SlideShare a Scribd company logo
1 of 21
Symantec Intelligence Report

    June 2011


Symantec Intelligence              1
New: The Symantec Intelligence Report
The new Symantec Intelligence Report combines the best
research and analysis from Symantec:
• Symantec.cloud MessageLabs Intelligence Report
• Symantec State of Spam & Phishing Report


The Symantec Intelligence Report integrated report provides the
latest analysis of cyber security threats, trends and insights from
the Symantec Intelligence team


The data used to compile the analysis for this combined report
includes data from May and June 2011.

Symantec Intelligence                                                 2
June 2011 Highlights
• Spam – 72.9% in June (a decrease of 2.9 percentage points since May 2011)
• Viruses – One in 300.7 emails in June contained malware (a decrease of 0.12
  percentage points since May 2011)
• Phishing – One in 330.6 emails comprised a phishing attack (a decrease of
  0.05 percentage points since May 2011)
• Malicious Web sites – 5,415 Web sites blocked per day (an increase of 70.8%
  since May 2011)
• 35.1% of all malicious domains blocked were new in June (a decrease of 1.7
  percentage points since May 2011)
• 20.3% of all Web-based malware blocked was new in June (a decrease of 4.3
  percentage points since May 2011)
• Report highlights
    –   Review of Spam-sending botnets in June 2011
    –   Clicking to Watch Videos Leads to Pharmacy Spam
    –   Wiki for Everything, Even for Spam
    –   Phishers Return for Tax Returns
    –   Fake Donations Continue to Haunt Japan
    –   Spam Subject Line Analysis

Symantec Intelligence                                                       3
Spam Rate & Sources




                      4
Trend Showing Fluctuating Global Daily Spam Volume
over Twelve Months




Symantec Intelligence                                5
Proportion of Spam Sent from Botnets Since March 2011




Symantec Intelligence                              6
Top Ten Spam-Sending Botnets (relative volumes)
Since March 2011




Symantec Intelligence                             7
Most Active Spam-Sending Botnets
                                                              Spam
                        % of                                    /bot    estimated
  Botnet                spam         spam/day    spam/min      /min    botnet size   Country of Infection
  Cutwail               16.1%    9,609,745,048   6,673,434        77       800k to   India (10%), Russia (9%), Brazil (8%)
                                                                            1200k
  Xarvester             6.7%     4,002,042,186    2,779,196     455     57k to 86k    United Kingdom (18%), France (13%), Italy
                                                                                     (9%)
  Maazben               3.1%     1,872,408,382    1,300,284      14        520k to    Rep. of Korea (14%), Russia (10%), India
                                                                                     (10%)
                                                                              780k
  Lethic                3.1%     1,824,416,511    1,266,956      45        230k to   Rep. of Korea (25%), Russia (15%),
                                                                                     Ukraine (7%)
                                                                              340k
  Grum                  3.0%     1,801,605,428    1,251,115     140        200k to   Russia (14%), India (14%), Ukraine (8%)
                                                                              290k
  Bagle                 2.7%     1,599,896,533    1,111,039      58        140k to   India (15%), Russia (1%), Argentina (8%)
                                                                              200k
  Fivetoone             2.3%     1,400,401,724     972,501       98    94k to 140k    Vietnam (20%), Brazil (12%), Indonesia
                                                                                     (11%)
  Festi                 1.2%      691,992,804      480,551      166     25k to 37k    India (10%), Vietnam (10%), Brazil (9%)
  Bobax                 0.4%      254,229,254      176,548       24    80k to 120k   Ukraine (27%), India (18%), Russia (18%)
  DarkMailer            0.5%       42,575,225       29,566      351     1k to 1.5k    France (27%), USA (16%), Germany
                                                                                     (13%)
  Other, smaller        0.5%       22,277,510       15,470      321     62k to 95k
  Botnets
  Unnamed Botnets       36.9%   21,962,912,697   15,252,023     196        660k to
                                                                             990k
  Total Botnet Spam     76.6%   45,084,503,302   31,308,683     162
  Non-botnet spam       23.4%    3,411,165,479    2,368,865
  Grand Total                   48,495,668,780   33,677,548



Symantec Intelligence                                                                                                             8
Geographical Distribution of Spam-Sending Botnets

  Country                                     % of Spam


  Korea, Republic of (South Korea)                11.2%
  Russian Federation                              11.1%
  India                                             8.7%
  Ukraine                                           6.1%
  Brazil                                            5.3%
  Vietnam                                           2.9%
  United States                                     2.8%
  United Kingdom                                    2.4%
  Taiwan                                            2.4%
  Romania                                           2.3%




Symantec Intelligence                                      9
Global Spam Categories
  Category Name          June 2011

