Bagle.M/N/O variants discovered
Sunday March 14, 2004
Three new variants of the Bagle worm have been discovered over the weekend: Bagle.M, Bagle.N, and Bagle.O. Unlike its predecessors, Bagle.N includes a polymorphic routine infecting PE_EXE files on affected systems. Bagle.N also includes a much more extensive list of security processes it attempts to shutdown. Bagle.N may arrive as a PIF, EXE, ZIP or RAR attachment. When sent as a ZIP or RAR, the file will be password protected. The password is included in an image file also attached which may display inline, depending on the mail reader.


No comments yet. Leave a Comment