Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

New Bagle Variant Sweeps the Internet
www.newsfactor.com ^ | 11 minutes ago | Erika Morphy,

Posted on 08/10/2004 12:24:20 PM PDT by BenLurkin

Antivirus companies are sounding the alarm about a new variant from the long-lived Bagle virus family: On Monday, Bagle.AM, also known as "Bagle.AQ" and "Bagle.AC," began spreading rapidly and infecting users.

Top-Grade Tech

The best gadgets to help students through the year, from new phones to gizmos for locking down your stuff.

Due to the high number of incidences, antivirus firms are ranking this new virus on the higher end of the threat spectrum.

Mass-Mailing Threat

Bagle.AQ is a mass-mailing threat that contains its own SMTP engine to construct outgoing messages, according to McAfee AVERT (Anti-virus and Vulnerability Emergency Response Team). The virus mass mails itself to addresses harvested from local files. It produces a message with a spoofed "From" address and contains a remote-access component -- with the notification sent to the hacker. It then copies itself to folders that have "shar" in the name, typically found in P2P applications, such as Kazaa, Bearshare and LimeWire.

The worm sends out a ZIP file that contains an HTML file. On vulnerable systems, it automatically runs an EXE file that is a downloader Trojan. The downloader Trojan then contacts a large number of remote Web sites to retrieve the virus itself.

"Users should be very wary and should most likely delete any e-mail containing "From : (address is spoofed); Subject : (blank); Body Text: * new price," McAfee said.

The virus also has been successful in shutting down various security processes, Panda Software CTO Patrick Hinojosa told NewsFactor. "That is why it was able to spread so quickly. It had a chance to really jumpstart infections."

The virus was already at the top of the list of 20 most-detected viruses this month, Hinojosa said.

Suspicious Timing

So far it does not appear as though the worm was designed to initiate a denial of service attack against a company. "It was obviously a launched worm," Hinojosa says, "aimed at individual machines."

The timing is a little suspect, though, considering the ire most hackers have towards Microsoft (Nasdaq: MSFT - news). "Microsoft came out with its new security service pack on the same day, so I am assuming this was done to take a shot at Microsoft," Hinojosa says.


TOPICS: Business/Economy; Miscellaneous; News/Current Events; Technical
KEYWORDS:

1 posted on 08/10/2004 12:24:20 PM PDT by BenLurkin
[ Post Reply | Private Reply | View Replies]

To: BenLurkin

I suspect the timing.


2 posted on 08/10/2004 12:24:50 PM PDT by Kornev
[ Post Reply | Private Reply | To 1 | View Replies]

To: BenLurkin

I love bagels.


3 posted on 08/10/2004 12:28:19 PM PDT by annyokie (Now with 20% More Infidel!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: BenLurkin
According to SANS: the virus downloads part of itself from a list of known websites. Blocking the following site at your perimeter can mitigate the risk of this virus

http://polobeer.de/2.jpg

http://www.no-abi2003.de/2.jpg

For home users, blackhole these sites in your hosts file, and the virus won't be able to connect to them.

4 posted on 08/10/2004 12:29:58 PM PDT by tacticalogic ( Controlled application of force is the sincerest form of communication.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: annyokie

If they sent it in tandem with a 'cream cheese' variant, it wouldn't seem so dastardly.


5 posted on 08/10/2004 12:33:23 PM PDT by mlbford2 (In TX, orange alert means releasing the safety on your shotgun)
[ Post Reply | Private Reply | To 3 | View Replies]

To: Kornev

You saw that . . .


6 posted on 08/10/2004 12:34:09 PM PDT by BenLurkin ("A republic, if we can revive it")
[ Post Reply | Private Reply | To 2 | View Replies]

To: annyokie

...with smear!


7 posted on 08/10/2004 12:34:18 PM PDT by Young Werther
[ Post Reply | Private Reply | To 3 | View Replies]

To: BenLurkin

Symantic Norton Antivirus failed to clean it out (at least yesterday it did).

MccAfee's Stinger did the trick!


8 posted on 08/10/2004 12:34:18 PM PDT by 1stFreedom (What are your thoughts? (Please spare the condescending "get over it" comments.))
[ Post Reply | Private Reply | To 1 | View Replies]

To: BenLurkin
I use Trend Micro virus checking program. Last week, they issued an update definitions list. It contained 1985 new definitions. That is the largest single update I can remember.

It does appear that some time of cyber attack is in the works.

I do remember the summer of 2001 also having a rash of viruses. I got 3 different ones that summer and ended up having to reformat and reload my pc each time.
9 posted on 08/10/2004 12:35:03 PM PDT by TomGuy (After 20 years in the Senate, all Kerry has to run on is 4 months of service in Viet Nam.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: TomGuy

I wonder, when XP SP2 comes out.. Would it be better to use it or to use Trend Micro's firewall?

