On The Insider: Britney's Bikini-Clad Top 10
BNET Business Network:
BNET
TechRepublic
ZDNet

By David Becker
Posted on ZDNet News: Aug 9, 2004 8:47:00 PM

A prolific new variant of the mass-mailing Bagle worm began flooding e-mail accounts Monday with bogus price quotes.

Like previous versions of Bagle, the new Bagle.AQ worm spreads by sending out messages with an infected attachment compressed under the common Zip format. Both the name of the attachment and the body of the message are a variant on "price" or "new price."

Unlike earlier Bagles, the new version also packs in a 3-year-old piece of JavaScript code that, once executed, attempts to send the infected PC to various Web sites to pick up more Bagle code, said Vincent Gullotto, vice president of the antivirus emergency response team for security specialist McAfee.

Bagle.AQ started spreading Monday morning and quickly began bombarding some corporate e-mail systems with thousands of infected messages, Gullotto said.

"It made its way into the public eye in a rather grandiose fashion," he said.

Gullotto attributed the worm's fast start to use of the old JavaScript trick and initial distribution that included an unusually large number of e-mail addresses to target. "Someone has used a rather spamlike technique to get it going," he said.

Those same techniques should also ensure a relatively brief heyday for the worm, as e-mail security systems learn to block the variant, Gullotto said. "I don't expect it'll last more than 24 hours," he said. "Then it's onto the next pest."

The initial Bagle virus emerged early this year and appeared to be a fairly standard mass-mailing worm. But the pest has gone on to spawn dozens of variations, thanks partly to an apparent feud between the Bagle coder and the creator of the rival Netsky worm.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 28 Talkback(s)
He, He, Trolled yourself. . .
If you could comprehend my inverted humor, you might have figured out by reading the next sentence that they were smart enough to learn how to rename file extensions. And it works well enough to filter out the garbage.... (Read the rest)
Posted by: boomslang_z Posted on: 08/11/04 You are currently: a Guest | | Terms of Use
How to secure email  alterego_z | 08/09/04
Two other ways ...  George Jay | 08/09/04
So do you have passenger pigeons in the back of your PCs also?  itanalyst | 08/10/04
Sucks worse to have your network infected. . .  boomslang_z | 08/10/04
Give the end user a break  ibabadur1 | 08/10/04
Something special about computers.  Anton Philidor | 08/10/04
He, He, Trolled yourself. . .  boomslang_z | 08/11/04
This is not NEWS!!!  tamuhockey | 08/10/04
So, your company fired you, eh?  boomslang_z | 08/10/04
hardly  tamuhockey | 08/10/04
Oh, that VPN thing. . .  boomslang_z | 08/10/04
Encouraging open discussion, eh(?)  Anton Philidor | 08/10/04
babysitting  tamuhockey | 08/10/04
Waiting for the day...  Anton Philidor | 08/10/04
please  tamuhockey | 08/10/04
Better to read your mind than your prose...  Anton Philidor | 08/10/04
I will apologize Anton  tamuhockey | 08/10/04
Apology accepted, of course.  Anton Philidor | 08/10/04
You and your CEO are both fools.  bhanes@... | 08/10/04
maybe  tamuhockey | 08/10/04
All hail the rocket scientist  ibabadur1 | 08/10/04
reading for comprehension  tamuhockey | 08/10/04
Good Luck  ibabadur1 | 08/10/04
maybe so  tamuhockey | 08/10/04
Here is a thought  bhanes@... | 08/10/04
not very productive is it?  tamuhockey | 08/10/04
Good thing SP2 protects me from #^@#%&#$&$#$  Xunil_Sierutuf | 08/10/04
I know what you mean  tamuhockey | 08/10/04

What do you think?

advertisement
Click Here
advertisement
Click Here

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here