The largest knowledge base of Internet threats in the world

MessageLabs knows the enemy. We work around the clock to identify and stop millions of email, web and IM based threats every day before they can reach our customers. Whether its viruses, phishing attacks, malicious web links, spam, trojans, or spyware, we have a hard-earned reputation of stopping known and unknown threats long before the competition. We do this by drawing on the scale of our software as a service (SaaS) delivery model and the intelligence drawn from the billions of messages and web pages we process through our network every day. This intelligence is fed in ‘real time’ to our patented Skeptic technology to form the most comprehensive and up to date knowledge base of Internet threats in the world.


>IM THREAT IMAGES

PSYME

>PSYME
>Trojan Downloader
By simply visiting a legitimate website which had been comprised by Psyme, a user can unknowingly become infected with spyware or some other type of malware, such as a botnet. This sample was downloaded by visiting a website accessed through a hyperlink shared over IM.

CLICKR

>CLICKER
>IM Worm
'Drive-by' attacks over IM cause fast-spreading damage. An IM is sent to all the contacts in the victims' contact lists with a malicious hyperlink contained in the message. When activated, each new victim's contact list will also be spammed with malicious hyperlinks, and so on.

 

>NON-THREAT IMAGES: A VISUAL SYNOPSIS

>DEVELOPING THE ART

FOLLOWING ON FROM THE ORIGINAL MESSAGELABS THREAT ART COLLECTION, NEW ARTWORK WAS COMMISSIONED TO REPRESENT THE MESSAGELABS ARCHIVING, BOUNDARY ENCRYPTION AND EMAIL CONTINUITY SERVICES. EACH SAMPLE OF ANONYMOUS CUSTOMER DATA WAS SELECTED TO SUGGEST VISUAL FORMS THAT BEST REPRESENT THE DATA ELEMENTS.

ALGORITHMS WERE THEN DEVELOPED AND IMPLEMENTED THAT WOULD POSITION EACH COMPONENT OF THE IMAGE BASED ON THE UNDERLYING DATA OF ATTACHMENT SIZE, GEOGRAPHICAL LOCATION OF EMAIL AND EMAIL VOLUME. THE ALGORITHMS WERE THEN RENDERED AS A 3-DIMENSIONAL IMAGE.

archive

>EMAILARCHIVE1

> ANONYMIZED DATA BASED ON 24 HOURS OF DETAILED STATISTICS FROM ONE CLIENT TO DEMONSTRATE TYPICAL USAGE OF ARCHIVING, RETRIEVAL, SEARCH AND RECOVERY TOOLS
> CLIENT: 5 SERVERS ACROSS 4 SITES IN 3 CONTINENTS
> ARCHIVE SIZE: 402.6GB, INCLUDING 11,259,264 EMAILS FROM 1,059 INBOXES
> AVERAGE INBOX SIZE: 389MB WITH 10,632 MESSAGES CONTAINED WITHIN

IN THE IMAGE, EMAILS ARE REPRESENTED BY 3-DIMENSIONAL “VOXELS” WHERE THE DATA SIZE OF THE EMAIL IS PROPORTIONAL TO THE VOLUME OF THE VOXEL. THE SPHERE IS LAYERED WITH THE MOST RECENT ARCHIVED EMAILS STORED NEAR THE SURFACE (BLUE) AND OLDER EMAILS INHERIT BRIGHTER COLORS TOWARD THE CORE (RED). THE 3-DIMENSIONAL FORMS CHANGE VOLUME AND SHAPE BASED ON ATTACHMENT SIZE.

 

encryption

>BOUNDARYENCRYPTION1

> ANONYMIZED SENDER AND RECIPIENT DATA BASED ON A 24-HOUR SNAPSHOT OF  MESSAGELABS BOUNDARY ENCRYPTION SERVICE USE
> OVER 15,000 MESSAGES DELIVERED, OF WHICH 15 PERCENT WERE ENCRYPTED
> DATA: GEOGRAPHIC LOCATION OF COMMUNICATION ENDPOINTS, ENCRYPTION  CIPHER, KEY STRENGTH, ENCRYPTION ENFORCEMENT BASED ON CLIENT POLICY OR  OPPORTUNISTIC, NEGOTIATED AS PART OF THE CONNECTION

DATA ANALYSIS OF EMAIL TRAFFIC TO AND FROM A MESSAGELABS CUSTOMER, INCLUDING THE LONGITUDE AND LATITUDE OF EMAILS SENT AND RECEIVED IN ONE 24-HOUR PERIOD, HAS BEEN MAPPED INTO A 3-DIMENSIONAL SPACE. DATA SIZE IS REPRESENTED AS BRANCH THICKNESS AND EACH COLOR REPRESENTS THE ENCRYPTION STRENGTH APPLIED TO THE EMAIL (GREEN: ENFORCED/STRONG; BLUE: OPPORTUNISTIC/STRONG; YELLOW: WEAK; RED: UNENCRYPTED).

 

continuity

>EMAILCONTINUITY1

> ANONYMIZED DATA BASED ON A THREE-MONTH SNAPSHOT OF REGULAR EMAIL USAGE  FROM A MESSAGELABS EMAIL CONTINUITY SERVICE CUSTOMER WITH NO INTERRUPTION OF SERVICE DURING TIMES WHEN EMAIL WAS DOWN.
> DATA: SENDER AND RECIPIENT DETAILS, HOURLY FREQUENCY OF INBOUND/OUTBOUND EMAIL TRAFFIC WITH NO SERVICE INTERRUPTION

EMAIL FREQUENCY AND VOLUME DATA IS REPRESENTED IN THE IMAGE AS AN UNINTERRUPTED ARC FROM SENDER TO RECIPIENT. THE OBJECTS AROUND THE EDGE REPRESENT EMAIL INBOXES AND THEIR SIZE REPRESENTS THE SIZE OF THE DATA IN AN EMAIL. THE ARCS REPRESENT INTERNAL AND EXTERNAL EMAIL COMMUNICATIONS. THE FADED ARCS ARE OLDER EMAILS WHILE THE BRIGHTEST ARCS ARE MORE RECENT MESSAGES.

