查看: 4094|回复: 24
收起左侧

[资讯] 全球病毒趋势---2007年8月

[复制链接]
The EQs
发表于 2007-9-7 16:10:48 | 显示全部楼层 |阅读模式
Win32/Obfuscated was the top threat during August, according to ESET, who have created a global infection reporting system called “ThreatSense.Net” ©. Out of the top 10 ranking threats, obfuscated threats constituted more than 7.58% of all threats.
Obscured by codes…
During the month of August, close to 7.58% of all detections were for obfuscated threats. The label Win32/Obfuscated is used to identify malicious software that uses various methods of code obfuscation to hide the malicious functionality from detection by ESET’s NOD32 and other scanners. This is a generic name that ESET uses to apply to a variety of Windows threats using obfuscation techniques such as runtime packing, polymorphism and junk code injection, often these threats are part of the same family, with slight alterations.
Secret Agents…
Second in the ranking for August, we find Win32/Agent which reached 3.40 % of detections during last month. Once again, the label "Agent" is given to a wide range of malware threats that have Trojan capabilities, and act as ‘agents’ on the compromised machine. These files can either connect back to a central command server to receive their instructions or open a backdoor on the victim's system which can be used by an attacker to control the machine. These detections are based on the generic detection algorithms in ESET’s NOD32 which are able to detect a wide variety of new threats without the need for updating.
Animania…
In third place we find Win32/TrojanDownloader.Ani.gen. This threat is designed to exploit a recent vulnerability discovered in the way Windows processes animated cursor files. Attackers exploit this security flaw to install malicious code onto the system, and then download additional malicious files to the victim’s system. Again, this is a generic detection that detects any attempt to exploit this vulnerability.
2


The Fourth Protocol…
Win32/Agent.ARK was number 4 in August with around 2.33 % of detections. This malware connects to a command and control server that seems to be located in Singapore. The purpose of this malicious software is to keep control of an infected system for future use; it can be used to execute commands on the infected host and download additional software. Very often such botnet software is able to update itself with new components which add new functionality, and which help it to evade detection by signature based anti-virus software.
Taking the Fifth…
The fifth place in the rankings for August was once again held by Win32/Adware.Virtumonde. This is a potentially unwanted application, and it’s used to deliver advertisement to user’s PC. It’s optional whether to detect such objects in ESET’s NOD32, but many users don’t realize they’ve installed these ad-servers, and don’t want them on their systems.
Six of the worst…
Below Virtumonde we find Win32/Adware.Ezula, a piece of malware that comes with the icon of a normal installer but, when a user double clicks on the file, no dialog is displayed to the user. The installation of this unwanted software is completely silent and does not
Global Threat Trends
3
give any information to the user on what is installing on the system; an important component in deciding whether something is malware or not is how much consent or information the user is given. Once installed on a victim's system, this software downloads and executes additional software components from a website currently located in the Philippines. Furthermore, this malware keeps tracks of search keywords that are then sent to a pre defined list of websites. Finally, this software also sporadically displays ads when the user is browsing the Internet, often targeted according to the victims’ browsing habits
Unlucky Seven…
In seventh place we find INF/Autorun, which, once again identifies a generic variety of malware theats that use the file autorun.inf to load. The file autorun.inf contains information on programs that run automatically when media (USB keys, CD’s etc) are inserted into a computer. Viruses that install via or modify autorun.inf files are detected as INF/Autorun by ESET NOD32. Malware that spread on USB sticks are often detected as INF/Autorun
Final Remains…
In the last three positions of the August TOP 10 we find two Trojans (Win32/Rjump.A – last month’s number two - and Win32/Agent.AB), and a mass mailing worm (Win32/Pacex.gen). The three threats garner between 1.32% and 1.67% of all detections each.
Worldwide Coverage with ESET’s ThreatSense.Net
Currently, most of the spreading malware out there has different features and capabilities, and often there are several variants of each type. Because of this, in addition to frequently updating your anti-virus solution, it is important to have proactive detection features, such as those in ESET’s NOD32, to be protected against the new and unknown threats that appear daily.
ThreatSense.Net, which reports detection statistics from millions client computers around the world is believed to be the most comprehensive malware reporting system in existence.
4
From an original idea, realized in VIRUS RADAR® http://www.virusradar.com, the reporting system has evolved to what is now ThreatSense.Net, vastly improving the statistical data gathered. Rather than only being email based, as with VIRUS RADAR, the information from ThreatSense.Net includes data about all types of threats seen attacking user systems. The (anonymous) statistical information is collected from NOD32 users who enable the reporting service in the product, and it gives a more comprehensive view of the behavior and spread of malware in the real world. Currently data is collected from more than 10 million systems, and has tracked more than 10,000 different threats and malware families.# # #
610 West

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
kidaaaa
发表于 2007-9-7 16:57:03 | 显示全部楼层
呵呵,为什么无敌的Win32/Genetik没有入选?[:27:]
812
发表于 2007-9-7 17:20:51 | 显示全部楼层
看不懂。。。
dancerock
发表于 2007-9-7 17:30:02 | 显示全部楼层
流氓软件rootkit排名第一
SuperQDI
发表于 2007-9-7 19:57:24 | 显示全部楼层
新版论坛很漂亮。
老大你的帖要慢慢看了
woai_jolin
发表于 2007-9-7 20:07:45 | 显示全部楼层
agent
sb
发表于 2007-9-7 20:23:10 | 显示全部楼层
E文,看不懂
kidaaaa
发表于 2007-9-7 20:52:40 | 显示全部楼层
现在越来越佩服eset的技术实力了!实在太牛了!
wuxian1001
发表于 2007-9-7 21:00:32 | 显示全部楼层
英文太差啊
hj5abc
发表于 2007-9-8 17:44:10 | 显示全部楼层
头两名Win32/Obfuscated和Win32/Agent都是generic signature ..[:26:] 而且Agent在卡饭误报不低.
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-5-5 15:55 , Processed in 0.127069 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表