NEWS FROM THE LAB - Friday, August 12, 2005

Two certain things in life: Bagle and taxes Posted by Mikko @ 04:47 GMT

Series of Bagle variants has been released over the last 16 hours. We detect them as Email-Worm.Win32.Bagle.cb, .cc, .cd, .ce, .cf, .cg and .ch.

These are minor variants of each other, sending emails with attachments related to Taxation, such as The_reporting_of_taxes.zip or To_reduce_the_tax.zip. Once again, these archives contain executable files with misleading icons.

Some of the archives are ZIP files, some of them are RAR files and some of them are ZIP files with a .RAR extension. The wrong extension is used by the virus apparently because some gateway filters might fail to unpack such files while many unpackers used by end users will unpack them fine.

For the record: F-Secure Internet Gatekeeper, F-Secure Anti-Virus for Microsoft Exchange and F-Secure Anti-Virus for Firewalls are able to unpack such archives fine.