  Pharmaceutical            40.0%

  Adult/Sex/Dating          19.0%

  Watches/Jewelry           17.5%

  Newsletters               11.5%

  Casino/Gambling            7.0%

  Unknown                    2.5%

  Degrees/Diplomas           1.5%

  Weight Loss                1.0%



Symantec Intelligence                10
Spam Subject Line Analysis
             Total Spam: May 2011 Top Subject    No. of                                                 No. of
    Rank     Lines                               Days     Total Spam: April 2011 Top Subject Lines      Days
      1      Blank Subject line                   31      Re: ru girl                                    24
             Re: Windows 7, Office 2010, Adobe
      2                                           16      Blank Subject line                             30
             CS5 …
      3      im online now                        31      Re: Windows 7, Office 2010, Adobe CS5 …        12
      4      my new pics :)                       31      Save-80%-On-Viagra-Levitra-And-Cialis          14
      5      drop me a line                       31      Express Delivery system notification            7
      6      r u online now?                      31      Re:Hi                                          29
      7      hi darling..                         31      Re: sale wiagrow                                7
                                                          Do you have problem with
                                                          ErectileDysfunction? ViagraCan help you and
      8      new email                            31                                                     16
                                                          make sure it is a unique drug for
                                                          treatingImpotence.
                                                          BuyV!AGRA (SildenafilCitrate) Generic
      9      found you :)                         31      Tablets – Online Drugstore. ViagraCan help     16
                                                          your ErectileDysfunction

                                                          Find Out How You Can Start Making $6487 a
     10      my hot pics :)                       31                                                     19
                                                          Month At HOME



Symantec Intelligence                                                                                            11
Additional Spam Metrics
Spam URL TLD Distribution                             Spam Attack Vectors
                                                      16%
                                          Change
TLD                May         April
                                        (% points)

com              53.4%        55.0%           -1.6    12%

ru               19.2%        10.1%          +9.1

info             14.9%        18.5%           -3.6
                                                      8%
net                5.5%        6.9%           -1.4

 Average Spam Message Size
                                                      4%
                                           Change
 Message Size           May     April
                                         (% points)

 0kb-5kb           62.33%     69.59%          -7.26   0%




                                                                                                         16 May


                                                                                                                  19 May


                                                                                                                            22 May


                                                                                                                                     25 May
                                                            01 May


                                                                     04 May


                                                                              07 May


                                                                                       10 May


                                                                                                13 May




                                                                                                                                              28 May


                                                                                                                                                       31 May
 5kb-10kb          24.23%     16.18%         +8.05

 10kb+             13.44%     14.23%          -0.79
                                                                                   Attachment            NDR               Malware




Symantec Intelligence                                                                                                                                           12
Virus Rate




Symantec Intelligence   13
Most Frequently Blocked Email Malware
  Malware Name                          % Malware

  Exploit/SuspLink-d1f2                     4.85%

  Link-Trojan.Generic.5483393-4cac          2.89%

  W32/NewMalware!836b                       2.41%

  W32/NewMalware!0575                       2.39%

  Exploit/Link-FakeAdobeReader-8069         2.32%

  Trojan.Bredolab!eml-1f08                  1.97%

  Exploit/LinkAliasPostcard-d361            1.52%

  W32/Packed.Generic-7946                   1.46%

  W32/Bredolab.gen!eml                      1.36%

  Exploit/FakeAttach-844a                   1.39%



Symantec Intelligence                               14
Phishing Rate & Sources




                          15
Phishing Website Locations




Symantec Intelligence        16
Tactics of Phishing Distribution




Symantec Intelligence              17
Organizations Spoofed in Phishing Attacks, by Industry
Sector




Symantec Intelligence                                    18
New Malware and Spyware Sites Per Day




Symantec Intelligence                   19
Policy, Malware & Potentially Unwanted Programs




Symantec Intelligence                             20
Most Frequently Blocked Malware at the Endpoint
  Malware Name                                                                                                                                   % Malware

  W32.Ramnit!html                                                                                                                                            9.47%
  W32.Sality.AE                                                                                                                                              8.49%
  Trojan.Bamital                                                                                                                                             8.23%
  W32.Ramnit.B!inf                                                                                                                                           7.59%
  W32.Downadup.B                                                                                                                                             3.76%
  W32.Virut.CF                                                                                                                                               2.70%
  W32.Almanahe.B!inf                                                                                                                                         2.50%
  W32.SillyFDC                                                                                                                                               1.99%
  Trojan.ADH.2                                                                                                                                               1.91%
  Trojan.ADH                                                                                                                                                 1.90%
                                                                                        Generic Detection*                                                   16.9%



                        [1] For further information on these threats, please visit: http://www.symantec.com/business/security_response/landing/threats.jsp




Symantec Intelligence                                                                                                                                                21

More Related Content

Similar to June 2011 Symantec Intelligence Report

2012 July Symantec Intelligence Report
2012 July Symantec Intelligence Report2012 July Symantec Intelligence Report
2012 July Symantec Intelligence ReportSymantec
 
Asia’s social media map and users’ online (june 2010)
Asia’s social media map and users’ online (june 2010)Asia’s social media map and users’ online (june 2010)
Asia’s social media map and users’ online (june 2010)Michael Netzley, Ph.D.
 
Online child victimization: A perspective
Online child victimization: A perspectiveOnline child victimization: A perspective
Online child victimization: A perspectiveMicrosoft Eesti
 
Terza Reunion Alumni Continuity Program ELIS
Terza Reunion Alumni Continuity Program ELIS Terza Reunion Alumni Continuity Program ELIS
Terza Reunion Alumni Continuity Program ELIS alumnielis
 
Bruno Progress Report
Bruno Progress ReportBruno Progress Report
Bruno Progress Reportguest1d18e9
 
Adventures With Social Media [Am Cham Sg No Video]
Adventures With Social Media [Am Cham Sg No Video]Adventures With Social Media [Am Cham Sg No Video]
Adventures With Social Media [Am Cham Sg No Video]Michael Netzley, Ph.D.
 
The State of the Internet - Comscore
The State of the Internet - ComscoreThe State of the Internet - Comscore
The State of the Internet - ComscorePablo Capurro
 
2011 October Symantec Intelligence Report
2011 October Symantec Intelligence Report2011 October Symantec Intelligence Report
2011 October Symantec Intelligence ReportSymantec
 
State of the Domain Naming System - Anand Vora & Ulrich Reatzlaff - Public In...
State of the Domain Naming System - Anand Vora & Ulrich Reatzlaff - Public In...State of the Domain Naming System - Anand Vora & Ulrich Reatzlaff - Public In...
State of the Domain Naming System - Anand Vora & Ulrich Reatzlaff - Public In...ResellerClub
 
The Emergence of Private Equity in Asia
The Emergence of Private Equity in AsiaThe Emergence of Private Equity in Asia
The Emergence of Private Equity in AsiaTuck Seng Low
 
Android data insight report Q2 2011
Android data insight report Q2 2011Android data insight report Q2 2011
Android data insight report Q2 2011Umeng
 
Transforming Public Engagement- Craig Thomler v3.2
Transforming Public Engagement- Craig Thomler v3.2Transforming Public Engagement- Craig Thomler v3.2
Transforming Public Engagement- Craig Thomler v3.2PublicVoice
 
SSP Fall Meeting Mobile Gunter Nov 2011
SSP  Fall Meeting Mobile Gunter Nov 2011SSP  Fall Meeting Mobile Gunter Nov 2011
SSP Fall Meeting Mobile Gunter Nov 2011Darrell W. Gunter
 

Similar to June 2011 Symantec Intelligence Report (20)

2012 July Symantec Intelligence Report
2012 July Symantec Intelligence Report2012 July Symantec Intelligence Report
2012 July Symantec Intelligence Report
 
Asia’s social media map and users’ online (june 2010)
Asia’s social media map and users’ online (june 2010)Asia’s social media map and users’ online (june 2010)
Asia’s social media map and users’ online (june 2010)
 
UBS Ad:Tech 2009
UBS Ad:Tech 2009UBS Ad:Tech 2009
UBS Ad:Tech 2009
 
Online child victimization: A perspective
Online child victimization: A perspectiveOnline child victimization: A perspective
Online child victimization: A perspective
 
Terza Reunion Alumni Continuity Program ELIS
Terza Reunion Alumni Continuity Program ELIS Terza Reunion Alumni Continuity Program ELIS
Terza Reunion Alumni Continuity Program ELIS
 
Bruno Progress Report
Bruno Progress ReportBruno Progress Report
Bruno Progress Report
 
Bruno Progress
Bruno ProgressBruno Progress
Bruno Progress
 
Adventures With Social Media [Am Cham Sg No Video]
Adventures With Social Media [Am Cham Sg No Video]Adventures With Social Media [Am Cham Sg No Video]
Adventures With Social Media [Am Cham Sg No Video]
 
The State of the Internet - Comscore
The State of the Internet - ComscoreThe State of the Internet - Comscore
The State of the Internet - Comscore
 
2011 October Symantec Intelligence Report
2011 October Symantec Intelligence Report2011 October Symantec Intelligence Report
2011 October Symantec Intelligence Report
 
State of the Domain Naming System - Anand Vora & Ulrich Reatzlaff - Public In...
State of the Domain Naming System - Anand Vora & Ulrich Reatzlaff - Public In...State of the Domain Naming System - Anand Vora & Ulrich Reatzlaff - Public In...
State of the Domain Naming System - Anand Vora & Ulrich Reatzlaff - Public In...
 
eTourism in Russia
eTourism in RussiaeTourism in Russia
eTourism in Russia
 
The Emergence of Private Equity in Asia
The Emergence of Private Equity in AsiaThe Emergence of Private Equity in Asia
The Emergence of Private Equity in Asia
 
EU Trade Policy: Looking East
EU Trade Policy: Looking EastEU Trade Policy: Looking East
EU Trade Policy: Looking East
 
Android data insight report Q2 2011
Android data insight report Q2 2011Android data insight report Q2 2011
Android data insight report Q2 2011
 
Real estate
Real estateReal estate
Real estate
 
Pan Asian Challenge
Pan Asian ChallengePan Asian Challenge
Pan Asian Challenge
 
Transforming Public Engagement- Craig Thomler v3.2
Transforming Public Engagement- Craig Thomler v3.2Transforming Public Engagement- Craig Thomler v3.2
Transforming Public Engagement- Craig Thomler v3.2
 
Cs3 p8 dyck listenning to the voices of rural mb
Cs3 p8 dyck listenning to the voices of rural mbCs3 p8 dyck listenning to the voices of rural mb
Cs3 p8 dyck listenning to the voices of rural mb
 
SSP Fall Meeting Mobile Gunter Nov 2011
SSP  Fall Meeting Mobile Gunter Nov 2011SSP  Fall Meeting Mobile Gunter Nov 2011
SSP Fall Meeting Mobile Gunter Nov 2011
 

More from Symantec

Symantec Enterprise Security Products are now part of Broadcom
Symantec Enterprise Security Products are now part of BroadcomSymantec Enterprise Security Products are now part of Broadcom
Symantec Enterprise Security Products are now part of BroadcomSymantec
 
Symantec Webinar | National Cyber Security Awareness Month: Fostering a Secur...
Symantec Webinar | National Cyber Security Awareness Month: Fostering a Secur...Symantec Webinar | National Cyber Security Awareness Month: Fostering a Secur...
Symantec Webinar | National Cyber Security Awareness Month: Fostering a Secur...Symantec
 
Symantec Webinar | National Cyber Security Awareness Month: Protect IT
Symantec Webinar | National Cyber Security Awareness Month: Protect ITSymantec Webinar | National Cyber Security Awareness Month: Protect IT
Symantec Webinar | National Cyber Security Awareness Month: Protect ITSymantec
 
Symantec Webinar | National Cyber Security Awareness Month: Secure IT
Symantec Webinar | National Cyber Security Awareness Month: Secure ITSymantec Webinar | National Cyber Security Awareness Month: Secure IT
Symantec Webinar | National Cyber Security Awareness Month: Secure ITSymantec
 
Symantec Webinar | National Cyber Security Awareness Month - Own IT
Symantec Webinar | National Cyber Security Awareness Month - Own ITSymantec Webinar | National Cyber Security Awareness Month - Own IT
Symantec Webinar | National Cyber Security Awareness Month - Own ITSymantec
 
Symantec Webinar: Preparing for the California Consumer Privacy Act (CCPA)
Symantec Webinar: Preparing for the California Consumer Privacy Act (CCPA)Symantec Webinar: Preparing for the California Consumer Privacy Act (CCPA)
Symantec Webinar: Preparing for the California Consumer Privacy Act (CCPA)Symantec
 
Symantec Webinar | How to Detect Targeted Ransomware with MITRE ATT&CK
Symantec Webinar | How to Detect Targeted Ransomware with MITRE ATT&CKSymantec Webinar | How to Detect Targeted Ransomware with MITRE ATT&CK
Symantec Webinar | How to Detect Targeted Ransomware with MITRE ATT&CKSymantec
 
Symantec Mobile Security Webinar
Symantec Mobile Security WebinarSymantec Mobile Security Webinar
Symantec Mobile Security WebinarSymantec
 
Symantec Webinar Cloud Security Threat Report
Symantec Webinar Cloud Security Threat ReportSymantec Webinar Cloud Security Threat Report
Symantec Webinar Cloud Security Threat ReportSymantec
 
Symantec Cloud Security Threat Report
Symantec Cloud Security Threat ReportSymantec Cloud Security Threat Report
Symantec Cloud Security Threat ReportSymantec
 
Symantec Webinar | Security Analytics Breached! Next Generation Network Foren...
Symantec Webinar | Security Analytics Breached! Next Generation Network Foren...Symantec Webinar | Security Analytics Breached! Next Generation Network Foren...
Symantec Webinar | Security Analytics Breached! Next Generation Network Foren...Symantec
 
Symantec Webinar | Implementing a Zero Trust Framework to Secure Modern Workf...
Symantec Webinar | Implementing a Zero Trust Framework to Secure Modern Workf...Symantec Webinar | Implementing a Zero Trust Framework to Secure Modern Workf...
Symantec Webinar | Implementing a Zero Trust Framework to Secure Modern Workf...Symantec
 
Symantec Webinar | Tips for Successful CASB Projects
Symantec Webinar |  Tips for Successful CASB ProjectsSymantec Webinar |  Tips for Successful CASB Projects
Symantec Webinar | Tips for Successful CASB ProjectsSymantec
 
Symantec Webinar: What Cyber Threats Are Lurking in Your Network?
Symantec Webinar: What Cyber Threats Are Lurking in Your Network?Symantec Webinar: What Cyber Threats Are Lurking in Your Network?
Symantec Webinar: What Cyber Threats Are Lurking in Your Network?Symantec
 
Symantec Webinar: GDPR 1 Year On
Symantec Webinar: GDPR 1 Year OnSymantec Webinar: GDPR 1 Year On
Symantec Webinar: GDPR 1 Year OnSymantec
 
