Sophos

Talk to our experts

Find your local press contact

Resources

Sophos blogs

Info feeds

What are info feeds?

1 September 2005

Top ten viruses and hoaxes reported to Sophos in August 2005 Netsky stays top as Zotob fails to make impact

Sophos, a world leader in protecting businesses against viruses, spyware and spam, has revealed the top ten viruses and hoaxes causing problems for businesses around the world during the month of August 2005.

The report, compiled from Sophos's global network of monitoring stations reveals that Netsky-P, the worm written by the convicted German teenager, Sven Jaschan, has yet again retained its position at the top of the charts this month. The recent Zotob worms are notable by their absence in the chart despite having received a great deal of press attention for successfully infecting several high profile media organisations.

The top ten viruses in August were as follows:

Position Last
month
Malware Percentage of reports
11W32/Netsky-P
   14.7%
22W32/Mytob-AS
   7.9%
33W32/Mytob-BE
   7.2%
45W32/Zafi-D
   3.6%
5Re-entryW32/Zafi-B
   2.9%
6NewW32/Mytob-C
   2.8%
74W32/Mytob-EP
   2.8%
86W32/Mytob-CX
   2.7%
97W32/Netsky-D
   2.5%
108W32/Mytob-CJ
   2.4%
Others49.5%

The prevalence of the Netsky-P worm rose slightly in August, from 13.9% to 14.7%, but variants of the Mytob worm remain the dominant threat to computer users, accounting for 54% of all viruses reported to Sophos in August. In addition, research now suggests that the Zotob group of viruses is also directly linked to Mytob.

"Mytob and Zotob may spread in different ways, but the source code is very similar," said Carole Theriault, security consultant at Sophos. "Moreover, the Zotob author's nickname, Diabl0, appears in more than twenty of the Mytob variants, suggesting that they may have been created by the same person. One thing is for sure - Mytob is still causing chaos in organisations that haven't updated their virus protection and patched software vulnerabilities."

The threats listed in the August virus chart have had a much smaller impact and claimed fewer victims than the previous months. Sophos's research shows that 1.99%, or one in 50 emails, circulating during the month of August were viral - a significant drop when compared to the May results of one in 38 emails.

"Rather than being a sign that virus writers are giving up trying to infect computers, the reason for this decrease is most likely due to August being a favourite holiday time for many people," explained Theriault. "While people are enjoying a cocktail of sun, sea and sand, a large number of computers are switched off and therefore immune to infection".

In order to minimise exposure to viruses, Sophos recommends that companies deploy a policy at their email gateway which blocks unwanted executable attachments from being sent into their organisation from the outside world. Companies should also run up-to-date anti-virus software, firewalls and install the latest security patches.

Sophos identified and protected against 1,626 new viruses in August. The total number of viruses Sophos now protects against is 109,244.

The top ten hoaxes reported to Sophos during August 2005 were as follows:

Position Hoax Percentage of reports
1Hotmail hoax
   13.5%
2Bonsai kitten
   10.0%
3Meninas da Playboy
   9.8%
4Budweiser frogs screensaver
   8.8%
5ICE virus hoax
   6.9%
6A virtual card for you
   5.7%
7WTC Survivor
   4.7%
8Jamie Bulger
   3.8%
9Mobile phone hoax
   1.9%
10Bill Gates fortune
   1.8%
Others33.1%

"Though the Hotmail hoax is now in its 14th month at the top of the chart, it has fallen in volume by 20% from July - though this may be explained by the reduction in user activity," added Theriault. "With London still recovering from last month's bombings, it is not surprising that the ICE virus hoax, which exploits a genuine 'In Case of Emergency' campaign, has risen several places in the chart."

Sophos has made available a free, constantly updated information feed for intranets and websites which means users can always find out about the latest viruses and hoaxes.

Graphics of the above top ten virus chart are available here.

More information about safe computing, including anti-hoax policies.

  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

About Sophos

Sophos enables enterprises all over the world to secure and control their IT infrastructure. Sophos's network access control, endpoint, web and email solutions simplify security to provide integrated defenses against malware, spyware, intrusions, unwanted applications, spam, policy abuse, data leakage and compliance drift. With over 20 years of experience, Sophos protects over 100 million users in nearly 150 countries with its reliably engineered security solutions and services. Recognized for its high level of customer satisfaction and powerful yet easy-to-use solutions, Sophos has received many industry awards, as well as positive reviews and certifications.

Sophos is headquartered in Boston, US and Oxford, UK. More information is available at www.sophos.com