Bagle.bb joins war of the worms
Bagle.bb joins war of the worms
R E L A T E D   C O N T E N T
ADVERTISEMENT

New Bagle virus declares cyber war

Mass-mailing worm spreading fast

Robert Jaques, vnunet.com 29 Oct 2004
ADVERTISEMENT

IT security experts have warned that a newly intercepted mutant of the infamous mass-mailing Bagle worm, dubbed Bagle.bb, has begun to spread rapidly across the internet.

Over one million email infections were reported within a few hours of the virus being discovered in the wild on Friday morning. The peak infection rate was between 8am and 9am, when virus infection rates trebled from the hour previously, according to email security company BlackSpider Technologies.

This latest Bagle variant, a mass-mailing worm containing its own SMTP engine, comes packed with PeX with the attachment in the executable of a name, McAfee's Avert antivirus team warned.

Bagle.bb harvests addresses from local files and uses them in the 'From' field to send itself. This produces a message with a spoofed 'From' address. The attachment comes in the form of an executable and opens TCP port 81 for remote access of the user's computer.

According to Avert, users should be very wary and delete any email containing the following:

From: [spoofed address]

Subject:
Re:
Re: Hello
Re: Thank you!
Re: Thanks :)
Re: Hi

Message Body:
:)
:))

Attachment: The attachment is an executable of name:
Price
Joke

After being executed, Bagle.bb copies itself into the Windows System directory (C:\WINNT\SYSTEM32\WINGO.EXE). The following Registry key is added to hook system startup: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\
Run "wingo" = C:\WINNT\SYSTEM32\WINGO.EXE

The following Registry key is also added to store data (within a 'TimeKey' key): HKEY_CURRENT_USER\Software\Params

Bagle.bb also copies itself to folders containing 'shar' in the name, such as common peer-to-peer applications Kazaa, Bearshare, Limewire, etc.

Luis Corrons, head of PandaLabs, said the virus "is here to pick up the cyber war that started a few months ago between several groups of virus creators. This time, it is a malicious code that uses social engineering and can spread extremely rapidly."

See also:

Worm contains backdoor for hacker to execute arbitrary programs  27 Jan 2005
Virus top 10Difficult for newer viruses to compete, reports Sophos  01 Nov 2004
Bagle.BC spreading fastSecurity experts increase threat rating as new variant spreads rapidly  01 Nov 2004
Cyber security mythsCommonly held misconceptions highlight problems  27 Oct 2004
Bagle.aq alertExperts increase risk assessment on Bagle.aq as worm spreads rapidly  10 Aug 2004
Lovgate and Bagle virusesSecurity experts increase risk assessment as latest worms begin to spread  06 Jul 2004
Netsky and Bagle: the saga continues  13 May 2004
SecurityThe latest wave of cyber-crimes and acts of vandalism have demonstrated once again that many systems are still vulnerable to attack.  15 Apr 2004
Take cover - here comes another MyDoom/Netsky/Bagle variant ...  17 Mar 2004
It's cyber-handbags at dawn as worm authors turn on each other  03 Mar 2004
Risk assessment of newly discovered virus raised to medium  18 Feb 2004

All Enterprise Security Technology

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| Aston Carter
Senior C# Agile Web Developer, Online Gaming, London My Client provides adult customers with high quality gambling and gaming services in an environment that is convenient, entertaining, fair, regulated and secure. My Client is one ... more >
| Aston Carter
EMC, NetApps, West London, Media • NetApps FAS ... more >
| Abraxas
Data Analyst / MI Analyst – Leading Online Gaming Company A Data Analyst / Trafficker is sought by a leading online gaming company. The role encompasses all aspects of online advertising including data handling, communicating ... more >
| JAM Recruitment
Field Applications Engineer Power Electronics/Supplies Europe/Based Surrey Permanent Position £35-45k Basic+Bonus 10-15%+Car/Car allowance A global organisation involved with the design and development of power supplies actively requires a Field Applications Engineer to strengthen it existing ... more >
More job opportunities