{"id":25965,"date":"2011-06-08T14:25:06","date_gmt":"2011-06-08T12:25:06","guid":{"rendered":"http:\/\/mybroadband.co.za\/news\/?p=25965"},"modified":"2011-06-08T17:15:32","modified_gmt":"2011-06-08T15:15:32","slug":"top-20-malicious-programs-on-the-internet-kaspersky-may-2011-malware-report","status":"publish","type":"post","link":"https:\/\/mybroadband.co.za\/news\/internet\/25965-top-20-malicious-programs-on-the-internet-kaspersky-may-2011-malware-report.html","title":{"rendered":"Top 20 malicious programs on the Internet"},"content":{"rendered":"<p>Kaspersky Lab said in a recent <a href=\"http:\/\/www.securelist.com\/en\/blog\/508\/Monthly_Malware_Statistics_May_2011\" target=\"_blank\">press release and blog post<\/a> that May 2011 was characterised by a rogue antivirus program for Mac OS X, a banking rootkit for 64-bit Windows from a group of Brazilian cyber-criminals, and Sony remaining a target for hackers.<\/p>\n<p>Two other malicious programs for 64-bit Windows were also mentioned: a new 64-bit version of the ZeroAccess Trojan and Necurs.<\/p>\n<p>Kaspersky also listed the top 20 malicious programs on the Internet and the top 20 malware detections for May 2011.<\/p>\n<h3 class=\"my-4\">Top 20 malicious programs on the Internet<\/h3>\n<div class=\"table-responsive\"><table class=\"table\" style=\"background-color: #f0f0f0; width: 100%;\" border=\"1\" cellpadding=\"5\">\n<tbody>\n<tr>\n<td style=\"background-color: #999999;\"><strong>Current rank<\/strong><\/td>\n<td style=\"background-color: #999999;\"><strong>Change in<br \/>\nposition<\/strong><\/td>\n<td style=\"background-color: #999999;\"><strong>Verdict<\/strong><\/td>\n<td style=\"background-color: #999999;\"><strong>Number of<br \/>\nattacks<\/strong><\/td>\n<\/tr>\n<tr>\n<td>1<\/td>\n<td>0<\/td>\n<td>AdWare.Win32.HotBar.dh<\/td>\n<td>783931<\/td>\n<\/tr>\n<tr>\n<td>2<\/td>\n<td>0<\/td>\n<td>Trojan.JS.Popupper.aw<\/td>\n<td>739998<\/td>\n<\/tr>\n<tr>\n<td>3<\/td>\n<td>+4<\/td>\n<td>AdWare.Win32.FunWeb.kd<\/td>\n<td>472777<\/td>\n<\/tr>\n<tr>\n<td>4<\/td>\n<td>New<\/td>\n<td>Trojan-Downloader.JS.IstBar.cx<\/td>\n<td>364197<\/td>\n<\/tr>\n<tr>\n<td>5<\/td>\n<td>+1<\/td>\n<td>AdWare.Win32.FunWeb.jp<\/td>\n<td>243612<\/td>\n<\/tr>\n<tr>\n<td>6<\/td>\n<td>New<\/td>\n<td>Trojan-Downloader.JS.Agent.fxq<\/td>\n<td>233868<\/td>\n<\/tr>\n<tr>\n<td>7<\/td>\n<td>New<\/td>\n<td>Exploit.HTML.CVE-2010-4452.h<\/td>\n<td>182151<\/td>\n<\/tr>\n<tr>\n<td>8<\/td>\n<td>New<\/td>\n<td>Trojan.JS.Agent.bun<\/td>\n<td>180370<\/td>\n<\/tr>\n<tr>\n<td>9<\/td>\n<td>New<\/td>\n<td>Trojan-Downloader.JS.Iframe.cew<\/td>\n<td><\/td>\n<\/tr>\n<tr>\n<td>10<\/td>\n<td>New<\/td>\n<td>Exploit.JS.CVE-2010-1885.k<\/td>\n<td><\/td>\n<\/tr>\n<tr>\n<td>11<\/td>\n<td>+4<\/td>\n<td>Trojan.HTML.Iframe.dl<\/td>\n<td><\/td>\n<\/tr>\n<tr>\n<td>12<\/td>\n<td>New<\/td>\n<td>Trojan-Downloader.HTML.JScript.l<\/td>\n<td><\/td>\n<\/tr>\n<tr>\n<td