ZeroHour
Kaspersky Securelistpublished ()ingested @Securelist

Bagles massively spammed

highMalwareimportance 42

Indicators of compromiseAll →

TypeIndicatorContext
md518ae7a2fa4dbbf703c3ae157f224186a13312 bytes File: text.exe – Email-Worm.Win32.Bagle.eg MD5: 18ae7a2fa4dbbf703c3ae157f224186a Size: 10752 bytes Latest Webinars Reports Kaspersky researc
md57b2f9ddebd027d54e36408c89804afdbmay vary) File: Loader.exe – Email-Worm.Win32.Bagle.ee MD5: 7b2f9ddebd027d54e36408c89804afdb Size: 9728 bytes File: t_535475.exe – Email-Worm.Win32.Bagl
md58275444ac2caac4b90bfd07d0b2b17be8 bytes File: t_535475.exe – Email-Worm.Win32.Bagle.ef MD5: 8275444ac2caac4b90bfd07d0b2b17be Size: 13312 bytes File: text.exe – Email-Worm.Win32.Bagle.e
Full article205 words · extracted from securelist.com · click to collapse

Malware descriptions

Malware descriptions

02 Nov 2005

minute read

Over the course of the last hours we’ve been seeing a number of new Bagles massively spammed.

They are detected as Email-Worm.Win32.Bagle.ed-eg.

As before these Bagles don’t have a functioning emailing routine.

These Bagles are likely to arrive in a .zip archive with both the archive as the executable having a random name.

Some quick info on the most common ones:(Note that filenames may vary)

File: Loader.exe – Email-Worm.Win32.Bagle.ee
MD5: 7b2f9ddebd027d54e36408c89804afdb
Size: 9728 bytes

File: t_535475.exe – Email-Worm.Win32.Bagle.ef
MD5: 8275444ac2caac4b90bfd07d0b2b17be
Size: 13312 bytes

File: text.exe – Email-Worm.Win32.Bagle.eg
MD5: 18ae7a2fa4dbbf703c3ae157f224186a
Size: 10752 bytes

Latest Webinars
Reports

Kaspersky researchers have discovered new Mirage Kitten attacks using previously undocumented malware families: NodeRabbit in Node.js and PollCat in JavaScript.

Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network connections from security tools and threat analysts.

Kaspersky experts break down a new Armored Likho campaign that poses as a fundraising efforts and delivers a new Still Toolkit aimed at stealing Telegram data and eavesdropping on victims.

Kaspersky researchers reveal previously undocumented malware attributed to Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore): NightLedger backdoor, ArcBridge, and BridgeHead tunneling tools.

Text extracted automatically; images, tables and formatting may be missing. Original: https://securelist.com/bagles-massively-spammed/30076/