Advertisement
Promo

Security threats Toolkit

Conficker wakes up, updates itself over P2P

Elinor Mills CNET

Published: 09 Apr 2009 14:02 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The Conficker worm started to update itself on Wednesday via peer-to-peer, and dropped a payload on infected computers, according to Trend Micro.

At the time of writing researchers were analyzing the code of the software that had been dropped onto infected computers. The researchers suspected that it was a keystroke logger, or some other data-stealing program, said David Perry, global director of security education at Trend Micro.

Researchers for Trend Micro said that the software appeared to be a .sys component hiding behind a rootkit, which is software that is designed to hide the fact that a computer has been compromised. The software was heavily encrypted, which made code analysis difficult, the researchers said.

The update appeared to be attempting to access the Waledac domain, according to a post on the TrendLabs Malware Blog on Wednesday. W32.Waledac steals sensitive information, turns computers into spam zombies, and establishes a back door remote access.

The worm also tried to connect to MySpace.com, MSN.com, eBay.com, CNN.com and AOL.com, to test if the computer had internet connectivity. It then deleted all traces of itself in the host machine, and was set to shut down on 3 May, according to the TrendLabs Malware blog.

Infected computers are receiving the new component in a staggered manner rather than all at once, so there should be no disruption to the websites the computers visit, said Paul Ferguson, advanced threats researcher for Trend Micro.

On Tuesday night Trend Micro researchers noticed a new file in the Windows Temp folder and a huge encrypted TCP response from a known Conficker P2P IP node hosted in Korea.

Read this

Roundup
Roundup: Countdown to Conficker

ZDNet reports on the latest news and updates

Read more +

"As expected, the P2P communications of the Downad/Conficker botnet may have just been used to serve an update, and not via HTTP," the blog post says. "The Conficker/Downad P2P communications is now running in full swing!"

A previous variant, Conficker.C, failed to make a splash a week ago despite the fact that it was programmed to activate on 1 April. It has infected between three million and 12 million computers, according to Perry.

Initially, researchers thought they were seeing a new variant of the Conficker worm, but now they believe it is merely a new component of the worm.

Security company Symantec said on Thursday that the update was for machines infected with the first variant of the worm, Conficker.A.

The worm spreads via a hole in Windows that Microsoft patched in October, as well as through removable storage devices and network shares with weak passwords. The worm disables security software and blocks access to security websites.

Tom Espiner from ZDNet UK contributed to this article.

Credit: Conficker wakes up, updates via P2P, drops payload from CNET.co.uk

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
11 out of 11 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:





Video icon

Video

Sentry Posts Blog

DNA details of innocent will be kept f...

The government has announced that it plans to keep innocent people's DNA details for up to six years. In response to a consultation it launched last December, the government said... More

4 comments

Motorola Droid Drops Today: Happy Droi...

Motorola Droid Drops Today: Happy Droid Day America! Author: Eric Everson, Mobile Security Expert If you’re wondering what all of the buzz is about with words like Droid and Android... More

Post a comment

Mobile Security Profile: BlackBerry St...

Mobile Security Profile: BlackBerry Storm2 Author: Eric Everson BlackBerry handsets are a staple of office culture; from syncing calendars to sharing business-related data,... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters