W32/Bagle.ai Virus Now Spreading in the Wild Reports MessageLabs
NEW YORK--(BUSINESS WIRE)--July 19, 2004--Over the last few hours, MessageLabs, the leading provider of managed email security services to businesses worldwide, has intercepted more than 17,615 copies of the latest variant of Bagle, W32.Bagle.ai@mm.
More than 15,000 copies of the virus were intercepted within the 45 minutes of the virus being detected by MessageLabs' proprietary Skeptic technology.
Name: W32/Bagle.ai@mm
Number of copies intercepted so far: 17,615+
Time & date first captured: July 19, 2004; 11:22 ET
Origin of first intercepted copy: UK
General Information
Bagle.ai is a mass-mailing worm with its own SMTP mass-mailing engine that harvests addresses from infected machines and includes a remote access program. The virus is being sent with multiple attachment types. In some cases, the body of the message contains a password for attached password-protected ZIP files. The virus can copy itself to file sharing folders common, for example, with peer-to-peer networks, and can terminate existing security applications processes.
Attachment names (with com, cpl, exe, scr, zip extensions) are:
-- Cat
-- Cool_MP3
-- Dog
-- Doll
-- Fish
-- Garry
-- MP3
-- Music_MP3
Email Characteristics
From: Random, spoofed email address
Subject: Random
Size: Varies
MessageLabs is in the process of confirming spreading methods, which may include peer-to-peer networks.
Detection
MessageLabs detected all strains of this virus proactively, using its unique and patented Skeptic(TM) predictive heuristics technology.
About MessageLabs
MessageLabs is the leading provider of managed email security services to businesses worldwide. The company currently protects more than 8,500 businesses worldwide from email threats such as viruses, spam and other unwanted content before they reach their networks and without requiring additional hardware or software. Powered by a global network of control towers that currently spans the United States, the United Kingdom, Germany, the Netherlands and Hong Kong, MessageLabs scans tens of millions of emails a day on behalf of customers such as The British Government, The Bank of New York, EMI Music, HealthPartners, StorageTek, Air Products and Chemicals, SC Johnson, Conde Nast Publications, Fujitsu and Diageo. For more information on MessageLabs and its industry-leading email security and management services, please visit: www.messagelabs.com.
Contacts
Magnet Communications
Shelley Driscoll, 212-367-6898
sdriscoll@magnet.com
or
MessageLabs
Lori Sinsley, 646-519-8149
lsinsley@messagelabs.com
[ Comment, Edit or Article Submission ]