IronPort Threat Operations Center

The 24x7x365 IronPort Threat Operation Center provides human oversight to ensure speed and accuracy. Experienced analysts use sophisticated tools to verify anomalies and approve automatically generated Outbreak Rules.

What is a Virus Outbreak?

Of the email-based viruses that occur on a daily basis, only few qualify for Virus Outbreak status. For a virus to be classified as an outbreak, it must:

  • be a new virus (or a new variant of an existing known virus),
  • have moderate to significant damage potential,
  • have a widespread distribution, and
  • be an infection that IronPort has seen several instances of, from varied sources.

If any of these occurrences satisfy the above criteria, our Threat Operation Center (TOC) investigates the incident and issues outbreak rules to protect our customers.

Current Virus Outbreak Threat Level

Virus Outbreak Threat Level
Red - Virus Outbreak In Progress
Orange - Virus Outbreak In Last 24 Hours
Green - No Virus Outbreak In Last 24 Hours

 

Virus Outbreaks in the Last 24 Hours (Last Updated: May 22, 2012)

Trojan variant

Virus Outbreak Filters Lead Times

Below are the 20 most recent outbreaks tracked by the IronPort Threat Operations Center and the lead time that IronPort Virus Outbreak Filters provided for each, relative to the signature times of several other anti-virus vendors.

Legend
Zero Hour Detection Post Zero Hour Detection
All times are GMT and in 24 hour format
Virus Name IronPort Sophos McAfee Trend Micro Symantec
Troj/DwnLdr-JYV 05/21/2012 09:41 +0d 10h 14m Not Published Not Published Not Published
Troj/Zbot-BXJ 05/21/2012 09:29 +0d 10h 26m Not Published Not Published +0d 3h 11m
Troj/Dorkbot-BV 05/21/2012 08:23 +0d 3h 27m Not Published +0d 12h 52m +0d 3h 17m
Troj/DwnLdr-JZI 05/21/2012 06:31 +0d 13h 24m Not Published Not Published Not Published
Troj/DwnLdr-JYT 05/20/2012 12:50 +0d 9h 15m Not Published Not Published Not Published
Troj/Agent-WHL 05/20/2012 02:00 +0d 5h 20m Not Published Not Published Not Published
Mal/Generic-L 05/20/2012 00:05 +1d 19h 50m +1d 15h 35m +1d 4h 45m Not Published
Troj/Bredo-XT 05/19/2012 07:11 +0d 11h 54m Not Published Not Published Not Published
Troj/Bancos-BQP 05/18/2012 10:24 +0d 10h 36m Not Published Not Published Not Published
Troj/DwnLdr-JYQ 05/18/2012 09:59 +0d 11h 1m Not Published Not Published Not Published
Troj/Mdrop-EFQ 05/18/2012 08:26 +0d 12h 34m Not Published Not Published +0d 9h 24m
Troj/Rorpian-AR 05/18/2012 08:00 +0d 3h 30m Not Published +0d 19h 0m +0d 9h 50m
Troj/DwnLdr-JYS 05/18/2012 06:51 +0d 14h 9m Not Published Not Published Not Published
Troj/Bredo-XR 05/18/2012 05:54 +0d 5h 36m Not Published Not Published +0d 4h 46m
Troj/Dapato-M 05/18/2012 05:49 +1d 0h 36m Not Published Not Published +0d 4h 51m
W32/VBNA-L 05/18/2012 01:10 +0d 10h 20m Not Published Not Published +0d 16h 40m
Troj/VB-FXF 05/17/2012 23:37 +0d 9h 18m Not Published Not Published Not Published
Troj/Zbot-BXH 05/17/2012 16:26 +0d 7h 54m Not Published Not Published +0d 14h 59m
Troj/Zbot-BXH 05/17/2012 12:35 +0d 11h 45m Not Published Not Published +0d 4h 10m
Troj/Bredo-XS 05/17/2012 10:50 +1d 0h 40m Not Published Not Published +1d 7h 0m

Note: The AV signature times referenced are the first publicly published signature times. If signature time is not available, first publicly published alert time is used. Generic signatures not included.