This variant of Bagle sends variable emails, some of which contain
password-protected ZIP files, with messages such as:
From: random-email@address
To: address@f-secure.com
Subject: rebecca
If I'm online, it problably means I'm pretty bored....
so feel free to message me and say hi or whatever else comes to mind at the moment.
archive password: 06458
Attachment: Mary.zip (encrypted with password 06458)
The worm also has a block of random data in it, making the virus (and the zip files)
variable.
Other possible subject fields include:
Audra
Bad girl
beautiful
Caitie
Fotograf
Gallery photos
groom
Juli
kate
My Name is Frenk
Katrina
Kelley
kleopatra
Mandy
Mary-Anne
My photos
Myphotos
Photoalbum
Tammy
The message and attachment name varies too, but attachment is typically EXE or SCR,
which then might be Zipped.
The icon of the infected attachments looks like a folder, making it easy to double-click
on it by accident