Posted by Trancer on Mar 01 2009

VirusRight after an exploit code was published for the MS08-067 vulnerability it was only a matter of time until virus coders will write a virus that use this vulnerability to spread.
Well, exploiting this vulnerability is one of the techniques the Conficker (aka Downadup and Kido) virus use to spread itself, and that’s what makes it so dangerous.
With more then 20 millions infected computers out there, security firms say it is the severest computer virus since the SQL Slammer, and Microsoft is going nuts over it, offering a $250,000 bounty for information leading to the catch of the guys who created and/or distribute the virus.
In my opinion, 20 million is a really rough estimate of the infected computers out there. I believe the numbers are greater, due to the fact that the virus also spread itself through portable storage devices (USB drives and other removable media) and by that slipping in to organizations internal networks. Here’s where the numbers are getting blurry, we don’t know what’s the virus infection scale inside these internal networks, where it can spread much more easily using network shares, computers with weak passwords and exploiting the MS08-067 vulnerability.
It’s a known fact that the software and operating systems inside these organizations internal networks aren’t always up-to-date, and sometimes it takes months, if not years, for these organizations to update their computers.
It happens mostly when vendors release major service packs or… after a virus infects their networks :-)
Conficker is that example, a lesson for all these organizations that doesn’t patch their systems. I guess they need these kind of lesson every once and a while.
Even the IDF internal networks got infected by Conficker (Hebrew).

Conficker comes in three variants – Win32/Conficker.A, Win32/Conficker.B and Win32/Conficker.B++.
SRI International Malware Threat Center wrote a great analysis for the virus and all the variants here – An Analysis of Conficker’s Logic and Rendezvous Points.
See also:
Downadup – Advanced Crypto Protection by Elia Florio of Symantec.
Microsoft help protecting yourself against the Conficker worm.

Update:
Win32/Conficker.C is on the loose, armed with more self protection mechanisms and a larger domain pool.
On April 1st, Conficker.C will attempt to dial home to 500 random domains out of 50000 generated domains. A great change from the previous variants that would dial home to 32 out of 250 domains.
This time the worm is also much more violent and will attempt to disable Windows Automatic Updates and stop access to the Windows Security Center, also killing anti-virus processes, preventing access to anti-virus websites, delete system restore points, disable various protection services such as Windows Defender and the Windows Error Reporting Service and much more.

For a detailed analysis of Conficker.C, check the CA Win32/Conficker.C Virus Analysis and the SRI International Malware Threat Center analysis of Conficker C.
Also see this Detecting Conficker in your Network paper.

See you on Conficker.D ?!

Categories: Malware

One Response to “Conficker”

  1. iDig.co.il says:

    מימדי ההתפשטות של תולעת Conficker…

    דעה לגבי מימדי ההתפשטות של תולעת Conficker (הידועה גם בשם Kido ו- Downadup), אסור לשכוח שהתולעת עוד בגרסאות הראשונות שלה מתפשטת באמצעות ms08-067 והדבקה של …

Leave a Reply


Follow Recognize-Security on Twitter