New Bagle Variant Called Worst of the Year

New Bagle Variant Called Worst of the Year

Written By
Dennis Fisher
Dennis Fisher
Jul 19, 2004
2 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Another version of the tenacious Bagle virus is on the loose, and some security experts and administrators say it is among the more persistent viruses theyve seen all year.

Bagle.AI, which was discovered Monday, is quite similar to the dozens of other variants in its family, and there seems to be little reason for its success rate. It arrives via e-mail, usually with a subject line of “Re:” and a spoofed sending address. The body text is random, as is the name of the attachment.

The attachment has one of several file extensions, including .scr, .exe, .zip, .cpl and .com. In some instances, the Zip file is password-protected, in which case the body of the infected e-mail includes a password, pass and key, all of which are random numbers, according to McAfee Inc.s analysis of the worm. The name of the attachment often contains the term MP3 in one form or another.

/zimages/5/28571.gifFor insights on security coverage around the Web, check out eWEEK.com Security Center Editor Larry Seltzers Weblog.

Once it executes, Bagle.AI copies itself to the Windows System directory in a file named WinXP.exe and opens TCP port 1080 and UDP port 1040. It appears that the worm uses these ports to communicate with its creator and report back each time it infects a new machine.

McAfee, based in Santa Clara, Calif., said it received more than 150 submissions of Bagle.AI on Monday. Bill Franklin, president of Miami-based Zero Spam Network Corp., which provides a managed e-mail security and anti-spam service, said his companys servers have been bombarded by copies of the new variant all day.

“This is by far the worst one of the year,” Franklin said.

The latest member of the Bagle family is the fourth variant to be released since Thursday, when Bagle.AF hit the Internet.

/zimages/5/28571.gifCheck outeWEEK.coms Security Centerat http://security.eweek.com for security news, views and analysis.

/zimages/5/77042.gif

Be sure to add our eWEEK.com security news feed to your RSS newsreader or My Yahoo page:/zimages/5/19420.gifhttp://us.i1.yimg.com/us.yimg.com/i/us/my/addtomyyahoo2.gif

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.