English
The Internet threat alert status is currently normal. At present, no major epidemics or other serious incidents have been recorded by Kaspersky Lab’s monitoring service. Internet threat level: 1

Fresh Bagles ahead

Costin Raiu
Kaspersky Lab Expert
Posted May 31, 15:37  GMT
Tags: Bagle
0
 

Two new Bagle variants have been spotted today. Both are 36352 bytes in size and are very similar in operation. Actually, the second one looks like a repack of the first variant in order to avoid detection. Both work through a downloader component, which connects to a set of websites and attempts to fetch a file. Just as it usually happens with Sober, the author may choose to upload a trojan with unexepected effects at the "update" URLs. We are currently monitoring them for any changes.

Below you can find the MD5's for these two new variants:

(Email-Worm.Win32.Bagle.bo)

f4271a7bd37b7502ecab0ec2964d87c6 - first sample
71379e8529c54c80ead31f5499e3406b - second sample

We released detection for the most recent version at 18:59.

[update] A description for Bagle.bo is now available in the Virus Encyclopedia.


Comments

If you would like to comment on this article you must first
login


Bookmark and Share
Share

Analysis

Blog

Alerts