BAGLE.AZ - MEDIUM RISK by Secunia and McAfee
BAGLE.AZ - MEDIUM RISK (DAT 4395 RELEASED)
http://secunia.com/virus_information/12352/bagle.az/
http://www.sarc.com/avcenter/venc/data/w32.beagle.ar@mm.html
http://vil.nai.com/vil/content/v_128582.htm
http://www.f-secure.com/v-descs/bagle_as.shtml
This is a mass-mailing worm with the following characteristics:
- contains its own SMTP engine to construct outgoing messages
- harvests email addresses from the victim machine
- the From: address of messages is spoofed
- contains a remote access component
- copies itself to folders that have the phrase shar in the name (such as common peer-to-peer applications; KaZaa, Bearshare, Limewire, etc)
FORMAT OF INFECTED EMAIL MESSAGES
From : (address is spoofed)
Subject :
Re:
Re: Hello
Re: Thank you!
Re: Thanks :)
Re: Hi
Body Text:
:)
:))
Attachment: (with an extension of .exe, .scr, .com or .cpl)
Price
price