpodcast.com/2006/07/virus-targets-antivirus-researchers-sort-of/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