>13<\/td>\n<td>New<\/td>\n<td>Trojan-Downloader.SWF.Agent.ec<\/td>\n<td><\/td>\n<\/tr>\n<tr>\n<td>14<\/td>\n<td>New<\/td>\n<td>Exploit.Java.CVE-2010-4452.a<\/td>\n<td><\/td>\n<\/tr>\n<tr>\n<td>15<\/td>\n<td>-3<\/td>\n<td>Trojan.JS.Agent.uo<\/td>\n<td><\/td>\n<\/tr>\n<tr>\n<td>16<\/td>\n<td>New<\/td>\n<td>Trojan-Downloader.JS.Agent.fww<\/td>\n<td><\/td>\n<\/tr>\n<tr>\n<td>17<\/td>\n<td>-4<\/td>\n<td>Trojan-Downloader.JS.Iframe.cdh<\/td>\n<td><\/td>\n<\/tr>\n<tr>\n<td>18<\/td>\n<td>New<\/td>\n<td>Trojan-Downloader.JS.Agent.fyk<\/td>\n<td><\/td>\n<\/tr>\n<tr>\n<td>19<\/td>\n<td>New<\/td>\n<td>Hoax.Win32.Screensaver.b<\/td>\n<td>72975<\/td>\n<\/tr>\n<tr>\n<td>20<\/td>\n<td>New<\/td>\n<td>Hoax.Win32.ArchSMS.huey<\/td>\n<td>71125<\/td>\n<\/tr>\n<\/tbody>\n<\/table><\/div>\n<h3 class=\"my-4\">Top 20 malicious programs detected on users\u2019 computers<\/h3>\n<div class=\"table-responsive\"><table class=\"table\" style=\"background-color: #f0f0f0; width: 100%;\" border=\"1\" cellpadding=\"5\">\n<tbody>\n<tr>\n<td style=\"background-color: #999999;\"><strong>Current rank<\/strong><\/td>\n<td style=\"background-color: #999999;\"><strong>Change in<br \/>\nposition<\/strong><\/td>\n<td style=\"background-color: #999999;\"><strong>Verdict<\/strong><\/td>\n<td style=\"background-color: #999999;\"><strong>Number of unique<br \/>\nusers<\/strong><\/td>\n<\/tr>\n<tr>\n<td>1<\/td>\n<td>0<\/td>\n<td>Net-Worm.Win32.Kido.ir<\/td>\n<td>465397<\/td>\n<\/tr>\n<tr>\n<td>2<\/td>\n<td>1<\/td>\n<td>Virus.Win32.Sality.aa<\/td>\n<td>200381<\/td>\n<\/tr>\n<tr>\n<td>3<\/td>\n<td>-1<\/td>\n<td>Net-Worm.Win32.Kido.ih<\/td>\n<td>183936<\/td>\n<\/tr>\n<tr>\n<td>4<\/td>\n<td>New<\/td>\n<td>AdWare.Win32.FunWeb.kd<\/td>\n<td>179700<\/td>\n<\/tr>\n<tr>\n<td>5<\/td>\n<td>1<\/td>\n<td>Trojan.Win32.Starter.yy<\/td>\n<td>158218<\/td>\n<\/tr>\n<tr>\n<td>6<\/td>\n<td>-1<\/td>\n<td>Virus.Win32.Sality.bh<\/td>\n<td>147599<\/td>\n<\/tr>\n<tr>\n<td>7<\/td>\n<td>2<\/td>\n<td>Trojan-Downloader.Win32.Geral.cnh<\/td>\n<td>93831<\/td>\n<\/tr>\n<tr>\n<td>8<\/td>\n<td>8<\/td>\n<td>Virus.Win32.Sality.ag<\/td>\n<td>84662<\/td>\n<\/tr>\n<tr>\n<td>9<\/td>\n<td>1<\/td>\n<td>HackTool.Win32.Kiser.il<\/td>\n<td>83925<\/td>\n<\/tr>\n<tr>\n<td>10<\/td>\n<td>New<\/td>\n<td>Trojan-Downloader.Win32.FlyStudio.kx<\/td>\n<td>70375<\/td>\n<\/tr>\n<tr>\n<td>11<\/td>\n<td>New<\/td>\n<td>Exploit.Win32.CVE-2010-2568.d<\/td>\n<td>67924<\/td>\n<\/tr>\n<tr>\n<td>12<\/td>\n<td>8<\/td>\n<td>Virus.Win32.Nimnul.a<\/td>\n<td>67094<\/td>\n<\/tr>\n<tr>\n<td>13<\/td>\n<td>-5<\/td>\n<td>HackTool.Win32.Kiser.zv<\/td>\n<td>64813<\/td>\n<\/tr>\n<tr>\n<td>14<\/td>\n<td>-2<\/td>\n<td>Worm.Win32.FlyStudio.cu<\/td>\n<td>64593<\/td>\n<\/tr>\n<tr>\n<td>15<\/td>\n<td>-8<\/td>\n<td>Hoax.Win32.ArchSMS.pxm<\/td>\n<td>64074<\/td>\n<\/tr>\n<tr>\n<td>16<\/td>\n<td>2<\/td>\n<td>Worm.Win32.Mabezat.b<\/td>\n<td>62011<\/td>\n<\/tr>\n<tr>\n<td>17<\/td>\n<td>-6<\/td>\n<td>Hoax.Win32.Screensaver.b<\/td>\n<td>60218<\/td>\n<\/tr>\n<tr>\n<td>18<\/td>\n<td>-4<\/td>\n<td>Trojan.JS.Agent.bhr<\/td>\n<td>59722<\/td>\n<\/tr>\n<tr>\n<td>19<\/td>\n<td>-2<\/td>\n<td>Trojan-Downloader.Win32.VB.eql<\/td>\n<td>58577<\/td>\n<\/tr>\n<tr>\n<td>20<\/td>\n<td>New<\/td>\n<td>Trojan.Win32.AutoRun.bhs<\/td>\n<td>55422<\/td>\n<\/tr>\n<\/tbody>\n<\/table><\/div>\n<p>The full press release is below.<\/p>\n<blockquote><p>Kaspersky Lab presented their monthly report about malicious activity on users\u2019 computers and on the Internet.<\/p>\n<h3 class=\"my-4\">May in figures<\/h3>\n<p>The following statistics were compiled in May using data from computers running Kaspersky Lab products:<\/p>\n<ul>\n<li>242,7 mln network attacks blocked;<\/li>\n<li>71,3 mln attempted web-borne infections prevented;<\/li>\n<li>213,7 mln malicious programs detected and neutralized on users\u2019 computers; 84,3 mln heuristic verdicts registered.<\/li>\n<\/ul>\n<h3 class=\"my-4\">Rogue antivirus program for Mac OS X<\/h3>\n<p>In May, there were 109,218 attempts to infect users\u2019 computers with rogue antivirus programs via the Internet. This is twice as low as the peak activity seen in February-March 2010 \u2013 during this period, some 200,000 security incidents occurred each month. Nevertheless, rogue antivirus attacks came as a surprise to users of Apple computers. The first attacks were detected on 02 May when the web was a buzz with news about the death of Osama bin Laden. Some users searching Google for information about this event did not receive search results, but instead were presented with a notification in their browser windows that a Trojan had been detected on their machines and could be removed. If a user agreed to try the suggested anti-malware software, the rogue antivirus (MAC defender in this case) would say that it had detected several malicious programs on the computer (which in fact were not there), and ask $59-80 to remove them. If the victim paid for the fake program they received a registration key; when the user entered this key, the system stated it was now malware-free.<\/p>\n<p>Interestingly, the purported number of \u201csignatures\u2019 in MAC Defender\u2019s \u201cantivirus database\u201d is 184,230. For comparison, the number of malicious programs created for Mac to date amounts to hundreds, but not tens of thousands.<\/p>\n<h3 class=\"my-4\">Malware for Win64<\/h3>\n<p>The growth in the number of users who prefer the 64-bit OS did not go unnoticed. In May, Brazilian cybercriminals whose main \u201cspecialisation\u201d over the last several years has been banking Trojans released the first banking rootkit for the Windows 64-bit OS (Rootkit.Win64.Banker). They targeted users\u2019 logins and passwords to online banking systems. During the attack the users were redirected to phishing pages which imitated the websites of respectable banks. May was also marked by ZeroAccess\u2019 comeback, but this time the Trojan was capable of functioning on x64 systems. Computers were infected using a drive-by download attack. After ZeroAccess penetrates a victim\u2019s computer it determines whether the victim\u2019s computer runs either a 32- or 64-bit operating system and downloads the appropriate version of the backdoor to it.