Home > Security News > Bagle-A worm moving quickly
Security News:
EMAIL THIS

Bagle-A worm moving quickly

By Edward Hurley, News Writer
19 Jan 2004 | SearchSecurity.com

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

You definitely don't want Bagle-A with your coffee this morning.

Bagle is a new mass-mailing worm, and it came on strong on Sunday, prompting antivirus software companies to raise threat alerts. The worm also opens an unassigned port, where it tries to listen for commands from the writer.

Finnish antivirus firm F-Secure Corp. has rated Bagle a level 1 threat, the company's highest rating, because of the worm's pervasiveness. U.K.-based e-mail content-scanning outsourcer MessageLabs Inc. had intercepted nearly 69,000 copies of the worm as of 9 a.m. EST today. McAfee Security and Trend Micro Inc., meanwhile, have Bagle rated as a medium risk. Symantec Corp. rated it a 2, or a low risk. U.K.-based Sophos PLC said it has received hundreds of reports from customers.

The worm is also called "Bagel" and "Beagle." The writer has included the word "beagle" throughout the code, but antivirus researchers have tweaked the name to avoid calling it what the writer presumably named it.

Bagle is such a basic worm in terms of functionality and social engineering that, initially, antivirus researchers expected little from it. Blocking executable files at the gateway, a recommended practice for enterprises, should prevent infection.

"We really thought it was never going to spread because it's so stupid," said Mikko Hypponen, manager of antivirus research for F-Secure. "But people seem to be clicking on it."

Compared to recent attacks, like the Mimail-P worm and the Xombe Trojan, which looked like legitimate messages from PayPal and Microsoft, respectively, Bagle seems downright primitive. Bagle's message uses the subject line "Hi," and the message contains randomly generated gibberish. A copy of Bagle intercepted by SearchSecurity.com says:


Test =)
rjptxjqstsqgtrployrq
--
Test, yep.

The attached worm in the message looks like the Windows calculator icon. The worm uses a random name for the attached copy, which is probably done to prevent administrators from blocking a specific file name, said Graham Cluley, senior technology consultant at Sophos.

If the attachment is run, the worm verifies that the computer's internal calendar reads a date earlier than Jan. 28, 2004; the program will terminate if it reads a later date. The worm then executes the Windows calculator, calc.exe, as a smokescreen while it copies itself to the Windows system directory as "bbeagle.exe." It also creates a registry key so it will run at startup:

HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun "d3dupdate.exe" = C:WINNTSystem32bbeagle.exe

Bagle creates these other registry keys as well:


HKEY_CURRENT_USERSoftwareWindows98 "frun"
HKEY_CURRENT_USERSoftwareWindows98 "uid"

The worm then searches the infected system's various files, including the Windows address book, as well as Web pages for e-mail addresses. The worm sends spoofed copies of itself to those addresses using its SMTP engine.

The one different thing Bagle tries is listening on TCP port 6777, presumably so it can take commands from the worm writer, experts said. But it appears a bug in the worm is preventing this functionality from working, Hypponen said. The worm may be from Germany or Russia -- it tries to connect to a series of Web sites based in those countries.

Users can check the Windows system directory to determine whether they've been infected. Removing the worm manually is just a matter of killing "bbeagle.exe" in the Task Manager. The registry keys created by the worm also need to be removed.



Tags: Common Vulnerabilities and Prevention TipsSecuring the DesktopSecuring your Products/PlatformsSecuring the Internet and E-CommerceInfrastructure and Network SecurityVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Common Vulnerabilities and Prevention Tips
What's your infosec IQ?
IE update clears up spoofing issue
Countdown begins for Mydoom DDoS attacks
Microsoft to disable spoofing syntax in IE
Mydoom variant targets security features, Microsoft
IE flaw could fool users in illicit downloads
Hackers scanning for ports opened by Mydoom
Dangerous, familiar application vulnerabilities top list
Potent Mydoom worm flooding inboxes
Worm opens two backdoors, logs keystrokes

Securing the Desktop
Sensitive student data cracked at U. of Georgia
Microsoft wrapping up PC services trial
IE update clears up spoofing issue
Geer slams Windows dominance, calls for government intervention
Countdown begins for Mydoom DDoS attacks
Microsoft to disable spoofing syntax in IE
IE flaw could fool users in illicit downloads
Mydoom variant targets security features, Microsoft
Hackers scanning for ports opened by Mydoom
Dangerous, familiar application vulnerabilities top list

Securing your Products/Platforms
Sensitive student data cracked at U. of Georgia
Microsoft patches IE spoofing problem
IE update clears up spoofing issue
Countdown begins for Mydoom DDoS attacks
Microsoft to disable spoofing syntax in IE
IE flaw could fool users in illicit downloads
Mydoom variant targets security features, Microsoft
Hackers scanning for ports opened by Mydoom
Dangerous, familiar application vulnerabilities top list
Potent Mydoom worm flooding inboxes

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts