Advertisement
Promo

Security threats Toolkit

Massed bagles launch their attack

Dan Ilet ZDNet.co.uk

Published: 29 Oct 2004 17:54 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Antivirus experts have declared today as 'Bagle day' after discovering three variants of the virus within a few hours.

The variants apparently modify themselves by stealing file icons stored on hard drives and attach them to the emails they spread with. The laboratory technicians at F-Secure found one of the variants (Bagle.AV) on a Web site accessed by another version of the virus.

Bagle.AV, the company said on its Web log, was likely to be a prototype as it only sent itself to a limited number of email addresses. The virus even borrowed an F-Secure icon when it sent itself.

"This is probably a test variant because it just has a bunch of addresses in its email folder," said Patrik Runald, technical manager for F-Secure. "The others are self-perpetuating viruses that travel via email and peer-to-peer file sharing folders."

According to the firm, Bagle.AT appeared shortly afterwards and was causing 36 percent of the company's virus reports at the time of writing. F-Secure said that Bagle.AT, which was given a level-two threat alert, was number one in the virus statistics today.

The third variant of the virus, Bagle.AU, popped its head around the corner shortly afterwards. F-Secure said that the virus had the same functionality as Bagle.AT, but used a different control panel applet to execute with. Bagle.AU was ranked as number 12 in the company's virus statistics.

"It's a massmailer like .AT," said Runald. ".AU is a replicated variant, but the fundamentals of the virus are the same."

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
70 out of 96 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:





Video icon

Video

Sentry Posts Blog

Met will not reopen phone hack investi...

The Metropolitan Police will not reopen its investigation into alleged phone hacking by the News of the World. In a press statement delivered outside Scotland Yard on Thursday, Assistant... More

Post a comment

FUD over ChromeOS's security already?

It hasn't taken long for the security vendors to wake to the potential of Google's new ChromeOS. The potential that is, to create FUD – fear uncertainty and doubt. In a release today,... More

Post a comment

Feds take DDoS in their stride

The US Department of Homeland Security has said that a series of distributed denial-of-service attacks began on US government networks on 4 July. However, Amy Kudwa, deputy press... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters