archives  If you want an RSS feed try this xml rss V0.91 feed

Monday, November 03, 2003

Virus Mimail-XXX

AV companies, including Trend Micro and Kaspersky Labs are warning of a medium risk virus propogating in the wild. The so called MIMAIL virus appears too have a number of variants all of which affect Win-32/Outlook style mail clients.
ecommnet's practical experience is shown below with two tables; extracts of various live reports from a BorderWare MXtreme email firewall from a customer where the e-mail firewall is on evaluation.

Number of Virus Attacks

Virus NameNum per Week
I-Worm.Mimail.c36
I-Worm.Dumaru.a28
I-Worm.Mimail.txt25
Exploit.IFrame.FileDownload21
I-Worm.Sober20
I-Worm.Mimail.g13
I-Worm.Swen10
I-Worm.Mimail.h3
I-Worm.Tanatos.b3
I-Worm.Tanatos.dam3

Traffic Analysis Report

Mail Filter (acted upon)Num per Week
STA High Spam (Token Analysis)302
STA Low Spam (Token Analysis)63
BULK (DCC Checksum)438
Blackhole List (RBL)216
Brightmail Spam0
Forbidden Attachment16
Virus169
Malformed28
Pattern Filter SPAM0
Pattern Filter Reject3
Attempted Relay, Rejected46
Dropped175
Undeliverable0
Reject on No Reverse DNS0
De-queued by Admin0
Clean or not Scanned6063
Total Messages7519
Percent Blocked19

The report shown covers the last 7 days only, and is ample demonstration of the prevalence of the virus. The fact is that the MXtreme e-mail firewall with the Kaspersky anti virus engine has prevented well over 1000 items of SPAM, and 169 viruses, and almost 300 other undesireable emails in less than a week.
Related Links
BorderWare e-mail firewall MXtreme
MS Outlook Web Access Vulnerabilities

posted by Robert Campbell 8:17 PM


Powered by Blogger Pro™