WORM_BAGLE.GEN-1

 Analysis by: Rhena Inocencio

 ALIASES:

W32.Beagle@mm!zip(Symantec), W32/Bagle-Zip(Sophos), Email-Worm.Win32.Bagle.gen(Kaspersky), Worm/Bagle.AI(Avira), W32/Bagle@MM!pwdzip(McAfee)

 PLATFORM:

Windows 2000, Windows XP, Windows Server 2003

 OVERALL RISK RATING:
 DAMAGE POTENTIAL:
 DISTRIBUTION POTENTIAL:
 REPORTED INFECTION:

  • Threat Type: Worm

  • Destructiveness: No

  • Encrypted:

  • In the wild: Yes

  OVERVIEW

This worm arrives as an attachment to email messages spammed by other malware/grayware or malicious users.

  TECHNICAL DETAILS

File Size:

12,420 bytes

File Type:

ZIP

Initial Samples Received Date:

04 Sep 2006

Arrival Details

This worm arrives as an attachment to email messages spammed by other malware/grayware or malicious users.

NOTES:
This is Trend Micro's detection for password-protected ZIP-compressed copies of the following WORM_BAGLE variants:

Files detected as this malware are compressed and must be extracted before they can execute. If they are ever executed on a system, Trend Micro antivirus will detect the extracted or decompressed files as the specific variants listed above.