
Kaspersky Lab published a rating of harmful programs for February 2010, which clearly illustrates the situation today: the main danger of computers infects users on the Internet.
{pic_1 c}
If earlier users have lured malicious sites created by attackers, then recently cybercriminals have changed tactics: they hack legitimate resources. A script is posted on the hacked page, which redirects the user to the attackers' website, after which the malicious program imperceptibly loads the victim in the event of a successful attack.
In such a difficult situation, the recommendations for users remain the same: it is necessary to use modern complex protective equipment, not forgetting about regular software updates. And with active work on the Internet, care should be observed, the LC said in a message .
Of the 20 programs in February, only six appeared in similar ratings in the previous months. 14 positions are busy with beginners. For comparison, among the programs blocked directly on user computers (harmful programs loading from the Internet do not get into this rating) only 4 new ones.
Of the 20 most active threats on the Internet, 8 can be used to redirect visitors to hacking legitimate resources for malicious sites. According to the above scheme, the notion in the ranking of the infamous Gumblar in the ranking, which indicates the next wave of an epidemic of this script bootloader. The scale of the epidemic of a similar Gumblar PEGEL bootloader that began in January is growing. Among the programs for the first time in the rating, there are four representatives of this family, and one of them was immediately in third place.
As mentioned above, an executable malicious file is downloaded to the computers of users who have fallen on malicious sites. For this, attackers most often operate vulnerabilities in large software products, such as Internet Explorer and Adobe Reader. At the same time, in such attacks, vulnerabilities discovered several years ago are often used. This indicates that many users did not work hard to patch holes in a timely manner in their computers.
Unfortunately, even installing all updates for large software packages, one cannot be sure that the computer is safe, since manufacturers of such software do not always produce “patches” for detected vulnerabilities in time.
Confirmation of this is the presence in the 9th place in the exploit.js.aurora.a. This exploit of vulnerability in Internet Explorer was used in a targeted attack on large companies (such as Google and Adobe) in order to obtain personal information of users and intellectual property of companies. Despite the fact that the presence of vulnerability in Microsoft was known long before the attack, it was fixed only a few weeks after its implementation.
Exploit.js.aurora.a also hit the 7th place in the ranking of harmful and potentially unwanted programs that were affected and neutralized on user computers in the first contacting them. The leading in this ranking, which occupied the three out of the five -first positions, the KIDO network worm, the epidemic of which has been going on for many months.