Bagle.B: new Windows worm
The latest critical Windows worm is a new variant called Bagle.B. (It does not run on the Mac, but it can still hijack Mac email addresses and affect us with other problems, like previous Windows worms.)
NAME: Bagle.B
ALIAS: I-Worm.Bagle.B, WORM_BAGLE.B, W32.Beagle.B@mm, W32/Tanx.A, W32/Yourid.A, W32.Alua@mm, Win32.HLLM.Strato
SIZE: 11264
F-Secure is upgrading Bagle.B worm to Level 1, as it keeps spreading rapidly. It arrives in email with random subject and attachment name with an EXE extension. The worm installs a backdoor that listens on port 8866. Bagle.B worm has been programmed to stop spreading on February 25th.
Found on 17th of February 2004, Bagle.B is a variant of the successful Bagle. As its predecessor it is mass-mailing worm. The worm sends messages with the subject 'ID [random string]... thanks' and random EXE attachment names. It also installs a backdoor.
[ Pete
| 02/18/2004 10:58
| Comments (1)
| TrackBack (0)
]
1 Comments
Noah [02/19/2004 18:44]:
Note these links to the official Network Associates (who dubbed it "W32/Bagle.b@MM") and Symantec (who dubbed it "W32.Beagle.B@mm") pages.