Fresh Bagles ahead
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| md5 | 71379e8529c54c80ead31f5499e3406b | 2.Bagle.bo) f4271a7bd37b7502ecab0ec2964d87c6 – first sample 71379e8529c54c80ead31f5499e3406b – second sample We released detection for the most recent v |
| md5 | f4271a7bd37b7502ecab0ec2964d87c6 | 5’s for these two new variants: (Email-Worm.Win32.Bagle.bo) f4271a7bd37b7502ecab0ec2964d87c6 – first sample 71379e8529c54c80ead31f5499e3406b – second sa |
Full article227 words · extracted from securelist.com · click to collapse
Two new Bagle variants have been spotted today. Both are 36352 bytes in size and are very similar in operation. Actually, the second one looks like a repack of the first variant in order to avoid detection. Both work through a downloader component, which connects to a set of websites and attempts to fetch a file. Just as it usually happens with Sober, the author may choose to upload a trojan with unexepected effects at the “update” URLs. We are currently monitoring them for any changes.
Below you can find the MD5’s for these two new variants:
(Email-Worm.Win32.Bagle.bo)
f4271a7bd37b7502ecab0ec2964d87c6 – first sample
71379e8529c54c80ead31f5499e3406b – second sample
We released detection for the most recent version at 18:59.
Latest Webinars
Reports
Kaspersky researchers have discovered new Mirage Kitten attacks using previously undocumented malware families: NodeRabbit in Node.js and PollCat in JavaScript.
Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network connections from security tools and threat analysts.
Kaspersky experts break down a new Armored Likho campaign that poses as a fundraising efforts and delivers a new Still Toolkit aimed at stealing Telegram data and eavesdropping on victims.
Kaspersky researchers reveal previously undocumented malware attributed to Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore): NightLedger backdoor, ArcBridge, and BridgeHead tunneling tools.
Text extracted automatically; images, tables and formatting may be missing. Original: https://securelist.com/fresh-bagles-ahead/30020/