Trojan.MSIL.Disfa

Detect Date 02/17/2016
Class Trojan
Platform MSIL
Description

Malware in this family often is disguised as an image file or as legitimate software. When the user opens the malware, it shows an image or window that does not contain actual content. The malware then extracts a file, contained inside of it, to a temporary folder. This file (in most cases, a keylogger) is added by the malware to the list of programs automatically launched by the operating system during startup.

Geographical distribution of attacks by the Trojan.MSIL.Disfa family

Geographical distribution of attacks during the period from 14 March 2015 to 14 March 2016

Top 10 countries with most attacked users (% of total attacks)

Country % of users attacked worldwide*
1 Algeria 12.25
2 India 10.96
3 Saudi Arabia 5.24
4 Russian Federation 4.97
5 Iraq 3.83
6 Egypt 3.52
7 Turkey 3.30
8 Brazil 3.20
9 Vietnam 2.58
10 Germany 2.53

* Percentage among all unique Kaspersky users worldwide who were attacked by this malware