{"id":7189,"date":"2004-03-03T18:20:32","date_gmt":"2004-03-03T23:20:32","guid":{"rendered":"http:\/\/www.ezrasf.com\/wplog\/?p=7189"},"modified":"2013-06-29T18:30:11","modified_gmt":"2013-06-29T22:30:11","slug":"worm_bagle-j","status":"publish","type":"post","link":"https:\/\/www.ezrasf.com\/wplog\/2004\/03\/03\/worm_bagle-j\/","title":{"rendered":"WORM_BAGLE.J"},"content":{"rendered":"<p>There seem to be a ton of computer worm variants hitting the Internet lately. Kudos to those technicians putting in overtime to identify them.<\/p>\n<p>My favorite social engineering worm (at the moment) is\u00c2\u00a0<a href=\"http:\/\/www.trendmicro.com\/vinfo\/virusencyclo\/default5.asp?VName=WORM_BAGLE.J\" target=\"_new\">WORM_BAGLE.J<\/a>\u00c2\u00a0(aka W32\/Bagle-J).<\/p>\n<blockquote><p>Dear user of e-mail server &#8220;___&#8221;,<\/p>\n<p>Our antivirus software has detected a large ammount of viruses outgoing from your email account, you may use our free anti-virus tool to clean up your computer software.<\/p>\n<p>Further details can be obtained from attached file.<\/p>\n<p>Sincerely,<\/p>\n<p>The __ team http:\/\/www.domain.com<\/p><\/blockquote>\n<p>The clueless user clicks on the attachment (the virus) and infects the computer. Brilliant! Some days it sucks to read IT help desk email.<\/p>\n<p>There are of course other messages the outgoing email could use. I just can see a large number of people reading the one above and getting conned.<\/p>\n<hr \/>\n<p>Preserved comments:<\/p>\n<ul>\n<li>\n<div id=\"ctext-118851864\">It&#8217;s weird &#8211; I&#8217;ve already received 3 of these just since reading about this&#8230;and so have a few of my coworkers. They&#8217;re already cleaned &#8211; but still. Very tricky jerks these wormers.<\/div>\n<div>Posted 3\/3\/2004 9:25 AM by\u00c2\u00a0<a href=\"http:\/\/freekycheek.xanga.com\/\">freekycheek<\/a><\/div>\n<\/li>\n<li>\n<div id=\"ctext-118875728\">\n<p>Yeah. I had only gotten one at the time I wrote it. Since I have gotten another 8 emails.<\/p>\n<p>Of course, variants B,C, and D of another virus Netsky have been upgraded to medium threats which means they are more widespread. Betting Bagle.J will hit medium by tonight and high by the end of the week.<\/p>\n<p>Damn. If I could make $50 off everyone needing their machine cleaned and hire a 1\/2 dozen people to work for me, then I&#8217;d e rolling in the dough.<\/p>\n<\/div>\n<div>Posted 3\/3\/2004 11:26 AM by <a href=\"http:\/\/sneezypb.xanga.com\/\">sneezypb<\/a><\/div>\n<\/li>\n<li>\n<div id=\"ctext-119056208\">Yep&#8230;it made it to our office apparently.<\/div>\n<div>Posted 3\/3\/2004 7:46 PM by anonymous<\/div>\n<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>There seem to be a ton of computer worm variants hitting the Internet lately. Kudos to those technicians putting in overtime to identify them. My favorite social engineering worm (at the moment) is\u00c2\u00a0WORM_BAGLE.J\u00c2\u00a0(aka W32\/Bagle-J). Dear user of e-mail server &#8220;___&#8221;, Our antivirus software has detected a large ammount of viruses outgoing from your email account, [&hellip;]<\/p>\n","protected":false},"author":11,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"activitypub_content_warning":"","activitypub_content_visibility":"","activitypub_max_image_attachments":4,"activitypub_interaction_policy_quote":"anyone","activitypub_status":"","footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2},"jetpack_post_was_ever_published":false},"categories":[1198],"tags":[],"class_list":["post-7189","post","type-post","status-publish","format-standard","hentry","category-cybersecurity"],"jetpack_publicize_connections":[],"jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p1rUBW-1RX","jetpack-related-posts":[],"jetpack_likes_enabled":true,"jetpack_featured_media_url":"","_links":{"self":[{"href":"https:\/\/www.ezrasf.com\/wplog\/wp-json\/wp\/v2\/posts\/7189","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.ezrasf.com\/wplog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.ezrasf.com\/wplog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.ezrasf.com\/wplog\/wp-json\/wp\/v2\/users\/11"}],"replies":[{"embeddable":true,"href":"https:\/\/www.ezrasf.com\/wplog\/wp-json\/wp\/v2\/comments?post=7189"}],"version-history":[{"count":0,"href":"https:\/\/www.ezrasf.com\/wplog\/wp-json\/wp\/v2\/posts\/7189\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.ezrasf.com\/wplog\/wp-json\/wp\/v2\/media?parent=7189"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.ezrasf.com\/wplog\/wp-json\/wp\/v2\/categories?post=7189"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.ezrasf.com\/wplog\/wp-json\/wp\/v2\/tags?post=7189"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}