Slashdot Mirror


'Bagle' Worm Heading For A Windows PC Near You

mrSinclair writes "the 'Bagle' or 'Beagle' worm is expected to hit the U.S. by midweek, probably Tuesday as many employees return from a three-day weekend." He points to this Washington Post story (via Yahoo!), which describes the Windows mass-mailing worm as being transmitted via email as an .exe attachment and as installing "a program that lets attackers connect to infected machines, install malicious software or steal files." The article says Bagle has been detected in more than 100 countries. Other readers have sent in links to coverage at the BBC and at SearchSecurity.com.

13 of 606 comments (clear)

  1. Antivirus Company Submissions by cyt0plas · · Score: 4, Informative

    So far, I've submitted copies of this to Symantec, and ClamAV, both of which did not detect it in the latest definitions. If anyone else has submitted this to an A/V manufacturer, or knows of an A/V that currently detects this, please post.

    --
    Contact Me (got tired of viruses emailing me).
    1. Re:Antivirus Company Submissions by Neva · · Score: 5, Informative

      F-Secure detects it, since yesterday. There's a removal tool there too.

      Bagle description

    2. Re:Antivirus Company Submissions by fo0bar · · Score: 4, Informative

      ClamAV and Kaspersky both seem to be catching them here.

  2. Fast moving little sucker by Kris_J · · Score: 4, Informative

    We've already received two of these at work, one as early as 8am yesterday morning, local time. Fortunately our server-based anti-virus filter is on the ball: "Executable DOS/Windows programs are dangerous in email (kraencha.exe)"

  3. Interesting Tidbit by jmt9581 · · Score: 5, Informative

    It looks like the writers of the virus DOS'ed themselves (from the aformentioned Yahoo! article):

    Bagle also tries to download an unknown program from one of more than 30 Web sites located mostly in Germany and Russia. None of those Web sites was reachable as of Monday afternoon.

    Or is it more likely that these servers in Russia and Germany were also hacked and were just being used?

    In any rate, this doesn't look so bad. The searchsecurity.com article says that "Removing the worm manually is just a matter of killing "bbeagle.exe" in the Task Manager. The registry keys created by the worm also need to be removed." Hopefully this one won't be as bad as Sobig. :)

    --

    My blog

  4. Great Ways to Prevent Spreading Viruses by teledyne · · Score: 4, Informative

    1. Don't open any attachments that are potential virus, (.exe, .vbs, .com, etc.)

    2. Disable your email client's automatically message preview pane. This makes exploit viruses a little easier on you, as you can select the message and delete it without having to preview it instantaneously.

    3. Download a mail proxy program (I use MailWasher), it'll filter out spam, and allow you to see a text version of the message, without downloading the attachment.

    4. Have your AV update its definition religiously. Of course, this only helps if your AV company updates its definition religiously as well.

    Of course, the first 3 don't require a virus scanner at all, just common sense. As a gamer, I hated having NAV or McAfee VirusScan hog up 30MB of my memory, so I removed it. I make smart and conscious decisions, and have never had a virus on my computer for several years.

  5. It's already here (My story) by Trillian_1138 · · Score: 5, Informative

    I'm the resident geek in my dorm, and have spent the last 24 hours getting rid of it on computers of anyone and everyone. The particular strain we saw came in an email with the subject of simply "Hi" and contained (basically) the following test.

    Hi!
    This is a test.
    (random string of letters)
    Testy test.

    The attached file was a modified version of the Windows calculator which (according to the Symantec site) "Emails all the contacts it can find inside files with the extensions .wab, .htm, .html, and .txt"

    It's interesting because apparently that's ALL it does. It doesn't screw with files or settings, or run malicous code (outside the actual act of reproducing itself). It's annoying, however, because it sends emails to people who are NOT in your address book, but merely mentioned in text files somewhere on your computer. In the last 24 hours I've gotten emails with the virus from friends, random people in my university, at least one university email address that should have been run by someone who knew better, and a couple random friends-of-friends.

    Also, according to Symantec, it dies on the 28th.

    It was really interested to see the spread at my college. For us, it began around 1 AM Monday morning, peaked around 2, and was already slacking off by 3 AM. I know this from my own inbox, people in my dorm, and talking to people elsewhere.

    I do find it currious the virus didn't DO anything. Is it just someone screwing around, a test for a future release or (as some of the more paranoid people in my dorm are suggesting) a released virus by the anti-virus companies to keep people in enough fear to demand their products.

    As a side note, I also spent hours cleaning the assorted spyware and adware that builds up when people don't know how to properly use their computers....more than one person could literaly not do work becasue of the porn popups that plagued their computer.

    -Trillian

    1. Re:It's already here (My story) by Trillian_1138 · · Score: 4, Informative

      Last one, I promise.

      I missread Symantec's site (didn't scroll far enough down). It does indeed contain malicious code beyond it's own reproduction:
      from http://securityresponse.symantec.com/avcenter/venc /data/w32.beagle.a@mm.html

      #

      # Creates a listening thread on port 6777 (this port can change during the worm execution) that allows a remote attacker to:

      - execute commands on the local system as if he were the current user
      - download executables onto the local system
      - terminate and delete the worm program

      # Creates a notification thread that will contact a remote website (using local browser proxy settings) and announce the presence of the worm on the local system every 10 minutes.

      The list of websites contacted is predetermined and are contained within the body of the worm.

      -Trillian

  6. NAV already detects it... by antdude · · Score: 5, Informative

    ... according to Symantec's Security Response (since 1/18/2004).

    --
    Ant(Dude) @ Quality Foraged Links (AQFL.net) & The Ant Farm (antfarm.ma.cx / antfarm.home.dhs.org).
  7. Executables in email by slutdot · · Score: 4, Informative

    I know this has been mentioned about a thousand times but if you're a sysadmin, do yourself a favor and block executables, scripts, or any other file type that can execute. If someone needs an executable to be sent in-bound, set up either an FTP server or a dummy account outside your company's mail system. I have a domain set up just for this purpose where only the admins have rights to the mail accounts. If someone needs a file, the employees just send a request to have an admin check the mailbox for a specific filename from a specific user. We'll even ask for file sizes just to make sure. While checking the mailbox might take about 3-5 minutes out of my day, this method saves me the many headaches of removing viruses all week.

  8. Of course you know that this means war! by shanen · · Score: 4, Informative

    Already old news here. Been dealing with it for a couple of days...

    The Subject: is actually more applicable to the spammers, who really are waging all out war on the utility of email. This one is more like a hit-and-run attack.

    Still, the similarity is that they are hoping to find a few "good" suckers to click on their links. This one is actually an interesting combination. Partly it seems to be testing the efficiency of a propagation mechanism, which seems to result in greater "apparent locality" of the email, with higher odds that it seems to have come from someone you know. However, it also seems to be ready to launch some more insidious payload that was to be downloaded from some Web sites.

    Right now all of those Web sites seem to have been taken off the net--or maybe they're waiting to pop them onto the net once the thing has propagated sufficiently. That part of the Trojan apparently tries to check in every 10 minutes to announce itself.

    The thing that bothers me about this combination malware is that the anti-virus people could easily miss something. For example, in this case, what if the thing included a new variation on the email backchannel for the harvested email addresses. Or maybe a well-concealed bit of code to suddenly mung the URLs to point to live sites somewhere else? However, whatever it is hasn't triggered yet, and the anti-virus people perhaps have only detected the distractor HTTP-channel. If that were the case, they could still get a massive harvest of email addresses. (Yes, I still think the spammers are probably really the people behind this one--spamming just naturally attracts the lowest life forms. It's a question of the crudest motivations for the crudest acts.)

    By the way, has anyone seen the reason for the bagle/beagle confusion here? Trying to incriminate the Israelis? Or the dogs? Or both?

    --
    Freedom = (Meaningful - Coerced) Choice != (Speech | Beer^2), and sad sock puppets' bad mods avail them naught.
  9. Re: AVG's got it... by MachDelta · · Score: 5, Informative

    ...since yesterday, apparently. Good to see Grisoft keeping AVG up to date.
    Oh, and they've got a little blurb on the virus too.

  10. OS X user accounts are more secure by Aqua+OS+X · · Score: 4, Informative

    Yes, but by default OS X users are given a user account, separate from root. And, even if they have an admin account (not to be confused with root), they have to type in an administrator password to confirm installations that affect areas outside of the user's home directory.

    You can send an OS X user a malicious Apple Script file with an MPEG icon on it, and they'll probably double click it thinking they are going to view free prOn. But as soon as the "administrator password" box comes up, odds are they are going to hit "cancel" and not grant access to their root directory :/

    Moreover user accounts in OS X are quite flexible. Unlike Windows users, OS X users rarely require the need to login to, and remain working within, the root level.

    Every Windows office I've ever administered has had numerous problems with user accounts, users working in root 24/7, etc

    --
    "Things are more moderner than before- bigger, and yet smaller- it's computers-- San Dimas High School football RULES!"