Go Back   PCMech Forums > General & Off Topic > General Discussion

Need Some Help? Type Your Keywords Here:

Reply
 
LinkBack Thread Tools Search this Thread Rate Thread Display Modes
Old 03-03-2004, 11:38 AM   #1
Member (12 bit)
 
Byte 2.0's Avatar
 
Join Date: Aug 1999
Location: Secret City (Oak Ridge, TN)
Posts: 3,271
Send a message via ICQ to Byte 2.0 Send a message via AIM to Byte 2.0 Send a message via MSN to Byte 2.0 Send a message via Yahoo to Byte 2.0
W32.Beagle.A@mm is going around again

http://securityresponse.symantec.com...agle.a@mm.html


Email arrives that appears to be management@yourISP.com or .net or somethign allong those lines. I have not had time to read much but I is being checked out where I work right now. apparently there have been serveral calls in today.
__________________

Last Job ADSL Support Specialist (Tier 2), until It was outsourced overseas.
http://www.despair.com/discovery.html

A Plus Certified : Certified Help Desk Professional.
Home setup. Comcast Cable, Linksys Router, 10/100 switch, 4 wired PCs, 2 wireless laptops

vontar@gmail.com
From the Network Admin, In God We Trust, All others we monitor.

Byte 2.0 is offline   Reply With Quote
Old 03-03-2004, 06:00 PM   #2
Barefoot on the Moon!
Staff
Premium Member
 
Force Flow's Avatar
 
Join Date: Aug 2002
Location: Northeastern USA
Posts: 13,285
My ISP sent out this warning, so it must be serious

Quote:
Information Technology Services warns all users of the email system of two new worms overwhelming Internet email servers. Please promptly delete any messages with the following characteristics. Do not open the messages, and/or do not click on the attachment links.

BEAGLE.K
====================================================================
W32.Beagle.K@mm is a variant of W32.Beagle.J@mm that opens a backdoor on TCP port 2745 and uses its own SMTP engine to spread through email. It also sends the attacker the port on which the backdoor listens, as well as the IP address. W32.Beagle.J@mm also attempts to spread through file-sharing networks, such as Kazaa and iMesh, by dropping itself into the folders that contain "shar" in their names.

The email has the following characteristics:
Wrom: DDJBLVLMHAALPTCXLYRWTQTIPWIGYOKSTTZRCLBDXRQBGJSNBOHMKHJYFMYXOEAIJJPHSCRTNHGSWZIDREXCAXZOWCONEUQZAAFX ISHJE

management
administration
staff
noreply
support

Attachment: A randomly named .exe file, inside a .zip file, or an .pif file. The zip file will be password-protected.

Also Known As: Win32.Bagle.K [Computer Associates], Bagle.K [F-Secure], W32/Bagle.k@MM [McAfee], W32/Bagle.K.worm [Panda], W32/Bagle-K [Sophos], WORM_BAGLE.K [Trend Micro]

BEAGLE.J
==================================================================
W32.Beagle.J@mm is a mass-mailing worm that opens a backdoor on TCP port 2745 and uses its own SMTP engine to spread through email. It also sends the attacker the port on which the backdoor listens, as well as the IP address. W32.Beagle.J@mm also attempts to spread through file-sharing networks, such as Kazaa and iMesh, by dropping itself into the folders that contain "shar" in their names.

The email has the following characteristics:
Wrom: XXIMQZUIVOTQNQEMSFDULHPQQWOYIYZUNNYCGPKYLEJGDGVCJVTLBXFGGMEPYOQKEDOTWFAOBUZXUWLSZLKBRNVWWCUFPEGAUTFJ MVRESK

management
administration
staff
noreply
support
Attachment: A randomly named .exe file, inside a .zip file, or an .pif file. The zip file will be password-protected.

Note: LiveUpdate virus definitions released on 3/1/04 detect this threat as W32.Beagle.A@mm.

Also Known As: W32/Bagle.j@MM [McAfee]
Variants: W32.Beagle.I@mm
__________________
There are two secrets to staying young, being happy, and achieving success. You have to laugh and find humor every day, and you have to have a dream.
Force Flow is offline   Reply With Quote
Reply

Bookmarks

Still Need Help? Type Your Keywords Here:


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -5. The time now is 02:57 PM.
Powered by vBulletin® Version 3.8.6
Copyright ©2000 - 2012, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.6.0