IT in Manufacturing


Trojans continue to dominate BitDefender’s top 10 e-threats for October

November 2009 IT in Manufacturing

Trojan.Clicker.CM continues its hold as the number one e-threat

The top spot on BitDefender’s top ten list of e-threats for October is once again Trojan.Clicker.CM, which is mostly present on websites hosting illegal applications such as cracks, keygens and serial numbers for popular commercial software applications. It is typically used to force advertisements inside the browser and comprises 9,47% of infected files this month.

Ranking second with 8,54% of the worldwide infections, Trojan.AutorunInf.Gen is a generic mechanism used to spread malware via removable devices such as flash drives, memory cards or external hard-disk drives. Win32.Worm.Downadup si Win32.TDSS are two of the most famous families of malware to use this approach to trigger newer infections.

Win32.Worm.Downadup takes third position with 5,29% of the total amount of infected machines. Also known as Conficker or Kido, the worm restricts access to the websites associated with IT security vendors. More than that, the latest variant of the worm installs rogue security software on the compromised machines.

Trojan.Wimad comes in fourth place with 4,90% of the global infections. It takes advantage of a less-known feature implemented by Microsoft in order to store coordinated digital media data. The Trojan affects ASF files, an extensible file format that supports data delivery over a wide variety of networks and is extremely easy to play back locally. A specially crafted ASF file abuses the feature which allows it to download the appropriate codec in order to install Trojans instead.

Exploit.PDF-JS.Gen, the fifth offender, is a generic detection for specially crafted PDF files that exploit different vulnerabilities found in Adobe PDF Reader's Javascript engine in order to execute malicious code on the user's computer. Upon opening an infected PDF file, a specially crafted Javascript code triggers the download of malicious binaries from remote locations. This threat makes up 4,84% of the worldwide infections.

Win32.Sality.OG takes the sixth position with 2,31% of the infections triggered globally. It is a polymorphic file infector that appends its encrypted code to executable files (.exe and .scr binaries). In order to hide its presence on the infected machine, it deploys a rootkit and attempts to kill antivirus applications installed locally.

The seventh place goes to Trojan.Autorun.AET at 2,20% of global infections, a malicious code spreading via the Windows shared folders, as well as through removable storage devices. The Trojan exploits the Autorun feature implemented in Windows for automatically launching applications when an infected storage device is plugged in.

Worm.Autorun.VHG is an Internet/network worm that exploits the Windows MS08-067 vulnerability in order to execute itself remotely using a specially crafted RPC (remote procedure call) package (an approach also used by Win32.Worm.Downadup). The worm ranks eight with 1,49% of the global infections.

Trojan.Swizzor.6 is yet another variant of the Swizzor family, 'obfuscated' downloaders that would try to save and execute new threats on infected machines. The Trojan adds its key to the Windows Registry in order to execute a copy of itself each time Windows is started. This specific variant of Swizzor accounts for 1,22% of the global infections.

Ranking last in this month’s top 10 E-threats, Gen:Adware.Heur.wq0@j4oukhei scores 1,21% of the global infections. This generic routine detects a wide range of adware applications, especially the NaviPromo family.

BitDefender’s October 2009 Top 10 E-Threat list includes:

1. Trojan.Clicker.CM: 9,47%

2. Trojan.AutorunINF.Gen: 8,54%

3. Win32.Worm.Downadup.Gen: 5,29%

4. Trojan.Wimad.Gen.1: 4,90%

5. Exploit.PDF-JS.Gen: 4,84%

6. Win32.Sality.OG: 2,31%

7. Trojan.Autorun.AET: 2,20%

8. Worm.Autorun.VHG: 1,49%

9. Trojan.Swizzor.6: 1,22%

10. Gen:Adware.Heur.wq0@j4oukhei: 1,21%

Others: 58.53%

For more information contact Alina Anton, senior PR and marketing coordinator, EMEA and APAC Business Unit, +40 212 063 470, [email protected], www.bitdefender.com





Share this article:
Share via emailShare via LinkedInPrint this page

Further reading:

South Africa’s AI revolution is here – but are we secure?
IT in Manufacturing
South African businesses are sprinting to embrace generative AI, lured by its potential to drive efficiency, productivity and innovation. But here’s the stark reality: without a rock-solid cybersecurity foundation, AI will become a Trojan horse, opening the floodgates to sophisticated cyber threats.

Read more...
Black Rock Mining centralises mining operations with AVEVA
IT in Manufacturing
Black Rock Mine Operations replaced and upgraded its existing infrastructure, and installed additional capacity to expand production from 3 to 4,6 million tons in three years. The new system is powered by a suite of AVEVA solutions.

Read more...
Shaping data resilience strategies with AI and hybrid cloud solutions
IT in Manufacturing
In today’s rapidly evolving digital landscape, organisations are under growing pressure to secure their operations against increasingly sophisticated cyberthreats, including those that leverage AI to enhance the success rate of attacks. In this landscape, it has become essential to ‘fight fire with fire’ – harnessing AI as a means to counter these threats.

Read more...
Cloud or on-prem? Decoding the choices for South African enterprises
IT in Manufacturing
The debate between on-premise and cloud computing architectures remains a prominent topic among businesses, particularly in South Africa.

Read more...
Advancements in wire rope testing
IT in Manufacturing
Being able to get instant, real-time and portable detection of wire rope flaws can make a significant difference for operational teams. There have been a number of significant technological advancements and tools entering the market that help wire rope operators detect and resolve problems faster.

Read more...
Quantum computing power: four steps to protecting your business
IT in Manufacturing
Are you ready for Q-day? Post-quantum cryptography isn’t just an IT issue, it’s a business continuity concern. Quantum computing is fast becoming a reality.

Read more...
Schneider Electric relaunches legacy access control systems
Schneider Electric South Africa IT in Manufacturing
Schneider Electric South Africa has relaunched its comprehensive access control platform to help customers upgrade from ageing and obsolete systems.

Read more...
Digitalisation in mining - the advantage you need now
Schneider Electric South Africa IT in Manufacturing
Digitalisation offers immense and proven benefits such as streamlining operations, reducing error and accelerating workflows. Mining operators today leverage digital technologies to improve efficiency, sustainability and very importantly, safety.

Read more...
The shape of water – automating hydropower operations
Schneider Electric South Africa IT in Manufacturing
Hydropower is undoubtedly one of the building blocks of today’s renewable energy industry and its operations need to be efficient, reliable and sustainable. Automation must therefore form part of today’s modern hydropower operations to improve resource management and enhance reliability.

Read more...
What lies beneath – the hidden cost of AI
Schneider Electric South Africa IT in Manufacturing
The world is quickly realising that with the rapid advancement in AI there are also caveats. In short, apart from environmental implications, it also has major significant financial ramifications.

Read more...