ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Virus with SOCKS appeal targets corporate PCs

Munir Kotadia ZDNet Australia

Published: 08 Aug 2005 14:40 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A new variant of the Bagle virus incorporates a SOCKS proxy and Web services technology aimed at bypassing corporate firewalls, security experts have warned.

The latest Bagle variant — alias Bagle.b.w (F-Secure) and W32/Bagle.CB@MM (McAfee) — was discovered late last week and although security companies say it's not spreading very quickly, computers that have been compromised by the worm will not be easy to detect.

Adam Biviano, senior systems engineer at Trend Micro Australia and New Zealand, said the latest variants show that the Bagle authors are starting to seriously target corporate users.

"This is starting to prove that these variants are targeting corporate machines as opposed to just home users. Most corporate networks are set up to block your typical Trojan access vectors such as IRC and chatrooms. [This variant] uses Web services and SOCKS, which are typical corporate gateway services that would be allowed to go through firewalls," said Biviano.

On the F-Secure blog, Jarkko Turkulainen, the Finnish antivirus company's binary virus researcher, said the latest Bagle no longer tries to "download Mitglieder trojans for opening up spam proxies on infected computers", instead the malware "can also act as SOCKS v4/5 proxy, HTTP CONNECT proxy and SMTP relay."

"It is probably easier to take advantage of home users but probably a logical step in the evolution … would be to try and take advantage of corporate computing resources. IT managers are going to have to look at some kind of monitoring on their Web gateways to make sure information isn't being leaked out of the organisation by these applications," said Trend Micro's Biviano.

Allan Bell, marketing director for McAfee, described the various weapons that the latest Bagle variant has at its disposal and said the worm won't send copies of itself to email addresses from security organisations "to try and hide itself a little bit longer".

"Bagle traditionally has been used for spamming — it has a spam engine — but it can be remotely controlled and used to download and run other applications. It can disable your antivirus and firewall… it also tries to propagate using P2P [peer-to-peer] by jumping into shared folders," said Bell.

Bell said the latest Bagle is "low risk" and most enterprises are unlikely to see it. However, its relative rarity is also one of the tricks used by malware authors to keep their creations low key, according to Eugene Kaspersky, founder of Kaspersky Labs.

At the AusCERT conference in Australia's Gold Coast earlier this year, Kaspersky said that virus authors are no longer trying to infect as many computers as possible with the same virus.

"Do I need a million computers to send spam? No. To do a DDoS attack, 5,000 or 10,000 PCs is more than enough. That is why virus writers and hackers have changed their tactics of infection — they don't need a global epidemic," said Kaspersky.

Munir Kotadia reported from Sydney for ZDNet Australia. For more ZDNet Australia stories, click here.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Kyocera

Did you find this article useful?
50 out of 116 people found this useful


Full Talkback thread

0 comments


Related Jobs

Systems Administrator / 2nd Line Support, Deeside, 20,000

Technical Requirements: - Exchange support & maintenance - Windows Server 2003 support & maintenance - Backup Exec - Proxy/Firewall/VPN - Antivirus & ...

Systems Engineer, Windows 2003 / Cisco / Linux / VMWare- Oxfordshire

Unix, Red Hat, Mandrake, SUSE, Solaris, HP-UX, Cisco, Cisco IOS, Router, Firewall, PIX, Firewall 1, TCP/IP, DNS, DHCP, proxy, email, MS Exchange, ...

Cisco Security Pre-Sales Consultant, PIX, ASA, Firewalls, CCSP, London

Cisco Security Pre-Sales Consultant required for pivotal role within a WAN IT Security Management company with offices in central London & Paris. You ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Biometric devices. Do you need one?

When saying “biometrics” I am not thinking about law enforcement, AFIS systems, national ID and visa projects. I first think about personal solutions that will make my life easier.... More

1 comment

Barracuda launches counter-suit agains...

Court cases are never pleasant or simple. The ongoing battle between security companies Trend Micro and Barracuda Networks took a new twist on Wednesday, when Barracuda launched a counter-suit... More

Post a comment

Mobile Speed Demon: Wireless Surpasses...

Mobile Speed Demon: Wireless Surpasses Landline Author: Eric Everson, Founder MyMobiSafe.com As I look around my house and throughout my network of friends, I instantly realize... More

Post a comment