Report: Trojans Continue To Dominate Malware Threat Landscape

GFI Software recently announced the top 10 most prevalent malware threats for the month of November. The report, compiled from monthly scans performed by GFI's anti-malware solution, VIPRE Antivirus, and its antispyware tool, CounterSpy, is a service of GFI Labs.

As in recent months, Trojans dominated the threat landscape in November. ThreatNet data revealed that seven of the top 10 malware threats were classified as Trojans. The number-one detection, Trojan.Win32.Generic!BT, is a Trojan comprising over 20 percent of the ThreatNet detections.

“There is another picture in the top-10 numbers,” said Tom Kelchner, GFI Software communications and research analyst. “Three of them go after applications or server software that hasn’t been patched. The number six detection, Exploit.PDF-JS.Gen (v), tries to exploit a security flaw in PDF files with embedded JavaScript. That’s aiming at Adobe products. It often installs downloaders that pull down other malware from remote Web sites.”

Worm.Win32.Downad.Gen (v,) the Downadup worm (also called Conficker and Kido) in the number seven spot, is a worm that spreads across a network by taking advantage of a vulnerability in Windows Server service which allows remote code execution when file sharing is enabled. This vulnerability was patched some time ago.

Trojan.ASF.Wimad (v), in the number nine spot, is a VIPRE detection for a group of Trojanized Windows media files that exploit an old vulnerability in Windows Media Player. It redirects the victim’s browser to a web site to download malicious files. This is also is an old vulnerability that’s been fixed.

“If this malcode is still circulating, it means that the malcode writers are seeing a landscape with lots of unpatched and vulnerable machines. The conclusion is pretty clear for both enterprises and consumers: update Windows operating systems (including servers), browsers, Adobe products and media players and keep them updated,” said Kelchner.

Top 10 detections for November 
                Detection 	                   Type 	  	Percent 					
1. 	Trojan.Win32.Generic!BT 		Trojan 		22.44 
2. 	Trojan-Spy.Win32.Zbot.gen 		Trojan 		3.88 
3. 	Trojan.Win32.Generic.pak!cobra 	Trojan 		3.53 
4. 	Trojan.Win32.Generic!SB.0 		Trojan 		3.46 
5. 	INF.Autorun (v) 		         Trojan 		1.83 
6. 	Exploit.PDF-JS.Gen (v) 		Exploit 		1.45 
7. 	Worm.Win32.Downad.Gen (v) 		Worm.W32 		1.42 
8. 	Trojan.Win32.Malware.a 	         Trojan 		0.83 
9. 	Trojan.ASF.Wimad (v) 		Trojan 		0.76 
10. 	Trojan.Win32.Meredrop 		Trojan Downloader 	0.68

Featured

New Products

  • Mobile Safe Shield

    Mobile Safe Shield

    SafeWood Designs, Inc., a manufacturer of patented bullet resistant products, is excited to announce the launch of the Mobile Safe Shield. The Mobile Safe Shield is a moveable bullet resistant shield that provides protection in the event of an assailant and supplies cover in the event of an active shooter. With a heavy-duty steel frame, quality castor wheels, and bullet resistant core, the Mobile Safe Shield is a perfect addition to any guard station, security desks, courthouses, police stations, schools, office spaces and more. The Mobile Safe Shield is incredibly customizable. Bullet resistant materials are available in UL 752 Levels 1 through 8 and include glass, white board, tack board, veneer, and plastic laminate. Flexibility in bullet resistant materials allows for the Mobile Safe Shield to blend more with current interior décor for a seamless design aesthetic. Optional custom paint colors are also available for the steel frame.

  • PE80 Series

    PE80 Series by SARGENT / ED4000/PED5000 Series by Corbin Russwin

    ASSA ABLOY, a global leader in access solutions, has announced the launch of two next generation exit devices from long-standing leaders in the premium exit device market: the PE80 Series by SARGENT and the PED4000/PED5000 Series by Corbin Russwin. These new exit devices boast industry-first features that are specifically designed to provide enhanced safety, security and convenience, setting new standards for exit solutions. The SARGENT PE80 and Corbin Russwin PED4000/PED5000 Series exit devices are engineered to meet the ever-evolving needs of modern buildings. Featuring the high strength, security and durability that ASSA ABLOY is known for, the new exit devices deliver several innovative, industry-first features in addition to elegant design finishes for every opening.

  • Connect ONE’s powerful cloud-hosted management platform provides the means to tailor lockdowns and emergency mass notifications throughout a facility – while simultaneously alerting occupants to hazards or next steps, like evacuation.

    Connect ONE®

    Connect ONE’s powerful cloud-hosted management platform provides the means to tailor lockdowns and emergency mass notifications throughout a facility – while simultaneously alerting occupants to hazards or next steps, like evacuation.