Newsletter:

Skip Navigation LinksHome > News > Security > Storm Worm crashes February malware charts

Storm Worm crashes February malware charts

By Matt Chapman
5 March 2007 08:12AM
Tags: storm | worm | crashes | february | malware | charts

Malware disguises itself to look like harmless code.

An email worm disguising itself as a news message about the February storms in Europe topped the malware charts for February.

Storm Worm made up 50.3 per cent of all malware tracked by Sophos, making it the number one threat seen by the security company. 

Meanwhile, Fortinet ranked it as the fourth worst threat in February in a table that included phishing attacks. 

Fortinet detected W32/Tibs.gen, which is also called Mal/HckPk-A, Worm.Win32.Zhelatin.j, Tibs Trojan, WORM_NUWAR.CQ and Storm Worm, in 3.91 per cent of emails containing a threat.

"HckPk is a bit like Mr Potato Head in that it uses disguises to bamboozle antivirus protection into thinking the attachment is safe when, in reality, malicious code lies within," said Carole Theriault, senior security consultant at Sophos.

"Users need to check that their antivirus protection can proactively detect against previously unseen malware, otherwise they could be next in a long line of victims."

Theriault said that today's most widespread threats, such as Dref and Dorf, use HckPk and that cyber-criminals are constantly modifying its disguises in an attempt to bypass defences.

Guillaume Lovet, EMEA threat response team leader at Fortinet, added that at least 36 different variants of the Storm Worm were active in February, although a single variant accounted for almost 60 per cent of detections.

"The overwhelming presence of the Storm Worm is not without consequence, as it is being used to generate and relay massive amounts of spam," he said.

In February, Sophos found that 0.39 per cent or one in 256 emails were infected and the company identified 7,757 new threats.

Copyright © 2008 vnunet.com

   


Ads by Google


Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 


Tripwire - Click here to win an iTouch



Product Reviews

Star Rating
The Lieberman Software Enterprise Random Pass­word Manager is a full-on password manager and randomiser for...
Star Rating
Proginet SecurForce is a little bit of a horse of a different color for this month's Group Test.
Star Rating
On the surface, RoboForm Enterprise starts out looking like a single sign-on product, but that is just on the...
Star Rating
The Symark PowerBroker is a policy-driven, privileged access control application.
Star Rating
The Symark PowerKeeper is a hardened appliance. It comes with a sealed operating system that provides a...
iTnews 2009 Job Survey

TopTopics
(6825) -  top
(3292) -  microsoft
(2305) -  broadband
(2170) -  content
(2132) -  company
(2129) -  data
(1915) -  terria
(1859) -  isp
(1813) -  nbn
(1725) -  filtering
(1697) -  telstra
(1585) -  internode
(1542) -  voip
(1445) -  centre
(1212) -  consumers