|
|
I-Worm.Bagle. Viruses Information
| Name: |
I-Worm.Bagle. |
| Category: |
Viruses |
| Description:
|
Details
I-Worm.Bagle.s
Bagle.s is an Internet worm spreading as an attachment to infected emails.
The worm is a PE exe file about 8 KB in size. Bagle.s is compressed by FSG and the unpacked file is about 37KB in size.
Infected messages have the following characteristics:
Sender address:
random
Subject:
none
Body:
empty
Attachment name:
random characters
Attachment file type:
.exe
Installation
After launch Bagle.s copies itself into the Windows system registry as gigabit.exe and registers this file in the system registry autorun key:
[HKLMSOFTWAREMicrosoftWindowsCurrentVersionRun]
"gigabit.exe" = "%system%gigabit.exe"
Bagle.s then creates the key:
[SOFTWAREWindows2004]
"gsed"
where it stores it's variables.
Bagle.s also launches mshearts.exe - The Miscrosoft Hearts Network.
Finally, Bagle.s attempts to connect to several remote sites and store id information from the infected machine on these sites.
Propagation
Bagle.s searches disks for files with the following extensions:
adb
asp
cfg
cgi
dbx
dhtm
eml
htm
jsp
mbx
mdx
mht
mmf
msg
nch
ods
oft
php
pl
sht
shtm
stm
tbb
txt
uin
wab
wsh
xls
xml
and sends copies of itself to all email addresses detected in these files using an inbuilt SMTP-engine.
Remote Administration
Bagle.s opens and monitors port 4751. The inbuilt backdoor function allows the master to:
Execute commands
Download files |
Top Viruses Visited Pages:
Invader. - 239 visits
not-a-virus:RiskWare.Tool.RegPatch. - 73 visits
Worm.P2P.Harex. - 66 visits
not-a-virus:RemoteAdmin.Win32.RAdmin.2 - 60 visits
Small.58. - 56 visits
Coito.64 - 54 visits
I-Worm.Mapson. - 48 visits
Win32.Hidra - 43 visits
Win16.Klon.1177 - 42 visits
Marine.500 - 35 visits
Random Viruses Pages:
TrojanDownloader.Win32.Aphe
Win95.Mutea.49
Procuro
Devil.94
I-Worm.Potar.
Macro.Word97.Jot
VirDem.60
Airwalker.38
Exterminator.42
RedCode.151
|
|