Virus: TR/Bagle.95027 Date discovered: 03/11/2009 Type: Trojan In the wild: Yes Reported Infections: Low Distribution Potential: Low Damage Potential: Low to medium Static file: Yes File size: 95.027 Bytes MD5 checksum: e483e6456eb99c156fb36e5de6df9c03 IVDF version: 7.01.06.185 - Tuesday, November 3, 2009
General Aliases: • Mcafee: W32/Bagle.gen virus • Sophos: Mal/Behav-191 • Panda: W32/Bagle.RC.worm • Eset: Win32/Bagle.TK • Bitdefender: Win32.Bagle.SUQ@mm Platforms / OS: • Windows 2000 • Windows XP • Windows 2003 Side effects: • Downloads malicious files • Drops malicious files • Registry modification Files It copies itself to the following location: • %HOME%\Application Data\m\flec006.exe It tries to download some files: – The locations are the following: • http://pose-service.com/1/********** • http://ip-kamery.com/1/********** • http://hot-chilli-shop.de/1/********** • http://www.sabasahar.com/1/********** • http://techart.ncompany.org/1/********** • http://rosengarten.webtar.hu/1/********** • http://www.desarroya.net/1/********** • http://cbhbooks.com/1/********** • http://ruralpoint.com/1/********** • http://compoundbtl.com/1/********** • http://bierpub.de/1/********** • http://checiny.pl/1/********** • http://1dim-giann.pel.sch.gr/1/********** • http://barpini.ch/1/********** • http://construction-barascud.com/1/********** • http://hoj-design.dk/1/********** At the time of writing this file was not online for further investigation. – The locations are the following: • http://jsahagung.110mb.com/********** • http://www.copymobil.de/********** • http://www.ecolubkiss.hu/********** At the time of writing this file was not online for further investigation. – The locations are the following: • http://refreshcreative.sk/1/********** • http://pose-service.com/1/********** • http://www.sabasahar.com/1/********** • http://tallercero.com/1/********** • http://rosengarten.webtar.hu/1/********** • http://www.enzo.pl/1/********** • http://barpini.ch/1/********** • http://1insider1.1i.funpic.de/1/********** • http://idealabs.tv/1/********** • http://compoundbtl.com/1/********** • http://techart.ncompany.org/1/********** • http://1dim-giann.pel.sch.gr/1/********** • http://www.desarroya.net/1/********** • http://ip-kamery.com/1/********** • http://construction-barascud.com/1/********** At the time of writing this file was not online for further investigation. – The location is the following: • http://www.copymobil.de/**********?page=404 At the time of writing this file was not online for further investigation. Registry One of the following values is added in order to run the process after reboot: – [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] • "mule_st_key"="%home% \Application Data\m\flec006.exe" File details Runtime packer: In order to aggravate detection and reduce size of the file it is packed with a runtime packer.
Description inserted by Petre Galan on Thursday, March 4, 2010 Description updated by Petre Galan on Thursday, March 4, 2010
Back
.
.
.
.