Symantec ISTR 24 Webcast 2019
Symantec ISTR 24 Webcast 2019Symantec ISTR 24 Webcast 2019
Symantec ISTR 24 Webcast 2019Symantec
 
Symantec Best Practices for Cloud Security: Insights from the Front Lines
Symantec Best Practices for Cloud Security: Insights from the Front LinesSymantec Best Practices for Cloud Security: Insights from the Front Lines
Symantec Best Practices for Cloud Security: Insights from the Front LinesSymantec
 
Symantec - The Importance of Building Your Zero Trust Program on a Solid Plat...
Symantec - The Importance of Building Your Zero Trust Program on a Solid Plat...Symantec - The Importance of Building Your Zero Trust Program on a Solid Plat...
Symantec - The Importance of Building Your Zero Trust Program on a Solid Plat...Symantec
 
Symantec Webinar | Redefining Endpoint Security- How to Better Secure the End...
Symantec Webinar | Redefining Endpoint Security- How to Better Secure the End...Symantec Webinar | Redefining Endpoint Security- How to Better Secure the End...
Symantec Webinar | Redefining Endpoint Security- How to Better Secure the End...Symantec
 
Symantec Webinar Using Advanced Detection and MITRE ATT&CK to Cage Fancy Bear
Symantec Webinar Using Advanced Detection and MITRE ATT&CK to Cage Fancy BearSymantec Webinar Using Advanced Detection and MITRE ATT&CK to Cage Fancy Bear
Symantec Webinar Using Advanced Detection and MITRE ATT&CK to Cage Fancy BearSymantec
 

More from Symantec (20)

Symantec Enterprise Security Products are now part of Broadcom
Symantec Enterprise Security Products are now part of BroadcomSymantec Enterprise Security Products are now part of Broadcom
Symantec Enterprise Security Products are now part of Broadcom
 
Symantec Webinar | National Cyber Security Awareness Month: Fostering a Secur...
Symantec Webinar | National Cyber Security Awareness Month: Fostering a Secur...Symantec Webinar | National Cyber Security Awareness Month: Fostering a Secur...
Symantec Webinar | National Cyber Security Awareness Month: Fostering a Secur...
 
Symantec Webinar | National Cyber Security Awareness Month: Protect IT
Symantec Webinar | National Cyber Security Awareness Month: Protect ITSymantec Webinar | National Cyber Security Awareness Month: Protect IT
Symantec Webinar | National Cyber Security Awareness Month: Protect IT
 
Symantec Webinar | National Cyber Security Awareness Month: Secure IT
Symantec Webinar | National Cyber Security Awareness Month: Secure ITSymantec Webinar | National Cyber Security Awareness Month: Secure IT
Symantec Webinar | National Cyber Security Awareness Month: Secure IT
 
Symantec Webinar | National Cyber Security Awareness Month - Own IT
Symantec Webinar | National Cyber Security Awareness Month - Own ITSymantec Webinar | National Cyber Security Awareness Month - Own IT
Symantec Webinar | National Cyber Security Awareness Month - Own IT
 
Symantec Webinar: Preparing for the California Consumer Privacy Act (CCPA)
Symantec Webinar: Preparing for the California Consumer Privacy Act (CCPA)Symantec Webinar: Preparing for the California Consumer Privacy Act (CCPA)
Symantec Webinar: Preparing for the California Consumer Privacy Act (CCPA)
 
Symantec Webinar | How to Detect Targeted Ransomware with MITRE ATT&CK
Symantec Webinar | How to Detect Targeted Ransomware with MITRE ATT&CKSymantec Webinar | How to Detect Targeted Ransomware with MITRE ATT&CK
Symantec Webinar | How to Detect Targeted Ransomware with MITRE ATT&CK
 
Symantec Mobile Security Webinar
Symantec Mobile Security WebinarSymantec Mobile Security Webinar
Symantec Mobile Security Webinar
 
Symantec Webinar Cloud Security Threat Report
Symantec Webinar Cloud Security Threat ReportSymantec Webinar Cloud Security Threat Report
Symantec Webinar Cloud Security Threat Report
 
Symantec Cloud Security Threat Report
Symantec Cloud Security Threat ReportSymantec Cloud Security Threat Report
Symantec Cloud Security Threat Report
 
Symantec Webinar | Security Analytics Breached! Next Generation Network Foren...
Symantec Webinar | Security Analytics Breached! Next Generation Network Foren...Symantec Webinar | Security Analytics Breached! Next Generation Network Foren...
Symantec Webinar | Security Analytics Breached! Next Generation Network Foren...
 
Symantec Webinar | Implementing a Zero Trust Framework to Secure Modern Workf...
Symantec Webinar | Implementing a Zero Trust Framework to Secure Modern Workf...Symantec Webinar | Implementing a Zero Trust Framework to Secure Modern Workf...
Symantec Webinar | Implementing a Zero Trust Framework to Secure Modern Workf...
 
