Virus production from Russia increases again, says Network Box

1/7/10

Virus production from Russia is on the up again, after a temporary decline last month when Russian hosting service, PROXIEZ-NET – notoriously used by criminal gangs – was taken down in early May.  This is according to analysis of internet threats in June, by managed security company, Network Box.

Russia is now responsible for 7.4 per cent of the world’s malware, and is back to being in the top four virus-producing countries, behind the US (13 per cent), Korea (10.1 per cent) and India (9.2 per cent).

This follows a similar pattern to malware production after the McColo shutdown in the US, in November 2008, when the US’s threat production decreased dramatically temporarily, but was back up to normal levels within a month.

Levels of viruses and spam from the UK remain high. The UK has the dubious honour of being the world’s fourth-largest producer of spam, with 4.1 per cent of spam originating from home shores, the same as last month. This is behind the US (11.1 per cent), India (8.0 per cent) and Brazil (4.2 per cent).

Virus levels from the UK are slightly down from last month (2.9 per cent, down from 5.9 per cent), but this figure results from an increase in production from other countries, notably India (up to 9.2 per cent of viruses from 5.5 per cent last month) and Russia. The US is back at the top spot, overtaking Korea, and is now responsible for 13.6 per cent of the world’s malware (up from 11.6 per cent last month).

Simon Heron, Internet Security Analyst for Network Box, says: "We predicted that Russian malware and spam production would be back up to normal levels this month, and this has proved to be the case. Any efforts to shut down criminal hosting services is to be applauded, it makes life a little harder for those who would prey on others but sadly in the current political climate it doesn’t normally have a long term effect, as the criminals simply go elsewhere."

June threat statistics:

Top 10 sources of viruses

Country Daily Average %
US 13.66681
Korea 10.16695
India 9.27236
Russia 7.44086
Ukraine 3.47102
UK 2.94449
China 2.66920
Brazil 1.95030
Italy 1.76265
Colombia 1.71784

Top 10 sources of spam

Country Daily Average %
US 11.18616
India 8.06602
Brazil 4.27874
UK 4.10843
Russia 4.06244
Germany 3.43837
Korea 3.38516
China 2.96543
Italy 2.87920
France 2.85326

Top 10 viruses

Threat Name Daily Average %
nbh-bbadhdr 10.45143
trojan-downloader.js.pegel.g 8.71642
trojan.js.redirector.dz 5.92738
clm.email.trojan-114 5.25708
trojan-downloader.js.pegel.bc 5.23349
nbh-multext 5.16276
spam.virus.nb_virus_goog_zip 4.77317
spam.porn.spam_nb_porn_subj_csk_1 4.28543
spam.virus.nb_spam_cat_virus_malware 3.00029
nbh-bscript 2.75905

Top 10 Trojans

Threat Name Daily Average %
trojan.js.redirector.dz 0.18868
trojan-downloader.js.pegel.g 0.18142
clm.email.trojan-114 0.03961
trojan-downloader.js.pegel.bc 0.03910
trojan.win32.tdss.bemg 0.02367
trojan.win32.tdss.bhjg 0.01795
trojan.win32.tdss.belr 0.00897
trojan.win32.agent.eihj 0.00781
trojan.win32.oficla.bf 0.00683
trojan.win32.oficla.bb 0.00565

Top 10 intrusions

Threat Name Daily Average %
NETBIOS 37.41794
BOGON 7.80680
PINGFLOOD 1.44071
HTTP-S-WEBDAV 0.41195
SOBIG-F 0.07229
ICMP 0.04319
HTTP-S-WEBDEX 0.02051
HTTP-S-UNIXATTACK 0.01214
HTTP-S-NIMDA 0.00444
HTTP-S-IISATTACK 0.00287

Top Ten Firewall blocks by Port

Protocol / Port Daily Average %
TCP:80 16.65413
UDP:137 9.57126
TCP:8080 6.53132
UDP:123 4.17522
UDP:53 3.70315
TCP:443 2.84564
UDP:138 2.79298
UDP:161 2.18610
TCP:25 2.16044
UDP:80 2.15646

For more information on security issues, see www.network-box.co.uk, or visit Simon Heron’s blog at: http://blog.network-box.co.uk/, or follow Simon on Twitter: http://twitter.com/networkbox.

Back