Malware reports

Malware Miscellany, September 2007

September brings a change of seasons – has the colder weather caused any familiar malicious programs to go into hibernation? Let’s find out by taking a look at this month’s malware miscellany:

  1. Greediest Trojan Targeting Banks: this title goes to a modification of Trojan-Spy.Win32.Small.dg, which manages to target the clients of 134 banks at once – quite an impressive feat!.
  2. Greediest Trojan Targeting Payment Systems: Trojan-Spy.Win32.Agent.baa is the winner this month, and it’s designed to harvest access data for three different e-payment systems.
  3. Greediest Trojan Targeting Plastic Cards: Once again the title goes to a Banbra variant – this month it’s Trojan-Spy.Win32.Banbra.df, which targets three payment card systems. And for the third month running, it’s a program with Brazilian roots that wins this category.
  4. Stealthiest Malicious Program: Trojan.Win32.Delf.or, which is packed ten times with a variety of different packers, takes September’s title.
  5. Smallest Malicious Program: This month brings us the tiny 19 byte Trojan.BAT.KillFiles.gc, but in spite of its small size, this program is able to delete plenty of data from the user’s computer.
  6. Biggest Malicious Program: This title goes to a modification of, which weighs in at a hefty 234 MB – the authors of this Trojan don’t seemed to be at all concerned about efficient use of resources!
  7. Most Malicious Program: Autumn’s leader so far is Trojan-Downloader.Win32.Agent.bxx, which uses a variety of methods to disable security solutions, including terminating processes in memory and deleting the security programs themselves.
  8. Most Common Malicious Program in Email Traffic: Although Email-Worm.Win32.NetSky.q has been around for years, it still managed to account for 25.22% of all malicious email traffic in September – 4% higher than in August.
  9. Most Common Trojan Family: The winner in this category is Trojan-Downloader.Win32.Agent, with a ‘mere’ 663 modifications – nearly a hundred fewer than August’s winner.
  10. Most Common Virus/ Worm Family: This nomination goes to Zhelatin, back after two months off with 55 new modifications detected this month.

This month has seen some regulars either retaining their dominance, or returning after a break. The first snows here have had an effect on our physical surroundings – we’ll see next month if there’s been any impact on the malware landscape.

Malware Miscellany, September 2007

Your email address will not be published. Required fields are marked *



Operation TunnelSnake

A newly discovered rootkit that we dub ‘Moriya’ is used by an unknown actor to deploy passive backdoors on public facing servers, facilitating the creation of a covert C&C communication channel through which they can be silently controlled. The victims are located in Africa, South and South-East Asia.

APT trends report Q1 2021

This report highlights significant events related to advanced persistent threat (APT) activity observed in Q1 2021. The summaries are based on our threat intelligence research and provide a representative snapshot of what we have published and discussed in greater detail in our private APT reports.

The leap of a Cycldek-related threat actor

The investigation described in this article started with one such file which caught our attention due to the various improvements it brought to this well-known infection vector.

Subscribe to our weekly e-mails

The hottest research right in your inbox