Is this email a virus? (msg w/ jpeg & encrypted zip archive attachments)

Is this email a virus? (msg w/ jpeg & encrypted zip archive attachments)

Secure Home | Search | About
 General Computer Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Is this email a virus? (msg w/ jpeg & encrypted zip archive attachments) Peter Pan 07-22-2004
Posted by Peter Pan on July 22, 2004, 11:09 am
If you were  Registered and logged in, you could reply and use other advanced thread options
I received a strange email from an address I don't recorgnize. I suspect
that it is either spam or a virus, but I'm not sure. I hope somebody can
recognize it and tell me what it is (and how it is supposed to work).

The email is a short HTML message with two MIME attachements:

- a encrypted zip archive named Garry.zip
- a small jpeg file which renders to an image with the word "Key"
followed by a number

The key in the jpeg file unlocks the zip archive. The latter contains:

- an .exe file with a random-looking (alphabetic) name
- a .cfg file with a different random-looking (alphabetic) name

The content of the .cfg file is binary.

The HTML message body has almost nothing except an <img> tag referring
to the jpeg in the attachment.

Can somebody tell me what this is (and how it is supposed to work)?


Posted by Frank Slootweg on July 22, 2004, 2:09 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Most likely a virus and most likely W32/Bagle.AA.

See for example the "Virus report" of 20 Jul 2004 on
<http://metro.com.mx/virusreport/report.cfm?>.

Note: A simple Google search on "garry.zip" (without quotes) gave this
as the *second* hit (of only 23). That wasn't too hard, was it? :-(

For W32/Bagle.AA aka W32.Beagle.X@mm see
http://securityresponse.symantec.com/avcenter/venc/data/w32.beagle.x@mm.html
(again a simple search of Symantec's site on "W32/Bagle.AA" (without
quotes)).

Why don't you scan the file and see if it contains the above mentioned
virus (or any other one for that matter)?

Please also see http://www.justfuckinggoogleit.com/

> I received a strange email from an address I don't recorgnize. I suspect
> that it is either spam or a virus, but I'm not sure. I hope somebody can
> recognize it and tell me what it is (and how it is supposed to work).
>
> The email is a short HTML message with two MIME attachements:
>
> - a encrypted zip archive named Garry.zip
> - a small jpeg file which renders to an image with the word "Key"
> followed by a number
>
> The key in the jpeg file unlocks the zip archive. The latter contains:
>
> - an .exe file with a random-looking (alphabetic) name
> - a .cfg file with a different random-looking (alphabetic) name
>
> The content of the .cfg file is binary.
>
> The HTML message body has almost nothing except an <img> tag referring
> to the jpeg in the attachment.
>
> Can somebody tell me what this is (and how it is supposed to work)?


Similar ThreadsPosted
Is it safe to email scanned documents as attachments? June 21, 2008, 11:45 am
Re: New Virus/Email Worm? Retirement Subject Lines July 26, 2006, 4:58 pm
Public archive of computer viruses? April 17, 2005, 2:51 pm
Encrypted traffic November 10, 2005, 7:53 pm
pre-encrypted web pages August 2, 2007, 3:51 am
encrypted web page caching August 25, 2005, 3:24 pm
Can you keep a secret? This encrypted drive can... October 30, 2006, 11:25 pm
Standard encrypted file format? December 15, 2006, 7:38 am
Webmasterslookup launches Encrypted Messaging Service. March 10, 2008, 4:27 pm
Distribution of encrypted content and DRM - technologies( a patent spoiler?). December 2, 2005, 10:26 am

The site map in XML format XML site map

Contact Us | Privacy Policy