HarBag.A is Trojan that searches for email addresses in files with the following extensions: ADB, ASP, CFG, CGI, DBX, DHTM, EML, HTM, JSP, MBX, MDX, MHT, MMF, MSG, NCH, ODS, OFT, PHP, SHT, SHTM, STM, TBB, TXT, UIN, WAB, WSH, XLS and XML. Then, it sends the addresses it has gathered using the POST method of the HTTP protocol to a certain URL. These email addresses are used to send new variants of the worm Bagle. HarBag.A does not spread automatically using its own means. It needs an attacking user's intervention in order to reach the affected computer. > |