Sophos

Talk to our experts

Find your local press contact

Resources

Info feeds

What are info feeds?

27 January 2004

New Bagle-A worm arrives in Australia

Sophos, a world leader in protecting businesses against spam and viruses, is warning of a new worm called W32/Bagle-A, which has already been spotted at a number of sites in Australia. The worm arrives in an email with the subject "Hi", and contains a message which looks like this:

Test =)
[random characters]
--
Test, yep.

Attached to the email is a program file with a random name. This file has the icon of the Windows Calculator, and if you run it, the calculator will indeed pop up on your screen - after the worm has gone to work. The worm saves itself into your System folder under the name "bbeagle.exe".

"The Bagle worm disguises itself as a 'techie-looking' test email," warns Sean Richmond, Sophos's Support Manager for Australia and New Zealand.

"The attachment it carries looks like the Windows Calculator, and appears to behave like the calculator - but it isn't. You should be wary of any programs delivered to you by email, even if they seem to come from someone you know. If you are an IT techie who likes to email programs around, you should get out of the habit, as it sets low standards for your users."

Sophos has published information about and protection against this worm.

Sophos recommends the use of email gateway software such as Sophos MailMonitor and Sophos PureMessage, which can block all programs, whether infected or not, in order to enforce safe computing practices. Further guidelines for "safe hex" are available from Sophos.

  • USA number 1 for malware and spam
  • Huge surge in email attachment attacks
  • Scareware makes users buy bogus products

About Sophos

Sophos enables enterprises all over the world to secure and control their IT infrastructure. Sophos's network access control, endpoint, web and email solutions simplify security to provide integrated defenses against malware, spyware, intrusions, unwanted applications, spam, policy abuse, data leakage and compliance drift. With over 20 years of experience, Sophos protects over 100 million users in nearly 150 countries with its reliably engineered security solutions and services. Recognized for its high level of customer satisfaction and powerful yet easy-to-use solutions, Sophos has received many industry awards, as well as positive reviews and certifications.

Sophos is headquartered in Boston, US and Oxford, UK. More information is available at www.sophos.com