I already have a hardware router with firewall on, but I'd want to use a software one too just in case. Apparently the SP2's is kinda slick, like Zonealarm.. Asks if it's ok for programs to access the net and all.


10 posted on 08/10/2004 12:42:58 PM PDT by Kornev
[ Post Reply | Private Reply | To 9 | View Replies]

To: BenLurkin
Bagle.AM, also known as "Bagle.AQ" and "Bagle.AC," began spreading rapidly and infecting users.

Lox of luck

11 posted on 08/10/2004 12:51:47 PM PDT by NautiNurse ("I served in Viet Nam, and we have better hair"----John F'n Kerry campaign platform)
[ Post Reply | Private Reply | To 1 | View Replies]

To: 1stFreedom

For those running email servers, I recommend GFI Mail Security. It caught it even before the new virus definitions were uploaded. Protects the whole company.


12 posted on 08/10/2004 12:56:02 PM PDT by js1138 (In a minute there is time, for decisions and revisions which a minute will reverse. J Forbes Kerry)
[ Post Reply | Private Reply | To 8 | View Replies]

To: tacticalogic
Thanks for the info, could I ask a simple question, should I write
127.0.0.1 http://polobeer.de/
OR
127.0.0.1 polobeer.de
in the Hosts file? Or something else, I'm not quite sure, I d/l an adblocking hosts file, never looked into this too much.
13 posted on 08/10/2004 12:57:49 PM PDT by JerseyHighlander
[ Post Reply | Private Reply | To 4 | View Replies]

To: BenLurkin
I could be wrong. But it seems to me that any attempt to read or write to a disk sector, or to read or write through a communication port, has to at some point go through the OS; particularly Windows which years ago promoted itself on the basis of reducing everything to drivers and channels.

Why can't Windows catch or challenge a process instance at that point? It might add overhead, sure. But processors are fast, and the recently approved instances could be stacked for quick reference in each session. Part of the challenge for communication might simply to be to see if the address is 'spoofed'. But much else could also be checked.

Of course, part of reason that many suggest for other OS being more stable is that Windows is so popular. So the bomb makers who create these things want to break Windows, not any competitor. I still see no reason why that 'price of success' prevents M$ for doing something suggested above.

14 posted on 08/10/2004 1:08:36 PM PDT by sevry
[ Post Reply | Private Reply | To 1 | View Replies]

To: BenLurkin

Between the Bagle and Spam, I should never feel hungry again!


15 posted on 08/10/2004 1:10:29 PM PDT by Egon (A students end up teaching. B students end up working for C students.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: NautiNurse
Lox of luck

Now, that was truly "nauti"!

16 posted on 08/10/2004 1:13:01 PM PDT by Not A Snowbird (Official RKBA Landscaper and Arborist, Duchess of Green Leafy Things)
[ Post Reply | Private Reply | To 11 | View Replies]

To: JerseyHighlander
127.0.0.1 polobeer.de

The http:// just specifies what protocol you want to connect with. It doesn't have anything to do with the host address.

17 posted on 08/10/2004 1:13:32 PM PDT by tacticalogic ( Controlled application of force is the sincerest form of communication.)
[ Post Reply | Private Reply | To 13 | View Replies]

To: sevry
The reason Linux remains rarely attacked, is not due to popularity (or lack thereof--that's a whole 'nother issue), but for the reason you just gave.

Linux prevents or allows reading/writing to disk based on the user running at that time. Since most people don't run as root most of the time, access to system-level files and directories is usually prohibited.

As a result, virii cannot proliferate as easily in that environment.

18 posted on 08/10/2004 1:15:55 PM PDT by ShadowAce (Linux -- The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 14 | View Replies]

To: Kornev

I use the free version of ZoneAlarm firewall. It works great, except that the last update messed up Forte Agent for downloading yenc zipped files in newsgroups.

I un-installed the ZoneAlarm and went back to the previous version. Forte Agent downloads work again.

[I hate when an upgrade to one thing messes up other things. I am always leary of upgrades and whether they end up doing more damage than good.]

I tested McAfee's firewall once. BIG mistake. Couldn't uninstall all the crap it put on my pc. 2 or 3 months afterward, McAfee was still trying to do auto updates, etc. I ended up having to format and re-install everything to get rid of McAfee.


19 posted on 08/10/2004 1:17:47 PM PDT by TomGuy (After 20 years in the Senate, all Kerry has to run on is 4 months of service in Viet Nam.)
[ Post Reply | Private Reply | To 10 | View Replies]

To: BenLurkin

Thanks again, Microsoft! Couldn't do it without you or your crappy malware!


20 posted on 08/10/2004 1:24:30 PM PDT by Prime Choice (When Clinton lies, he insults our integrity. When Kerry lies, he insults our intelligence.)
[ Post Reply | Private Reply | To 1 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson