Virus Top Twenty for March 2004

01 Apr 2004
Virus News

PositionChange in positionNamePercentage by occurrence
1+1I-Worm.Netsky.b (Moodown.b) 52.78%
2-1I-Worm.Mydoom.a12.45%
3newI-Worm.Netsky.d8.98%
4-I-Worm.Mydoom.e 5.45%
5newI-Worm.Netsky.q2.90%
6-3I-Worm.Swen2.37%
7newPSW-Worm2.31%
8newI-Worm.Mydoom.g2.30%
9+6I-Worm.Netsky.c1.65%
10newI-Worm.Bagle.i0.75%
11newI-Worm.Bagle.s0.47%
12newI-Worm.Bagle.j0.45%
13-5I-Worm.Klez.h0.40%
14newI-Worm.Bagle.e0.35%
15newI-Worm.Bagle.g0.35%
16-6I-Worm.Mimail.q0.33%
17newI-Worm.Lentin.v 0.32%
18-11I-Worm.Mimail.a0.31%
19-7I-Worm.Mimail.c0.27%
20newI-Worm.Bagle.c0.25%
other malicious programs*4.56%

March 2004 was an even more virus filled month than February. February's virus Top Twenty contained six new email worms; this figure nearly doubled in March, with 11 new viruses entering the charts.

As predicted, March was the month of the Bagles. Five new versions of Bagle appeared. In seventh place is PSW-Worm, an umbrella identification which includes several versions of Bagle. These differ from other worms in the Bagle family in that they spread in password protected ZIP and RAR archives, and the password is either included in the message or contained in a graphics file. Such an approach is not new, but Bagle exploited it with great success. Incidentally, tricks like this have positively influenced the development of new antivirus technology designed to detect and intercept such sneaky viruses.

Statistics for March show that Netsky.b (also known as Moodown.b) and Mydoom.a have changed places, with Netsky.b now leading the charts. Worms from the Netsky family made a significant impact in March, with four versions appearing in the first 9 positions. Netsky was also the initiator of a virtual war, deleting Mydoom, Bagle and Mimail from machines infected by these viruses: an antivirus virus. This action, together with the rapid propagation of Netsky led to three groups of virus writers writing insults directed at the other groups into the code of their viruses.

Those viruses which have appeared in the Top Twenty before also show interesting results. Naïve or careless users managed to keep Swen, Klez.h and also three worms (a, c and the polymorphic q) from the Mimail family in the ratings. A leader in previous months, Sober.c has disappeared altogether from the charts. However, Kaspersky Lab detected 2 new versions of the worm in March, and it is entirely likely that one of them, Sober.e will make an appearance in the Top Twenty in the future.

Additionally, Sobig.f, last year's overall leader, finally disappeared from the ratings. Sobig.f has been sliding down the charts over the last six months, but this month it finally lost the battle, yielding to the new families of malicious code.

The final new entrant is the latest modification of the Lentin worm, Lentin.v. It was first detected in December 2003, and has quietly made its way into seventeenth place. Lentin.v and Klez.h are two classic email worms, which do not use spam technology or extensive networks of infected machines to replicate. It is interesting to speculate whether this month's chart toppers would have reached their current positions if they had used more traditional methods of propagation.

Other malicious programs made up a significant amount of virus traffic; over 1200 different malicious programes were detected last month.

Summary:

New viruses: 11 in total - Netsky.D, Netsky.Q, PSW-Worm, Mydoom.G, Bagle.S, Bagle.J, Bagle.I, Bagle.E, Bagle.G, Bagle.C, Lentin.V

Moved up: Netsky.B, Netsky.C

Moved down: Mydoom.A, Swen, Klez.H, Mimail.Q, Mimail.A, Mimail.C