BleepingComputer.com: Bagle.CZ - New variant uses CPL extension

Jump to content

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Bagle.CZ - New variant uses CPL extension

#1 User is offline   harrywaldron 

  • Security Reporter
  • PipPipPipPip
  • Find Topics
  • Group: Members
  • Posts: 509
  • Joined: 10-April 04
  • Gender:Male
  • Location:Roanoke, Virginia

Posted 12 September 2005 - 03:57 PM

Bagle.CZ - New variant uses CPL extension

This new variant was massively spammed via email and while the downloader component doesn't appear to be working, this new variant can deactivate existing AV or FW software installed on the PC. The CPL extensions are typically found inside of a zipped archieve

McAfee information on this massively spammed variant
http://vil.nai.com/vil/content/v_129588.htm

Trend information
http://secunia.com/virus_information/21411/trojbagle.cz/

Sophos information
http://www.sophos.com/virusinfo/analyses/trojdropperbc.html

ISC information
http://isc.sans.org/diary.php?storyid=665

Quote

Multiple new variants of this threat were recently mass spammed.  Filenames include 1.cpl and price.cpl and may arrive in a ZIP file named newprice.zip , price_09.zip, price some number.zip , etc

The variants seen thus far are non functional, and deemed a low risk.  The first such variant drops a corrupt file (ceeweewe.exe) to the %windir%.  The corrupt file is detected as W32/Bagle.dam.  Detection will be enhanced in the 4580 DAT release to detect and delete these newly discovered damaged variants.  This is a generic detection covering many variants of the W32/Bagle@MM virus when sent in "CPL" format.


Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users