Michal Čihař - What happened on last day of April?

What happened on last day of April?

I just looked on server statistics and I was shocked by amount of spam and viruses rejected during last three days. Is there some new virus for Windows which tries random email addresses on all servers it can reach? I didn't analyse those messages, as they are rejected at RCPT time, because sender tries random addresses which do not work on my server. For now I try to reduce them by blacklisting in iptables, but this doesn't seem to help much as IP addresses change too often.

I think that graph shows best what big change has happened:

Mail graphs

Update: It seems to be new Sober variant causing this mess.