PDA

View Full Version : Bagle spreads new threat


1024
2004-03-20, 03:05 AM
The Bagle worm is exploiting an old Outlook flaw to spread even more quickly, while an ancient Trojan has gained a new name and a new lease of life.

Users no longer have to click on an attachment to spread the Bagle virus because the latest variants are exploiting an old flaw in Microsoft Outlook that allows the worm to spread even more quickly.

Until the appearance of Bagle variants Q, R and S, users had to click on an e-mailed attachment to be infected by the worm. However, these attachments were easily spotted by antivirus programs and eliminated. To fool antivirus software, the next batch of Bagles was sent with the attachment hidden inside (http://zdnet.com.com/2100-1105-5170007.html?tag=nl)infected an encrypted Zip file, with the password to open the file contained in the e-mail's text. Antivirus companies dealt with this change within a few days, so in the next variant (http://zdnet.com.com/2100-1105-5173129.html?tag=nl) the password appeared in a small graphic file, making it more difficult to scan.






The latest Bagle incarnation has done away with the attachment altogether and spreads when a vulnerable user opens the e-mail using an unpatched version of Microsoft Outlook. If their Outlook preview pane is open, the victim's machine will be compromised automatically. Because of this change in tactics, experts fear the worm could spread very quickly.

Sophos's senior technology consultant, Graham Cluley, said: "This is a really sneaky, cunning trick. It's exploiting a five- or six-month-old Outlook security vulnerability so that just previewing an e-mail--not the attachment--in an unpatched copy of Outlook will result in the virus being dragged from an infected machine to your machine. This has the potential to spread very quickly because so many people, particularly home users, have not applied the patches."

Mikko Hypp�nen, director of antivirus research at F-Secure, told ZDNet UK that the latest variant uses a list of about 600 IP addresses, which all seem to be home computers connected to an ADSL service that have been infected by previous versions of Bagle. These "zombie" machines have been updated and are now used to send copies of the new worm to any computer on which the victim uses a vulnerable copy of Outlook to view an infected e-mail message.

Outlook uses elements of Internet Explorer to render the HTML for its preview pane, so to avoid the new Bagle worms, users should apply a patch for Internet Explorer that released in October 2003 (http://dw.com.com/redir?destUrl=http%3A%2F%2Fwww.microsoft.com%2Ftec hnet%2Fsecurity%2Fbulletin%2FMS03-040.mspx&siteId=2&oId=2100-1105-5175172&ontId=11&lop=nl_ex)Microsoft .

New Bagle viruses are not the only problem brewing for Windows users. A new iteration of a Trojan horse with an unusually comprehensive set of features has also appeared.

Phatbot, also known as Agobot, is a powerful piece of malware that opens a back door on a computer and connects to its own peer-to-peer network of infected machines. Once a computer is infected and connected to this P2P network, the author of Phatbot has complete control over the computer and can use it for any number of malicious tasks.

"Phatbot is dangerous because it is so feature-rich that you can do anything--it's probably the largest back-door we have ever seen in terms of features. It has multitude of different methods of gaining access to a machine, including the back doors left by Bagle, MyDoom and Blaster. Phatbot is the Swiss army knife of Trojan horses," said Hypp�nen. "When it gains control of a machine, it connects to this P2P network that allows the virus writer to control and send commands to the infected hosts.

As a backup, it also uses an IRC channel. There are hundreds of different commands ranging from various types of DDoS attacks to stealing everything from the address book to deleting files and finding new hosts to infect."

However, Sophos's Cluley said Phatbot can be dealt with by regular antivirus software and may be garnering attention partly because of its new moniker. "We have seen lots of different versions of this Agobot, but someone started referring to it with the trendier name of Phatbot and now people have started getting excited about it," he said.

http://zdnet.com.com/2100-1105_2-5175172.html

uh-oh.

Onizuka
2004-03-20, 10:09 AM
Ah, shit.

Infernus
2004-03-20, 10:53 AM
:scared: that sounds nasty...

worldvengence
2004-03-20, 12:17 PM
DAMNIT...im starting a campain to kill the fuckers who dont have anything better to do than mess up honest ppls computers..whos with me? pussy ass bastards /rant off

Everay
2004-03-20, 12:57 PM
eh, <----- not scared, just keep patchin, and keep that anti virus runnin.

Spee
2004-03-20, 01:01 PM
/me grabs cream cheese.

worldvengence
2004-03-20, 01:05 PM
:lol: was waiting for someone to make that joke

Dharkbayne
2004-03-20, 01:34 PM
I just check my emails via MSN IM, no outlook for me, I have it, too lazy to set the mofugger up.

Infernus
2004-03-20, 05:21 PM
I just check my emails via MSN IM, no outlook for me, I have it, too lazy to set the mofugger up.

heh... same here... why use outlook when you could use... ... ... ...something else...

worldvengence
2004-03-20, 09:57 PM
Outlook Express....meh, it was already set up for me when i instaled the DSL software

martyr
2004-03-21, 01:23 AM
i can't wait to start removing these things from stupid peoples' computers.

AztecWarrior
2004-03-21, 10:14 AM
OH GNOS!!!!111

Looks like I'll just have to switch to Netscape e-mail. Sucks to be you IE users right now, doesn't it?

ZeusCali
2004-03-21, 12:37 PM
mac doesn't get viruses :-D and i never am dumb enjoy to open any emails on my flawed PC micronuts version CE ME NT