In November, our customers received just under 950,000 viruses and vulnerabilities (324 different viruses, vulnerabilities and variants total) from over 81,000 unique IPs (this only includes viruses sent to customers running the latest beta and using this new feature, and does not include the majority of our customers). The following is a list of all viruses and vulnerabilities that our customers received at least 1,000 copies of in November (it may be easier to read if you use a fixed-width font):
W32/[EMAIL PROTECTED] 18.38% W32/[EMAIL PROTECTED] 16.59% [Outlook 'CR' Vulnerability] 16.57% W32/[EMAIL PROTECTED] 14.94% W32/[EMAIL PROTECTED] 12.62% W32/[EMAIL PROTECTED] 2.59% [Outlook 'Space Gap' Vulnerability] 1.73% [Outlook 'MIME Header' Vulnerability] 1.61% [Outlook 'Blank Folding' Vulnerability] 1.53% W32/Hybris.worm.B 1.34% [Partial Vulnerability] 1.29% W32/[EMAIL PROTECTED] 1.05% I-Worm/Yaha.G 0.98% [Conflicting Encoding Vulnerability] 0.96% W32/[EMAIL PROTECTED] 0.88% W32/[EMAIL PROTECTED] 0.88% W32/[EMAIL PROTECTED] 0.64% W32/[EMAIL PROTECTED] (corrupted) 0.59% [Outlook 'MIME segment in MIME Preamble' Vulnerability] 0.50% [Outlook 'MIME segment in MIME Postamble' Vulnerability] 0.43% W32/[EMAIL PROTECTED] 0.31% W32/[EMAIL PROTECTED] 0.30% W32/[EMAIL PROTECTED] 0.25% W32/[EMAIL PROTECTED] 0.20% W32/[EMAIL PROTECTED] 0.19% W32/[EMAIL PROTECTED] 0.17% W32/Bugbear.b.dam 0.15% W32/[EMAIL PROTECTED] 0.14% W32/[EMAIL PROTECTED] 0.14% W32/[EMAIL PROTECTED] 0.11% W32/[EMAIL PROTECTED] 0.10% W32/[EMAIL PROTECTED] 0.10% VBS/Lovelorn.dropper 0.10%
Note that some viruses may appear multiple times, due to variants (Sobig.A versus Sobig.F, for example), damaged versions, and different naming conventions among virus scanners.
Probably the most interesting thing about this data is that about 25% of the E-mails that were caught contained a vulnerability designed to bypass mailserver virus scanners. Although most of those E-mails are probably harmless(?) spam, it shows that vulnerabilities are very widespread. There were 7 different mailserver AV vulnerabilities that were detected in at least 1,000 E-mails sent to our customers in November. We believe there is a very good chance that Sobig.G will use a mailserver AV vulnerability, which is one way that they can get more people to open the virus (as many people who think that they are protected will receive the virus). Most mailserver AV programs will allow viruses through if they contain a mailserver vulnerability.
You can see the most recent viruses received at http://apps.declude.com/tools/virinfo.ch .
-Scott
---
Declude JunkMail: The advanced anti-spam solution for IMail mailservers.
Declude Virus: Catches known viruses and is the leader in mailserver vulnerability detection.
Find out what you have been missing: Ask for a free 30-day evaluation.
--- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]
To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/
