W32/Bagle.A@mm
| W32/Bagle.A@mm |
Destructivity: |
| • Detected by virus detection files published: 1/19/2004 | • Type: Worm |
| • Virus characteristics first published: 1/19/2004 | • Spreading mechanism: Email |
| • Virus characteristics latest update: 2/22/2007 | • Overall risk: Low |
| • Alias: | • Payload: Possible backdoor/update functionality |
| • Infection type: Microsoft Windows 95/98/98 SE/ME/NT 4/2000/XP/2003/Vista |
| Virus type |
Spreading mechanism |
Destructivity and payload |
Additional descriptions |
Detection and removal |
||||||||||
|
The worm sets up a thread on port 6777, listening for incoming connections. It is likely that this is a part of some update functionality. There is a list of web addresses in the worm body: http://www.elrasshop.de/1.php The worm will attempt to contact these sites with parameters describing port number it listens to and the user ID (which is a random string). The mentioned php script is however not present at any of the tested sites. |
||||||||||||||