Virus Top Twenty for July 2004

03 Aug 2004
Virus News

PositionChange in positionNamePercentage by occurrence
1no changeI-Worm.Zafi.b57.41%
2no changeI-Worm.Netsky.aa11.71%
3no changeI-Worm.Netsky.b10.72%
4no changeI-Worm.Netsky.q2.94%
5no changeI-Worm.Bagle.z2.34%
6+3I-Worm.Netsky.t2.08%
7no changeI-Worm.Netsky.y1.72%
8-2I-Worm.Netsky.d1.25%
9-1I-Worm.Lovgate.w1.18%
10newI-Worm.Bagle.gen0.75%
11+4I-Worm.Netsky.o0.40%
12newI-Worm.Bagle.ah0.35%
13re-entryI-Worm.Sobig.f0.31%
14newBackdoor.Rbot.gen0.28%
15newI-Worm.Bagle.ai0.27%
16-2I-Worm.Mydoom.g0.26%
17+3I-Worm.Netsky.m0.25%
18-7I-Worm.Netsky.r0.25%
19re-entryI-Worm.Mydoom.e0.24%
20- 8I-Worm.Swen0.24%
Other malicious programs (not in the Top 20)5.07%

Antivirus professionals have long known that viruses come in waves; June, July and December are usually down times. Maybe it's because virus writers are people too - they too take vacations and if they go away, they may even forget to take their computers along.

July 2004 confirms this theory, with very few changes from the June ratings. The top five viruses are identical to the top five in June; only the percentages have changed. Zafi.b is the absolute leader this summer with 57%, this figure making it the second most frequent virus of the year. Only Mydoom.a is ahead of Zafi.b with a recording-breaking almost 80%.

Zafi.b is a paradox - an average worm, with nothing interesting in the code or the social engineering methods used to trick users into opening infected attachments. And yet it has beat many more technologically advanced viruses. Certainly changing the language of the incoming email in accordance with the recipient's country is a novel idea. However this is Zafi.b's only interesting feature. Perhaps Zafi's dominance can be explained by the fact that users have relaxed now that summer is in full swing and are being less cautious about opening attachments.

There are very few new entries to the Top Twenty: Bagle.gen leads the way. Bagle.gen is a catchall for all Bagle variants that propagate as password protected attachments. There are also several new versions of Bagle which were most likely released by copycat coders after Bagle.aa appeared complete with the Bagle source code inside. Bagle.ai and Bagle.ah make a modest first appearance, but we are likely to see more remakes of this particular malicious oldie.

14th place is occupied by Backdoor.Rbot.gen, a catchall for 30 or so similar backdoors. This is worth remarking on as these programs are not the email worms which everyone has become so used to over the past few months. These backdoors use various Windows vulnerabilities to give the sender full control over infected machines. Rbot variants accept commands to send copies of themselves via email, which probably accounts for the appearance of this backdoor in the virus top twenty.

And finally, like the Phoenix rising from the ashes, Sobig.f has not only returned, but even jumped immediately to number 13. This program last made an appearance in the Top Twenty in February this year.

Other malware continued to make up a significant amount of traffic for the third month in a row. In total, over 1000 different viruses were detected in July, over 3 times more than in June.

Summary

New virusesI-Worm.Bagle.ai, Bagle.ah, Bagle.gen
Moved up:Netsky.t, Netsky.o, Netsky.m
Moved downNetsky.d, Lovgate.w, Mydoom.g, Netsky.r, Mydoom.e, Swen
No changeZafi.b, Netsky.aa, Netsky.b, Netsky.q, Bagle.z, Netsky.y
ReturnedSobig.f