<\/p>\n<h3 class=\"my-4\">Sony targeted yet again<\/h3>\n<p>The hackers did not give Sony a chance to relax. After attacks on the Sony Playstation and Sony Online Entertainment Networks in late April \u2013 early May they compromised Sony\u2019s Thai site on 20 May. As a result, a phishing page targeting Italian credit card owners was hosted on hdworld.sony.co.th.<\/p>\n<p>However this was not the end of it. On 22 May, the Greek site SonyMusic.gr was attacked, making user data available for public access, including users\u2019 nicknames, real names and email addresses. Two days later several vulnerabilities were detected on sony.co.jp. Nonetheless this time the stolen database did not contain users\u2019 personal data.<\/p>\n<p>In our forecasts for 2011 we suggested that information of any type would become the target of many attacks. Unfortunately, the number of attacks on Sony reinforces the accuracy of this prediction. Currently, IT security issues are extremely important as services such as PSN and iTunes harvest as much information as possible. The legislation surrounding personal data security is not always clear and all users can really do is to stop using these services. There can be no doubt that the attacks on Sony were well planned and executed. We can confidently predict that in the future, services similar to PSN will become the targets of such attacks. Therefore users need to be very careful when using these services and with the companies that provide them.<\/p><\/blockquote>\n<div class=\"table-responsive\"><table class=\"table\" border=\"1\" cellspacing=\"0\" cellpadding=\"5\">\n<tbody>\n<tr>\n<td><strong>Current rank<\/strong><\/td>\n<td><strong>Change in position<\/strong><\/td>\n<td><strong>Verdict<\/strong><\/td>\n<td><strong>Number of unique users<\/strong><\/td>\n<\/tr>\n<tr>\n<td>1<\/td>\n<td>0<\/td>\n<td>Net-Worm.Win32.Kido.ir<\/td>\n<td>465397<\/td>\n<\/tr>\n<tr>\n<td>2<\/td>\n<td>1<\/td>\n<td>Virus.Win32.Sality.aa<\/td>\n<td>200381<\/td>\n<\/tr>\n<tr>\n<td>3<\/td>\n<td>-1<\/td>\n<td>Net-Worm.Win32.Kido.ih<\/td>\n<td>183936<\/td>\n<\/tr>\n<tr>\n<td>4<\/td>\n<td>New<\/td>\n<td>AdWare.Win32.FunWeb.kd<\/td>\n<td>179700<\/td>\n<\/tr>\n<tr>\n<td>5<\/td>\n<td>1<\/td>\n<td>Trojan.Win32.Starter.yy<\/td>\n<td>158218<\/td>\n<\/tr>\n<tr>\n<td>6<\/td>\n<td>-1<\/td>\n<td>Virus.Win32.Sality.bh<\/td>\n<td>147599<\/td>\n<\/tr>\n<tr>\n<td>7<\/td>\n<td>2<\/td>\n<td>Trojan-Downloader.Win32.Geral.cnh<\/td>\n<td>93831<\/td>\n<\/tr>\n<tr>\n<td>8<\/td>\n<td>8<\/td>\n<td>Virus.Win32.Sality.ag<\/td>\n<td>84662<\/td>\n<\/tr>\n<tr>\n<td>9<\/td>\n<td>1<\/td>\n<td>HackTool.Win32.Kiser.il<\/td>\n<td>83925<\/td>\n<\/tr>\n<tr>\n<td>10<\/td>\n<td>New<\/td>\n<td>Trojan-Downloader.Win32.FlyStudio.kx<\/td>\n<td>70375<\/td>\n<\/tr>\n<tr>\n<td>11<\/td>\n<td>New<\/td>\n<td>Exploit.Win32.CVE-2010-2568.d<\/td>\n<td>67924<\/td>\n<\/tr>\n<tr>\n<td>12<\/td>\n<td>8<\/td>\n<td>Virus.Win32.Nimnul.a<\/td>\n<td>67094<\/td>\n<\/tr>\n<tr>\n<td>13<\/td>\n<td>-5<\/td>\n<td>HackTool.Win32.Kiser.zv<\/td>\n<td>64813<\/td>\n<\/tr>\n<tr>\n<td>14<\/td>\n<td>-2<\/td>\n<td>Worm.Win32.FlyStudio.cu<\/td>\n<td>64593<\/td>\n<\/tr>\n<tr>\n<td>15<\/td>\n<td>-8<\/td>\n<td>Hoax.Win32.ArchSMS.pxm<\/td>\n<td>64074<\/td>\n<\/tr>\n<tr>\n<td>16<\/td>\n<td>2<\/td>\n<td>Worm.Win32.Mabezat.b<\/td>\n<td>62011<\/td>\n<\/tr>\n<tr>\n<td>17<\/td>\n<td>-6<\/td>\n<td>Hoax.Win32.Screensaver.b<\/td>\n<td>60218<\/td>\n<\/tr>\n<tr>\n<td>18<\/td>\n<td>-4<\/td>\n<td>Trojan.JS.Agent.bhr<\/td>\n<td>59722<\/td>\n<\/tr>\n<tr>\n<td>19<\/td>\n<td>-2<\/td>\n<td>Trojan-Downloader.Win32.VB.eql<\/td>\n<td>58577<\/td>\n<\/tr>\n<tr>\n<td>20<\/td>\n<td>New<\/td>\n<td>Trojan.Win32.AutoRun.bhs<\/td>\n<td>55422<\/td>\n<\/tr>\n<\/tbody>\n<\/table><\/div>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Kaspersky highlights malicious programs attacking Mac OS X, 64-bit Windows and Sony hacks as the most significant events of May<\/p>\n","protected":false},"author":15,"featured_media":25989,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_sma_x_autopost_status":"idle","_sma_x_autopost_error":"","_sma_x_post_id":"","_sma_facebook_post_id":"","_sma_instagram_post_id":"","_sma_threads_post_id":"","_sma_x_attempts":0,"footnotes":""},"categories":[18,27],"tags":[36,199,799,705,805,801,803,193,807,809,811],"class_list":["post-25965","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-internet","category-security","tag-active","tag-hackers","tag-kaspersky-lab","tag-mac-os-x","tag-mac-os-x-malware","tag-malware","tag-malware-report","tag-sony","tag-windows","tag-windows-64-bit","tag-windows-64-bit-malware"],"_links":{"self":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/25965"}],"collection":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/users\/15"}],"replies":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/comments?post=25965"}],"version-history":[{"count":1,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/25965\/revisions"}],"predecessor-version":[{"id":25967,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/25965\/revisions\/25967"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media\/25989"}],"wp:attachment":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media?parent=25965"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/categories?post=25965"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/tags?post=25965"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}