Up to 59% of companies could have active malware on their networks, according to data gathered by Malware Radar

Some 59% of companies that scanned between 20 and 30,000 PCs with Malware Radar had active malware on their computers, according to Panda Security’s Malware Radar, an online, on-demand, automated malware audit service for businesses.
The increase in malware and the need for companies to have additional protection is reflected in the data gathered by Malware Radar from over 4,500 companies of all sizes. Active malicious code was found in almost half (47%) of companies that audited between 10 and 19 computers. 37% of companies that scanned between 5 and 9 computers had malware running at the time of the scan. As for companies that scanned between 1 and 4 computers, active malware was found in 35% of cases.


Detection ratios
Companies
With active malware
1 to 4 PCs
35%
5 PCs or more
37%
10 PCs or more
47%
20 PCs or more
59%

“This spectacular increase in the amount of malicious code in circulation (PandaLabs detected as much malware in 2006 as in the previous 15 years combined) has shown that traditional solutions are no longer enough. Panda offers companies a new security model based on complementing solutions already installed on desktops and servers. The model features periodic scans with Malware Radar, capable of finding and removing even the malware that evades traditional solutions”, explains Borja Bonilla, Malware Radar Product Manager.

The Malware Rader detects and eliminates all malicious code (viruses, Trojans, spyware...) installed on corporate networks and also identifies security flaws in computers. It is based on a new Collective Intelligence system developed by Panda Research and housed in a network of data centers. The system is based on three key factors:

1) Collection of data from the community. The system centrally collects and stores behavioral patterns of programs, file traces, new malware samples, etc. This data comes from Panda users, and from other companies and collaborators. This extensive capacity to collect information provides greater visibility of active Internet threats.

2) Automatic leverage of data. The system automatically analyzes and classifies the thousands of new samples received every day. To do this, an expert system correlates the data received from the user community with PandaLab’s extensive malware knowledge base. The system automatically returns verdicts (malware or goodware) on the new files received, thereby drastically reducing the manual workload at PandaLabs.

3) Making the knowledge available. This knowledge is delivered to users as Web services or through signature file updates.

As it’s an online service, it does not require installation on computers; simply a computer with an Internet connection is enough to scan the corporate network.

Malware Radar is not only compatible with any anti-malware solution installed on the computer, but complements them to improve network security. The service is also transparent to the end-user and resource usage can be adapted to the administrator's preferences.

Free trials of Malware Radar, as well as the full product, are available online from http://www.malwareradar.com.

Panda Security’s new consumer solutions protect against malware distributed from web pages

Panda’s solutions detect infection attempts launched from web pages, warning users and blocking the attacks.

Panda Security’s new consumer solutions (Panda Antivirus 2008, Panda Antivirus+Firewall 2008 and Panda Internet Security 2008) include a technology that allows detecting infection attempts from web pages. If a user’s security is compromised on visiting a web page, then the Panda solutions warn them and stop the attack.

Panda consumer solutions can detect scripts (sections of malicious code written in languages like JavaScript and designed to exploit vulnerabilities on computers) hosted on web pages that are trying to infect the user’s system. If this happens, users are warned that their security is at risk and that they must leave the web page.

“Cases like Mpack, a tool for installing malware through exploits which distributed malware from over 350,000 web pages, highlights the importance of having a tool that can protect users from this type of infection”, explains Almike Santisteban, Consumer Product Manager at Panda Security.

Panda Security consumer solutions can also detect vulnerabilities existing on users’ computers and report them so they can be patched. In this way, protection against malware hosted on web pages is further reinforced.

“These malicious codes exploit design flaws in programs to infect computers. If users keep their computers up-to-date, codes like those will be useless. We help users protect themselves by warning them against vulnerabilities on their computers”, says Santisteban.

This protection is complemented with blocking of malicious URLs. The system consists of a blacklist of pages that try to download spyware onto computers. If a user tries to access any of these pages, the Panda solutions will prevent them from doing so, warning them of the implicit risk.

“You must take into account that, on many occasions, the pages that download malware are legitimate pages which, due to a design flaw, are used by cyber-crooks to insert their creations in them and infect visitors. For this reason, it‘s essential that you have a good security solution that can warn you when you are in danger”, concludes Santisteban.

£600 to become a cyber-crook

This is all needed for Web criminals to earn millions of pounds. Hundreds of Internet pages and forums offer tools needed to infect users.

A Trojan costs between £175 and £350, while lists with one million email addresses are sold for £50.

Just over six hundred pounds can buy a cyber-crook the tool needed to turn malicious action into financial profit, according to data from PandaLabs. This is thanks to a black market on the Web where malicious code and tools are available at knock-down prices.

All types of crimeware tools can be bought on hundreds of forums. Even though most Web pages are located in Eastern Europe, Internet mafia networks extend worldwide.

Buying malware

If a cyber-crook wanted to buy a Trojan, say, he would only have to shell out between £175 and £350. A password stealer Trojan for example, costs £300, and a Limbo Trojan–with less features- costs around £250, although they have been sold for as little as £175. They both steal passwords to access online banks. Cyber-crooks would have to pay £250 for a Trojan that captures payment platform accounts, such as Webmoney, although there are often ‘special offers’. In one case, the first 100 buyers only had to pay £200.

The next step is to get a list of email addresses to distribute the Trojan. For this, they only have to visit another web page, where they can get mailing lists of all sizes. Prices vary from £50 per million addresses to £750 for 32 million. If they also want to send links that download the Trojan to instant messaging users, they can buy a million ICQ addresses for £75.

The next step? Making sure antivirus programs will not detect the malicious code. For between one and five dollars per hidden executable, they can hire a service that protects the malware against security tools. If they want to do it themselves, they can get polymorphic encryption software called Polaris for just £10.

The last step is to send emails to distribute the Trojan. For approximately £250, cyber-crooks can rent a spam server. Then, they just have to wait for the victims to be infected.

The profitability of malware

A few simple calculations are all that’s needed to underline how lucrative this activity can be. If a Trojan costs £250 and a million-address mailing list costs around £50, that means £300 is enough to infect a million people. Then add a £10 encryption program and a £250 spam server. With almost a 10 percent (really low) success rate, hackers could infect 100,000 people.

If they then managed to steal bank details from 10 percent of them, it would mean access to 10,000 bank accounts. Just imagine the money the average person has in a current account and multiply it by 10,000 to calculate the cyber-crooks’ profits.

However, emptying thousands of accounts would be very suspicious and crooks seek to obtain money invisibly. They, therefore, only take a small sum of money from each account, a hundred pounds, for example. Multiplied by 10,000, it still totals a million pounds. In other words, cyber-crooks can become millionaires with a £600 investment in very little time. Bearing in mind that very low success ratios were used in the calculations, the amount could be higher in real life.

If you think your computer might have been infected by these or other malicious codes, you can scan it free at www.nanoscan.com