Symantec Webinar | Tips for Successful CASB Projects
Symantec Webinar |  Tips for Successful CASB ProjectsSymantec Webinar |  Tips for Successful CASB Projects
Symantec Webinar | Tips for Successful CASB Projects
 
Symantec Webinar: What Cyber Threats Are Lurking in Your Network?
Symantec Webinar: What Cyber Threats Are Lurking in Your Network?Symantec Webinar: What Cyber Threats Are Lurking in Your Network?
Symantec Webinar: What Cyber Threats Are Lurking in Your Network?
 
Symantec Webinar: GDPR 1 Year On
Symantec Webinar: GDPR 1 Year OnSymantec Webinar: GDPR 1 Year On
Symantec Webinar: GDPR 1 Year On
 
Symantec ISTR 24 Webcast 2019
Symantec ISTR 24 Webcast 2019Symantec ISTR 24 Webcast 2019
Symantec ISTR 24 Webcast 2019
 
Symantec Best Practices for Cloud Security: Insights from the Front Lines
Symantec Best Practices for Cloud Security: Insights from the Front LinesSymantec Best Practices for Cloud Security: Insights from the Front Lines
Symantec Best Practices for Cloud Security: Insights from the Front Lines
 
Symantec - The Importance of Building Your Zero Trust Program on a Solid Plat...
Symantec - The Importance of Building Your Zero Trust Program on a Solid Plat...Symantec - The Importance of Building Your Zero Trust Program on a Solid Plat...
Symantec - The Importance of Building Your Zero Trust Program on a Solid Plat...
 
Symantec Webinar | Redefining Endpoint Security- How to Better Secure the End...
Symantec Webinar | Redefining Endpoint Security- How to Better Secure the End...Symantec Webinar | Redefining Endpoint Security- How to Better Secure the End...
Symantec Webinar | Redefining Endpoint Security- How to Better Secure the End...
 
Symantec Webinar Using Advanced Detection and MITRE ATT&CK to Cage Fancy Bear
Symantec Webinar Using Advanced Detection and MITRE ATT&CK to Cage Fancy BearSymantec Webinar Using Advanced Detection and MITRE ATT&CK to Cage Fancy Bear
Symantec Webinar Using Advanced Detection and MITRE ATT&CK to Cage Fancy Bear
 

Recently uploaded

DevoxxFR 2024 Reproducible Builds with Apache Maven
DevoxxFR 2024 Reproducible Builds with Apache MavenDevoxxFR 2024 Reproducible Builds with Apache Maven
DevoxxFR 2024 Reproducible Builds with Apache MavenHervé Boutemy
 
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptx
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptxMerck Moving Beyond Passwords: FIDO Paris Seminar.pptx
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptxLoriGlavin3
 
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptx
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptxUse of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptx
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptxLoriGlavin3
 
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024BookNet Canada
 
Passkey Providers and Enabling Portability: FIDO Paris Seminar.pptx
Passkey Providers and Enabling Portability: FIDO Paris Seminar.pptxPasskey Providers and Enabling Portability: FIDO Paris Seminar.pptx
Passkey Providers and Enabling Portability: FIDO Paris Seminar.pptxLoriGlavin3
 
SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024Lorenzo Miniero
 
Unleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding ClubUnleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding ClubKalema Edgar
 
Digital Identity is Under Attack: FIDO Paris Seminar.pptx
Digital Identity is Under Attack: FIDO Paris Seminar.pptxDigital Identity is Under Attack: FIDO Paris Seminar.pptx
Digital Identity is Under Attack: FIDO Paris Seminar.pptxLoriGlavin3
 
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024BookNet Canada
 
From Family Reminiscence to Scholarly Archive .
From Family Reminiscence to Scholarly Archive .From Family Reminiscence to Scholarly Archive .
From Family Reminiscence to Scholarly Archive .Alan Dix
 
Scanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL CertsScanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL CertsRizwan Syed
 
What is DBT - The Ultimate Data Build Tool.pdf
What is DBT - The Ultimate Data Build Tool.pdfWhat is DBT - The Ultimate Data Build Tool.pdf
What is DBT - The Ultimate Data Build Tool.pdfMounikaPolabathina
 
Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!Commit University
 
SALESFORCE EDUCATION CLOUD | FEXLE SERVICES
SALESFORCE EDUCATION CLOUD | FEXLE SERVICESSALESFORCE EDUCATION CLOUD | FEXLE SERVICES
SALESFORCE EDUCATION CLOUD | FEXLE SERVICESmohitsingh558521
 
What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024Stephanie Beckett
 
TrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data PrivacyTrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data PrivacyTrustArc
 
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptxThe Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptxLoriGlavin3
 
WordPress Websites for Engineers: Elevate Your Brand
WordPress Websites for Engineers: Elevate Your BrandWordPress Websites for Engineers: Elevate Your Brand
WordPress Websites for Engineers: Elevate Your Brandgvaughan
 
Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 365Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 3652toLead Limited
 
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Mark Simos
 

Recently uploaded (20)

DevoxxFR 2024 Reproducible Builds with Apache Maven
DevoxxFR 2024 Reproducible Builds with Apache MavenDevoxxFR 2024 Reproducible Builds with Apache Maven
DevoxxFR 2024 Reproducible Builds with Apache Maven
 
