Symantec.com > Business > Security Response

Security Response

Our security research centers around the world provide unparalleled analysis of and protection from malware, security risks, vulnerabilities, and spam.
90 Day Global Threats, Risks, and Vulnerabilities Timeline
90 Day Global Threats, Risks, and Vulnerabilities Timeline
90 day view of discovered Threats, Security Risks and announced Vulnerabilities brought to you by the DeepSight Threat Management System
RiskThreatVulnerability
90 Day Attack Trends By Region
90 Day Attack Trends By Region
90 day attack trends by region information brought to you by the DeepSight Threat Management System.
Australia Africa N. America Europe S. America Asia
365 Day Global Spam Percentage
365 Day Global Spam Percentage
365 day view of the percentage of total global email volume that is spam. Brought to you by Symantec’s Brightmail operations.
Most Active New Threats
Most Active New Threats
Newly discovered threats that Symantec has blocked from customer machines.
Subscribe
NameTypeLast UpdatedDiscovered
Suspicious.Cloud.5Trojan Virus01/09/201001/09/2010
Suspicious.Cloud.5.DTrojan Virus01/09/201001/09/2010
Trojan.Zbot!gen10Trojan Virus31/08/201031/08/2010
W32.Sality!drTrojan01/09/201031/08/2010
Bloodhound.Exploit.353Trojan Virus30/08/201030/08/2010
Bloodhound.Java.3Trojan Virus28/08/201030/08/2010
W32.Pilleuz!gen10Worm27/08/201027/08/2010
Boot.TidservTrojan26/08/201026/08/2010
Backdoor.Tidserv.LTrojan25/08/201025/08/2010
Trojan.Bamital!gen1Trojan24/08/201024/08/2010
Threat Spotlight: W32.Waledac

W32.Waledac is a worm that spreads through email, drive-by downloads, and sometimes comes bundled with other threats. The worm joins a robust botnet, where it is usually used to send spam, reroute traffic, or download other risks on to the compromised computer.

Even though the primary purpose of the worm is profit-motivated, it also contains the ability to download plug-in modules, further expanding its functionality.

More information on W32.Waledac is available in the threat family writeup.

Best Practices for Symantec Endpoint Protection customers
With the rapid rise in the number of malware attacks it’s harder than ever to prevent machines from getting infected. But have you done everything you can do? Have you done the things you must do to stay protected? Following some simple best practices can make a tremendous difference in improving your protection. Symantec has assembled a set of best practices for today’s threat landscape.

Use these recommendations to know what you must, should and can do to protect your endpoints from malware.

Want to go further and really beef up protection on your endpoint machines? Symantec Endpoint Protection has a feature called Application and Device Control that gives you additional tools to protect your endpoints. Find out about Application and Device Control and download rulesets especially created by Symantec to increase your protection. Information available here.
White Paper Spotlight : Pay-Per-Install
Malware was once written mainly for fame and notoriety. However, it has now become a very profitable enterprise, backed by strong business modes. The pay-per-install distribution model is based on revenue sharing and commission. Malware authors do not have the resources or bandwidth to spread their malware on a large scale. Instead they rely on a network of affiliates, who distribute the malware, and in return get paid a commission for every install.

Download the full ‘Pay-Per-Install: The New Malware Distribution Network’ white paper.

View the full set of Symantec Security Response white papers.
Internet Security Threat Report
The Symantec Internet Security Threat Report provides an annual overview and detailed analysis of Internet threat activity, malicious code, and known vulnerabilities. The report also discusses trends in phishing, spam and observed activities on underground economy servers.

The latest report highlights that: malicious activity continues to be pushed to emerging countries; targeted attacks on enterprises are increasing, with Web-based attacks continuing to be a favored attack vector; readily available malicious code kits are making it simple for neophyte attackers to mount attacks; and the online underground economy and malicious activity are benefiting from the downturn in the global economy.

