IronPort Threat Operations Center

The 24x7x365 IronPort Threat Operation Center provides human oversight to ensure speed and accuracy. Experienced analysts use sophisticated tools to verify anomalies and approve automatically generated Outbreak Rules.

What is a Virus Outbreak?

Of the email-based viruses that occur on a daily basis, only few qualify for Virus Outbreak status. For a virus to be classified as an outbreak, it must:

  • be a new virus (or a new variant of an existing known virus),
  • have moderate to significant damage potential,
  • have a widespread distribution, and
  • be an infection that IronPort has seen several instances of, from varied sources.

If any of these occurrences satisfy the above criteria, our Threat Operation Center (TOC) investigates the incident and issues outbreak rules to protect our customers.

Current Virus Outbreak Threat Level

Virus Outbreak Threat Level
Red - Virus Outbreak In Progress
Orange - Virus Outbreak In Last 24 Hours
Green - No Virus Outbreak In Last 24 Hours

 

Virus Outbreaks in the Last 24 Hours (Last Updated: February 9, 2012)

Trojan variant
Trojan variant
Trojan variant
Trojan variant
Trojan variant
Trojan variant
Trojan variant
Trojan variant
Trojan variant

Virus Outbreak Filters Lead Times

Below are the 20 most recent outbreaks tracked by the IronPort Threat Operations Center and the lead time that IronPort Virus Outbreak Filters provided for each, relative to the signature times of several other anti-virus vendors.

Legend
Zero Hour Detection Post Zero Hour Detection
All times are GMT and in 24 hour format
Virus Name IronPort Sophos McAfee Trend Micro Symantec
Troj/Bredo-RE 02/08/2012 00:23 +0d 3h 47m Not Published Not Published +0d 4h 52m
Troj/Bredo-RD 02/07/2012 23:29 +0d 4h 41m Not Published Not Published +0d 16h 51m
Troj/Bredo-RD 02/07/2012 22:24 +0d 5h 46m Not Published Not Published Not Published
Troj/Bredo-RD 02/07/2012 17:24 +0d 10h 46m +0d 23h 41m Not Published Not Published
Mal/EncPk-ZC 02/07/2012 15:59 +0d 12h 11m Not Published Not Published Not Published
Troj/Zbot-BKT 02/07/2012 14:40 +0d 3h 15m Not Published Not Published Not Published
W32/Gamarue-L 02/07/2012 13:23 +0d 9h 27m Not Published Not Published Not Published
Troj/DwnLdr-JRA 02/07/2012 12:18 +0d 10h 32m Not Published Not Published Not Published
Troj/Bredo-RB 02/07/2012 10:23 +0d 8h 27m Not Published +0d 6h 27m +0d 8h 37m
Mal/Zbot-EZ 02/07/2012 00:27 +0d 22h 23m Not Published Not Published +0d 8h 48m
Mal/Agent-AGB 02/06/2012 22:54 +0d 2h 6m Not Published Not Published +0d 6h 51m
Troj/Bredo-QY 02/06/2012 22:54 +0d 5h 51m Not Published Not Published +0d 1h 51m
Mal/Agent-AGB 02/06/2012 15:05 +0d 9h 55m Not Published Not Published Not Published
Troj/Bredo-QX 02/06/2012 14:43 +0d 6h 52m Not Published +0d 12h 52m +0d 7h 27m
Troj/Bredo-QV 02/06/2012 14:29 +0d 3h 1m Not Published Not Published +0d 1h 41m
Troj/Banker-FKN 02/06/2012 12:17 +0d 5h 13m Not Published Not Published Not Published
Troj/Zbot-BKP 02/06/2012 12:07 +0d 2h 33m Not Published Not Published +0d 12h 8m
Troj/Zbot-BKQ 02/06/2012 10:41 +0d 6h 49m Not Published Not Published +0d 13h 34m
Troj/FakeAV-FCM 02/06/2012 07:35 +0d 9h 55m Not Published Not Published +0d 11h 35m
Mal/FakeAV-PY 02/06/2012 06:25 +0d 5h 25m +0d 10h 40m Not Published Not Published

Note: The AV signature times referenced are the first publicly published signature times. If signature time is not available, first publicly published alert time is used. Generic signatures not included.