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptx
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptxMerck Moving Beyond Passwords: FIDO Paris Seminar.pptx
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptx
 
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptx
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptxUse of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptx
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptx
 
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
 
Passkey Providers and Enabling Portability: FIDO Paris Seminar.pptx
Passkey Providers and Enabling Portability: FIDO Paris Seminar.pptxPasskey Providers and Enabling Portability: FIDO Paris Seminar.pptx
Passkey Providers and Enabling Portability: FIDO Paris Seminar.pptx
 
SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024
 
Unleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding ClubUnleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding Club
 
Digital Identity is Under Attack: FIDO Paris Seminar.pptx
Digital Identity is Under Attack: FIDO Paris Seminar.pptxDigital Identity is Under Attack: FIDO Paris Seminar.pptx
Digital Identity is Under Attack: FIDO Paris Seminar.pptx
 
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
 
From Family Reminiscence to Scholarly Archive .
From Family Reminiscence to Scholarly Archive .From Family Reminiscence to Scholarly Archive .
From Family Reminiscence to Scholarly Archive .
 
Scanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL CertsScanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL Certs
 
What is DBT - The Ultimate Data Build Tool.pdf
What is DBT - The Ultimate Data Build Tool.pdfWhat is DBT - The Ultimate Data Build Tool.pdf
What is DBT - The Ultimate Data Build Tool.pdf
 
Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!
 
SALESFORCE EDUCATION CLOUD | FEXLE SERVICES
SALESFORCE EDUCATION CLOUD | FEXLE SERVICESSALESFORCE EDUCATION CLOUD | FEXLE SERVICES
SALESFORCE EDUCATION CLOUD | FEXLE SERVICES
 
What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024
 
TrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data PrivacyTrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data Privacy
 
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptxThe Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
 
WordPress Websites for Engineers: Elevate Your Brand
WordPress Websites for Engineers: Elevate Your BrandWordPress Websites for Engineers: Elevate Your Brand
WordPress Websites for Engineers: Elevate Your Brand
 
Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 365Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 365
 
