R E L A T E D   C O N T E N T

Free email newsletters




ADVERTISEMENT

Latest Bagle mutant on the rampage

Worm contains backdoor for hacker to execute arbitrary programs

Robert Jaques, vnunet.com 27 Jan 2005
ADVERTISEMENT

Security experts have today warned of a newly discovered Bagle mutant which is spreading in the wild from several countries.

Bagle.AY is similar to Bagle.AX in that it is polymorphic and arrives in emails with variable subjects and attachments. It also has peer-to-peer spreading capabilities.

Security firm F-Secure has warned that the worm also contains a backdoor that listens on TCP port 81. This password-protected backdoor code allows a hacker to connect to an infected computer and execute arbitrary programs.

Infected computers are reported to the worm's author by accessing several predefined URLs. Once installed on a compromised PC the worm tries to download and execute a file from this list of locations.

Bagle.AY also terminates security processes and antivirus software as well as some other applications.

The worm arrives in email as a packed executable, and can also spread with a Windows Control Panel Applet 'stub', a small program routine that substitutes for a longer program.

Somewhat oddly the worm has been programmed to cease its activity on 25 April 2006, so if a PC's system date is 25 April 2006 the worm uninstalls itself by deleting its start-up key in the Registry and terminating its own process.

When the worm's file is run, it copies itself as 'sysformat.exe' to Windows System folder and creates a start-up key for this file in the Registry. The worm creates two more files in Windows System folder: 'sysformat.exeopen' and 'sysformat.exeopenopen'.

These files are used when the worm spreads itself in emails. Bagle.AY scans the hard drive to collect email addresses of possible victims, but specifically excludes any addresses associated with antivirus and security companies.

The worm is particularly difficult to detect as it spreads itself in emails with randomly chosen subject lines, mail bodies and attachment names.

F-Secure noted that the worm can attach itself to emails as an executable file with com, exe, scr and cpl extensions.

Bagle.AY uses the following text strings as subjects for infected emails that it sends:

Delivery service mail
Delivery by mail
Registration is accepted
Is delivered mail
You are made active

Message bodies are randomly chosen from a predefined list:

Thanks for use of our software
Before use read the help

Attachment names can be one of the following with exe, scr, com, and cpl extensions:

wsd01
viupd02
siupd02
guupd02
zupd02
upd02
Jol03

"When spreading as a Windows Control Panel Applet file, the worm adds a small binary dropper to its executable file," said F-Secure.

"When the CPL file is activated, it copies itself as 'cjector.exe' file to Windows folder and then drops the worm's file into Windows System folder."

See also:

Bagle variants spreading fastLatest mutations disable antivirus and security tools  01 Mar 2005
Bagle BM mutant strikesSecurity firm predicts new wave of virus attacks  01 Mar 2005
2004 worst year on recordViruses, worms and Trojans taking their toll  01 Feb 2005
Tough times ahead as malware becomes increasingly sophisticatedHappy new year  04 Jan 2005
Bagle.BC spreading fastSecurity experts increase threat rating as new variant spreads rapidly  01 Nov 2004
Bagle.bb joins war of the wormsMass-mailing worm spreading fast  29 Oct 2004
Virus writers turn to spamVirus writers cash in with latest breed of email threat  17 Aug 2004

All Enterprise Security Technology

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
Welwyn Garden City, Hertfordshire, United Kingdom | Tesco.com
Technical Specialist Infrastructure - Welwyn Garden City Who's behind the world's most successful online retailer? Just over 10 years ago we started Tesco.com (aka Dotcom). Today, we've an incredible 750,000 active customers and sales at ... more >
Hertfordshire, United Kingdom | Tesco.com
Senior Business Analyst - Hertfordshire Who's behind the world's most successful online retailer? Just over 10 years ago we started Tesco.com (aka Dotcom). Today, we've an incredible 750,000 active customers and sales at just under ... more >
Solihull, United Kingdom | Enzen Global Limited
 BUSINESS CONSULTANT - Utilities - £35,000 - £40,000 - Solihull We are in need of a Business Consultant with strong analytical skills and a penchant for learning the domain knowledge of the Utilities sector (Gas ... more >
Shinfield Park, Reading, United Kingdom | Foster Wheeler
Our UK-headquartered operations employ more than 6,000 people and we are seeking qualified and experienced IT professionals to work in our head office in Reading, Berkshire. We are currently seeking an Analyst Programmer to join ... more >
More job opportunities