Test Center ThreatWatch: Oct 10

(URL: )

By Fahmida Y. Rashid, Samara Lynn, ChannelWeb


4:27 PM EDT Fri. Oct. 10, 2008


As the Test Center tweaks its security test bed, there will be some interruptions in spam analysis. Test Center reviewers will be supplementing the Threat Watch with results from various security vendors during this time.

Spam Watch: 10/7-10/9

Yesterday's spam volume receded back closer to normal volumes, with blocked and spam messages making up 83 percent of total mail. Virus activity remained low, as well. The eSoft Threat Center currently reports the threat level is elevated, but not yet high, which has been the case for the past few weeks.

Troj/Agent-HUH has dropped in its volume, but Mal/EncPk-ES worm is still very active. There is still a lot of activity from Germany, Netherlands, and the United Kingdom.

Foreign language spam continues to be one of the more common categories, although there is an increase in Microsoft-related messages as well. There seems very little correlation between the chaotic stock market and spam subject lines at this time.

Attack Watch: 10/10

There's lots of SMTP activity today, in particular, repeated spam attempts once again from host.cash-blaster.com. Other activity has decreased significantly since yesterday. The site www1.pageowners.com was logged as doing a Read and Close against the IIS Server. Pointing that URL to that browser showed us an Apache server home page.

Another attempt to discover a Veritas Backup Exex exploit was made by an IP address tracing back to Brazil.


Copyright 2009 Everything Channel