Advertisement
  • Networking
  • Storage
  • Security
  • Mobility and Wireless
  • Applications
  • OS and Servers
  • Mid-sized Business
  • Green IT

Home | News | Insight | How-tos | Case studies | Interviews | Briefings | Reviews | Blog

Computer & Internet Security News

06 March 2007

Bagle worm still swarming over Net

By John E. Dunn, Techworld

The Bagle worm continues to plague the Internet over three years after it first appeared, with many anti-virus engines unable to keep up, a security vendor has claimed.

Advertisement

In an analysis of the phenomenon released this week, Commtouch Software said its virus outbreak detection research Labs (VRDL) were still finding an average of 625 new variants of the mass-mailing worm per day, or up to 1,000 on peak days. The total number of new variants – defined as versions giving differing MD5 checksums – now stood at over 30,000 since the beginning of 2007 alone.

According to the company, the sheer volume of new variants means that traditional anti-virus and heuristic scanners were now unable to cope with the malware flood. That Bagle (or ‘Bagel’ as it is sometimes named) was now exploiting “stealth outbreaks”, whereby small numbers of a new variant were distributed in such a way as to exploit a window of opportunity before being spotted, had only made matters even worse.

Commtouch doesn’t offer any evidence that rival security products can’t detect the large number of polymorphic variants, though it seems likely that even these occurrences have common features that make them stand out.

The ultimate purpose of the vast Bagle family is, as ever, the distribution of spam, which goes a long way to explaining its continued popularity. It could even be the most successful piece of malware in computing history.

Having first appeared in January 2004, it has continued to appear in large volumes though at low risk levels. Since then, it has continued to make a nuisance of itself at regular intervals.

What is this?

back to index

Comments

What are your views on this subject? Use the form below to post a comment on this article up to 1000 characters.



Advertisement
Advertisement
IDG Connect UK
  • Strategies for Deploying Blade Servers in Existing Data Centers
    Installing blade servers in an existing data center creates a bewildering set of challenges and options. The white paper from American Power Conversion (APC), explains how options are evaluated and selected for a successful and predictable blade deployment.
  • Enabling Technology for Blade I/O Virtualization
    The BladeSystem c-Class portfolio was designed to address some of the key total cost of ownership (TCO) issues facing today’s datacenter, including server management costs, utilization, and power and cooling. In this technology brief, IDC examines HP Virtual Connect and the benefits and challenges associated with using this technology to virtualize I/O with HP BladeSystems.

Techworld topic pages