Archive notice: This article was originally published on December 7, 2007. Links and embedded videos are preserved as part of the historical record.
After three months without a change at the top of the monthly statistics for the most widespread malicious programs, Kaspersky Lab’s experts identified a new leader in November. There were no truly serious epidemics in e-mail traffic this month either.
The worms Scano.gen and Mytob.t improved their positions by twelve places, and NetSky.x slipped forward by eight places. The massive onslaught of these three worms led to the long-overdue replacement of Email-Worm.Win32.NetSky.q on the winner’s podium.
All in all, with the phishing program Fraud.ay, only a single pest was able to maintain its position from the previous month at least to some extent. This malicious program targets users of the Russian payment service „Yandex.Dengi“. It is not distinguished by any particular originality and is easily detected by both antivirus programs and spam filters. The phishing sites themselves are identified by the anti-phishing modules integrated into common browsers.
In November, the exploit of a vulnerability in Adobe products disappeared completely from the statistics. In October, its modifications in the form of malicious PDF files with a downloader function had still attracted attention and occupied top positions in the ranking. But just as quickly as they had appeared, they disappeared again. In return, IMG-WMF.y, another exploit, made the steepest climb of the month: IMG-WMF.y improved by 13 positions and now stands in sixth place.
Lovegate.w rose an impressive nine positions. In November there were a total of four returnees, including the worm Warezov.pk in seventh place. If one now also considers the five newcomers, of which Warzov.um in ninth place was able to record the greatest success, the result is a thoroughly unusual monthly statistic. On the one hand, representatives of well-known families of classic worms were found with NetSky, Mydoom, Bagle, Feebs, Nyxem and Scano, while on the other hand new trojan programs of the Trojan-Spy and Trojan-Downloader classes also appear in the monthly statistics. The situation will probably continue to develop according to a similar pattern in the coming months: traditional e-mail worms share the upper ranks, while trojan programs and exploits cavort in the lower section.
The remaining malicious programs active in e-mail traffic account for a not insignificant share of 11.25 percent measured against the total number of all intercepted malicious programs.
Summary:
New: Email-worm.win32.warezov.um, Trojan-Downloader.Win32.Agent.ezm, Trojan-Spy.Win32.Keylogger.rp, Net-Worm.Win32.Mytob.fm, Trojan.Win32.Pakes.bpn
Risen: Email-Worm.Win32.Scano.gen, Net-Worm.Win32.Mytob.t, Email-Worm.Win32.NetSky.x, Net-Worm.Win32.Mytob.c, Exploit.Win32.IMG-WMF.y, Email-Worm.Win32.LovGate.w, Net-Worm.Win32.Mytob.dam, Email-Worm.Win32.NetSky.b,
Fallen: Trojan-Spy.HTML.Fraud.ay, Email-Worm.Win32.NetSky.t, Worm.Win32.Feebs.gen
Re-entry: Email-Worm.Win32.Warezov.pk, Email-Worm.Win32.Womble.a, Net-Worm.Win32.Mytob.j, Net-Worm.Win32.Mytob.r
1 +12 Email-Worm.Win32.Scano.gen 16.03%
2 +12 Net-Worm.Win32.Mytob.t 9.42%
3 +8 Email-Worm.Win32.NetSky.x 6.45%
4 -2 Trojan-Spy.HTML.Fraud.ay 6.28%
5 +5 Net-Worm.Win32.Mytob.c 5.95%
6 +13 Exploit.Win32.IMG-WMF.y 5.95%
7 Re-entry Email-Worm.Win32.Warezov.pk 5.79%
8 +9 Email-Worm.Win32.LovGate.w 5.45%
9 New Email-worm.win32.warezov.um 5.12%
10 -3 Email-Worm.Win32.NetSky.t 3.64%
11 +7 Net-Worm.Win32.Mytob.dam 3.47%
12 Re-entry Email-Worm.Win32.Womble.a 3.31%
13 +3 Email-Worm.Win32.NetSky.b 2.15%
14 Re-entry Net-Worm.Win32.Mytob.j 1.98%
15 Re-entry Net-Worm.Win32.Mytob.r 1.65%
16 -12 Worm.Win32.Feebs.gen 1.32%
17 New Trojan-Downloader.Win32.Agent.ezm 1.32%
18 New Trojan-Spy.Win32.Keylogger.rp 1.32%
19 New Net-Worm.Win32.Mytob.fm 1.16%
20 New Trojan.Win32.Pakes.bpn 0.99%
Other malicious programs 11.25%