Common Tasks

Recent Posts

Community

Email Notifications

Personal Links

Archives

Security Protection - Harry Waldron (CS)

Security Best Practices, Breaking News, & Updates

Bagle.DW - Disguised as Software Cracking program

This new downloader version of Bagle pretends to be a software cracking program, but it attempts to download malicious content from the Internet.

Bagle.DW - Disguised as Software Cracking program
http://vil.nai.com/vil/content/v_138710.htm
http://securityresponse.symantec.com/avcenter/venc/data/w32.beagle.dv.html

W32/Bagle.dw is a trojan downloader that attempts to download and execute files from various compromised websites. As the website being communicated is normally controlled by the malware author, any files being downloaded can be remotely modified and the behavior of these new binaries altered - possibly with every user infection.

At the time of writing this description, McAfee AVERT did not see the downloading of any files as they may have been moved or deleted at the remote site. W32/Bagle.dw that was mass spammed on February 25th, 2006.