Obfuscated malware tops list in August

Threats include runtime packing, polymorphism and junk code injection

Written by Clement James

ESET, the Bratislava-based security firm behind the Nod32 antivirus suite, said this week that a high percentage of malware detected in August employed some kind of obfuscation technique.

Threats that use obfuscation techniques to hide their malicious function, such as runtime packing, polymorphism and junk code injection, accounted for 7.58 per cent of malware detected in August.

According to ESET's ThreatSense.Net, which reports detection statistics from millions of client computers around the world, Win32/Obfuscated, a generic name for malware that hides its true intention, was the number one threat to users.

In second place, accounting for 3.4 per cent of malware threats, was Win32/Agent, which includes malware that has Trojan capabilities to connect directly back to a central server or provide a backdoor into the infected machine.

Down from first to third place last month was Win32/TrojanDownloader.Ani.gen, while Win32/Agent.ARK was in fourth place with 2.33 per cent of detections.

"This malware connects to a command and control server that seems to be located in Singapore," said Paul Brook, managing director at ESET UK.

"The purpose of Win32/Agent.ARK seems to be to keep control of an infected system so that it can be used to execute commands on the infected host and download additional software.

"Such botnet software is often able to update itself with new components which add new functionality, and which help it to evade detection by signature-based antivirus software."

See also:

reader comments

related articles

Computer virus

Medion sells laptops with 13 year-old virus

Consumers baffled to find ancient DOS virus 14 Sep 2007

 

Hackers hit US Consulate General in Russia

Malicious code waiting for web surfers 13 Sep 2007

Skipi worm jumps on Skype users

Beware chat messages bearing jpegs 12 Sep 2007

Organised crime holding off on mobile viruses

Mostly the work of amateurs, say experts 12 Sep 2007

Ad-based Trojan hits MySpace, Bebo and others

Malware hidden in adverts 11 Sep 2007

Storm worm back with a vengeance

Quarter of all detected threats during August, says BitDefender 10 Sep 2007

Storm malware still blowing strong

One year on and no sign of fading away 28 Jan 2008

2007 Roundup: The march of the botnets

Top 10 malware list for 2007 24 Dec 2007

latest news

Exclusive: Bell Micro EMEA confims job cuts

Distributor looking to make cost savings of 10 per cent across the business 21 Nov 2008

Avnet looks forward to 2009

Chief executive Roy Vallee reveals why the distributor is confident of riding out the storm 21 Nov 2008

PC growth forecasts slashed by two-thirds

Market watcher downgrades 2009 PC growth expectations from 11.9 to 4.3 per cent 21 Nov 2008

poll

Securing the future

Securing the future

Does the security channel need a governing body?

Previous poll results

Vendor Q&A Session: Rick Wallis, NEC Computers

Vendor Q&A Session: Rick Wallis, NEC Computers

During this Q&A session Rick Wallis, UK Sales Director at NEC Computers, talks about the firm’s reasons for committing to a 100 per cent channel strategy

In the Studio with CRN: Oracle

CRN TV catches up with Alan Hartwell, vice president of technology solutions and channels at Oracle

events

Channel Expo 2009 logo

Channel Expo 2009

The UK's top reseller exhibition will return to the NEC on 20 May 2009

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Advertisement

White papers

Search white papers

Top categories

Primary Navigation