ZeroHour
Kaspersky Securelistpublished ()ingested @Securelist

Online Scanner Top Twenty for June 2006

highVulnerabilityimportance 42
Full article754 words · extracted from securelist.com · click to collapse

Malware reports

Malware reports

30 Jun 2006

minute read

Position Change in position Name Percentage
1. No Change
0
Trojan-Spy.Win32.Banker.anv 2.63
2. New!
New!
Trojan.Win32.Agent.vg 1.82
3. Up
+1
Email-Worm.Win32.Rays 1.68
4. New!
New!
Trojan-PSW.Win32.Lineage.acb 1.48
5. New!
New!
not-a-virus:Monitor.Win32.Perflogger.az 1.33
6. New!
New!
Email-Worm.Win32.Brontok.q 1.10
7. New!
New!
Trojan-Downloader.JS.Agent.ah 1.07
8. New!
New!
Trojan-PSW.Win32.Gamania.cl 1.03
9. Down
-4
Trojan.Win32.VB.ami 0.99
10. No Change
0
not-a-virus:PSWTool.Win32.RAS.a 0.94
11. New!
New!
Trojan-Downloader.Win32.Adload.bo 0.91
12. New!
New!
Trojan-Spy.Win32.Banbra.gi 0.87
13. Down
-10
Trojan.Win32.Agent.qt 0.77
14. New!
New!
Trojan-PSW.Win32.Lineage.oz 0.74
15. New!
New!
not-a-virus:Monitor.Win32.Perflogger.ad 0.73
16. New!
New!
Email-Worm.Win32.Bagle.fy 0.73
17. Down
-8
Packed.Win32.Tibs 0.72
18. New!
New!
not-a-virus:Monitor.Win32.Perflogger.al 0.71
19. New!
New!
Trojan-Downloader.Win32.Bagle.at 0.67
20. New!
New!
Email-Worm.Win32.Bagle.gen 0.65
Other malicious programs 78.43

June turned out to be a watershed in terms of both the online scanner statistics and the email traffic rankings. Overall there are 14 new malicious programs in the Top 20, including several new types of Trojans. Banker.anv continues to lead the rankings. However, the malicious programs which took second and third place in May have dropped significantly. And even if the mail traffic rankings are often relatively stagnant during the summer months, this is more than compensated by the data from our online scanner.

The leader remains the same – a Trojan program that steals online bank account details. Banker.anv’s twin, Banker.ark, has been competing with .anv for first place for several months. However, in June, Banker.ark disappeared completely from the rankings, having been beaten back by antivirus solutions and their users. Banker.ark yielded its place to Agent.vg – a nondescript Trojan, and Agent.qt, which held 3rd place in May dropped to 10th this month.

However, none of this is as intriguing as the onslaught of Trojans that attack online gamers. Until now, these dangerous Trojans have not figured significantly in our rankings, but this month three variants gained 4th, 8th and 14th place. This flood of malware attacking gamers is directly tied to summer vacations, during which hundreds of thousands of school children and university students are gaming full-time. Lineage and Gamania — two of the most popular online games in Asia — have been targeted by virus writers for a while now. Characters and props can cost several thousand US dollars in both games, making stealing passwords in this sector as lucrative as stealing online banking information. As a result, Trojans designed to steal passwords to online games are now as common as Trojan-Downloaders and banking Trojans.

As a matter of fact, Trojan-Downloaders were not as active in June as in prior months. There are only three such programs in the rankings — the first one installs adware, the second one downloads other Trojans via a vulnerability in Microsoft Internet Explorer and the third one is directly tied to the multi-component Bagle family. Moreover, there isn’t a single piece of adware in the rankings this month.

The Bagle author woke up this month and launched several mass mailings of the latest variant – Bagle.fy. This particular variant stood out because it was spread in password protected archives, with the password to the archive sent as an image file. Cybercriminals first used this trick 2 years ago, but people still fall for it, get the password and open the protected archive. The result: the worm is launched. This single fact reminds us that there are still lots of uneducated users out there who have very little idea about basic computer security. Consequently, malware writers are continuing to take advantage of this situation: there are several Bagle family members in our rankings this month – Bagle.fy, Trojan-Downloader.Win32.Bagle.at and Email-Worm.Win32.Bagle.gen.

This month’s rankings also include the traditional keyloggers. The difference between keyloggers and banking or gaming Trojans is that keyloggers record all keystrokes, whereas the other Trojans record only relevant information. In any case, we do have a larger number of keyloggers this month.

Summary

New Trojan.Win32.Agent.vg, Trojan-PSW.Win32.Lineage.acb, not-a-virus:Monitor.Win32.Perflogger.az, Email-Worm.Win32.Brontok.q, Trojan-Downloader.JS.Agent.ah, Trojan-PSW.Win32.Gamania.cl, Trojan-Downloader.Win32.Adload.bo, Trojan-Spy.Win32.Banbra.gi, Trojan-PSW.Win32.Lineage.oz, not-a-virus:Monitor.Win32.Perflogger.ad, Email-Worm.Win32.Bagle.fy, Trojan-Downloader.Win32.Bagle.at, Email-Worm.Win32.Bagle.gen
Moved up Email-Worm.Win32.Rays
Moved down Trojan.Win32.VB.ami, Trojan.Win32.Agent.qt, Packed.Win32.Tibs
No Change Trojan-Spy.Win32.Banker.anv, not-a-virus:PSWTool.Win32.RAS.a
Latest Webinars
Reports

Kaspersky researchers have discovered new Mirage Kitten attacks using previously undocumented malware families: NodeRabbit in Node.js and PollCat in JavaScript.

Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network connections from security tools and threat analysts.

Kaspersky experts break down a new Armored Likho campaign that poses as a fundraising efforts and delivers a new Still Toolkit aimed at stealing Telegram data and eavesdropping on victims.

Kaspersky researchers reveal previously undocumented malware attributed to Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore): NightLedger backdoor, ArcBridge, and BridgeHead tunneling tools.

Text extracted automatically; images, tables and formatting may be missing. Original: https://securelist.com/online-scanner-top-twenty-for-june-2006/36091/