Saltar al contenido principal

Virus Top Twenty for September 2007

1 de octubre de 2007

Netsky.q is once again in first place. This worm has finally achieved notoriety as the most widespread malicious program in the history of the Internet.

PositionChange in positionNameProactive Detection FlagPercentage
1.No Change 0Email-Worm.Win32.NetSky.qTrojan.generic25.22
2.Up +1Email-Worm.Win32.NetSky.aaTrojan.generic10.83
3.Up +3Email-Worm.Win32.Mydoom.lTrojan.generic10.04
4.Down -2Email-Worm.Win32.Bagle.gtTrojan.generic7.62
5.Return ReturnEmail-Worm.Win32.Nyxem.eTrojan.generic6.03
6.Down -2Net-Worm.Win32.Mytob.cTrojan.generic5.18
7.Down -2Worm.Win32.Feebs.genHidden Data Sending4,69
8.Down -1Email-Worm.Win32.NetSky.tTrojan.generic3.03
9.New! NewTrojan-Spy.HTML.Paylap.bg[HTML]2.62
10.No Change 0Email-Worm.Win32.NetSky.bTrojan.generic2.62
11.No Change 0Email-Worm.Win32.NetSky.xTrojan.generic2.35
12.No Change 0Email-Worm.Win32.Scano.genTrojan.generic1.72
13.Down -5Exploit.Win32.IMG-WMF.y[WMF]1.58
14.Down -5Net-Worm.Win32.Mytob.tWorm.P2P.generic1.38
15.Up +3Net-Worm.Win32.Mytob.dam[Damaged]1.35
16.No Change 0Email-Worm.Win32.Womble.aTrojan.generic1.06
17.Return ReturnEmail-Worm.Win32.NetSky.dTrojan.generic1.03
18.Down -5Net-Worm.Win32.Mytob.uWorm.P2P.generic0.97
19.Return ReturnEmail-Worm.Win32.Mydoom.eTrojan.generic0.93
20.Return ReturnEmail-Worm.Win32.NetSky.yTrojan.generic0.83
Other malicious Programs8.92

Our forecasts for September turned out not to be spot on. Trojan-Downloader.Win32.Agent.brk, which was spreading actively in August, didn't extend the botnet that it builds, and as a result, there's not a single Warezov variant in September's Top Twenty.

However, the authors of another email worm, Zhelatin (aka the Storm worm) stepped up their activity. Throughout August security companies provided regular reports and estimates on the scale of the botnet created by the worm. Some estimates were as high as 2 million infected computers around the world – indicating that a new epidemic was on the horizon. However, September was remarkably calm from this point of view. Either the numbers were erroneous, or the authors of Zhelatin have decided to take a break until law enforcement agencies around the world direct their attention elsewhere.

Netsky.q is once again in first place. This worm has finally achieved notoriety as the most widespread malicious program in the history of the Internet. Mydoom.a remains the leader in terms of numbers (this worm infected 8 out of every ten emails at the peak of the epidemic in January 2004) but Netsky is way out in front overall.

Keeping the leader company in the top five positions are other longtime residents of the rankings: Netsky.aa, Mydoom.l, Bagle.gt, and Nyxem.e, in a surprising comeback. This worm was first detected in January 2006, with the peak of the epidemic being in summer/ autumn of the same year. We've seen this worm disappear from the rankings many times, but somehow it always manages to stage a comeback and climb to near the top of the table.

Exploit.Win32.IMG.WMF.y has become slightly less common. Having risen seven places up the table in August, in September it fell five places. However, its main partner, the Womble worm, remains unshakeable in sixteenth place. It's almost inevitable that in October we will again see these two in the mail traffic rankings.

Feebs.gen and Scano.gen, both script worms, managed to effectively retain their positions: Feebs fell by a mere two places, and Scano managed to hang onto twelfth place (having risen five positions in August), indicating that these programs will continue to be active in the future.

The only newcomer to the rankings is a phishing attack on PayPal customers: Trojan-Spy.HTML.Paylap.bg. The first examples of this phishing email were detected back in January 2005. And after two and a half years, some unknown malicious users have decided to breathe new life into this old approach, but not terribly successfully. Kaspersky® Anti-Virus detected this mass-mailing without the need for new signatures, simply using the old records from 2005.

Other malicious programs made up 8.92% of all malicious code in mail traffic, indicating that there is still a relatively large number of other worm and Trojan families in circulation.

Summary

  • New: Trojan-Spy.HTML.Paylap.bg
  • Went up: Email-Worm.Win32.NetSky.aa, Net-Worm.Win32.Mydoom.l, Net-Worm.Win32.Mytob.dam
  • Went down: Email-Worm.Win32.Bagle.gt, Net-Worm.Win32.Mytob.c, Worm.Win32.Feebs.gen, Email-Worm.Win32.NetSky.t, Exploit.Win32.IMG-WMF.y, Email-Worm.Win32.Mytob.t, Email-Worm.Win32.Mytob.u
  • Re-entry: Email-Worm.Win32.Nyxem.e, Email-Worm.Win32.NetSky.d, Email-Worm.Win32.Mydoom.e, Email-Worm.Win32.NetSky.y

Virus Top Twenty for September 2007

Netsky.q is once again in first place. This worm has finally achieved notoriety as the most widespread malicious program in the history of the Internet.
Kaspersky logo

Sobre Kaspersky

Kaspersky es una empresa de ciberseguridad y privacidad digital global fundada en 1997. Con más de mil millones de dispositivos protegidos hasta la fecha ante ciberamenazas emergentes y ataques dirigidos, la enorme experiencia de Kaspersky en cuestión de información y seguridad ante amenazas se transforma de forma constante en soluciones y servicios innovadores que ofrecen protección a negocios, infraestructuras vitales, gobiernos y consumidores de todo el mundo. El completísimo catálogo de la compañía incluye los mejores productos y servicios de protección de terminales, así como soluciones de ciberinmunidad para combatir amenazas digitales sofisticadas y en constante evolución. Ayudamos a que más de 200 000 clientes corporativos protejan aquello que más les importa. Más información en www.kaspersky.es.

Artículo relacionado Comunicados de prensa