W32/Bagle.X@mm

description-logoAnalysis


Specifics
Trojan is 32-bit and is a variant of the W32/Mitglieder family. The Mitglieder Trojan and the Bagle virus families share some code and structure. This Trojan functions as an SMTP mail relay on a compromised system.


Loading At Windows Startup
If the Trojan is run, it will copy itself into the System32 folder -

C:\WINNT\System32\WINDOW.exe

The Trojan will register to auto run at next Windows startup as in this example -

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\
"window.exe" = C:\WINNT\System32\window.exe


SMTP Proxy/Remote Access Capability
This Trojan will bind to randomly selected TCP port and await connection from a malicious user. It would be possible to telnet to a compromised system and issue SMTP commands and carry out SMTP delivery via the Trojan's SMTP proxy code.

The Trojan will attempt to notify its presence by connecting to compromised web servers and using a server-side script named "host.php", the Trojan will submit the TCP port in use and the IP address of the compromised system. These are the list of web addresses which are storing the server-side script "host.php" -

http://bohema.amillo.net
http://abc517.net
http://www.abc986.net


recommended-action-logoRecommended Action

  • Check the main screen using the web interface for your FortiGate unit to ensure that the latest AV/NIDS database has been downloaded and installed on your system - if required, enable the "Allow Push Update" option
  • Using the FortiGate manager, enable blocking these web addresses -

    http://bohema.amillo.net
    http://abc517.net
    http://www.abc986.net

Telemetry logoTelemetry

Detection Availability

FortiClient
Extreme
FortiMail
Extreme
FortiSandbox
Extreme
FortiWeb
Extreme
Web Application Firewall
Extreme
FortiIsolator
Extreme
FortiDeceptor
Extreme
FortiEDR

Version Updates

Date Version Detail
2023-05-23 91.03526
2023-05-15 91.03286
2023-04-04 91.02060
2023-04-04 91.02052
2023-04-03 91.02015
2023-02-06 91.00334
2023-01-06 90.09401
2021-09-21 89.02510
2021-07-15 87.00640
2018-11-20 64.31700 Sig Updated