Worm.Win32.Vobfus

Detect Date 02/17/2016
Class Worm
Platform Win32
Description

Malware of this family searches for computers on a network and creates copies of itself in folders with open access. For the program to be activated, the user must first run it on the computer. The code of this malware is written in the Visual Basic programming language and uses obfuscation, which is a distinguishing feature of this family. Code obfuscation complicates attempts by anti-virus software to analyze suspected malware.

Geographical distribution of attacks by the Worm.Win32.Vobfus family

Geographical distribution of attacks during the period from 14 March 2015 to 14 March 2016

Top 10 countries with most attacked users (% of total attacks)

Country % of users attacked worldwide*
1 Kazakhstan 12.87
2 Vietnam 11.56
3 Iran 8.81
4 Algeria 5.74
5 Peru 5.31
6 Uzbekistan 4.08
7 India 3.90
8 Mexico 3.35
9 Russian Federation 2.55
10 Egypt 2.32

* Percentage among all unique Kaspersky users worldwide who were attacked by this malware