Security News
September Virus Top 10
Tue, 24 October 2006
The calm before the “storm”
Tettnang 24 October 2006 - The latest Virus Top 10 released today by Avira shows that September was a period without any noticeable incidents, even if the total number of the threats identified by our Virus Laboratory increased with 9,3 % than last month. This malware ranking looks pretty much the same as the last top 10, with only few changes: two new entries and one re-entry.
During the first days of September the virus analysts discovered a new Zero-Day vulnerability in Office 2000. A trojan that made use of it was detected as "W97M/Mdropper.Q". After opening the infected documents the Trojan generates an “EXE” file which is detected by AntiVir as "TR/Small.KC".
On 4 September Avira detected a new variant of the MSN worms "Braban", a worm that spreads through the Instant Messenger MSN. "Worm/Braban.H" sends text messages with a link to the users who are in the contact list of MSN Messenger and as soon as the user clicks on this link, the worm is loaded.
The new entry – Worm/Womble.D, the sibling of Worm/Womble.A, was discovered on 12 September. Womble.D is a worm which contains an integrated SMTP engine in order to send emails to email addresses found in specific files on the system or to email addresses gathered from WAB (Windows Address Book). Like other old timers, this new menace uses two Microsoft vulnerabilities: MS04-011 (LSASS Vulnerability) and MS05-039 (Vulnerability in Plug and Play).
Worm/Mytob.MR is also a new entry in the malware hierarchy, being a worm which it is spreading via Windows Messenger. Like the other new entry, Mytob.MRuses the same Microsoft vulnerability - MS04-011. Besides these two new contenders, we have a new re-entry in the top 10 – Netsky.C, which brings back the top position of its malware family. After last month Mytob supremacy, now the Netsky family counts 4 members, with one member more than the Mytobs.
Another thing worth to mention is that we detected many more variants of W32/Sality.L and W32/Sality.Q as usual this month. Those two file infectors infect a copy of the Bagle worm in order to spread via email.
According to our specific statistic dates, spam made up 76.88 % of all discovered threats, with a 9.3 % increase from last month.
The number of phishing attacks (18 %) and viruses (5.12 %) detected in September was a little bit smaller than in August. As we said, no dreadful events happened during the last month. The amount of samples classified as viruses decreased with 19.17 % and the phishing attacks dropped slightly from 20.26 % to 18 %.
Here is a shot of our September Virus Top 10:
For technical information on any of these worms, please see the detailed descriptions on the Avira website. Also, please keep in mind that all Avira users are perfectly protected against these threats. Make sure you update your Avira product on a regular basis in order to detect the latest threats
|
Moving to the second part of our monthly malware ranking, we find little changes in the phishing attacks situation in September. There is no surprise to find out that the first two positions in the phishing hierarchy are occupied again by PayPal and Ebay.
This month the new targets of phishing attacks were:
Sierra Central Credit Union,
SunTrust Banks,
us bank,
Fairwinds Credit Union,
GTE Federal Credit Union,
Iowa Credit Union League,
America's First Federal Credit Union,
Hawaiian Tel Federal Credit Union,
Eli Lilly Federal Credit Union,
Tempe Schools Credit Union,
Empire Federal Credit Union,
Banesto,
Antioch Community Federal Credit Union,
My Bank,
Michigan Schools & Government Credit Union,
Marine Federal Credit Union and
Teachers Credit Union.
Avira strongly recommends all users to be careful with suspicious emails and unexpected attachments, no matter what interesting subjects they might claim to be carrying and to update their security product on a regular basis.
For more information on how to recognize a phishing fraud, take your time to read our dedicated page:
http://www.avira.com/en/threats/what_is_phishing.htmlRemember that we are here to assist you against the malware threat. Get rid of your doubts when facing a suspect file: just send it to
virus@avira.com and we will analyze it for you. Take a moment to see how to submit malware and then follow our instructions to send the suspicious file:
http://original.avira.com/en/pages/How_to_submit_malware.htmlAbout Avira Avira is a worldwide leading supplier of self-developed security solutions for professional and private use. With more than twenty years of experience, the company is one of the pioneers in this field.
The security expert has several locations in Germany and partnerships in Europe, Asia and America. At its headquarters in Tettnang near Lake Constance, Avira is one of the region’s largest employers with more than 180 employees. Worldwide more than 250 persons are employed and their work regularly wins awards. Avira AntiVir Personal, used by millions of private users, represents a significant contribution to security.
Avira’s national and international customers include renowned corporations listed on the stock exchange but also educational institutions and public authorities. In addition to protection of the virtual environment, Avira also provides for more protection and security in the real world by supporting the Auerbach Foundation. Established by the founder of the company, the Auerbach Foundation promotes charitable and social projects as well as the arts, culture and science.
Company Contact:Avira GmbH
Adela Kohl/Gernot Hacker
Lindauer Str. 21
D-88069 Tettnang
Telefon: +49 (0) 7542-500 0
Telefax: +49 (0) 7542-525 10
Email:
press@avira.comPress Contact:Jacklin Montag
LEWIS Global PR
Baierbrunner Strasse 15
D-81379 München
Tel.: +49 (0) 89-17 30 19 19
Telefax: +49 (0) 89 1730 19 99
Email:
avira@lewispr.com