Skip to main content

Beglur

Classification

Category:

Malware

Type:

Worm

Aliases:

  • Beglur
  • I-Worm.Beglur

Summary

Beglur is a mass-mailer that spreads as an attachment to emails mentioning Saddam Hussein and Osama Bin Laden. The worm uses IFrame exploit to automatically start its attachments on recipients' computers.

Removal

Technical Details

The worm's file is a Windows PE executable 8774 bytes long packed with UPX file compressor. The unpacked file size is about 27 kilobytes.

When the worm's file is started, it copies itself to Windows System folder as BGLR32.EXE and modifies SHELL= variable in SYSTEM.INI file or System Registry (depending on Windows version) to be always run with Windows.

Then the worm starts to scan all files on a C: drive. If it finds files with the following extensions:

.TXT .MHT .HTM .HTML .EML .JSE .ASP

the worm will look for email addresses inside those files.

The worm gets information about user's SMTP server address from the Registry. If this information is unavailable, the worm tries to use the following SMTP server:

smtp.hotpop.com

email messages sent by the worm look like that:

From:

Baath [baath@iraq.com]

Subject:

For World of Peace!

Body:

Saddam Hussien has been captured but Osama Bin Laden still have a power and US will never captured this person until somebody captured Bush. God Bless You!! A.Q.T.E

Attachment:

BGLR32.EXE

The worm uses IFrame exploit that allows the infected attachment to start automatically on older and unpatched versions of certain email clients.

Protect your devices from malware with F‑Secure Total

Protecting your devices from malicious software is essential for maintaining online security. F‑Secure Total makes this easy, helping you to secure your devices in a brilliantly simple way.

  • Award‑winning antivirus and malware protection

  • Online browsing, banking, and shopping protection

  • 24/7 online identity and data breach monitoring

  • Unlimited VPN service to safe­guard your privacy

  • Password manager with private data protection

Choose how many devices you want to protect to get started.

  • Free customer support

  • Cancel anytime

  • The trial does not obligate you to buy the product

After 30 days your subscription will renew automatically for one year at €69.99.

More Support

Community

Ask questions in our Community.

User guides

Check the user guide for instructions.

Contact Support

Chat with with or call an agent.

Submit a Sample

Submit a file or URL for analysis.