Home » 

UK ISP News Archives

 » 
Sponsored Links

New Virus Alert W32/Bugbear.B-mm

Posted: 06th Jun, 2003 By: Anne
Anti-Virus firm MessageLabs has reported a new virus W32/Bugbear.B-mm, which was first reported on the 4th June. There have already been reports in our forums of members receiving this virus:

Email Characteristics
From the copies that we have stopped so far:
From: The sender address may be spoofed, and may not indicate the true address of the sender. The virus contains a number of domains that it appears to be capable of spoofing. Further analysis will determine whether this is the case or not.

Subject: Emails that we have thus far seen have varying subject lines, seemingly relating to information or documents plagiarized from the recipient’s infected machine.
Message Body: The body-text of the message is variable and appears to be taken from documents and files found on the recipient’s infected machine.

Attachment: The attachment is compressed in a modified UPX format. The file size is 72,192 bytes. Attachment names are also variable, possibly based on from filenames found on the infected machine with an extension of.
Either; scr, .pif or .exe

For example:
Crimbo.exe.scr,
Lotto.mbd.pif,
052003.ptx.exe,
My Money Backup.mbf.scr,
Captletterhead.doc.scr


Virus Behavior
Initial analysis suggests that the virus is a mass mailer. It appears to be very polymorphic in nature and compressed using a variant of UPX, however, it seems to have the ability to repack or modify itself during each generation, presumably in an attempt to foil simple anti-virus signature fingerprinting techniques.
In some copies that we have stopped, the MS01-020 auto-open exploit has been found, which will automatically execute the attachment just by reading the email on an unpatched Windows system.

Virus Payload
Initial analysis indicates that this virus may also be able to disarm local security software, such as anti-virus or firewall software. It may also be able to spread via network shares, as was the case with the earlier Bugbear.A strain.

Furthermore, it may also install a key-logging Trojan component that will enable an unscrupulous hacker to take control of the infected machine and download a file containing the user’s keystrokes, including information entered on websites such as passwords or credit-card details for example.

Comment
The virus includes a number of domain names that it appears to be capable of spoofing, including many major international banks, financial institutions and government authorities.

This is a particularly worrying trend in terms of the social engineering techniques now almost customary for any new virus to take hold. Not only can Bugbear leach confidential information from an infected machine, but it may also leave a backdoor wide open for hackers to take control of the machine and misappropriate passwords, credit-card details or for some other nefarious purpose.
From the pattern of Bugbear.B emails that we have stopped already this morning, we anticipate that this is likely to reach high-level outbreak very soon, particularly as the US begin to come online.

Detection
MessageLabs detected all strains of this virus proactively, using its unique and patented Skeptic™ predictive heuristics technology.
Search ISP News
Search ISP Listings
Search ISP Reviews
 Latest UK ISP News
 Cheap BIG ISPs for 100Mbps+
Community Fibre UK ISP Logo
150Mbps
Gift: None
Virgin Media UK ISP Logo
Virgin Media £26.00
132Mbps
Gift: None
Shell Energy UK ISP Logo
Shell Energy £26.99
109Mbps
Gift: None
Plusnet UK ISP Logo
Plusnet £27.99
145Mbps
Gift: None
Zen Internet UK ISP Logo
Zen Internet £28.00 - 35.00
100Mbps
Gift: None
150,000+ Customers | View More ISPs
 Cheapest ISPs for 100Mbps+
Gigaclear UK ISP Logo
Gigaclear £17.00
200Mbps
Gift: None
YouFibre UK ISP Logo
YouFibre £19.99
150Mbps
Gift: None
Community Fibre UK ISP Logo
150Mbps
Gift: None
BeFibre UK ISP Logo
BeFibre £21.00
150Mbps
Gift: £25 Love2Shop Card
Hey! Broadband UK ISP Logo
150Mbps
Gift: None
Modest Availability | View More ISPs
Cheap BIG ISPs for 100Mbps+
Community Fibre UK ISP Logo
150Mbps
Gift: None
Virgin Media UK ISP Logo
Virgin Media £26.00
132Mbps
Gift: None
Shell Energy UK ISP Logo
Shell Energy £26.99
109Mbps
Gift: None
Plusnet UK ISP Logo
Plusnet £27.99
145Mbps
Gift: None
Zen Internet UK ISP Logo
Zen Internet £28.00 - 35.00
100Mbps
Gift: None
Large Availability | View All
Cheapest ISPs for 100Mbps+
Gigaclear UK ISP Logo
Gigaclear £17.00
200Mbps
Gift: None
YouFibre UK ISP Logo
YouFibre £19.99
150Mbps
Gift: None
Community Fibre UK ISP Logo
150Mbps
Gift: None
BeFibre UK ISP Logo
BeFibre £21.00
150Mbps
Gift: £25 Love2Shop Card
Hey! Broadband UK ISP Logo
150Mbps
Gift: None
Large Availability | View All

Helpful ISP Guides and Tips

Sponsored Links
The Top 15 Category Tags
  1. FTTP (5513)
  2. BT (3514)
  3. Politics (2535)
  4. Openreach (2297)
  5. Business (2261)
  6. Building Digital UK (2243)
  7. FTTC (2043)
  8. Mobile Broadband (1972)
  9. Statistics (1788)
  10. 4G (1663)
  11. Virgin Media (1619)
  12. Ofcom Regulation (1460)
  13. Fibre Optic (1394)
  14. Wireless Internet (1389)
  15. FTTH (1381)
Sponsored

Copyright © 1999 to Present - ISPreview.co.uk - All Rights Reserved - Terms  ,  Privacy and Cookie Policy  ,  Links  ,  Website Rules