Saltar al contenido principal

Online Scanner Top Twenty for June 2006

29 de junio de 2006

Kaspersky Lab's latest monthly analysis of the most active malicious programs reveals 14 new entries to the rankings

PositionChange in positionNamePercentage
1.No Change 0Trojan-Spy.Win32.Banker.anv2.63
2.New! New!Trojan.Win32.Agent.vg1.82
3.Up +1Email-Worm.Win32.Rays1.68
4.New! New!Trojan-PSW.Win32.Lineage.acb1.48
5.New! New!not-a-virus:Monitor.Win32.Perflogger.az1.33
6.New! New!Email-Worm.Win32.Brontok.q1.10
7.New! New!Trojan-Downloader.JS.Agent.ah1.07
8.New! New!Trojan-PSW.Win32.Gamania.cl1.03
9.Down -4Trojan.Win32.VB.ami0.99
10.No Change 0not-a-virus:PSWTool.Win32.RAS.a0.94
11.New! New!Trojan-Downloader.Win32.Adload.bo0.91
12.New! New!Trojan-Spy.Win32.Banbra.gi0.87
13.Down -10Trojan.Win32.Agent.qt0.77
14.New! New!Trojan-PSW.Win32.Lineage.oz0.74
15.New! New!not-a-virus:Monitor.Win32.Perflogger.ad0.73
16.New! New!Email-Worm.Win32.Bagle.fy0.73
17.Down -8Packed.Win32.Tibs0.72
18.New! New!not-a-virus:Monitor.Win32.Perflogger.al0.71
19.New! New!Trojan-Downloader.Win32.Bagle.at0.67
20.New! New!Email-Worm.Win32.Bagle.gen0.65
Other malicious programs78.43

June turned out to be a watershed in terms of both the online scanner statistics and the email traffic rankings. Overall there are 14 new malicious programs in the Top 20, including several new types of Trojans. Banker.anv continues to lead the rankings. However, the malicious programs which took second and third place in May have dropped significantly. And even if the mail traffic rankings are often relatively stagnant during the summer months, this is more than compensated by the data from our online scanner.

The leader remains the same – a Trojan program that steals online bank account details. Banker.anv’s twin, Banker.ark, has been competing with .anv for first place for several months. However, in June, Banker.ark disappeared completely from the rankings, having been beaten back by antivirus solutions and their users. Banker.ark yielded its place to Agent.vg – a nondescript Trojan, and Agent.qt, which held 3rd place in May dropped to 10th this month.

However, none of this is as intriguing as the onslaught of Trojans that attack online gamers. Until now, these dangerous Trojans have not figured significantly in our rankings, but this month three variants gained 4th, 8th and 14th place. This flood of malware attacking gamers is directly tied to summer vacations, during which hundreds of thousands of school children and university students are gaming full-time. Lineage and Gamania - two of the most popular online games in Asia - have been targeted by virus writers for a while now. Characters and props can cost several thousand US dollars in both games, making stealing passwords in this sector as lucrative as stealing online banking information. As a result, Trojans designed to steal passwords to online games are now as common as Trojan-Downloaders and banking Trojans.

As a matter of fact, Trojan-Downloaders were not as active in June as in prior months. There are only three such programs in the rankings - the first one installs adware, the second one downloads other Trojans via a vulnerability in Microsoft Internet Explorer and the third one is directly tied to the multi-component Bagle family. Moreover, there isn’t a single piece of adware in the rankings this month.

The Bagle author woke up this month and launched several mass mailings of the latest variant – Bagle.fy. This particular variant stood out because it was spread in password protected archives, with the password to the archive sent as an image file. Cybercriminals first used this trick 2 years ago, but people still fall for it, get the password and open the protected archive. The result: the worm is launched. This single fact reminds us that there are still lots of uneducated users out there who have very little idea about basic computer security. Consequently, malware writers are continuing to take advantage of this situation: there are several Bagle family members in our rankings this month – Bagle.fy, Trojan-Downloader.Win32.Bagle.at and Email-Worm.Win32.Bagle.gen.

This month’s rankings also include the traditional keyloggers. The difference between keyloggers and banking or gaming Trojans is that keyloggers record all keystrokes, whereas the other Trojans record only relevant information. In any case, we do have a larger number of keyloggers this month.

Summary

NewTrojan.Win32.Agent.vg, Trojan-PSW.Win32.Lineage.acb, not-a-virus:Monitor.Win32.Perflogger.az, Email-Worm.Win32.Brontok.q, Trojan-Downloader.JS.Agent.ah, Trojan-PSW.Win32.Gamania.cl, Trojan-Downloader.Win32.Adload.bo, Trojan-Spy.Win32.Banbra.gi, Trojan-PSW.Win32.Lineage.oz, not-a-virus:Monitor.Win32.Perflogger.ad, Email-Worm.Win32.Bagle.fy, Trojan-Downloader.Win32.Bagle.at, Email-Worm.Win32.Bagle.gen
Moved upEmail-Worm.Win32.Rays
Moved downTrojan.Win32.VB.ami, Trojan.Win32.Agent.qt, Packed.Win32.Tibs
No ChangeTrojan-Spy.Win32.Banker.anv, not-a-virus:PSWTool.Win32.RAS.a

Online Scanner Top Twenty for June 2006

Kaspersky Lab's latest monthly analysis of the most active malicious programs reveals 14 new entries to the rankings
Kaspersky logo

Sobre Kaspersky

Kaspersky es una empresa de ciberseguridad y privacidad digital global fundada en 1997. Con más de mil millones de dispositivos protegidos hasta la fecha ante ciberamenazas emergentes y ataques dirigidos, la enorme experiencia de Kaspersky en cuestión de información y seguridad ante amenazas se transforma de forma constante en soluciones y servicios innovadores que ofrecen protección a negocios, infraestructuras vitales, gobiernos y consumidores de todo el mundo. El completísimo catálogo de la compañía incluye los mejores productos y servicios de protección de terminales, así como soluciones de ciberinmunidad para combatir amenazas digitales sofisticadas y en constante evolución. Ayudamos a que más de 200 000 clientes corporativos protejan aquello que más les importa. Más información en www.kaspersky.es.

Artículo relacionado Comunicados de prensa