 

>ABOUT THE ARTIST

COMPUTATIONAL ARTIST JULIAN HODGSON FIRST BECAME INTERESTED IN THE FIELD OF GRAPHICS PROGRAMMING AFTER DEVELOPING HIS OWN TECHNIQUES TO VISUALLY MODEL COMPLEX MATHEMATICAL EQUATIONS. HE HAS BEEN WORKING IN POST-PRODUCTION FOR EIGHT YEARS AND IS CURRENTLY THE TECHNICAL DIRECTOR FOR AWARD WINNING PASSION PICTURES IN LONDON. JULIAN HAS A DEGREE IN MATHEMATICS FROM BRISTOL UNIVERSITY AND AN MSC FROM LIVERPOOL UNIVERSITY.



>NEW THREAT ART

CUTWAIL >CUTWAIL
>INSTALLER TROJAN
CUTWAIL also known as PUSHDO and PANDEX, is currently one of the world’s largest botnets controlling more than one million active bots.
CIMUZ >CIMUZ
>INFORMATION-STEALING TROJAN
CIMUZ is an information-stealing Trojan that hooks itself into Internet Explorer. By capturing information entered or saved by the user, including passwords, keystrokes and other confidential information, it transmits the harvested data to its controller. This terminates security software and unlocks firewalls, leaving the computer vulnerable to further attacks.
TODYNHO >TODYNHO
>INFORMATION-STEALING TROJAN
TODYNHO is an information-stealing Trojan originating from Brazil that steals a victim’s bank account details. The name TODYNHO was taken from the name of the email attachment.
HUIGEZI >HUIGEZI
>TARGETED TROJAN
HUIGEZI is a targeted Trojan dropped via a PDF exploit. It spies on audio and video communications, in addition to web, email, IM and others. It is most commonly used for industrial espionage.
TT.PDF >TT.PDF
>TARGETED TROJAN
TT.PDF is a PDF attached to an email which doesn’t contain any real content. If opened a message is displayed stating that the document is damaged and is being repaired. The document viewer may then crash as malicious code is written to disk and then executed. The first thing it then does is to display another PDF with the expected content in order to cover its tracks.
TT.DOC >TT.DOC
>TARGETED TROJAN
TT.DOC is document used to conceal a targeted trojan. It arrives in an email claiming to contain a report about security issues for the Beijing Olympics and was sent to a small number of businesses and sporting bodies involved with the Olympic Games.
Viruses

>A COMPUTER VIRUS IS A FORM OF MALWARE. SOME VIRUS CODES ATTACH THEMSELVES TO A PROGRAM IN THE HOST COMPUTER. VIRUSES THAT CAN RUN INDEPENDENTLY ARE KNOWN AS WORMS. A VIRUS IS EITHER DESIGNED TO COMPROMISE ITS HOST OR TO SELF-REPLICATE TO INFECT OTHER COMPUTERS.

Netsky Virut Parite / Netsky




Spam

>SPAM IS AN UNSOLICITED EMAIL. SPAMMERS SEND OUT MILLIONS OF IDENTICAL EMAILS, USUALLY FOR FINANCIAL GAIN. SPAM HAS BECOME INCREASINGLY SOPHISTICATED IN ORDER TO AVOID DETECTION, WITH AN INCREASE IN THE USE OF MALICIOUS LINKS, PDF, XLS AND MP3 SPAM.

Russian3 Degreesdiplomas Scamfraud4198




Phishing Attacks

>PHISHING IS A SPAMMING TECHNIQUE USED TO TRICK VICTIMS INTO REVEALING CONFIDENTIAL INFORMATION SUCH AS BANK DETAILS AND PASSWORDS. CYBER-CRIMINALS MIMIC EMAILS FROM REPUTABLE COMPANIES TO LURE VICTIMS TO SPOOF WEBSITES WHERE THEY ARE ASKED TO INPUT THEIR PERSONAL DETAILS.

Phishing1 Phishing2 Phishing9




Spyware

>SPYWARE IS AN APPLICATION WHICH SENDS THE VICTIM’S PRIVATE INFORMATION AND WEB SURFING HABITS TO A CYBER-CRIMINAL’S WEBSITE. SPYWARE OFTEN INSTALLS ITSELF WITHOUT THE USER’S KNOWLEDGE OR EXPLICIT PERMISSION.

Rogueware Spysherif Ghost




Malicious Links

>A MALICIOUS LINK IS A HYPERTEXT LINK THAT SENDS THE USER TO A WEBSITE. THE SITE THEN INFECTS THE VICTIM’S COMPUTER WITH MALWARE. USING WEB LINKS IS A COMMON TECHNIQUE BECAUSE IT AVOIDS THE USE OF MALICIOUS CODE WITHIN THE EMAIL.

Postcard Storm




Trojans

>UNLIKE VIRUSES, TROJANS ARE SELF-CONTAINED PROGRAMS WHICH RUN INDEPENDENTLY. AS THE NAME SUGGESTS, TROJANS ARE DISGUISED TO BE MORE DESTRUCTIVE THAN THEY FIRST SEEM. THEY CAN CONCEAL MALICIOUS PAYLOADS WHICH DOWNLOAD CONFIDENTIAL INFORMATION FOR CYBER-CRIMINALS.

Pwslineage Trojagentil3