At first glance it may seem that the April Top Twenty is identical to Top Twenties from the past six months or so. Computer virology seems to have frozen in time: the same worms have been in the ratings for a long time already. However, this is only at first glance. Mytob.c, the leader of recent ratings, has a long way to go to achieve the numerical heights achieved by its infamous predecessors, such as Mydoom or Sobig or Klez. Between them, these worms managed to terrorize users for several years running.
Despite the fact the Mytob versions dominate the ratings this month, other well known worms are not giving up the battle for control of our computers.
April 2006 is notable for the fact that we finally see Zafi versions disappear completely. We have been expecting this for several months now: Zafi versions led the ratings at one point and then started moving up and down, occasionally climbing almost back to the top. The long life of this worm, which turned 2 this month, is due to its very interesting replication methods. This worm is a true polyglot. It sends out infected emails in over 15 European languages. Zafi picks the languages using the recipient domain as a guide.
Zafi has Hungarian roots, while Lovgate comes from Asia, possibly South Korea. This old timer appeared at the same time as Mydoom, Bagle, Netsky and Zafi. Unlike Netsky, which is slowly yielding to Mytob, new versions of Lovgate continue to appear in the ratings: in April we see two versions in the top 5. The authors of Lovgate stubbornly continue to churn out new versions, creating more and more classical email worms. In the meantime, the author of NetSky has been arrested and tried, the Bagle authors focus on launching localized outbreaks of Trojans and Mydoom has simply mutated into Mytob. Mytob has visibly gained altitude this month with a total of nine places including number one.
As for the rest of the email ratings, the only other point of interest is that Mytob.y has jumped up 10 places and Mydoom.l has returned. The portion of other malicious code in email traffic has risen slightly from 13.33% to 15.73.
|New||Scano.e, NetSky.af, Mytob.cg|
|Moved up||NetSky NetSky.q, LovGate.ad, Mytob.y, Mytob.t, Mytob.w, Mytob.a|
|Moved down||NetSky.b, Mytob.u, Mytob.q, LovGate.ae, NetSky.y|
|No change||Mytob.c, NetSky.t, LovGate.w|