Monthly Malware Statistics: February 2010
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2007-5659 | Buffer Overflow in Adobe Acrobat and Reader via Malicious PDF JavaScript Adobe Acrobat and Reader contain a buffer overflow (CWE-119) in their handling of arguments passed to JavaScript methods when rendering PDF files. An attacker triggers the flaw by convincing a user to open a crafted PDF whose embedded JavaScript calls methods with overly long arguments, and no user privileges beyond viewing the file are required. Successful exploitation allows a remote attacker to execute arbitrary code in the context of the user running Acrobat or Reader. Anyone running the affected Acrobat or Reader versions (specific version ranges are not provided in the source data) is affected, with Adobe Reader historically being one of the most widely deployed desktop applications. CISA added the vulnerability to the Known Exploited Vulnerabilities catalog on 2022-06-08, confirming exploitation in the wild, and EPSS assigns a 94% probability of exploitation within 30 days (100th percentile); no public proof-of-concept is known and ransomware use is unknown. Do: Apply updates per vendor instructions by upgrading Acrobat and Reader to the patched releases Adobe made available for your version line, and audit the estate for legacy, unpatched Acrobat/Reader installs given the 2022 KEV listing. As an interim mitigation, disable or restrict JavaScript in the Acrobat/Reader preferences and treat PDFs from untrusted sources (email attachments, drive-by download sites, exploit-kit delivery channels) with caution. | — | 94% | KEV |
| masshundreds of millions of users/installations historically (Adobe Reader/Acrobat is among the most widely deployed desktop PDF viewers); current unpatched… | |
| CVE-2009-0927 | Stack-Based Buffer Overflow in Adobe Reader and Acrobat Enables Remote Code Execution CVE-2009-0927 is a stack-based buffer overflow (improper input validation, CWE-20) in Adobe Reader and Adobe Acrobat that allows remote attackers to execute arbitrary code on the victim's system. The flaw is triggered when the PDF handling code in these products processes malicious input, typically via a specially crafted PDF document delivered through email, the web, or exploit kits. Successful exploitation gives an attacker the ability to run arbitrary code, generally with the privileges of the user running the PDF application. Any user or endpoint running an affected version of Adobe Reader or Acrobat is exposed, and given the near-universal deployment of these PDF tools the potential population is very large. The vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-25) with a required action to apply vendor updates, and EPSS assigns a 96.6% probability of exploitation within 30 days, though no public proof-of-concept is known. Do: Apply updates per vendor instructions: upgrade all affected Adobe Reader and Acrobat installations to a patched release as required by the CISA KEV listing. As an interim mitigation, disable or restrict JavaScript in PDF files (the Acrobat JavaScript blocklist framework introduced around this period addresses this vector) and block PDFs from untrusted sources. Inventory endpoints for outdated Reader/Acrobat versions, prioritizing systems that open PDFs from email and the web. | — | 97% | KEV |
| masshundreds of millions of users (Adobe Reader was the dominant PDF viewer on desktops during the exploitation period) | |
| CVE-2010-0249 | Use-After-Free Remote Code Execution in Microsoft Internet Explorer Microsoft Internet Explorer contains a use-after-free flaw (CWE-416) in which the browser accesses a pointer to an object that has already been deleted, a defect historically associated with the January 2010 'Aurora' targeted attacks. The flaw is triggered when a user simply visits an attacker-crafted or attacker-controlled web page that forces the browser to free an in-use object and then dereference the dangling pointer during page rendering. Successful exploitation gives a remote attacker the ability to execute arbitrary code in the security context of the logged-on user, potentially installing programs; viewing, changing, or deleting data; or creating new accounts. Anyone running Internet Explorer is affected, especially organizations still relying on the now end-of-life/end-of-service browser on legacy Windows systems, which CISA says should discontinue use if mitigations are not applied. Exploitation is confirmed: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2026-05-20 and EPSS assigns a 91.9% probability of exploitation within 30 days (100th percentile), although no public proof-of-concept is cataloged. Do: Per CISA's KEV required action, apply Microsoft's mitigations: the January 2010 out-of-band cumulative security update for Internet Explorer (MS10-002) remediates this flaw, with workarounds including disabling Active Scripting or setting the Internet and Local intranet security zones to High. Inventory any systems still invoking Internet Explorer (legacy Windows builds and intranet apps) and migrate them to Microsoft Edge or another supported browser, discontinuing IE use entirely where mitigations are unavailable. | — | 92% | KEV |
| masshundreds of millions of legacy Windows/IE installs (IE held roughly 60% of global browser share when the flaw was disclosed) |
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | packed.win32.krap.ai | b 42830 15 New Trojan-Downloader.JS.Pegel.f 41526 16 Return Packed.Win32.Krap.ai 38567 17 New Trojan-Downloader.Win32.Lipler.axkd 38466 18 N |
Full article1,073 words · extracted from securelist.com · click to collapse
Malicious programs detected on users’ computers
The first Top Twenty lists malicious programs, adware and potentially unwanted programs that were detected and neutralized when accessed for the first time, i.e. by the on-access scanner.
