Common Tasks

Recent Posts

Community

Email Notifications

Personal Links

Archives

Security Protection - Harry Waldron (CS)

Security Best Practices, Breaking News, & Updates

W32/Bagle.BJ - New variant in-the-wild

This new variant is beginning to spread in the wild

W32/Bagle.BJ - New variant in the wild 
http://vil.nai.com/vil/content/v_131351.htm
http://www.f-secure.com/weblog/#00000450
http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM%5FBAGLE%2EAY
http://securityresponse.symantec.com/avcenter/venc/data/w32.beagle.ay@mm.html

Virus Characteristics:

* contains its own SMTP engine to construct outgoing messages
* harvests email addresses from the victim machine
* the From: address of messages is spoofed
* contains a remote access component (notification is sent to hacker)
* copies itself to folders that have the phrase shar in the name (such as common peer-to-peer applications; KaZaa, Bearshare, Limewire, etc)

EMAIL MESSAGE FORMAT

From : (address is spoofed)

Subject :
* Delivery service mail
* Delivery by mail
* Registration is accepted
* Is delivered mail
* You are made active

Body Text:
* Thanks for use of our software.
* Before use read the help

Attachment: (may be one of the following, with an extension of .exe, .scr, .com, or .cpl)
* wsd01
* viupd02
* siupd02
* guupd02
* zupd02
* upd02
* Jol03