Virus: TR/Dldr.Bagle.FO.3 Date discovered: 25/01/2006 Type: Trojan Subtype: Downloader In the wild: No Reported Infections: Low Distribution Potential: Low Damage Potential: Low to medium Static file: Yes File size: 33.741 Bytes MD5 checksum: 52678bb535c801d335090B8f5bee3e5a VDF version: 6.33.00.158
General Method of propagation: • No own spreading routine Aliases: • Symantec: W32.Imav.A • Kaspersky: Email-Worm.Win32.Bagle.fg • TrendMicro: TROJ_BAGLE.BU • F-Secure: W32/Mitglieder.HJ • Bitdefender: Win32.Bagle.GA@mm Platforms / OS: • Windows 95 • Windows 98 • Windows 98 SE • Windows NT • Windows ME • Windows 2000 • Windows XP • Windows 2003 Side effects: • Downloads files • Drops a file • Registry modification Files It copies itself to the following location: • %WINDIR% \im_1.exe The following file is created: – %SYSDIR% \im_2.exe Detected as: TR/Dldr.Bagle.FO.2 It tries to download some files: – The locations are the following: • http://www.cnsrvr.com/********** • http://www.casinofunnights.com/********** • http://www.ec.cox-wacotrib.com/********** • http://www.crazyiron.ru/********** • http://www.uni-esma.de/********** • http://www.sorisem.net/********** • http://www.varc.lv/********** • http://www.belwue.de/********** • http://www.thetildegroup.com/********** • http://www.vybercz.cz/********** • http://www.kyno.cz/********** • http://www.forumgestionvilles.com/********** • http://www.campus-and-more.com/********** • http://www.capitalforex.com/********** • http://www.capitalspreadspromo.com/********** • http://www.prineus.de/********** • http://www.databoots.de/********** • http://www.steintrade.net/********** • http://www.njzt.net/********** • http://www.emarrynet.com/********** • http://www.zebrachina.net/********** • http://www.lxlight.com/********** • http://www.yili-lighting.com/********** • http://www.fachman.com/********** • http://www.q-serwer.net/********** • http://www.wellness-i.com/********** • http://www.newportsystemsusa.com/********** • http://www.westcoastcadd.com/********** • http://www.wing49.cz/********** • http://www.posteffects.com/********** • http://www.provax.sk/********** • http://www.casinobrillen.de/********** • http://www.duodaydream.nl/********** • http://www.finlaw.ru/********** • http://www.fitdina.com/********** • http://www.flashcardplayer.com/********** • http://www.flox-avant.ru/********** • http://www.lotslink.com/********** • http://www.algor.com/********** • http://www.gaspekas.com/********** • http://www.ezybidz.com/********** • http://www.genesisfinancialonline.com/********** • http://www.georg-kuenzle.ch/********** • http://www.girardelli.com/********** • http://www.rodoslovia.ru/********** • http://www.golden-gross.ru/********** • http://www.gregoryolson.com/********** • http://www.gtechna.com/********** • http://www.lunardi.com/********** • http://www.sgmisburg.de/********** • http://www.harmony-farms.net/********** • http://www.hftmusic.com/********** • http://www.hiwmreport.com/********** • http://www.horizonimagingllc.com/********** • http://www.hotelbus.de/********** • http://www.howiwinmoney.com/********** • http://www.ietcn.com/********** • http://www.import-world.com/********** • http://www.houstonzoo.org/********** • http://www.interorient.ru/********** • http://www.internalcardreaders.com/********** • http://www.interstrom.ru/********** • http://www.iutoledo.org/********** • http://www.wena.net/********** • http://www.iesgrantarajal.org/********** • http://www.alexandriaradiology.com/********** • http://www.booksbyhunter.com/********** • http://www.wxcsxy.com/********** • http://www.coupdepinceau.com/********** • http://www.erotologist.com/********** • http://www.jackstitt.com/********** • http://www.imspress.com/********** • http://www.digitalefoto.net/********** • http://www.josemarimuro.com/********** • http://www.eversetic.com/********** • http://www.curious.be/********** • http://www.kameo-bijux.ru/********** • http://www.karrad6000.ru/********** • http://www.kaztransformator.kz/********** • http://www.keywordthief.com/********** It