| Position | Change in position | Name | Number of infected computers |
| 1 | 0 |
Net-Worm.Win32.Kido.ir | 274729 |
| 2 | 1 |
Virus.Win32.Sality.aa | 179218 |
| 3 | 1 |
Net-Worm.Win32.Kido.ih | 163467 |
| 4 | -2 |
Net-Worm.Win32.Kido.iq | 121130 |
| 5 | 0 |
Worm.Win32.FlyStudio.cu | 85345 |
| 6 | 3 |
Trojan-Downloader.Win32.VB.eql | 56998 |
| 7 | New |
Exploit.JS.Aurora.a | 49090 |
| 8 | 9 |
Worm.Win32.AutoIt.tc | 48418 |
| 9 | 1 |
Virus.Win32.Virut.ce | 47842 |
| 10 | 4 |
Packed.Win32.Krap.l | 47375 |
| 11 | -3 |
Trojan-Downloader.WMA.GetCodec.s | 43295 |
| 12 | 0 |
Virus.Win32.Induc.a | 40257 |
| 13 | New |
not-a-virus:AdWare.Win32.RK.aw | 39608 |
| 14 | -3 |
not-a-virus:AdWare.Win32.Boran.z | 39404 |
| 15 | 1 |
Worm.Win32.Mabezat.b | 38905 |
| 16 | New |
Trojan.JS.Agent.bau | 34842 |
| 17 | 3 |
Packed.Win32.Black.a | 32439 |
| 18 | 1 |
Trojan-Dropper.Win32.Flystud.yo | 32268 |
| 19 | Return |
Worm.Win32.AutoRun.dui | 32077 |
| 20 | New |
not-a-virus:AdWare.Win32.FunWeb.q | 30942 |
There was no change to the top 5 malicious programs this month and judging by the number of infections, the Kido epidemic has eased off slightly.
Exploit.JS.Aurora.a, which, as its name suggests, is a program designed to take advantage of vulnerabilities in a variety of software products. This exploit was widely used in February and consequently entered in the ratings in seventh place. Further details are given in the section “Malicious programs on the Internet”.
Other newcomers in February included two adware programs.
FunWeb.q in 20th place is a perfect example of an adware program. It’s a toolbar for popular browsers and provides users with easy access to resources on some websites (usually those with multimedia content). It also modifies the pages visited so that these pages display adverts.
The case of not-a-virus: AdWare.Win32.RK.aw (in thirteenth place) is rather more complex. This RelevantKnowledge application spreads and is installed along with other software products. The company’s privacy policy and ULA states that the program tracks virtually all user activity, particularly Internet activity, automatically collecting personal information and saving it to the company’s servers. It also says that all the data collected is used exclusively to “help shape the future of the Internet” and that the data is well secured. Whether this is true or not is up to the individual to decide.
Malicious programs on the Internet
The second Top Twenty presents data generated by the web antivirus component, and reflects the online threat landscape. This ranking includes malicious programs detected on web pages and malware downloaded to victim machines from web pages.
