This trojan dropper appeared on March 1st, 2005. The dropper was
spread in e-mail messages, but we are not sure whether they were
seeded e-mails or there was some Bagle variant behind that. At
the moment of creation of this description we have not seen any
Bagle variant that sends such a dropper in e-mails, however we
are seeing 2 new variants that send our similar droppers.
The dropped downloader is detected as 'Email-Worm.Win32.Bagle.bb'.
The description of the dropper and the dropped downloader can be
found here:
http://www.f-secure.com/v-descs/bagle_bb.shtml
F-Secure Anti-Virus detects this malware starting from the
following update:
[FSAV_Database_Version]
Version=2005-03-01_06
Technical Details:
Alexey Podrezov, March 1st, 2005;
Description Updated:
Alexey Podrezov, March 3rd, 2005;
F-Secure Corporation