Welcome to p2pnet.net - The original daily p2p and digital news site. Always First!
REGISTER | LOGIN
Cool Stuff
MPAA News
Games / Consoles
News
Music
Movies
Reviews
Open Source
Mobiles
Advertising
Products
P2P
Off Topic
Freedom
Politics
Interviews
Security
DRM
Links
Kids and Kartels
Scroogle Search: 
Search
 
Web p2pnet   
Search: 
Search
Torrent Site Tracker
    Sponsored by
Frostwire
 
p2pnet
 


mp3rocket
 
Add real-time p2pnet headlines to YOUR site ! Click here to download our newsfeed code

New Bagle on the loose

p2p news / p2pnet: Admins, block http access from your network to endoliteindia.com, warns F-Secure.

Why? It’s a hacked web server in India.

“We saw a new Bagle run start tonight,” says the company blog. “As usual, it was started by posting a new, undetected downloader to one of the dozens of URLs the already-infected Bagle machines are constantly polling.

“The difference this time is that every four minutes the link returns a different binary. Different size, different MD5. This is accomplished by repacking the same file with ASProtect again and again.

“endoliteindia.com”.

F-Secure says it was detecting these as W32/Bagle.GI, and the contents keep changing, and by way of an update, “At around 19:45 GMT, the download link died,” says the post.

Also See:
blogNew Bagle, new trick, March 30, 2006

HOME

Leave a Reply

ONLY items referencing the post at hand, please. No links to personal sites, no personal attacks, trolling, freebie advertising, or off-topic posts. Thanks. And Cheers!

    Sponsored by
tek savvy