Pages

Tampilkan postingan dengan label VIRUS. Tampilkan semua postingan
Tampilkan postingan dengan label VIRUS. Tampilkan semua postingan

4.13.2009

Conficker gang updates worm via peer-to-peer

In the end, the criminals behind the Conficker worm only waited a week to update the malicious program.

On late Tuesday, computers infected with the worm began downloading new commands to modify how the Conficker functions, security firms reported. The latest modifications to the program — also referred to as Downad, Downadup and Kido by different security companies — reactivates the worm's ability to spread using a flaw in Microsoft Windows and redirects most communications through the program's peer-to-peer network, said Stephan Chenette, manager of security research for network-protection firm Websense.

The latest update also causes compromised computer to go to a domain known to host a malicious program known as Waledac. The addition of peer-to-peer networking — a characteristic feature of Waledac and its cousin, the Storm Worm — suggests that the programs share the same creator or that the creators have some sort of relationship, Chenette said.

"Peer-to-peer is going to become a large part of what Conficker will use for updates and command and control," he said. "It is the same thing that Storm and Waledac did."

With the peer-to-peer update, the authors of the Conficker worm dodged the efforts of defenders to prevent the program from getting an upgrade. The mainstream media had focused on April 1 — the day that the previous version of Conficker would start searching through 50,000 random domains daily — as D-Day for the security community. Instead, the authors waited a week and never even used the Internet drop, or rendezvous, point system on which remediation efforts had focused.

Researchers with the Conficker Working Group, formerly called the Conficker Cabal, continued to analyze the latest cod, said Websense's Chenette. The current version also has an expiration date, after which the worm will likely stop trying to spread, but may keep listening for new commands sent through the peer-to-peer network.

"We are all still trying to figure out all the particular details of the new Conficker binary," Chenette said. "We are all trying to put this together — what this is doing and what it is ... As they change their methods, so we have to change they way we do our analyses. It takes a little while, but we will get all the details in time."

source by : http://www.securityfocus.com/brief/942

3.31.2009

Confickr.C - Is a Virus Threat Looming This April Fool’s Day?

By Maneesh Madambath • March 26, 2009

Graham Cluley, of the security specialist Sophos, has claimed that Conficker C is programmed “to hunt for new instructions on April 1″. There has been tremendous online buzz about Conficker C, a malicious virus for quite some time now. Will it Wont’t it and if it will what will it do are the many questions doing rounds.

Conficker C is a sophisticated piece of malicious computer software, or malware, that installs itself on a PC hard drive via specially written web pages and then conceals itself on a computer. According to PCMag, “avoiding detection is a major theme with Conficker.C. It’s not the first malware to try to defend itself in-memory against security software and diagnostic tools, but C does a lot of this. For instance, it disables Windows Automatic Updates and the Windows Security Center.”


Conficker.C is not the first of its kind though. There have been earlier versions A and B (and even a B++ if I am not wrong). Conficker first caught attention in 2008 infected over 9 million computers. According to Yahoo, Conficker C, the worm has grown incredibly complicated, powerful, and virulent… though no one is quite sure exactly what it will do when D-Day arrives. And that’s the catch. Everyone knows that the malware is going to be deployed, but what will it do and how will it harm just presents clueless faces.

The ET report suggests that on April 1 all the world’s millions of infected computers may receive simultaneous instructions to attack, or to flood the Internet with spam email. Cluley explains the situation as, “It’s as if someone is assembling an army of computers around the world, but hasn’t yet decided where to point them.”

Alright, so another exciting April 1 in the making. I figure the funny part would be that a lot of unwitting users might get their computers infected and not even know that their system has been infected. It will also put a lot of harmless online pranks under the microscope perhaps.