AplusWebMaster
Topic Starter
FYI…
- http://www.f-secure.com/weblog/archives/ar…6.html#00001036
November 30, 2006
"We haven't seen new Bagle attacks in a while. Last one - and even that was an isolated one - was exactly a month ago. But now something's up. Some of the old Bagle update URLs activated tonight, offering a new 188kB executable. This is downloaded and run by machines infected by previous Bagle variants… and it starts to spam out infected attachments with filenames talking about price lists. The spammed emails include a GIF which shows a password needed to decode the ZIPs files. When the email attachment is decoded and run by the user, the worm runs (as a decoy) either Notepad or Registry Editor. Notepad will display a fake error message…"
(Screenshots available at the URL above.)

- http://www.f-secure.com/weblog/archives/ar…6.html#00001036
November 30, 2006
"We haven't seen new Bagle attacks in a while. Last one - and even that was an isolated one - was exactly a month ago. But now something's up. Some of the old Bagle update URLs activated tonight, offering a new 188kB executable. This is downloaded and run by machines infected by previous Bagle variants… and it starts to spam out infected attachments with filenames talking about price lists. The spammed emails include a GIF which shows a password needed to decode the ZIPs files. When the email attachment is decoded and run by the user, the worm runs (as a decoy) either Notepad or Registry Editor. Notepad will display a fake error message…"
(Screenshots available at the URL above.)