Articles News Reviews Releases Downloads Contact Us White Papers

Bagle worm spawns five siblings


Five variations of the Bagle worm were released over the weekend, and two of them use tricks to bypass mail filters and antivirus scanners. Five new variants of the Bagle worm were released into the wild over the weekend, with two causing particular problems for enterprise antivirus software scanner technology, say experts. Bagle versions C, D, E, F and G started propagating over the weekend and although the first three are very similar to the original Bagle -- being spread through email and infecting PCs of users who open the attachment -- Bagle.F and Bagle.G are designed to slip past most enterprise antivirus gateways.

Mikko Hypponen, head of antivirus response at Finnish security company F-Secure, told ZDNet UK that the latest variant of the Bagle family is sent inside an encrypted Zip file attached to an email that contains the password required to access the file. This means that enterprises are unlikely to detect the virus at the perimeter because .zip files are not usually blocked and the encryption means that antivirus scanners will not be able to unzip the file: "This way they get through many gateway scanners that will not be able to unzip the file to scan it."

Read Full Story


News
Firefox AJAX Security Risk
Jun 28, 2006, 06:34 EST
Data Security Grabs Attention of Lawmakers
Jun 28, 2006, 06:33 EST
Identity Theft at Work
Jun 28, 2006, 06:31 EST
Security software slaps IE in Sandbox
Jun 28, 2006, 06:26 EST
SPI simulates hackers' brains
Jun 27, 2006, 13:36 EST
UK Firms Face Threat From Self-Activating USB Data Drain
Jun 27, 2006, 13:31 EST




Site Meter