Common Tasks

Recent Posts

Community

Email Notifications

Personal Links

Archives

Security Protection - Harry Waldron (CS)

Security Best Practices, Breaking News, & Updates

Bagle-KL: Uses Peoples Names in Subject and ZIP attachments

 This new variant is spreading and I've received copies in my personal email.  Avoid all ZIP attachments unless you are certain they are safe.

Bagle-KL: Uses Peoples Names in Subject and ZIP attachments
http://vil.nai.com/vil/content/v_139997.htm
http://secunia.com/virus_information/30068/bagle.fb/
http://secunia.com/virus_information/30087/bagle.fn/
http://secunia.com/virus_information/30073/bagle-km/
http://secunia.com/virus_information/30087/bagle.fn/

This new variant has the following characteristics:

* contains its own SMTP engine to construct outgoing messages
* harvests email addresses from the victim machine
* the From: address of messages is spoofed
* attachment is a password-protected zip file
* password for Zip Archieve included with message
* disables security protection
* drops a rootkit