Outbreak Name: W32/Mabutu-A

Outbreak Date: 11-17-05

IronPort's Virus Outbreak Filters Protect Customers from Mabutu Outbreak Additional 12 Hours and 26 Minutes Protection

Background

IronPort's Virus Outbreak Filters protects customers within the critical period between the first exploit of a virus outbreak and the release of an AV signature. During the recent Mabutu variant outbreak, W32/Mabutu-A, Outbreak Filters users were protected 12 hours and 26 minutes before an AV signature was available from any of the major AV vendors*. W32/Mabutu-A is an email worm and backdoor Trojan. It sends itself as an attachment to an email with a ZIP or SCR extension. Once W32/Mabutu-A has infected a PC, it attempts to gather personal information and send this information to remote users via an IRC channel.

Timeline

Outbreak Details & Timeline

Date November 17, 2005
Name** W32/Mabutu-A (Mabutu variant)
00:58 GMT Virus Threat Level raised and protection starts
13:24 GMT First anti-virus signature published*

Benefits

12 hours and 26 minutes of additional protection with Virus Outbreak Filters

* Calculated as first published alert time from any of the following vendors: Sophos, Trend Micro, Computer Associates, Kaspersky Labs, Symantec or McAfee.
** As named by Sophos.