Detect date
04/25/2018
Class
Packed
Platform
Multi

Parent class: Malware

Malicious tools are malicious programs designed to automatically create viruses, worms, or Trojans, conduct DoS attacks on remote servers, hack other computers, etc. Unlike viruses, worms, and Trojans, malware in this subclass does not present a direct threat to the computer it runs on, and the program’s malicious payload is only delivered on the direct order of the user.

Read more

Class: Packed

Malicious programs are frequently compressed – or packed – using a variety of methods combined with file encryption in order to prevent reverse engineering of the program and to hinder analysis of program behaviour with proactive and heuristic methods. Antivirus programs detect the results of the actions of suspicious packers, i.e. packed items. There are ways to prevent packed files from being unpacked: for example, the packer may not decipher the code fully, only to the extent that it is executed; or it may fully decrypt and launch a malicious program only on a certain day of the week. The main features that differentiate behaviours in the Suspicious Packers subclass are the type and number of packers used in the file compression process.

Read more

Platform: Multi

No platform description

Description

Malicious objects packed by various software packers more than three times. These software packers are often used for hindering deep analysis of malware and for hiding malware functionality.

Top 10 countries with most attacked users (% of total attacks)

1
France
27.26%
2
China
16.72%
3
Vietnam
13.24%
4
Russian Federation
4.25%
5
Algeria
3.58%
6
Germany
3.53%
7
United Kingdom
2.14%
8
Canada
2.07%
9
United States
1.60%
10
Hong Kong
1.37%

Read more

Find out the statistics of the vulnerabilities spreading in your region on statistics.securelist.com

Found an inaccuracy in the description of this vulnerability? Let us know!
Kaspersky Next
Let’s go Next: redefine your business’s cybersecurity
Learn more
New Kaspersky!
Your digital life deserves complete protection!
Learn more
Confirm changes?
Your message has been sent successfully.