Sophos

Talk to our experts

Find your local press contact

Resources

Info feeds

What are info feeds?

1 August 2007

Drive-by downloads remain cybercriminals' favorite web threats Sophos announces top ten web and email-borne threats for July 2007

Sophos, a world leader in IT security and control, has revealed the most prevalent malware threats causing problems for computer users around the world during July 2007.

The figures, compiled by Sophos's global network of monitoring stations, show a significant rise in the prevalence of the Mal/ObfJS family of web threats - up from just 1.8 percent last month to 17.3 percent this month. Despite this growth, Mal/ObjJS has not been able to dislodge Mal/Iframe from its number one position, accounting for more than half of all web threats seen by Sophos.

Top ten web threats

The top ten list of web-based malware threats in July 2007 reads as follows:

Position Malware Percentage of reports
1Mal/Iframe
   56.0%
2Mal/ObfJS
   17.3%
3Troj/Psyme
   10.4%
4Troj/Decdec
   3.5%
5Troj/Fujif
   1.9%
6Mal/Zlob
   1.1%
7VBS/Edibara
   0.9%
8Mal/Packer
   0.8%
9=Mal/Behav
   0.4%
9=VBS/Redlof
   0.4%
Others7.3%

Experts at SophosLabs™ note that the prominence of both threats in the top ten emphasises the popularity of the drive-by download technique with cybercriminals, as well as continued growth in the use of obfuscated Javascripts in compromising sites.

"The security dangers of the web still aren't fully registering with a great many businesses - this is providing rich pickings for hackers hell-bent on gaining access to sensitive information," said Carole Theriault, senior security consultant at Sophos. "It's no surprise to see legitimate webpages targeted for these attacks - businesses generally aren't too strict about stopping their employees accessing these websites, while the sites themselves will already have their own daily flow of user traffic, saving hackers the trouble of trying to entice unenlightened web surfers."

Top malware-hosting countries

The top ten list of countries hosting malware-infected webpages in July 2007, reads as follows:

Position Country Percentage of reports
1China (inc. Hong Kong)
   49.8%
2United States
   21.8%
3Russia
   14.7%
4Ukraine
   3.2%
5Germany
   1.2%
6Brazil
   1.0%
7=United Kingdom
   0.8%
7=Taiwan
   0.8%
8=Canada
   0.6%
8=Poland
   0.6%
Others5.5%

China has again retained its position as the primary nation responsible for hosting malware-infected webpages. Interestingly, the number of pages hosted by Russia has increased substantially since June 2007, where it stood at just 3.5 percent. This can be explained by the large number of Mal/Iframe and Mal/ObfJS-infected webpages in Russia that have been compromised to serve as drive-by sites.

"Last month Italy made the top ten - now it has disappeared and Russia is the main nation on the rise," continued Theriault. "It's important for countries to recognise that hackers don't have preferred locations for malware-hosting. They'll target any vulnerable web hosts that they can find, irrespective of country, meaning that no nation is immune to the threat. The only way for businesses to mitigate against the danger is by deploying up-to-date security solutions and ensuring that internet users don't jeopardise their networks through irresponsible online behavior."

Top ten email threats

The top ten list of email-based malware threats in July 2007 reads as follows:

Position Last
month
Malware Percentage of reports
11W32/Netsky
   27.2%
22W32/Mytob
   18.3%
36W32/Zafi
   12.4%
43Mal/Iframe
   9.8%
54W32/MyDoom
   5.6%
65W32/Sality
   4.1%
7NewTroj/Agent
   3.8%
8=6W32/Bagle
   3.4%
8=Re-entryMal/Clagger
   3.4%
10NewW32/Strati
   1.7%
Others10.3%

A graphic of the top ten email-based malware chart is available.

A week ago, Sophos published its Security Threat Report July 2007, examining the latest trends in malware, spam and cybercrime.

Top ten hoaxes and chain letters for July 2007

Position Hoax Percentage of reports
1Hotmail hoax
   34.7%
2Olympic torch
   6.6%
3A virtual card for you
   3.9%
4Meninas da Playboy
   2.8%
5Bonsai kitten
   2.3%
6Bill Gates fortune
   2.1%
7Music Top 50
   1.7%
8MSN is closing down
   1.6%
9Budweiser frogs screensaver
   1.4%
10Justice for Jamie
   1.3%
Others41.6%

Sophos experts have compiled simple best practice guides to adopting a multi-layered defense. With blended threats, spam and phishing attacks on the rise it has never been more important to educate end users about how best to protect themselves.

About Sophos

Sophos enables enterprises all over the world to secure and control their IT infrastructure. Sophos's network access control, endpoint, web and email solutions simplify security to provide integrated defenses against malware, spyware, intrusions, unwanted applications, spam, policy abuse, data leakage and compliance drift. With over 20 years of experience, Sophos protects over 100 million users in nearly 150 countries with its reliably engineered security solutions and services. Recognized for its high level of customer satisfaction and powerful yet easy-to-use solutions, Sophos has received many industry awards, as well as positive reviews and certifications.

Sophos is headquartered in Boston, US and Oxford, UK. More information is available at www.sophos.com

See also: