On GameSpot: BlizzCon 2008: Starcraft II now trilogy

Price not right on Bagle variant

Tags: Guest Contributor

  • Save
  • Print
  • 0

Takeaway: New version of worm floods e-mail in-boxes with bogus price quote messages.

Stay on top of the latest tech news with our free IT News Digest e-newsletter, delivered each weekday. Automatically sign up today!

By David Becker
Staff Writer, CNET News.com

A prolific new variant of the mass-mailing Bagle worm began flooding e-mail accounts Monday with bogus price quotes.

Like previous versions of Bagle, the new Bagle.AQ worm spreads by sending out messages with an infected attachment compressed under the common Zip format. Both the name of the attachment and the body of the message are a variant on "price" or "new price."

Unlike earlier Bagles, the new version also packs in a 3-year-old piece of JavaScript code that, once executed, attempts to send the infected PC to various Web sites to pick up more Bagle code, said Vincent Gullotto, vice president of the antivirus emergency response team for security specialist McAfee.

Bagle.AQ started spreading Monday morning and quickly began bombarding some corporate e-mail systems with thousands of infected messages, Gullotto said.

"It made its way into the public eye in a rather grandiose fashion," he said.

Gullotto attributed the worm's fast start to use of the old JavaScript trick and initial distribution that included an unusually large number of e-mail addresses to target. "Someone has used a rather spamlike technique to get it going," he said.

Those same techniques should also ensure a relatively brief heyday for the worm, as e-mail security systems learn to block the variant, Gullotto said. "I don't expect it'll last more than 24 hours," he said. "Then it's onto the next pest."

The initial Bagle virus emerged early this year and appeared to be a fairly standard mass-mailing worm. But the pest has gone on to spawn dozens of variations, thanks partly to an apparent feud between the Bagle coder and the creator of the rival Netsky worm.

  • Save
  • Print
  • 0

What do you think?

Article Categories

Security
Security Solutions, IT Locksmith
Networking and Communications
E-mail Administration NetNote, Cisco Routers and Switches
CIO and IT Management
Project Management, CIO Issues, Strategies that Scale
Desktops, Laptops & OS
Windows 2000 Professional, Microsoft Word, Microsoft Excel, Microsoft Access, Windows XP,
Data Management
Oracle, SQL Server
Servers
Windows NT, Linux NetNote, Windows Server 2003
Career Development
Geek Trivia
Software/Web Development
Web Development Zone, Visual Basic, .NET
advertisement
Click Here