Since we started collecting the data in the middle of the month, our customers received over 300,000 viruses and vulnerabilities from over 22,000 unique IPs (this only includes viruses sent to customers running the latest beta and using this new feature, and does not include the majority of our customers). The following is a list of all viruses and vulnerabilities that our customers received at least 1,000 copies of in September (it may be easier to read if you use a fixed-width font):
W32/[EMAIL PROTECTED] - 44.97% W32/[EMAIL PROTECTED] - 14.72% [Outlook 'CR' Vulnerability] - 13.58% W32/[EMAIL PROTECTED] - 8.28% W32/[EMAIL PROTECTED] - 4.81% W32/[EMAIL PROTECTED] - 2.12% [Outlook 'MIME Header' Vulnerability] - 1.79% W32/[EMAIL PROTECTED] (exact) - 1.15% [Outlook 'MIME segment in MIME Preamble' Vulnerability] - 0.94% [Conflicting Encoding Vulnerability] - 0.93% [Outlook 'Blank Folding' Vulnerability] - 0.73% W32/Hybris.worm.B - 0.73% W32/[EMAIL PROTECTED] - 0.58% W32/[EMAIL PROTECTED] - 0.53% [Partial Vulnerability] - 0.42% W32/[EMAIL PROTECTED] - 0.40% VBS/Lovelorn.dropper - 0.35% W32/[EMAIL PROTECTED] - 0.32% W32/[EMAIL PROTECTED] (corrupted) - 0.29% W32/[EMAIL PROTECTED] - 0.25% W32/[EMAIL PROTECTED] - 0.23% W32/[EMAIL PROTECTED] - 0.18% W32/[EMAIL PROTECTED] - 0.16% W32/[EMAIL PROTECTED] - 0.13% W32/[EMAIL PROTECTED] (exact) - 0.11% W32/Bugbear.b.dam - 0.07% application Exploit-MIME.gen.c - 0.07% W32/[EMAIL PROTECTED] - 0.05% W32/[EMAIL PROTECTED] - 0.05% [Outlook 'MIME segment in MIME Postamble' Vulnerability - 0.05% W32/[EMAIL PROTECTED] - 0.05% W32/[EMAIL PROTECTED] - 0.05% W32/Lovelorn.dr - 0.04% W32/[EMAIL PROTECTED] - 0.03% W32/[EMAIL PROTECTED] (corrupted) - 0.03%
Note that some viruses may appear multiple times, due to variants (Sobig.A versus Sobig.F, for example), damaged versions, and different naming conventions among virus scanners.
Probably the most interesting thing about this data is that over 15% of the E-mails that were caught contained a vulnerability designed to bypass mailserver virus scanners. Although most of those E-mails are probably harmless(?) spam, it shows that vulnerabilities are very widespread. There were 6 different mailserver AV vulnerabilities that were detected in at least 1,000 E-mails sent to our customers in September (with another 6 mailserver AV vulnerabilities that were detected in less than 1,000 E-mails sent to our customers). We believe there is a very good chance that Sobig.G will use a mailserver AV vulnerability, which is one way that they can get more people to open the virus (as many people who think that they are protected will receive the virus).
You can see the most recent viruses received at http://apps.declude.com/tools/virinfo.ch .
-Scott
---
Declude JunkMail: The advanced anti-spam solution for IMail mailservers.
Declude Virus: Catches known viruses and is the leader in mailserver vulnerability detection.
Find out what you have been missing: Ask for a free 30-day evaluation.
--- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]
To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/