For a review of the threat landscape in 2009, download your copy of Internet Security Threat Report XV.
For quarterly reports about what’s happening in 2010 visit the Symantec Intelligence Quarterly.
Threat Intelligence Twitter Feed
Subscribe

Views and updates from the Symantec Threat Intelligence (Security Response) team on all things security.
http://twitter.com/
threatintel
Symantec video shows the evolution of search engine poisoning http://bit.ly/cuv5yo yesterday
Facebook scam alert: If you are forced to "like" something before being allowed to see it, it's probably a scam - don't be fooled. yesterday
Apple QuickTime "_marshaled_punk" Vulnerability - Symantec protection - AV Bloodhound.Exploit.354 & IPS HTTP Apple QT RTSP Content Type BO 08-31-2010 1:38 PM
Facebook scam alert: Free iPad and iPhone 4 offer for being a tester is a scam - don't be fooled 08-30-2010 1:23 AM
If the boot record fits... How Tidserv installs itself on both 32-bit and 64-bit systems - http://bit.ly/bymxkz 08-27-2010 10:22 PM
New fake Facebook survey says it wants your opinion, but it’s really after your identity. http://bit.ly/ccAGqP 08-27-2010 10:04 PM
Latest Posts from Security Response Blogs
Subscribe

Evolution of SEO Poisoning

Andrea Lelli @ Wed, 1 Sep 2010 06:24:18
In previous blogs we have discussed how malware can exploit a search engine’s ...

Catching Flies with Honey

Gavin O Gorman @ Mon, 30 Aug 2010 09:17:16
Symantec often utilizes honeypots to acquire new samples and observe attacks ...

Tidserv’s Boot Methods

Piotr Krysiuk @ Fri, 27 Aug 2010 16:58:11
In this blog we continue our analysis of the recently discovered Tidserv ...

Fake Survey Seeking Opinions on Social Networking Features

Samir Patil @ Fri, 27 Aug 2010 16:40:47
Symantec has observed a new spam tactic being used in which fake surveys ...

Tidserv 64-bit Goes Into Hiding

Symantec Security Response @ Thu, 26 Aug 2010 13:29:18
Backdoor.Tidserv first came to light in back in 2008 as a Trojan that uses ...

The Language Spammers: Spam Trick Innovators

Vivian Ho @ Tue, 24 Aug 2010 15:59:45
Language spammers are quick to adapt all English spam tricks. We often see ...

Vulnerabilities
Vulnerabilities
A Vulnerability is a state in a computing system (or set of systems) which either (a) allows an attacker to execute commands as another user, (b) allows an attacker to access data that is contrary to the specified access restrictions for that data, (c) allows an attacker to pose as another entity, or (d) allows an attacker to conduct a denial of service.
Subscribe

Stay Secure

Definitions FeedSubscribe

Get the latest virus definitions status

Multiple Daily Updates Learn More

  • Symantec Endpoint Protection 11
  • Norton AntiVirus 2008 and newer
Virus Definitions created 31/08/10
Virus Definitions released 01/09/10
Defs Version: 120901ba
Sequence Number: 114554
Extended Version: 31/08/10 rev. 53
Total Detections (Threats & Risks): 8322103

Daily Updates Learn More

  • Symantec AntiVirus
  • Norton AntiVirus 2006/2007
Virus Definitions created 01/09/10
Virus Definitions released 01/09/10
Defs Version: 120902d
Sequence Number: 114563
Extended Version: 01/09/10 rev. 4
Total Detections (Threats & Risks): 8325705

Weekly Updates Learn More

Virus Definitions released 31/08/10

Symantec Endpoint Protection Security Updates Learn More

Proactive Threat Protection: 31/08/10 rev. 17
Network Threat Protection: 29/08/10 rev. 1
Norton AntiVirus for Mac Virus Definitions released 01/09/10
Symantec AntiVirus for Handhelds Virus Definitions released 24/08/10

Certified Intelligent Updater

The Intelligent Updater virus definitions are fully tested and certified by Quality Assurance. Intelligent Updater is an alternate delivery method for certified definitions, which consists of an executable file that can be downloaded and run manually.

ThreatCon

Level 1: Normal

Level 1: Normal

Learn more about threat levels
Stay Secure
Virus Definitions

Definitions FeedSubscribe

Get the latest virus definitions status

Intelligent Updater

Using the Intelligent Updater to update virus definition files. Read article

Submissions
Threat Sample
Submit a suspect file for analysis
Submit Sample Threat
Dispute Submission
Submit a Malware or Phishing False Positive report, or dispute a Security Risk classification or Download Insight rating
Submit Dispute
Software White-List Request
Proactively reduce the risk of false positives on your software
Submit White-List Request
Prevent Information Loss and Theft: Let Symantec help protect your business.  Shop Now