ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Bagle worm spawns five siblings

Munir Kotadia ZDNet.co.uk

Published: 01 Mar 2004 13:45 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Five new variants of the Bagle worm were released into the wild over the weekend, with two causing particular problems for enterprise antivirus software scanner technology, say experts.

Bagle versions C, D, E, F and G started propagating over the weekend and although the first three are very similar to the original Bagle -- being spread through email and infecting PCs of users who open the attachment -- Bagle.F and Bagle.G are designed to slip past most enterprise antivirus gateways.

Mikko Hypponen, head of antivirus response at Finnish security company F-Secure, told ZDNet UK that the latest variant of the Bagle family is sent inside an encrypted Zip file attached to an email that contains the password required to access the file. This means that enterprises are unlikely to detect the virus at the perimeter because .zip files are not usually blocked and the encryption means that antivirus scanners will not be able to unzip the file: "This way they get through many gateway scanners that will not be able to unzip the file to scan it."

Graham Cluley, senior technology consultant for antivirus company Sophos, said: "However good an ISP, Web email account or antivirus gateway product may be at scanning email, it will be useless at detecting the worm inside the encrypted Zip file."

David Emm, marketing manager at McAfee Avert, the antivirus company's research arm, agrees: "They are much less likely to block .zip files then they are an .exe, screensaver or .pif file, because it is much more likely that someone puts legitimate data inside a Zip. Also, if it looks like a folder then the user at the receiving end is much more likely to think it is something benign," he said.

Emm commented that he can't remember a worm with this many variants in such a short timeframe: "It's not unusual to see lots of variants, but I can't remember when we have seen so many in such a short amount of time."

Hypponen believes there are so many variants that are similar to each other because they are being modified just enough to keep ahead of the anti virus companies: "C and D are almost identical, F and G are also almost identical. Every time antivirus vendors add a detection, the virus writer/s responds by modifying it a little and releasing the new version," he said:

The Bagle F and G worms are coded to expire on 25 March, 2005.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
89 out of 201 people found this useful


Full Talkback thread

0 comments

Related Jobs

Oracle developer, work in a leading European Investment Bank,Training!

You will be working in a small team and must have solid experience in Oracle, SQL, Toad, XML, as well as, XML Open Gateway (XOG), NSQL, Gel scripting ...

Junior Level Desktop Support (Grad, Win XP, AD, TCP/IP) HEDGE FUND

Windows 2000/XP, MS Office 2003, Printer maintenance, basic networking TCP/IP, understanding what a subnet gateway is, PC Hardware One of Europes Top ...

Project Leader / Project Manager

Salary - 39,000 - 44,000 You will have a key responsibility for delivering ICT work-streams on the new, greenfield Gateway Programme. Seeking a ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

2 comments