IronPort Threat Operations Center
The 24x7x365 IronPort Threat Operation Center provides human oversight to ensure speed and accuracy. Experienced analysts use sophisticated tools to verify anomalies and approve automatically generated Outbreak Rules.
What is a Virus Outbreak?
Of the email-based viruses that occur on a daily basis, only few qualify for Virus Outbreak status. For a virus to be classified as an outbreak, it must:
- be a new virus (or a new variant of an existing known virus),
- have moderate to significant damage potential,
- have a widespread distribution, and
- be an infection that IronPort has seen several instances of, from varied sources.
If any of these occurrences satisfy the above criteria, our Threat Operation Center (TOC) investigates the incident and issues outbreak rules to protect our customers.
Current Virus Outbreak Threat Level
|
Virus Outbreaks in the Last 24 Hours (Last Updated: March 17, 2010)
|
Virus Outbreak Filters Lead Times
Below are the 20 most recent outbreaks tracked by the IronPort Threat Operations Center and the lead time that IronPort Virus Outbreak Filters provided for each, relative to the signature times of several other anti-virus vendors.
| Legend | |
|---|---|
| Zero Hour Detection | Post Zero Hour Detection |
| All times are GMT and in 24 hour format | |
| Virus Name | IronPort | Sophos | McAfee | Trend Micro | Symantec |
|---|---|---|---|---|---|
| Troj/FakeAV-AZZ | 03/15/2010 10:42 | +0d 1h 29m | Not Published | Not Published | +0d 7h 59m |
| Troj/FakeAV-AZQ | 03/11/2010 13:37 | +0d 2h 52m | Not Published | +0d 13h 52m | Not Published |
| Troj/DwnLdr-ICD | 03/10/2010 04:05 | +1d 3h 23m | Not Published | +2d 0h 37m | +0d 1h 17m |
| Troj/DNSChan-MW | 03/09/2010 14:55 | +2d 7h 45m | Not Published | Not Published | Not Published |
| Troj/FakeAV-AYP | 03/04/2010 13:08 | +0d 16h 58m | Not Published | Not Published | Not Published |
| Troj/Hosts-L | 03/01/2010 12:51 | +0d 21h 20m | Not Published | Not Published | Not Published |
| Troj/FakeAV-AXQ | 02/26/2010 15:24 | +0d 19h 7m | Not Published | Not Published | Not Published |
| Troj/Banker-EWN | 02/26/2010 15:04 | +1d 0h 0m | Not Published | Not Published | Not Published |
| Troj/Oficla-G | 02/26/2010 03:35 | +0d 2h 13m | Not Published | Not Published | +0d 3h 5m |
| Mal/Spy-G | 02/25/2010 15:50 | +0d 5h 43m | +0d 22h 0m | +0d 21h 35m | +0d 3h 21m |
| Troj/Bredo-BL | 02/25/2010 12:30 | +0d 6h 27m | Not Published | +0d 14h 53m | +0d 1h 48m |
| Troj/Bredo-BK | 02/25/2010 06:30 | +0d 1h 56m | Not Published | Not Published | +0d 11h 16m |
| Troj/Hosts-K | 02/24/2010 00:16 | +0d 7h 12m | Not Published | Not Published | Not Published |
| Troj/PDFJs-HN | 02/23/2010 05:54 | +2d 6h 13m | Not Published | Not Published | Not Published |
| Mal/PDFEx-H | 02/23/2010 05:08 | +2d 13h 49m | Not Published | Not Published | Not Published |
| Mal/Generic-A | 02/22/2010 12:46 | +0d 8h 38m | Not Published | Not Published | Not Published |
| Troj/Bredo-BE | 02/22/2010 05:39 | +0d 2h 56m | Not Published | +0d 8h 42m | Not Published |
| Troj/Bredo-BI | 02/19/2010 19:07 | +0d 0h 5m | Not Published | Not Published | +0d 0h 25m |
| Troj/Bank-AD | 02/18/2010 06:48 | +0d 5h 57m | Not Published | Not Published | Not Published |
| Mal/FakeAV-BW | 02/09/2010 14:55 | +0d 4h 26m | Not Published | +2d 12h 24m | +0d 2h 12m |
Note: The AV signature times referenced are the first publicly published signature times. If signature time is not available, first publicly published alert time is used. Generic signatures not included.
