PDA

View Full Version : Heads up! New Bagle downloader virus on the loose..


Mntsnow
05-31-2005, 12:31 PM
New Bagle Downloader spreading like wildfire via email - 45,769 copies intercepted in last hour at MessageLabs Anti Virus.

May 31, 2005 - Be on guard against a new variant of the Bagle downloader. MessageLabs has intercepted almost 70,000 copies already. The first copy was intercepted today at 13:24 GMT (14:24 BIT). 45,769 copies have been stopped in the last hour. The virus appears to have originated from a Yahoo group.

The as yet unnamed Bagle downloader variant drops a trojan that attempts to download Bagle from a vast list of locations. Computer users who activate the file attached in the email invoke the virus, which harvests email addresses it finds on the computer's hard drive. The virus then forwards itself onto the list of email addresses it has discovered in infected computer.

mickwish
05-31-2005, 9:24 PM
Hmm, not much detail on thjis one yet. How it works
This most recent Bagle downloader variant drops a trojan that attempts to download itself from a vast list of locations. Computer users who have been successfully tricked into activating the file attached invoke the virus, which harvests email addresses it finds on the hard drive. The virus then forwards itself onto the list of email addresses it has discovered in the infected computer.

Email characteristics:
Subject lines: <Empty>
Body Text: <Empty>


Damage
Once activated, the Bagle downloader variant drops a copy of an executable file onto infected computers, which in turn polls a vast list of URLs for the availability of a new mass-mailing component.

From MessageLabs press release (http://www.messagelabs.com/news/pressreleases/detail/default.asp?contentItemId=1417&region=).

McAffee (http://vil.nai.com/vil/content/v_129512.htm) has a bit more detail: There was another round of mass-spamming, of several new Bagle downloaders over the past few hours. Those messages contain a ZIP attachment. The ZIP file contains an executable (36532 bytes), such as:

16_05_2005.exe
19_04_2005.exe
20_04_2005.exe
01_05_2005.exe
02_05_2005.exe
03_05_2005.exe
Golden Rule: never open ANY unsolicited attachments, and keep your antivirus apps upto date. ;)

Cheers
Mick