Virus:TR/Bagle.95027
Date discovered:03/11/2009
Type:Trojan
In the wild:Yes
Reported Infections:Low
Distribution Potential:Low
Damage Potential:Low to medium
Static file:Yes
File size:95.027 Bytes
MD5 checksum:e483e6456eb99c156fb36e5de6df9c03
IVDF version:7.01.06.185 - Tuesday, November 3, 2009

 General Aliases:
   •  Mcafee: W32/Bagle.gen virus
   •  Sophos: Mal/Behav-191
   •  Panda: W32/Bagle.RC.worm
   •  Eset: Win32/Bagle.TK
   •  Bitdefender: Win32.Bagle.SUQ@mm


Platforms / OS:
   • Windows 2000
   • Windows XP
   • Windows 2003


Side effects:
   • Downloads malicious files
   • Drops malicious files
   • Registry modification

 Files It copies itself to the following location:
   • %HOME%\Application Data\m\flec006.exe




It tries to download some files:

– The locations are the following:
   • http://pose-service.com/1/**********
   • http://ip-kamery.com/1/**********
   • http://hot-chilli-shop.de/1/**********
   • http://www.sabasahar.com/1/**********
   • http://techart.ncompany.org/1/**********
   • http://rosengarten.webtar.hu/1/**********
   • http://www.desarroya.net/1/**********
   • http://cbhbooks.com/1/**********
   • http://ruralpoint.com/1/**********
   • http://compoundbtl.com/1/**********
   • http://bierpub.de/1/**********
   • http://checiny.pl/1/**********
   • http://1dim-giann.pel.sch.gr/1/**********
   • http://barpini.ch/1/**********
   • http://construction-barascud.com/1/**********
   • http://hoj-design.dk/1/**********
At the time of writing this file was not online for further investigation.

– The locations are the following:
   • http://jsahagung.110mb.com/**********
   • http://www.copymobil.de/**********
   • http://www.ecolubkiss.hu/**********
At the time of writing this file was not online for further investigation.

– The locations are the following:
   • http://refreshcreative.sk/1/**********
   • http://pose-service.com/1/**********
   • http://www.sabasahar.com/1/**********
   • http://tallercero.com/1/**********
   • http://rosengarten.webtar.hu/1/**********
   • http://www.enzo.pl/1/**********
   • http://barpini.ch/1/**********
   • http://1insider1.1i.funpic.de/1/**********
   • http://idealabs.tv/1/**********
   • http://compoundbtl.com/1/**********
   • http://techart.ncompany.org/1/**********
   • http://1dim-giann.pel.sch.gr/1/**********
   • http://www.desarroya.net/1/**********
   • http://ip-kamery.com/1/**********
   • http://construction-barascud.com/1/**********
At the time of writing this file was not online for further investigation.

– The location is the following:
   • http://www.copymobil.de/**********?page=404
At the time of writing this file was not online for further investigation.

 Registry One of the following values is added in order to run the process after reboot:

–  [HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
   • "mule_st_key"="%home%\Application Data\m\flec006.exe"

 File details Runtime packer:
In order to aggravate detection and reduce size of the file it is packed with a runtime packer.

Description inserted by Petre Galan on Thursday, March 4, 2010
Description updated by Petre Galan on Thursday, March 4, 2010

Back . . . .