Welcome to p2pnet.net - The original daily p2p and digital news site. Always First!
REGISTER | LOGIN
Cool Stuff
MPAA News
Games / Consoles
News
Music
Movies
Reviews
Open Source
Mobiles
Advertising
Products
P2P
Off Topic
Freedom
Politics
Interviews
Security
DRM
Links
Kids and Kartels
Scroogle Search: 
Search
 
Web p2pnet   
Search: 
Search
Torrent Site Tracker
    Sponsored by
Frostwire
 
p2pnet
 


mp3rocket
 
Add real-time p2pnet headlines to YOUR site ! Click here to download our newsfeed code

Today is Bagle Day

p2pnet.net News:- If you’re an e-worm watcher, you might be coming across Bagle variants with “quite interesting icons”.

That’s the view of F-Secure’s Alexey who says on the site blog that three new Bagle variations have already turned up today.

“One of the variants was found on a website that was accessed by another Bagle variant,” says the post. “This is most likely a test variant because it gets e-mails from C:EMAILS folder rather then from files on a hard disk (like ITW variants do). We have not seen any reports about this variant from the field. This variant was originally detected by us as W32/Bagle.AU@mm, but we are going to change detection name to W32/Bagle.AV@mm to avoid confusion with another widespread Bagle variant that appeared today (see below).

“The second variant of Bagle that appeared today is Bagle.AT. This variant is number 1 in our Virus Statistics.

“The third variant of Bagle appeared shortly after the second one and got the name Bagle.AU. This variant has the same functionality as Bagle.AT, but it uses a different CPL stub and it has a 2-byte corruption area in its text resources. This variant is currently number 12 in our Virus Statistics.”

But the most interesting aspect of these new Bagle variants is: they modify themselves before spreading, says Alexey.

“They search for applications on a hard disk and ‘borrow’ their icons. Then these icons are attached to Bagle’s files together with some garbage data (used as a decoy) and then these files are mailed out.”

=================

See:-
Alexey – We call it Bagle day, F-Secure, October 29, 2004

HOME

2 Responses to “Today is Bagle Day”

  1. Reader's Write Says:

    We call it Bagle day Posted by Alexey @ 15:39 GMT

    you’re going blind :)

  2. Reader's Write Says:

    You’re right. (ahem, blush)

    But Katrin DID post the item on the third new Bagle. (cough, cough)

    Anyhow, I’ve fixed it ; p

    Cheers!

Leave a Reply

ONLY items referencing the post at hand, please. No links to personal sites, no personal attacks, trolling, freebie advertising, or off-topic posts. Thanks. And Cheers!

    Sponsored by
tek savvy