| Position | Change in position | Name | Number of attempted downloads |
| 1 | Return |
Trojan-Downloader.JS.Gumblar.x | 453985 |
| 2 | -1 |
Trojan.JS.Redirector.l | 346637 |
| 3 | New |
Trojan-Downloader.JS.Pegel.b | 198348 |
| 4 | 3 |
not-a-virus:AdWare.Win32.Boran.z | 80185 |
| 5 | -2 |
Trojan-Downloader.JS.Zapchast.m | 80121 |
| 6 | New |
Trojan-Clicker.JS.Iframe.ea | 77067 |
| 7 | New |
Trojan.JS.Popupper.ap | 77015 |
| 8 | 3 |
Trojan.JS.Popupper.t | 64506 |
| 9 | New |
Exploit.JS.Aurora.a | 54102 |
| 10 | New |
Trojan.JS.Agent.aui | 53415 |
| 11 | New |
Trojan-Downloader.JS.Pegel.l | 51019 |
| 12 | New |
Trojan-Downloader.Java.Agent.an | 47765 |
| 13 | New |
Trojan-Clicker.JS.Agent.ma | 45525 |
| 14 | New |
Trojan-Downloader.Java.Agent.ab | 42830 |
| 15 | New |
Trojan-Downloader.JS.Pegel.f | 41526 |
| 16 | Return |
Packed.Win32.Krap.ai | 38567 |
| 17 | New |
Trojan-Downloader.Win32.Lipler.axkd | 38466 |
| 18 | New |
Exploit.JS.Agent.awd | 35024 |
| 19 | New |
Trojan-Downloader.JS.Pegel.k | 34665 |
| 20 | New |
Packed.Win32.Krap.an | 33538 |
The state of affairs regarding malware on the Internet in February was quite remarkable, which is reflected in our second rating.
First of all, there was a dramatic surge in Gumblar.x, which has once again regained top spot after virtually disappearing completely in January. Last month, we suggested there might be another Gumblar attack and it didn’t take long to materialize. However, this time the black hats haven’t changed their approach in any significant way; they’ve simply been gathering new data that can be used to access websites prior to infecting them en masse. We’ll be keeping track of any further developments.

Secondly, the Pegel epidemic that started in January grew almost six-fold – there are four representatives of this family among the new entries, one of which made it straight to third place. This is a downloader program and in some ways it’s not unlike Gumblar, in that it also infects perfectly legitimate websites. A user that visits an infected site is redirected by the malicious script to a cybercriminal resource. To ensure users don’t suspect anything, the names of popular websites are used in the addresses of malicious pages, for example:
http://friendster-com.youjizz.com.jeuxvideo-com.**********.ru:8080/sify.com/sify.com/pdfdatabase.com/google.com/allegro.pl.php
http://avast-com.deviantart.com.dangdang-com.**********.ru:8080/wsj.com/wsj.com/google.com/nokia.com/aweber.com.php
These links lead to pages containing another script which uses a number of different methods to download the main executable file. The methods used are mostly traditional – exploiting vulnerabilities in major software products such as Internet Explorer (CVE-2006-0003) and Adobe Reader (CVE-2007-5659, CVE-2009-0927 as well as downloading via a special Java applet. The main executable file is the now familiar Backdoor.Win32.Bredolab, packed using various malicious packers (several of which are detected as Packed.Win32.Krap.ar and Packed.Win32.Krap.ao). We have already written in some detail about this malware but it’s worth mentioning again that in addition to its main payload – remote management of infected machines – it can also download other malicious files.
And now back to Exploit.JS.Aurora.a, which was mentioned above. At number nine in the second rating, Aurora.a is the exploit targeting the CVE-2010-0249 vulnerability. It was identified after a massive targeted attack on several versions of Internet Explorer in January.
The attack, which received wide coverage in the IT media, targeted major organizations (including Google and Adobe) and was named Aurora after part of the file path name used in one of the main executable files. The attack was designed to gain access to personal data and corporate intellectual property such as project source code. The attack was carried out using emails with links to malicious sites; these sites contained exploits which resulted in the main executable file being stealthily downloaded to victim machines.

Remarkably, the programmers at Microsoft had been aware of this loophole for a number of months, but it was only patched a month after it began being exploited. It’s worth pointing out that in that time the source code of the exploit became publicly available and only the laziest cybercriminals failed to use it in their attacks: our collection already has more than a hundred malware variants that exploit this vulnerability.
The facts speak for themselves. Vulnerabilities in popular software continue to pose the main threat to users and their data. The fact that cybercriminals are still attempting to exploit vulnerabilities which were detected several years ago is evidence that these vulnerabilities still pose a security threat. Unfortunately, even updating software from major vendors on a regular basis does not guarantee security, as vendors may not always release patches promptly. It’s therefore important to exercise caution – particularly when surfing the Internet – and of course an up-to-date antivirus solution is a must!
Text extracted automatically; images, tables and formatting may be missing. Original: https://securelist.com/monthly-malware-statistics-february-2010/36292/
0
1
1
-2
0
3
New
9
1
4
-3
0
New
-3
1
New
3
1
Return
New
Return
-1
New
3
-2
New
New
3
New
New
New
New
New
New
New
Return
New
New
New
New