Doctor Web, Ltd. virus monitoring service conducted a survey of virus activity in October of 2007
The scale of Storm Worm spam mailing has been decreasing. However, one can't say that it has stopped. A user receives a mail message with a download link to a greetings card. Following the link loads a cartoon style page. The page code contains download script which is detected by Dr.Web antivirus as VBS.Psyme.438. Executing the script results in an unauthorized installation of an executable. After that it works the same way as before: an infected computer joins a P2P network and sends out spam messages. Besides, infected machines were used for DDoS attacks on anti-spam portals and sites distributing Win32.HLLM.Limar.
Lower activity of Storm Worm allowed authors of Win32.HLLM.Limar "to rear their heads". On October 20-21 a mass mailing was detected, messages contained an attached downloader that installed main modules of Win32.HLLM.Limar on an infected workstation. Win32.HLLM.Limar replaced Windows Messanger temprorarily and sent out messages containing its download links.
This month also saw two new malicious pieces of software spreading over Skype VoIP network - Win32.HLLW.Pykse and Trojan.PWS.Skype. It means that number of malicious programmes exploiting Skype may increase. We would like to remind you that another malicious programme for Skype - Win32.HLLW.Crazy - was discovered this summer.
We can't miss appearing of a malicious PDF document that exploits vulnerabilities of Adobe Systems Reader and Acrobat. Surely a lot of people remember the spam wave with PDF attachments. The first wave messages didn't contain destructive PDF files. However, the current mailing wave has shown that PDF files can impose a tangible threat to a computer of a user. Detecting such PDF files is included in Exploit.PDFUri Dr.Web bases.
October 2007 Spam activity summary
The event of the month was a new spam technique used to evade spam-filters - spam messages with MP3 attachments. But such MP3 files had a very low bit-rate so the new method was not very efficient and a mailing stopped rather quickly.
The amount of commercial spam containing business related information as well as so called "cultural spam" advertising a first night, an exhibition or other cultural events has increased this month.
9855 entries have been added to Dr.Web virus data-base in October.
The table below shows results of online scan for the last month:
You can also have a look at the summary table of viruses most frequently detected on mail servers in October 2007:
|Virus name||% of total quantity|
Tell us what you think
You will be awarded one Dr.Webling per comment. To ask Doctor Web’s site administration about a news item, enter @admin at the beginning of your comment. If your question is for the author of one of the comments, put @ before their names.