Bagles massively spammed
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| md5 | 18ae7a2fa4dbbf703c3ae157f224186a | 13312 bytes File: text.exe – Email-Worm.Win32.Bagle.eg MD5: 18ae7a2fa4dbbf703c3ae157f224186a Size: 10752 bytes Latest Webinars Reports Kaspersky researc |
| md5 | 7b2f9ddebd027d54e36408c89804afdb | may vary) File: Loader.exe – Email-Worm.Win32.Bagle.ee MD5: 7b2f9ddebd027d54e36408c89804afdb Size: 9728 bytes File: t_535475.exe – Email-Worm.Win32.Bagl |
| md5 | 8275444ac2caac4b90bfd07d0b2b17be | 8 bytes File: t_535475.exe – Email-Worm.Win32.Bagle.ef MD5: 8275444ac2caac4b90bfd07d0b2b17be Size: 13312 bytes File: text.exe – Email-Worm.Win32.Bagle.e |
Full article205 words · extracted from securelist.com · click to collapse
Over the course of the last hours we’ve been seeing a number of new Bagles massively spammed.
They are detected as Email-Worm.Win32.Bagle.ed-eg.
As before these Bagles don’t have a functioning emailing routine.
These Bagles are likely to arrive in a .zip archive with both the archive as the executable having a random name.
Some quick info on the most common ones:(Note that filenames may vary)
File: Loader.exe – Email-Worm.Win32.Bagle.ee
MD5: 7b2f9ddebd027d54e36408c89804afdb
Size: 9728 bytes
File: t_535475.exe – Email-Worm.Win32.Bagle.ef
MD5: 8275444ac2caac4b90bfd07d0b2b17be
Size: 13312 bytes
File: text.exe – Email-Worm.Win32.Bagle.eg
MD5: 18ae7a2fa4dbbf703c3ae157f224186a
Size: 10752 bytes
Latest Webinars
Reports
Kaspersky researchers have discovered new Mirage Kitten attacks using previously undocumented malware families: NodeRabbit in Node.js and PollCat in JavaScript.
Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network connections from security tools and threat analysts.
Kaspersky experts break down a new Armored Likho campaign that poses as a fundraising efforts and delivers a new Still Toolkit aimed at stealing Telegram data and eavesdropping on victims.
Kaspersky researchers reveal previously undocumented malware attributed to Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore): NightLedger backdoor, ArcBridge, and BridgeHead tunneling tools.
Text extracted automatically; images, tables and formatting may be missing. Original: https://securelist.com/bagles-massively-spammed/30076/