Security News
July Virus Top 10
Thu, 10 August 2006
First time after Sober.Y disappeared, we have a new number one threat - Worm/Bagz.D.3 dethroned Netsky.P
Tettnang, 8 August 2006 - Avira unveils the malware hierarchy for July, based on thorough statistic data and antivirus experts’ points of view. After several months of Netsky.P supremacy, July brings in a new contender - Worm/Bagz.D.3 with 32.5 % of all infections detected this month, which entered directly to the first position. Even though Netsky.P dropped slightly from 35.4% to 27.2% of viruses reported in July, this virus is still a potential threat to the users.
The malware ranking for this month includes two other new entries: Worm/Mytob.NT and Worm/Bagz.C.2, while Lovgate.W, Netsky.#1 and Worm/Lovgate.AU.2 disappeared from our virus top 10. This month's hierarchy consists of only three malware families - Netsky, Mytob and Bagz, indicating that virus writers are continuing to create versions of established threats, which is usually the fastest way to enhance and also proved to be most successful for financial gain for malware that focuses this aspect. However, it is shocking that the same old viruses are continuing to cause trouble. In order to stop spreading these viruses, Avira recommends to computer users to keep their antivirus up to date. Therefore Avira added Netsky.P to its removal tool in July.
The Avira virus experts discovered on 21st of July a virus which takes advantage of a security gap in Microsoft PowerPoint. The virus is able to activate himself by simply opening infected Microsoft PowerPoint presentations. Avira added special detection routines in order to detect the exploit code itself as HEUR/PPT.Dropper and HEUR/Office.Dropper. In July the total amount of the identified malware increased by 15.4 % while the number of obtained phishing emails increased by 48.2%.
Here is a shot of our July Virus Top 10:
For technical information on any of these worms, please see the detailed descriptions on the Avira website. Also, please keep in mind that all Avira users are perfectly protected against these threats. Make sure you update your Avira product on a regular basis in order to detect the latest threats.
|
Moving on to the second part of our monthly malware analysis, we discovered something incredible for this month: the
100th phishing description of PayPal was published on our website.
PayPal, the famous portal, was the number-one target of phishing authors all through July, counting more than 50 % of all phishing attacks. The reason that makes PayPal the number one phishing is the huge popularity of this global online payment system. |
The phishing authors make use of this portal’s popularity and the fact that it has thousands of new members every day which might have never been targeted before.
As we said the last two months, phishers have begun to target smaller entities besides large banking institutions, and we discovered again an incredible amount of new targets, such as:
Downey Savings,
Frontier Bank,
PNC Bank,
Affinity Plus Federal Credit Union,
Franklin Bank,
TD Canada Trust,
BHF-BANK,
Elevations Credit Union,
OnPoint Community Credit Union,
Banca Commerciala Romana,
Colorado State Employees Credit Union,
Fifth Third Bank, UBS,
Campus USA Credit Union,
The National Bank of Cambridge, Maryland;
TCF Bank,
Elizabethton Federal Savings Bank,
Flagstar Bank and
Hancock Bank.
Avira strongly recommends all users to be careful with suspicious emails and unexpected attachments, no matter what interesting subjects they might claim to be carrying and to update their security product on a regular basis.
If you want to know more about these forms of cyber crime, please see or search for detailed descriptions on our website:
http://www.avira.com/en/threats/index.htmlFor more information on how to recognize a phishing fraud, take your time to read our dedicated page:
http://www.avira.com/en/threats/what_is_phishing.htmlRemember that we are here to assist you against the malware threat. Get rid of your doubts when facing a suspect file: just send it to and we will analyze it for you. Take a moment to see how to submit malware and then follow our instructions to send the suspicious file:
http://original.avira.com/en/pages/How_to_submit_malware.htmlAbout AviraAvira is a worldwide leading supplier of self-developed security solutions for professional and private use. With more than twenty years of experience, the company is one of the pioneers in this field.
The security expert has several locations in Germany and partnerships in Europe, Asia and America. At its headquarters in Tettnang near Lake Constance, Avira is one of the region’s largest employers with more than 180 employees. Worldwide more than 250 persons are employed and their work regularly wins awards. Avira AntiVir Personal, used by millions of private users, represents a significant contribution to security.
Avira’s national and international customers include renowned corporations listed on the stock exchange but also educational institutions and public authorities. In addition to protection of the
virtual environment, Avira also provides for more protection and security in the real world by supporting the Auerbach Foundation.
Established by the founder of the company, the Auerbach Foundation promotes charitable and social projects as well as the arts, culture and science.
Press Contact:
Jacklin Montag Lewis Global PR Baierbrunner Str. 15 D-81379 Munich Telefon: +49 (0) 89 1730 19 19 Telefax: +49 (0) 89 1730 19 99 Email: avira@lewispr.com
|
Company Contact:
Adela Kohl/Gernot Hacker
Avira GmbH
Lindauer Str. 21
D-88069 Tettnang
Telefon: +49 (0) 7542-500 284
Telefax: +49 (0) 7542-525 10
Email: press@avira.com