Trend Micro Facebook TrendLabs Twitter Malware Blog RSS Feed You Tube - Trend Micro
Search our blog:

  • Recent Posts

  • Calendar

    February 2012
    S M T W T F S
    « Jan    
     1234
    567891011
    12131415161718
    19202122232425
    26272829  
  • About Us
    Malware Blog > Bagle Returns…

    Dec4
    10:53 am (UTC-7)   |    by

    Just a heads up…last Dec 1, we saw a lot of the bagle worm being spammed through e-mails. Trend Micro saw to this and has created detection as WORM_BAGLE.GS.


    This new bagle has all the techniques that a WORM_BAGLE should have, from the password protected file to a decoy text file to rootkits, to see a more technical analysis please check the malware report that was created here.


    I checked the download site again today, and what do you know, it’s still there! It has very minor tweaks in its body just to change the md5 sum in its effort to avoid detection.


    Trend Micro customers need not to worry though as we have already created solutions for this particular sample.


    Admins might also want to block www.bronko-m.ru, this is the domain of the download URL of WORM_BALGE.GS.





    Share this article
    Get the latest on malware protection from TrendLabs
    Email this story to a friend   Technorati   NewsVine   MySpace   Google   Live   del.icio.us   StumbleUpon




    Comments are closed.



     

    © Copyright 2011 Trend Micro Inc. All rights reserved. Legal Notice