Curly Howard
04-22-2004, 08:25 AM
I got an email from K-1 like I usually do and it had a zip file that said gift.zip
It's a virus. Guess their server is infected.
http://www.globalmma.com/Curly/k1virus.jpg
----------------------------------------------------------------------
I-Worm/Bagle
This worm spreads by emails as a message attachment.
I-Worm/Bagle.A
Installation:
When the worm is launched it checks actual date and if the date is later than January 28th 2004, it does nothing. In other case virus copies itself as bbeagle.exe to System Directory and registers itself as d3dupdate.exe in Run key in Windows Registry. Then it launches calc.exe too.
Spreading: e-mail
Worm spreads by sending itself to e-mail addresses that are taken from files with WAB, TXT, HTM and HTML extension, sender address is faked.
Message format is as following:
Subject:
Hi
Body:
Test =)
--
Test, yep.
Attachment name is random.
Backdoor:
Virus is listening and waiting for commands on port 6777. Virus also tries to download the file from web pages coded in virus body, but these pages aren`t accessible at this time.
It's a virus. Guess their server is infected.
http://www.globalmma.com/Curly/k1virus.jpg
----------------------------------------------------------------------
I-Worm/Bagle
This worm spreads by emails as a message attachment.
I-Worm/Bagle.A
Installation:
When the worm is launched it checks actual date and if the date is later than January 28th 2004, it does nothing. In other case virus copies itself as bbeagle.exe to System Directory and registers itself as d3dupdate.exe in Run key in Windows Registry. Then it launches calc.exe too.
Spreading: e-mail
Worm spreads by sending itself to e-mail addresses that are taken from files with WAB, TXT, HTM and HTML extension, sender address is faked.
Message format is as following:
Subject:
Hi
Body:
Test =)
--
Test, yep.
Attachment name is random.
Backdoor:
Virus is listening and waiting for commands on port 6777. Virus also tries to download the file from web pages coded in virus body, but these pages aren`t accessible at this time.