Home > Security News > New Conficker variant has ties to Storm botnet
Security News:
EMAIL THIS

New Conficker variant has ties to Storm botnet

By SearchSecurity.com Staff
09 Apr 2009 | SearchSecurity.com

Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

A new Conficker/Downadup variant is on the loose, one with connections to the Storm botnet.

Conficker.E, as it has been named by several security companies, is infecting computers compromised by previous versions of the worm. Unlike its predecessors, it is dropping a binary that connects to the malicious Waledac worm giving Conficker.E self-propagation abilities. Previous versions, which exploited a remote procedure call vulnerability in Windows Server Services (MS08-067), spread only via peer-to-peer networks or downloads from a variety of URLs.

More on Conficker
Conficker flaw yields new tool for detection: A flaw in the way Conficker infects machines has given security experts the ability to design a new tool to remotely detect infections over the network.
Conficker leaves security industry looking clueless: The true Conficker story may well turn into an introspective of the security industry. It should start with hard questions of security vendors and service providers.
Conficker updates with no problems reported: Despite hyped reports of a trail of destruction, the latest Conficker worm upped the ante April 1, but security researchers are successfully blocking it from receiving orders.

Waledac is capable of harvesting and forwarding passwords and spreads via email attachments with topical subject lines; previous iterations of Waledac used holiday-related subject lines and tried to lure users to open with promises of an e-card.

"Waledac is used mainly for spam," said Orla Cox, security operations manager with Symantec Security Response. "We believe Waledac is connected with Storm. Waledac uses many of the same techniques as Storm; this one is a new iteration."

Another new twist is that Conficker.E will delete itself on May 3. Cox said the worm is likely giving itself a few weeks to spread and by then, this capability will be less relevant and will make the worm less obvious on an infected system.

Trend Micro advanced threat researcher Paul Ferguson said analysis of the variant has been difficult because some of the worm's binaries have been encrypted. He confirms the crossover between Conficker, Waledac and Storm.

"Some of us expected a new twist to appear at some point in time because it's got the
same fingerprints as the Russian Ukrainian organized crime operations that are probably pulling the strings behind both Conficker and Waledac and may even have been involved in Storm previous to Waledac," Ferguson said. "Most of this stuff is extraordinarily professionally designed."

Cox said Conficker.E has not been as active as previous variants. Systems that are patched against the MS 08-067 vulnerability are protected; most antivirus signatures have been updated in the past 24 hours as well.

"This one has not been as widespread. That may be why we're seeing these worming capabilities," Cox said. "It's getting harder to infect with this method."

Much was expected of Conficker.C on April 1, when it was to download orders from a large list of domains and URLs of command-and-control servers. Researchers, including the collaboration known as the Conficker Working Group had been able to successfully block the malware's efforts and the expected outbreak was a dud.



Tags: Emerging Information Security ThreatsMalware, Viruses, Trojans and SpywareWindows Security: Alerts, Updates and Best PracticesVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
Emerging Information Security Threats
RSA security conference 2010: news, interviews and updates
Hackers to sharpen malware, malicious software in 2010
Modern malware, stealthy botnets, adapt quickly, expert says
New ransomware Trojan pushes victims to buy software
Bruce Schneier on outsourcing, awareness training
US-CERT warns of BlackBerry snooping software
Marcus Ranum on cyberwarfare, infosec careers
Researchers find thousands of flawed embedded devices
Enterprise botnets contain thousands of malware variants
Nuke and pave to eradicate botnets

Malware, Viruses, Trojans and Spyware
New Zeus spam poses as Social Security statements
Increase in Gumblar backdoors poses FTP credential problems
Hackers to sharpen malware, malicious software in 2010
iPhone worm Rickrolls jailbroken phones
Israeli Mossad add Trojan Horse to Syrian laptop
Schneier-Ranum Face-Off: Is antivirus dead?
Modern malware, stealthy botnets, adapt quickly, expert says
Computer worm infections up, scareware antivirus down, Microsoft says
Web-based attacks skyrocket, pirating sites surge, security firms say
Mini guide: How to remove and prevent Trojans, malware and spyware

Windows Security: Alerts, Updates and Best Practices
Exploit code targets Internet Explorer zero-day display flaw
Windows 7 DoS flaw allows hackers to freeze Microsoft's newest OS
Microsoft patches serious Windows kernel flaws
Microsoft to address flaws in Windows, Office for Mac
Microsoft fixes security update that breaks Internet Explorer
What is the best database patch management process?
Microsoft addresses critical SMBv2 flaw, fixes record number of flaws
Microsoft to address SMB zero-day, IIS FTP Service vulnerabilities
Microsoft releases temporary fix for SMB2 zero-day vulnerability
Microsoft issues SMB vulnerability advisory, patch pending

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
DNS rebinding attack  (SearchSecurity.com)
drive-by pharming  (SearchSecurity.com)
JavaScript hijacking  (SearchSecurity.com)
man in the browser  (SearchSecurity.com)
phlashing  (SearchSecurity.com)
polymorphic malware  (SearchSecurity.com)
pulsing zombie  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts