Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Bagle variants punch, punch and punch again
ZDNet News ^ | June 2, 2005 | Matt Loney

Posted on 06/02/2005 10:51:00 AM PDT by infocats

The latest variants of the Bagle worm have alarmed antivirus companies because of the multiple-stage process they use to attack PCs.

The variants, which Computer Associates International has given a new name--Glieder--because it says they are so different from previous Bagle worms, combine several elements in a way not seen before. In this staged approach, viruses seed their victims, then disarm them, and then finally exploit them.

"We've seen blended threats before where a virus uses several methods to spread, but not like this" said Chris Thomas, a Computer Associates Australia security architect.

The Win32.Glieder worm spreads using a common mass-mailing method, relying on people to click on an attachment so it e-mails itself on to names in the address book. "This is the beachhead," said Thomas. "The whole point is to get to as many victims as fast as possible with a lightweight piece of malware." On Tuesday, CA saw eight variants released.

As well as e-mailing itself, the mass-mailer downloads a Trojan called Win32.Fantibag to the infected machine, which is designed to block antivirus software updates. It also blocks Microsoft's update site, windowsupdate.microsoft.com, said Thomas. "This stops the machines (from) protecting themselves," he added. "It means that software can’t get updates, that victims can't go for help and that effectively infected PC users are isolated."

The final part of the triumvirate is a second Trojan, called Win32.Mitglieder, which disables firewalls and antivirus software, further lowering the shields, and then hijacks the infected PC for use as part of a botnet. Botnets are groups of networked machines, often numbering in the thousands, that are hired as spam relays, for tracking users' behavior and for identity theft.

"There is a commodities market for victimized PCs," Thomas said. "Recently we’ve seen spammers and criminals engaged in fraud, paying approximately five cents per machine for compromised PCs."

The latest attack has been very effective. "The stats we have seen show it is still spreading quickly," said Thomas.

Thomas said the virus does not appear to block access to Computer Associates' virus patch update site, but could not offer an explanation as to why this had been missed off the list.


TOPICS: Business/Economy; Crime/Corruption; Culture/Society; Technical
KEYWORDS: bagle; lowqualitycrap; microsoft; virus; windows; worm

1 posted on 06/02/2005 10:51:00 AM PDT by infocats
[ Post Reply | Private Reply | View Replies]

To: rdb3; chance33_98; Calvinist_Dark_Lord; Bush2000; PenguinWry; GodGunsandGuts; CyberCowboy777; ...

2 posted on 06/02/2005 10:58:58 AM PDT by ShadowAce (Linux -- The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 1 | View Replies]

To: infocats
I can hear the stampede (12 ppl) coming from the apple (crowd?)
3 posted on 06/02/2005 11:03:32 AM PDT by Xenophobic Alien (OK gang, you know the rules, no humping, no licking, no sniffing hineys.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: infocats

bump


4 posted on 06/02/2005 11:05:31 AM PDT by NonValueAdded (NEWSWEEK LIED, PEOPLE DIED)
[ Post Reply | Private Reply | To 1 | View Replies]

To: ShadowAce
Are all files with the name "Win32" prefix, viruses or worms or Trojans???? I have found several on my comp.
5 posted on 06/02/2005 11:29:32 AM PDT by clearsight
[ Post Reply | Private Reply | To 2 | View Replies]

To: clearsight
Are all files with the name "Win32" prefix, viruses or worms or Trojans???? I have found several on my comp.

No. Lost of win32's are a normal part of windows.

6 posted on 06/02/2005 11:34:34 AM PDT by The_Victor (Doh!... stupid tagline)
[ Post Reply | Private Reply | To 5 | View Replies]

To: The_Victor
Lost = Lots

I hate when typos make a word.

7 posted on 06/02/2005 11:36:22 AM PDT by The_Victor (Doh!... stupid tagline)
[ Post Reply | Private Reply | To 6 | View Replies]

To: infocats
I'm not even sure that it is worthwhile to comment on yet another Windows trojan, but I'll Bump it for general awareness. There are a lot of people who don't realize how vulnerable they leave themselves.
8 posted on 06/02/2005 12:41:57 PM PDT by zeugma (Come to the Dark Side...... We have cookies!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: zeugma

Better alert your Linux buddies of all these new vulnerablities announced the last few days too. 6 in the Red Hat distro yesterday and today.

http://lwn.net/Alerts/


9 posted on 06/02/2005 6:01:54 PM PDT by Golden Eagle
[ Post Reply | Private Reply | To 8 | View Replies]

To: infocats

My wife got one yesterday, I got one today. An infected email.

The title is something like.
Finally, Osama Bin Laden caught!

Then goes on to say that the news hasn't hit the media yet but if you want to see some screen captures, open this little .zip file.(Trend Micro caught it )

Duh!!

Bet a zillion people fall for it.


10 posted on 06/03/2005 2:37:42 PM PDT by Vinnie
[ Post Reply | Private Reply | To 1 | View Replies]

To: Vinnie
My wife got one yesterday, I got one today. An infected email.

The title is something like. Finally, Osama Bin Laden caught!

Then goes on to say that the news hasn't hit the media yet but if you want to see some screen captures, open this little .zip file.(Trend Micro caught it )

Everyone...Keep your anti-viral signatures up to date

11 posted on 06/03/2005 2:43:00 PM PDT by infocats
[ Post Reply | Private Reply | To 10 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson