Current Blackworm numbers

Given all the noise that this issue has caused on the list, I
thought I'd take a moment this afternoon and forward a URL that
good folks over at LURHQ have made available with more realistic,
and current, statistics on the BlackWorm cruft:

http://www.lurhq.com/blackworm-stats.html

Thanks to Joe Stewart at LURHQ.

Cheers,

- ferg

Fergie wrote:

Given all the noise that this issue has caused on the list, I
thought I'd take a moment this afternoon and forward a URL that
good folks over at LURHQ have made available with more realistic,
and current, statistics on the BlackWorm cruft:

http://www.lurhq.com/blackworm-stats.html

Thanks to Joe Stewart at LURHQ.

Indeed! Joe Stewart (at LURHQ) and his work are both amazing.

He took the information we at the TISF BlackWorm task force got from RCN (.com/.net - I have never seen a more whitehat ISP in my life) with the FBI's help, and spent days working on the worm and the data, de-duping, removing the hosts trying to poison the logs data or DDoS, etc.

He deserves the credit!

There are so many other people working day and night on this:

The incredible Johannes Ullrich at SANS ISC and tireless Prof. Randy Vaughn at Baylor EDU, as well as many others...

Many from the net-ops community.
The SANS handlers (ALL OF THEM), who are always there when called.

The FBI, US-CERT, DoD-CERT, REN-ISAC, KrCERT, FortiNet, MessageLabs... ... .. and many many others around the globe who still work on this and invest a ton of effort. They deserve the credit.

Like Joe wrote:
"Even so, 300,000 infected users worldwide is not a terribly large amount when compared to previous worms like Sober or Mydoom. However, with this worm it isn't the quantity of infected users, it is the destructive payload which is most concerning."

  Gadi.

Vmyths used to be a great source for debunking a lot of the virus
hype. Everything old seems to be new again. In 1999, the Chernobyl
virus was the end of the world. It erased disks and BIOS of computers.

http://news.bbc.co.uk/2/hi/science/nature/329688.stm

Sean Donelan wrote:

"Even so, 300,000 infected users worldwide is not a terribly large
amount when compared to previous worms like Sober or Mydoom. However,
with this worm it isn't the quantity of infected users, it is the
destructive payload which is most concerning."

Vmyths used to be a great source for debunking a lot of the virus
hype. Everything old seems to be new again. In 1999, the Chernobyl
virus was the end of the world. It erased disks and BIOS of computers.

BBC News | Sci/Tech | Chernobyl virus causes Asian meltdown

I would quote Dr. Alan Solomon here, but I have to ask for his permission. You have the right of it.

Back then though, they had no way of knowing how many got infected, further -- this was down-played by AV vendors until they had no other choice, for it shows once again how the AV is not an all-powerful solution for everything anymore.

  Gadi.