In the last 2 hours I can see something new.
F-Prot is
catching it with result code 8 as unknown virus
Looking
at the first examples:
Subject: a random name like Alice, Emanuel,
Martha, Cybil, Ester, ....
Body: empty html
Attachment: ZIP-file with
another random name like them in the subject line
Inside the ZIP is an
exe-file 1.exe
The entire message has around 10 kByte
Virustotal
result says
This is a report processed by VirusTotal on 11/23/2005 at 18:40:34 (CET) after
scanning the file "Emanuel.zip" file.
| Antivirus | Version | Update | Result |
| AntiVir | 6.32.0.6 | 11.23.2005 | TR/Bagle.EC |
| Avast | 4.6.695.0 | 11.23.2005 | Win32:Beagle-FR |
| AVG | 718 | 11.23.2005 | I-Worm/Bagle |
| Avira | 6.32.0.6 | 11.23.2005 | TR/Bagle.EC |
| BitDefender | 7.2 | 11.23.2005 | Trojan.Downloader.Bagle.F |
| CAT-QuickHeal | 8.00 | 11.23.2005 | (Suspicious) - DNAScan |
| ClamAV | devel-20051108 | 11.23.2005 | Worm.Bagle.Gen-9 |
| DrWeb | 4.33 | 11.23.2005 | Win32.HLLM.Beagle.9219 |
| eTrust-Iris | 7.1.194.0 | 11.23.2005 | no virus found |
| eTrust-Vet | 11.9.1.0 | 11.23.2005 | no virus found |
| Fortinet | 2.48.0.0 | 11.23.2005 | suspicious |
| F-Prot | 3.16c | 11.23.2005 | security risk named W32/Mitglieder.GH |
| Ikarus | 0.2.59.0 | 11.23.2005 | no virus found |
| Kaspersky | 4.0.2.24 | 11.23.2005 | Trojan-Downloader.Win32.Bagle.f |
| McAfee | 4634 | 11.22.2005 | no virus found |
| NOD32v2 | 1.1300 | 11.23.2005 | Win32/Bagle.DR |
| Norman | 5.70.10 | 11.23.2005 | W32/[EMAIL PROTECTED] |
| Panda | 8.02.00 | 11.23.2005 | no virus found |
| Sophos | 3.99.0 | 11.23.2005 | no virus found |
| Symantec | 8.0 | 11.22.2005 | no virus found |
| TheHacker | 5.9.1.043 | 11.23.2005 | Trojan/Downloader.Bagle.f |
| VBA32 | 3.10.5 | 11.23.2005 | suspected of Email-Worm.Bagle.22 |
