Welcome to P2PNET.net - The original daily p2p and digital news site. Always First!
Register | Login
RIAA News
Cool Stuff
MPAA News
Games / Consoles
News
Music
Movies
TV
Open Source
Mobiles
Advertising
Product News
P2P
Off Topic
Freedom
Politics
Interviews
Security
DRM
Links
Kids and Kartels
Search: 
Search
 
Web P2PNET   
Search: 
Search
Torrent Site Tracker
TekSavvy
 
Add real-time p2pnet headlines to YOUR site ! Click here to download our newsfeed code

New Bagle worm likes p2p

p2pnet.net News:- Finland’s F-secure has upgraded worm Bagle.AY, which has a marked taste for p2p, to Level 2.

Two variants showed up on Wednesday and yesterday. This variant is polymorphic and arrives in emails with different subjects and attachments, says F-Secure.

The worm contains a backdoor that listens on TCP port 81 and is launched when unsuspecting users open an infected file in an e-mail message – or a shared folder on a p2p network.

If it finds a folder name that contains ’shar’ substring, Bagle.AY copies itself there with these names:

  • 1.exe
  • 2.exe
  • 3.exe
  • 4.exe
  • 5.exe
  • 6.exe
  • 7.exe
  • 8.exe
  • 9.exe
  • 10.exe
  • Ahead Nero 7.exe
  • Windown Longhorn Beta Leak.exe
  • Opera 8 New!.exe
  • XXX hardcore images.exe
  • WinAmp 6 New!.exe
  • WinAmp 5 Pro Keygen Crack Update.exe
  • Adobe Photoshop 9 full.exe
  • Matrix 3 Revolution English Subtitles.exe
  • ACDSee 9.exe

Bagle.AY arrives in email as a packed executable. It can also spread with a prepended Windows Control Panel Applet (CPL) stub.

The backdoor code is encrypted with a password so the author can connect to the computer and execute arbitrary programs and, “Infected computers are reported to the worm’s author by accessing several predefined URLs,” says F-Secure.

Bagle.AY tries to download and execute a file saved as %SystemDir%re_file.exe from list of predefined URLs, says F-Secure, also listing 63 security and antivirus software processes, as well as several other applications, Bagle.AY terminates.

The worm, scheduled to ‘die’ on April 25, 2006, uses several different icons, such as a wedge of cheese, for the attachments it sends.

Something you think we should know about? tips[at]p2pnet.net

===================

See:-
taste for p2pF-Secure Virus Descriptions : Bagle.AY, F-Secure, January 27, 2005

HOME

4 Responses to “New Bagle worm likes p2p”

  1. Reader's Write Says:

    Wonder if the major labels are behind this????????

  2. Reader's Write Says:

    No, it’s obviusly the software indistry! I mean look at the file names. lol

  3. Reader's Write Says:
  4. Reader's Write Says:

Leave a Reply

Please no Spam, flaming (attacking others), trolling, and posting off-topic. Thanks.

    Advertisements
MP3Rocket


Remove Spyware with AntiSpyware for Windows®