Major AV engines failing to detect malware

 

Summary

E-mail viruses see spike over the last two months and antivirus signatures have proven to be ineffective in fight against them, new report warns.

Events

IBM Technology Conference & Expo 2012
May 23, 2012

Convention Centre B2 Room at 22nd Floor, Centara Grand @ Central World, 999/99 Rama I Road, Pathumwan, Bangkok 10330

Echelon 2012
June 11 and 12, 2012

University Cultural Centre, National University of Singapore

Startup Asia Jakarta 2012
June 7 and 8, 2012

12th Floor, Annex Building, Wisma Nusantara Complex, Jl. M.H. Thamrin No. 59 Jakarta 10350, Indonesia

MMA Forum Singapore
April 23-25, 2012

Grand Hyatt Singapore

Antivirus vendors are having trouble keeping up with e-mail viruses, according to a new security report.

Released Tuesday, the Commtouch Q2 2009 Internet Threats Trend Report noted a spike in the number of e-mail viruses that slipped past major antivirus engines between late May and June. The security vendor based its findings on the analysis of over 2 billion e-mail messages and Internet transactions daily in its cloud-based global detection centers.

The dramatic rise, said the Israel-headquartered security vendor, was due to "aggressive" new variants of a number of Trojans. Several outbreaks had a wide distribution, which caused malware numbers to increase exponentially from typically low quantities circulated via e-mail.

With every new malware variant, there is a window where antivirus companies recognize and implement dedicated new signatures to protect their customers, explained CommTouch. This method, however, proved inefficient with the massive growth, so security vendors resorted to generic signatures to block all variants of the same malware family, which have not been effective against the recent variants, it added.

Total viruses missed by major AV engines (Jan-Jun 2009)


"For the last year-and-a-half, antivirus engines effectively blocked many virus variants with generic signatures," Amir Lev, chief technology officer of Commtouch, said in a company statement. "In the second quarter, however, malware distributors introduced large quantities of new variants which are immune to these generic signatures, therefore causing sharp increases in undetected malware samples that were blocked by Commtouch."

Some of the top malware cited by CommTouch as undetected by major antivirus software, were Mal/WaledPak-A, Troj/Agent-KBE and Mal/WaledPak-A.

The report also noted a sharp rise in the number of newly activated zombie PCs or bots during the same period. For the second quarter, an average of 376,000 new bots were activated each day for malicious use.

Between April and June, Brazil had the biggest share of zombie machines, with a 17.5 percent share of global bot activity, said CommTouch.

Mac malware is also on the rise, according to the company. Last month, security researchers warned of two new attacks targeting OS X users.

Citing security software company ParetoLogic, CommTouch said in its report there was an increasing number of Mac Trojans in the wild, as malware writers expand their attack surface by including as many platforms and browsers as they can. This trend is expected to continue for the rest of the year, it added.

Talkback

Major AV engines failing to detect malware

Funny...I've notice a tripling of spam in inbox and tripling in junkbox also around the same time.

need to start using commtouch...

Glenn Bestebreur July 16, 2009

RE: Major AV engines failing to detect malware

I also notice the same thing!

Anonymous July 17, 2009

RE: Major AV engines failing to detect malware

I also notice the same thing!

Anonymous July 17, 2009
Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment

ZDNet Asia Live

Sudden departure of Pacnet CEO, no explanation - ZDNet Asia: Sudden departure of Pacnet CEO, no explanationZDNet... http://t.co/UVG3OKCG

@ChemarieMonica : Malaysia organizations don't realize severity of cyberattacks - ZDN... http://t.co/iO8wdbz8 http://t.co/1QrdIsaV #tech

Malaysia organizations don't realize severity of cyberattacks. http://t.co/QK7PKdaP

RT @daryllau: Malaysia offers some manufacturing benefits over China http://t.co/mH23Uumr

Malaysia organizations don't realize severity of cyberattacks - ZDNet Asia http://t.co/HniF8J72 #news

#InfoSec Malaysia organizations don't realize severity of cyberattacks - ZDNet Asia http://t.co/vFzACdwm #CyberSecurity

http://t.co/bTDnDh7J Malaysia organizations don't realize severity of cyberattacks - ZDNet Asi... http://t.co/CzsMF2zn #infosec #security

Malaysia organizations don't realize severity of cyberattacks - ZDNet Asia: Malaysia organizat... http://t.co/iUpDhbeU #cloud #fail #TCN

Pacnet CEO departs; acquisition rumors gain steam. http://t.co/Nu2Mdcj0

Malaysia organizations don't realize severity of cyberattacks http://t.co/zeaxHbYa http://t.co/erFSwAUB #arcavir

http://t.co/VNaUVSe1 Malaysia organizations don't realize severity of cyberattacks: Cyberatt... http://t.co/TA5zWvUI http://t.co/wiqTBKkj

Malaysia organizations don't realize severity of cyberattacks - ZDNet Asia: Malaysia organizations don't realize... http://t.co/x1BJ0qSK

Malaysia organizations don't realize severity of cyberattacks - ZDNet Asia: Malaysia organizations don't realize... http://t.co/3Yaa40JE

Malaysia organizations don't realize severity of cyberattacks, country's minister of sci, tech, innovation says http://t.co/KGEHLi18 #in

Malaysia offers some manufacturing benefits over China http://t.co/mH23Uumr

So much as we know , MTK6575 extremely integrated frequency1GHz ARM Cortex-A9 processor, the superiority of 3G / HSPA Modem, and help the...

1 day ago by y15822137359 on 5 SaaS adoption speed bumps to avoid

I reckon your view: "CRM is strategy, not software", if a company replicating the approach uses in ERP implementation into CRM, what they...

2 days ago by wykoong on Gartner: Mobile CRM gives better ROI than social

This video will teach you about the Excel fill handle but also provide you with a workook to download... http://www.youtube.com/watch?v=...

2 days ago by TradeBrother on A quick fill handle trick for Microsoft Excel

waiting...

4 days ago by eapete on What should count in a company's market value?

Boy, you've opened a can of worms now.

Wait for the rants & raves.

4 days ago by eapete on What should count in a company's market value?

I was puzzling before this whether to replicate the success formula we executed for a financial institute, and come out with a standard s...

5 days ago by wykoong on Drop the egos, copy ideas, then innovate