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
 

June 2011 Symantec Intelligence Report

  • 1. Symantec Intelligence Report June 2011 Symantec Intelligence 1
  • 2. New: The Symantec Intelligence Report The new Symantec Intelligence Report combines the best research and analysis from Symantec: • Symantec.cloud MessageLabs Intelligence Report • Symantec State of Spam & Phishing Report The Symantec Intelligence Report integrated report provides the latest analysis of cyber security threats, trends and insights from the Symantec Intelligence team The data used to compile the analysis for this combined report includes data from May and June 2011. Symantec Intelligence 2
  • 3. June 2011 Highlights • Spam – 72.9% in June (a decrease of 2.9 percentage points since May 2011) • Viruses – One in 300.7 emails in June contained malware (a decrease of 0.12 percentage points since May 2011) • Phishing – One in 330.6 emails comprised a phishing attack (a decrease of 0.05 percentage points since May 2011) • Malicious Web sites – 5,415 Web sites blocked per day (an increase of 70.8% since May 2011) • 35.1% of all malicious domains blocked were new in June (a decrease of 1.7 percentage points since May 2011) • 20.3% of all Web-based malware blocked was new in June (a decrease of 4.3 percentage points since May 2011) • Report highlights – Review of Spam-sending botnets in June 2011 – Clicking to Watch Videos Leads to Pharmacy Spam – Wiki for Everything, Even for Spam – Phishers Return for Tax Returns – Fake Donations Continue to Haunt Japan – Spam Subject Line Analysis Symantec Intelligence 3
  • 4. Spam Rate & Sources 4
  • 5. Trend Showing Fluctuating Global Daily Spam Volume over Twelve Months Symantec Intelligence 5
  • 6. Proportion of Spam Sent from Botnets Since March 2011 Symantec Intelligence 6
  • 7. Top Ten Spam-Sending Botnets (relative volumes) Since March 2011 Symantec Intelligence 7
  • 8. Most Active Spam-Sending Botnets Spam % of /bot estimated Botnet spam spam/day spam/min /min botnet size Country of Infection Cutwail 16.1% 9,609,745,048 6,673,434 77 800k to India (10%), Russia (9%), Brazil (8%) 1200k Xarvester 6.7% 4,002,042,186 2,779,196 455 57k to 86k United Kingdom (18%), France (13%), Italy (9%) Maazben 3.1% 1,872,408,382 1,300,284 14 520k to Rep. of Korea (14%), Russia (10%), India (10%) 780k Lethic 3.1% 1,824,416,511 1,266,956 45 230k to Rep. of Korea (25%), Russia (15%), Ukraine (7%) 340k Grum 3.0% 1,801,605,428 1,251,115 140 200k to Russia (14%), India (14%), Ukraine (8%) 290k Bagle 2.7% 1,599,896,533 1,111,039 58 140k to India (15%), Russia (1%), Argentina (8%) 200k Fivetoone 2.3% 1,400,401,724 972,501 98 94k to 140k Vietnam (20%), Brazil (12%), Indonesia (11%) Festi 1.2% 691,992,804 480,551 166 25k to 37k India (10%), Vietnam (10%), Brazil (9%) Bobax 0.4% 254,229,254 176,548 24 80k to 120k Ukraine (27%), India (18%), Russia (18%) DarkMailer 0.5% 42,575,225 29,566 351 1k to 1.5k France (27%), USA (16%), Germany (13%) Other, smaller 0.5% 22,277,510 15,470 321 62k to 95k Botnets Unnamed Botnets 36.9% 21,962,912,697 15,252,023 196 660k to 990k Total Botnet Spam 76.6% 45,084,503,302 31,308,683 162 Non-botnet spam 23.4% 3,411,165,479 2,368,865 Grand Total 48,495,668,780 33,677,548 Symantec Intelligence 8
  • 9. Geographical Distribution of Spam-Sending Botnets Country % of Spam Korea, Republic of (South Korea) 11.2% Russian Federation 11.1% India 8.7% Ukraine 6.1% Brazil 5.3% Vietnam 2.9% United States 2.8% United Kingdom 2.4% Taiwan 2.4% Romania 2.3% Symantec Intelligence 9
  • 10. Global Spam Categories Category Name June 2011 Pharmaceutical 40.0% Adult/Sex/Dating 19.0% Watches/Jewelry 17.5% Newsletters 11.5% Casino/Gambling 7.0% Unknown 2.5% Degrees/Diplomas 1.5% Weight Loss 1.0% Symantec Intelligence 10
  • 11. Spam Subject Line Analysis Total Spam: May 2011 Top Subject No. of No. of Rank Lines Days Total Spam: April 2011 Top Subject Lines Days 1 Blank Subject line 31 Re: ru girl 24 Re: Windows 7, Office 2010, Adobe 2 16 Blank Subject line 30 CS5 … 3 im online now 31 Re: Windows 7, Office 2010, Adobe CS5 … 12 4 my new pics :) 31 Save-80%-On-Viagra-Levitra-And-Cialis 14 5 drop me a line 31 Express Delivery system notification 7 6 r u online now? 31 Re:Hi 29 7 hi darling.. 31 Re: sale wiagrow 7 Do you have problem with ErectileDysfunction? ViagraCan help you and 8 new email 31 16 make sure it is a unique drug for treatingImpotence. BuyV!AGRA (SildenafilCitrate) Generic 9 found you :) 31 Tablets – Online Drugstore. ViagraCan help 16 your ErectileDysfunction Find Out How You Can Start Making $6487 a 10 my hot pics :) 31 19 Month At HOME Symantec Intelligence 11
  • 12. Additional Spam Metrics Spam URL TLD Distribution Spam Attack Vectors 16% Change TLD May April (% points) com 53.4% 55.0% -1.6 12% ru 19.2% 10.1% +9.1 info 14.9% 18.5% -3.6 8% net 5.5% 6.9% -1.4 Average Spam Message Size 4% Change Message Size May April (% points) 0kb-5kb 62.33% 69.59% -7.26 0% 16 May 19 May 22 May 25 May 01 May 04 May 07 May 10 May 13 May 28 May 31 May 5kb-10kb 24.23% 16.18% +8.05 10kb+ 13.44% 14.23% -0.79 Attachment NDR Malware Symantec Intelligence 12
  • 14. Most Frequently Blocked Email Malware Malware Name % Malware Exploit/SuspLink-d1f2 4.85% Link-Trojan.Generic.5483393-4cac 2.89% W32/NewMalware!836b 2.41% W32/NewMalware!0575 2.39% Exploit/Link-FakeAdobeReader-8069 2.32% Trojan.Bredolab!eml-1f08 1.97% Exploit/LinkAliasPostcard-d361 1.52% W32/Packed.Generic-7946 1.46% W32/Bredolab.gen!eml 1.36% Exploit/FakeAttach-844a 1.39% Symantec Intelligence 14
  • 15. Phishing Rate & Sources 15
  • 17. Tactics of Phishing Distribution Symantec Intelligence 17
  • 18. Organizations Spoofed in Phishing Attacks, by Industry Sector Symantec Intelligence 18
  • 19. New Malware and Spyware Sites Per Day Symantec Intelligence 19
  • 20. Policy, Malware & Potentially Unwanted Programs Symantec Intelligence 20
  • 21. Most Frequently Blocked Malware at the Endpoint Malware Name % Malware W32.Ramnit!html 9.47% W32.Sality.AE 8.49% Trojan.Bamital 8.23% W32.Ramnit.B!inf 7.59% W32.Downadup.B 3.76% W32.Virut.CF 2.70% W32.Almanahe.B!inf 2.50% W32.SillyFDC 1.99% Trojan.ADH.2 1.91% Trojan.ADH 1.90% Generic Detection* 16.9% [1] For further information on these threats, please visit: http://www.symantec.com/business/security_response/landing/threats.jsp Symantec Intelligence 21