Feeds

Bagle source code unleashed

Tools for s'kiddies

  • alert
  • submit to reddit

Intelligent flash storage arrays

Virus writers are distributing viral source code with the latest version of the Bagle virus series, Bagle-AD. Much like its 29 predecessors, Bagle-AD is a mass-mailing worm that is packed using UPX file compression. IT comes in the form of a password-protected .ZIP file, with the password included in the message body as plain text or within an image. The ZIP file contains an executable with the extensions EXE, COM or SCR.

After being executed, Bagle-AD emails itself, using its own built-in SMTP engine to addresses harvested from an infected PC. Infected emails come from spoofed email addresses. The remote access component of the virus listens to TCP port 1234 for commands, a feature which allows crackers to use infected PCs as zombie drones in DDoS attack networks or to distribute spam.

When mass-mailing itself, the worm may also include a copy of its source code (written in Assembler) within a ZIP archive. This makes it easier for copycats to design more versions of the virus. It also gives its author an excuse for why source code is discovered on a PC, if he is ever arrested.

Anti-virus firm McAfee increased the risk assessment on Bagle-AD overnight, reclassifying the worm as a medium-risk threat. Inevitably, Bagle-AD is a Windows-only menace. ®

Related stories

Zombie PCs spew out 80% of spam
Would you like a cherry Bagle with your zombie PC?
Latest Bagle worms spread on auto-pilot
War of the worms turns into war of words (NetSky vs Bagle)
Phatbot arrest throws open trade in zombie PCs

Top 5 reasons to deploy VMware with Tegile

Whitepapers

Choosing cloud Backup services
Demystify how you can address your data protection needs in your small- to medium-sized business and select the best online backup service to meet your needs.
Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.