The IT Security Suite Network's Blogs
« Self Employed & Home Based Business must take IT Security very seriouslyIT Security Education and Awareness 04-09 #1 - IT Security is a people problem, not an industry one »

Conficker wakes up, updates, drops payload

Permalink 04/09/09 14:27, by Brett A. Scudder, Categories: General IT News, Updates and Information , Tags: aol, cnet, cnn, conficker, dancho danchev, ebay, msn, myspace, payload, rootkit, security, trend micro, worm

Link: http://blogs.zdnet.com/BTL/?p=16082&tag=nl.e019

Conficker wakes up, updates, drops payload
April 9th, 2009
Posted by Andrew Nusca @ 4:09 am | http://blogs.zdnet.com/BTL/?p=16082&tag=nl.e019
Categories: Security

The Conficker worm is finally active, updating via peer-to-peer between infected computers and dropping a mystery payload on infected computers, Trend Micro said on Wednesday.

CNET’s Elinor Mills reports that researchers are analyzing the code of the software that is being dropped onto infected computers and suspect that it is a keystroke logger or some other program designed to steal data from the machine.

The software appeared to be a .sys component hiding behind a rootkit, which is software that is designed to hide the fact that a computer has been compromised, according to Trend Micro. The software is heavily encrypted, which makes code analysis difficult, the researchers said.

Just yesterday, Zero Day blogger Dancho Danchev noted that a Conficker copycat was already making its rounds.

According to a post on the TrendLabs Malware blog, the awakened worm tries to connect to MySpace.com, MSN.com, eBay.com, CNN.com and AOL.com as a way to test that the computer has Internet connectivity. It then deletes all traces of itself in the host machine, and is scheduled to shut down on May 3.

Mills reports:

Because infected computers are receiving the new component in a staggered manner rather than all at once there should be no disruption to the Web sites the computers visit, said Paul Ferguson, advanced threats researcher for Trend Micro.

“After May 3, it shuts down and won’t do any replication,” Perry said. However, infected computers could still be remotely controlled to do something else, he added.

The development was found when Trend Micro researchers noticed a new file in the Windows Temp folder and a large encrypted TCP response from a known Conficker P2P IP node hosted in Korea:

Two things can be summed up from the events that transpired:

1. As expected, the P2P communications of the Downad/Conficker botnet may have just been used to serve an update, and not via HTTP. The Conficker/Downad P2P communications is now running in full swing!

2. Conficker-Waledac connection? Possible, but we still have to dig deeper into this…

As for the second point, researchers said the worm tries to access a known Waledac domain and download another encrypted file, but they’re still trying to examine the connection.

More Conficker news on ZDNet:

· Dancho Danchev: Conficker worm’s copycat Neeris spreading over IM
· Adrian Kingsley-Hughes: Friday Rant - Conficker worm hype
· Ryan Naraine: Eyeballing Conficker with eye-charts and maps
· Tom Espiner: Conficker an April Fool’s joke? Maybe not

Andrew J. Nusca is an assistant editor for ZDNet.com. See his full profile and disclosure of his industry affiliations.

1 comment »

1 comment

I have followed all things that you said. Thanks.
04/02/10 @ 10:07

Leave a comment


Your email address will not be revealed on this site.

Your URL will be displayed.
PoorExcellent
(Line breaks become <br />)
(Name, email & website)
(Allow users to contact you through a message form (your email will not be revealed.)
September 2010
Sun Mon Tue Wed Thu Fri Sat
 << <   > >>
      1 2 3 4
5 6 7 8 9 10 11
12 13 14 15 16 17 18
19 20 21 22 23 24 25
26 27 28 29 30    
Here are all The IT Security Suite Network's Blogs aggregated on this page. It automatically aggregates all posts from all other blogs. This allows you to easily track everything that is posted on this system. For specific blogs please see the various categories.

Search

Categories

TITSSN's Main Blogs Suite

TITSSN's Members and Associates Suite

The IT Security Suite Network's Chapters Suite

Events and Happenings Suite

TITSSN's Executives Suite

TITSSN's Vendors Suite

The ThreatTrix - IT Security Alerts and Info

TITSSN's Photoblog

TITSSN's Partners/Groups Suite

TITSSN's Polls

The IT Security City

Our Webcasts and Presentations

XML Feeds

TITSSN's Linkblog

blogtool