Malware Miscellany, September 2009
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | www.gddsz.store.qq.com | us programs 1142 unique malicious programs were spread from www.gddsz.store.qq.com. The programs vary widely, and cover virtually all the diff |
Full article538 words · extracted from securelist.com · click to collapse
After a lengthy interlude, we’re renewing our monthly malware almanac by popular demand. We’ve made quite a few changes to it, hopefully for the better – we’ll let you be the judge of that.
| Категория | Наименование |
| Top 3 countries for malicious URLs |
Canada takes first |
| Top 3 countries hosting sites which spread malware |
China claims first |
| Malicious site which affects the biggest number of Internet users |
www.langlangdor.com |
| Site spreading the biggest number of unique malicious programs |
1142 unique |
| Biggest malicious program |
In September, this |
| Smallest malicious program |
Trojan.BAT.Shutdown.ab |
| Most widespread vulnerability on users’ computers |
In late July, Adobe |
| Most common exploit |
Exploit.JS.DirektShow: |
| Most widespread malware on the Internet |
In just a month, Packed.Win32.TDSS.z tried to penetrate |
| Worst joke (hoax programs that scare or annoy users but don’t have a clearly malicious payload) |
Hoax.JS.Agent.c displays an obscene video clip and bombards victims with offensive messages which can’t be stopped. |
Latest Webinars
Reports
Kaspersky researchers have discovered new Mirage Kitten attacks using previously undocumented malware families: NodeRabbit in Node.js and PollCat in JavaScript.
Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network connections from security tools and threat analysts.
Kaspersky experts break down a new Armored Likho campaign that poses as a fundraising efforts and delivers a new Still Toolkit aimed at stealing Telegram data and eavesdropping on victims.
Kaspersky researchers reveal previously undocumented malware attributed to Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore): NightLedger backdoor, ArcBridge, and BridgeHead tunneling tools.
Text extracted automatically; images, tables and formatting may be missing. Original: https://securelist.com/malware-miscellany-september-2009/36270/