Kaspersky Lab presents its email top 20 for September 2007

The September rating was unable to confirm some forecasts by the virus experts at Kaspersky Lab: Contrary to expectations, the active spread of the Trojan Trojan-Downloader.Win32.Agent.brk in August did not lead to the creation of a botnet, and the Warezov family is entirely absent from the September top 20.

Archive notice: This article was originally published on October 9, 2007. Links and embedded videos are preserved as part of the historical record.

In addition, another email worm, Zhelatin alias Storm Worm, reduced its activity. In August, one regularly heard from various IT security companies about a botnet that the “Storm Worm” was building, and at times there was talk of two million infected computers worldwide. Based on these figures, Kaspersky Lab’s experts expected a new epidemic. In September, however, nothing of the kind happened. Whether the size of the botnet was misjudged or the Zhelatin authors took time out can only be speculated about.

NetSky.q also holds firmly onto first place in Kaspersky Lab’s email top 20 in September. This worm has long since earned the status of the most widespread malicious program in the entire history of the Internet. In terms of scale over the entire period of its existence, NetSky leads the hit list off by a large margin.

The veterans NetSky.aa, Mydoom.l and Bagle.gt keep the leader company. In fifth place, an old acquaintance, Nyxem.e, joins the ranks of the top 10. It was discovered in January 2006, and its spread reached epidemic proportions that peaked in summer/autumn 2006.

Exploit.Win32.IMG-WMF.y was unable to continue its rapid rise and fell five positions to number 13. Its “main partner” Womble.a, by contrast, remained steadfast in 16th place. The virus experts at Kaspersky Lab predict the two a place in the hit parade of extreme viruses in September in the mail-traffic category.

The script worms Feebs.gen and Scano.gen were likewise able to hold their positions. Feebs.gen fell by only two places, and Scano.gen shows staying power in 12th place.

The only newcomer to the rating is the Trojan Trojan-Spy.HTML.Paylap.bg. With its phishing attack on PayPal customers, it joins the virus top 20. The first specimens of these phishing emails were registered as early as January 2005. After two and a half years, cybercrimnals now tried to revive the program – though without much success. Kaspersky Anti-Virus stopped the spam mailing without an update using the antivirus database from 2005.

At 8.92 percent, the category “other malicious programs” forms a share that cannot be neglected, measured against the total number of intercepted malicious programs.

Summary:

New: Trojan-Spy.HTML.Paylap.bg

Risen: Email-Worm.Win32.NetSky.aa, Net-Worm.Win32.Mydoom.l, Net-Worm.Win32.Mytob.dam

Fallen: Email-Worm.Win32.Bagle.gt, Net-Worm.Win32.Mytob.c, Worm.Win32.Feebs.gen, Email-Worm.Win32.NetSky.t, Exploit.Win32.IMG-WMF.y, Email-Worm.Win32.Mytob.t, Email-Worm.Win32.Mytob.u

Re-entry : Email-Worm.Win32.Nyxem.e, Email-Worm.Win32.NetSky.d, Email-Worm.Win32.Mydoom.e, Email-Worm.Win32.NetSky.y

1 – Email-Worm.Win32.NetSky.q 25.22%

2 +1 Email-Worm.Win32.NetSky.aa 10.83%

3 +3 Email-Worm.Win32.Mydoom.l 10.04%

4 -2 Email-Worm.Win32.Bagle.gt 7.62%

5 Re-entry Email-Worm.Win32.Nyxem.e 6.03%

6 -2 Net-Worm.Win32.Mytob.c 5.18%

7 -2 Worm.Win32.Feebs.gen 4.69%

8 -1 Email-Worm.Win32.NetSky.t 3.03%

9 New Trojan-Spy.HTML.Paylap.bg 2.62%

10 – Email-Worm.Win32.NetSky.b 2.62%

11 – Email-Worm.Win32.NetSky.x 2.35%

12 – Email-Worm.Win32.Scano.gen 1.72%

13 -5 Exploit.Win32.IMG-WMF.y 1.58%

14 -5 Net-Worm.Win32.Mytob.t 1.38%

15 +3 Net-Worm.Win32.Mytob.dam 1.35%

16 – Email-Worm.Win32.Womble.a 1.06%

17 Re-entry Email-Worm.Win32.NetSky.d 1.03%

18 -5 Net-Worm.Win32.Mytob.u 0.97%

19 Re-entry Email-Worm.Win32.Mydoom.e 0.93%

20 Re-entry Email-Worm.Win32.NetSky.y 0.83%