W32/Bagle.BJ - New variant in-the-wild
This new variant is beginning to spread in the wild
W32/Bagle.BJ - New variant in the wild
http://vil.nai.com/vil/content/v_131351.htm
http://www.f-secure.com/weblog/#00000450
http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM%5FBAGLE%2EAY
http://securityresponse.symantec.com/avcenter/venc/data/w32.beagle.ay@mm.html
Virus Characteristics:
* contains its own SMTP engine to construct outgoing messages
* harvests email addresses from the victim machine
* the From: address of messages is spoofed
* contains a remote access component (notification is sent to hacker)
* copies itself to folders that have the phrase shar in the name (such as common peer-to-peer applications; KaZaa, Bearshare, Limewire, etc)
EMAIL MESSAGE FORMAT
From : (address is spoofed)
Subject :
* Delivery service mail
* Delivery by mail
* Registration is accepted
* Is delivered mail
* You are made active
Body Text:
* Thanks for use of our software.
* Before use read the help
Attachment: (may be one of the following, with an extension of .exe, .scr, .com, or .cpl)
* wsd01
* viupd02
* siupd02
* guupd02
* zupd02
* upd02
* Jol03