Anti-Virus specialists Sophos are warning over a new, rapidly spreading virus.
Going by the name of Bagle (which people are pronouncing Beagle), the virus arrives in an email with a simple subject line of 'Hi'.
Sophos have reported a rapid spread in Australia and are now being swamped by reports of the virus in the UK.
We here at I.T. Vibe had a few of these caught by our anti-virus as early today as 5am.
Any infected users would see the Bagle virus trying to email itself to every single one of your contacts. It would also use a fake From: address to make it harder to be traced.
Furthermore, it will start listening on TCP port 6667 for an incoming connection into which an attacker could connect and upload a malicious program.
If the attachment in the email is run, it launches the Calculator application in a bid to put people off thinking nothing has happened, or to stop their suspicions being raised.
Graham Cluley, Senior Technology Consultant at Sophos said,
"As users come back to work after the weekend they are at risk of finding the malicious Bagle worm in their email inbox. The worm pretends to be a 'techie looking' test email to fool people into running the dangerous attachment - not knowing they are potentially giving hackers the power to run destructive code on their computer."
Strangely, the Bagle virus is set to self destruct on 28th January 2004. It will cease to work at all after this date.
UPDATE: Bagle virus disinfection
|
|