is saved on the local hard drive under: %system drive root% \__dwn_sp.exe At the time of writing this file was not online for further investigation. – The locations are the following: • http://www.cnsrvr.com/********** • http://www.casinofunnights.com/********** • http://www.ec.cox-wacotrib.com/********** • http://www.crazyiron.ru/********** • http://www.uni-esma.de/********** • http://www.sorisem.net/********** • http://www.varc.lv/********** • http://www.belwue.de/********** • http://www.thetildegroup.com/********** • http://www.vybercz.cz/********** • http://www.kyno.cz/********** • http://www.forumgestionvilles.com/********** • http://www.campus-and-more.com/********** • http://www.capitalforex.com/********** • http://www.capitalspreadspromo.com/********** • http://www.prineus.de/********** • http://www.databoots.de/********** • http://www.steintrade.net/********** • http://www.njzt.net/********** • http://www.emarrynet.com/********** • http://www.zebrachina.net/********** • http://www.lxlight.com/********** • http://www.yili-lighting.com/********** • http://www.fachman.com/********** • http://www.q-serwer.net/********** • http://www.wellness-i.com/********** • http://www.newportsystemsusa.com/********** • http://www.westcoastcadd.com/********** • http://www.wing49.cz/********** • http://www.posteffects.com/********** • http://www.provax.sk/********** • http://www.casinobrillen.de/********** • http://www.duodaydream.nl/********** • http://www.finlaw.ru/********** • http://www.fitdina.com/********** • http://www.flashcardplayer.com/********** • http://www.flox-avant.ru/********** • http://www.lotslink.com/********** • http://www.algor.com/********** • http://www.gaspekas.com/********** • http://www.ezybidz.com/********** • http://www.genesisfinancialonline.com/********** • http://www.georg-kuenzle.ch/********** • http://www.girardelli.com/********** • http://www.rodoslovia.ru/********** • http://www.golden-gross.ru/********** • http://www.gregoryolson.com/********** • http://www.gtechna.com/********** • http://www.lunardi.com/********** • http://www.sgmisburg.de/********** • http://www.harmony-farms.net/********** • http://www.hftmusic.com/********** • http://www.hiwmreport.com/********** • http://www.horizonimagingllc.com/********** • http://www.hotelbus.de/********** • http://www.howiwinmoney.com/********** • http://www.ietcn.com/********** • http://www.import-world.com/********** • http://www.houstonzoo.org/********** • http://www.interorient.ru/********** • http://www.internalcardreaders.com/********** • http://www.interstrom.ru/********** • http://www.iutoledo.org/********** • http://www.wena.net/********** • http://www.iesgrantarajal.org/********** • http://www.alexandriaradiology.com/********** • http://www.booksbyhunter.com/********** • http://www.wxcsxy.com/********** • http://www.coupdepinceau.com/********** • http://www.erotologist.com/********** • http://www.jackstitt.com/********** • http://www.imspress.com/********** • http://www.digitalefoto.net/********** • http://www.josemarimuro.com/********** • http://www.eversetic.com/********** • http://www.curious.be/********** • http://www.kameo-bijux.ru/********** • http://www.karrad6000.ru/********** • http://www.kaztransformator.kz/********** • http://www.keywordthief.com/********** It is saved on the local hard drive under: %WINDIR% \__dwn.exe At the time of writing this file was not online for further investigation. Registry The following registry key is added in order to run the process after reboot: – [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] • im_autorn = %SYSDIR% \im_1.exe The following registry keys are added: – [HKCU\Software\Microsoft\IME] • FirstRun = dword:00000001 – [HKLM\SOFTWARE\Microsoft\DownloadManager] File details Runtime packer: In order to aggravate detection and reduce size of the file it is packed with a runtime packer.
Description inserted by Andrei Gherman on Wednesday, February 1, 2006 Description updated by Andrei Gherman on Wednesday, February 1, 2006
Back
.
.
.
.