« Other Blogs | Main | Modeling Botnet Propagation Using Time Zones »

The Nyxem Email Virus: Analysis and Inferences

This came out this morning. The amazing finding: 45k of the half million computers (up to about 10%) had other malware easily identifiable on them. Looks like some people can't help but pick up all sorts of crud.
While email viruses and worms are a ubiquitous part of the online environment, Nyxem was relatively rare in that newly infected hosts connect once to a single website, providing a single source of information about the infected population.

Of more critical interest to those infected, the virus also contained a malicious payload designed to overwrite files with certain extensions on the 3rd of every month (beginning February 3, 2006). Affected file types include: .doc, .xls, .mdb, .mde, .ppt, .pps, .zip, .rar, .pdf, .psd, and .dmp.

We estimate that between 469,507 and 946,835 computers in more than 200 countries were infected by the Nyxem virus between January 15 23:40:54 UTC 2006 and Wednesday February 1 05:00:12 UTC. At least 45,401 of the infected computers were also compromised by other forms of spyware or bot software.

Source: The Nyxem Email Virus: Analysis and Inferences, an analysis by David Moore (dmoore@caida.org) and Colleen Shannon (cshannon@caida.org) of the spread of the Nyxem (or Blackworm or Kama Sutra or MyWife or CME 24) Virus in January and early February 2006.

February 6, 2006 in mass mailers, papers | Permalink
Tell others: digg submit | del.icio.us this | Reddit

Comments

I totally agree with this comment, thanks for sharing, have a nice day!!

Posted by: Generic Viagra | Sep 21, 2009 11:21:43 AM

Interesting post about The Nyxem Email Virus: Analysis and Inferences!!!

Have a nice day!

Posted by: Men Relationships | Sep 24, 2009 1:49:32 PM

Hello folks
We estimate that between 469,507 and 946,835 computers in more than 200 countries were infected by the Nyxem virus between January 15 23:40:54 UTC 2006 can you believe this numbers
John B. Barnhart

Posted by: Generic Viagra | Sep 25, 2009 7:14:22 PM

Hmmm..that is one nasty virus...basically..looking at the types of file extensions it deletes (doc, .xls, .mdb, .mde, .ppt, .pps, .zip, .rar, .pdf, .psd, and .dmp) I would say it pretty much deletes 80%-90% of all files on each PC it gets on...

Posted by: Alessandro | Dec 11, 2009 8:47:48 AM

Hi guys I totally agree with this comment, thanks for sharing, have a nice day!!

Posted by: Generic Cialis | Jan 15, 2010 7:40:03 PM

Hey, my buddy was asking me about this a few days ago, I'm gonna pass this page onto him to see what he thinks.

-Phil

Posted by: How to Lose Weight | Feb 28, 2010 7:48:28 AM

Hi! I read your post about "The Nyxem Email Virus: Analysis and Inferences" and found it really interesting. Thanks!

Posted by: Online pharmacy | Mar 18, 2010 7:50:14 AM

Oh hell!!! You are just too cool man. I never knew that there could be something better to know about than from this piece of article. I shall have this forwarded to all my friends and even my dad, I am sure they too shall enjoy reading this piece.

Posted by: viagra online prescription | Nov 10, 2011 4:45:59 AM

What a great post! Just one suggestion:If you add some pics, it would be easiler to follow! I like the cartoon type logo! From what I have a playful spirit!

Posted by: kamagra online | Nov 10, 2011 4:47:12 AM

I just came by your article and it get my attention. i thought I'd leave my first comment just to appreciate the hard work you done.

Posted by: generic viagra | Nov 10, 2011 4:48:47 AM

The comments to this entry are closed.