Advertisement
Co Presented By
Co Presented By

Close To 3.5 Million Infected Botnets, Downadup On The Loose

Worm:Win32/Conflicker.B makes use of a year-old Windows vulnerability, spreads by taking over botnets, and also through removable media.

Advertisement
FP Archives|Jan 31, 2017, 02:06:07 IST

There’s a new villain in town and though he’s been here before, this time around he’s smarter and bigger. Although the above reference may closely define a ‘50s western, it actually defines a quick spreading menace, by the name of Worm:Win32/Conficker.B, also more commonly known as Downadup.

Last year, on October 23, 2008, Microsoft released a security update for Windows, namely MS08-067. Isolated attacks existed at the time of the bulletin release and in their blog they strongly recommended installing the security update as quickly as possible. However, beyond exploiting MS08-067, the new variant, Win32/Conflicker.B also uses other propagation methods such as copying itself to network shares by guessing their passwords. It also tries to spread via removable media.

Advertisement

Over the last couple of weeks, the worm has been affecting customers quite heavily. F-Secure initially estimated close to 2,395,963 infected botnets worldwide, however, as of today this count has gone up to a little over a million.

China has been identified as having close to 38,277 infected botnets with India clocking in at number four, with 16,497 infected botnets.

biztechMore from Biztech

“The worm uses a complicated algorithm, which changes daily and is based on timestamps from public websites such as Google.com and Baidu.com. With this algorithm, the worm generates many possible domain names every day. Hundreds of names have been generated such as: qimkwaify .ws, mphtfrxs .net, gxjofpj .ws, imctaef .cc, and hcweu .org. This makes it impossible and/or impractical for us good guys to trace them all and shut them down — most of them are never registered in the first place,” say experts from F-secure on the company’s blog.

Advertisement

Here’s an excerpt from Microsoft’s Malware Protection Blog:

“The malware utilises several layers of polymorphism and packing to hinder analysis and detection. Beyond that, infected users may have difficulty locating Conficker’s dropped files. It replaces the access rights for its registered key under HKLMSYSTEMCurrentControlSetServices, allowing only Local System account to read, traverse or change discretionary ACL (Access Control List). Similar behaviour goes for its system32 DLL file – all the NTFS permissions, except file execute, are stripped for all users. Additionally, the malware keeps a system lock on its entire file making it difficult for standard tools to access and/ or remove the threat while it is running. The January version of the MSRT can detect and remove this worm despite all these tricks.”

To help customers, who are affected, MS has added capabilities to detect and remove this worm to the January version of the MSRT, which can be found here. Microsoft has also posted information on the removal of this Trojan, and recommends that infected environments must have the update in order to continue working smoothly.

Handpicked stories, in your inbox
Global stories. Indian perspective. Zero noise.
No Spam. Unsubscribe Any Time.
First Published:Jan 16, 2009, 12:57:07 IST
Advertisement
Advertisement
Advertisement
Advertisement
Up Next