<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; conficker payload</title>
	<atom:link href="http://www.darknet.org.uk/tag/conficker-payload/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Conficker Finally Awakes &amp; Dumps Payload</title>
		<link>http://www.darknet.org.uk/2009/04/conficker-finally-awakes-dumps-payload/</link>
		<comments>http://www.darknet.org.uk/2009/04/conficker-finally-awakes-dumps-payload/#comments</comments>
		<pubDate>Fri, 10 Apr 2009 08:20:09 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[General Hacking]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[conficker]]></category>
		<category><![CDATA[conficker payload]]></category>
		<category><![CDATA[conficker virus]]></category>
		<category><![CDATA[confiicker worm]]></category>
		<category><![CDATA[downadup]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[viruses]]></category>
		<category><![CDATA[waledac]]></category>
		<category><![CDATA[worms]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1697</guid>
		<description><![CDATA[So it seems something big was brewing with Conficker, they just didn&#8217;t want to do what everyone expected and unleash it on April 1st when all eyes were on them. Smart move really, they kept quiet and waited a week or so after before dropping some fairly serious and complex payloads (encrypted rootkits). It seems [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>So it seems something big was brewing with <a href="http://www.darknet.org.uk/tag/conficker/">Conficker</a>, they just didn&#8217;t want to do what everyone expected and unleash it on April 1st when all eyes were on them.</p>
<p>Smart move really, they kept quiet and waited a week or so after before dropping some fairly serious and complex payloads (encrypted rootkits).</p>
<p>It seems like they are going for the old ransom tactic and duping users into buying dodgy anti-virus software.</p>
<blockquote><p>An updated version of the Conficker worm is installing malware that attempts to lure people into buying rogue anti-virus software. Security researchers also say the worm is downloading malware tied to the notorious Waledac botnet.</p>
<p>Conficker&#8217;s latest move may be tied to a scheme to lure users into downloading fake anti-virus software.</p>
<p>Security researchers monitoring the Conficker worm&#8217;s activities say the malware has been observed downloading a file detected by Kaspersky Lab as FraudTool.Win32.SpywareProtect2009.s.</p>
<p>&#8220;Once it&#8217;s run, you see the app interface, which naturally asks if you want to remove the threats it&#8217;s &#8216;detected,&#8217;&#8221; wrote Aleks Gostev on Kaspersky Lab&#8217;s Analyst&#8217;s Diary blog. &#8220;Of course, this service comes at a price—$49.95.&#8221;</p></blockquote>
<p>There is also some links to <a href="http://www.darknet.org.uk/tag/waledac/">Waledac</a> a supposed next-gen botnet for spamming purposes that came shortly after the demise of <a href="http://www.darknet.org.uk/tag/storm/">Storm</a>.</p>
<p>It seems like Conficker is not going to be laying dormant any more, perhaps they weren&#8217;t making enough from renting out sections to spammers and DDoSers &#8211; now they really want to monetize the infected machines they have gathered.</p>
<blockquote><p>In addition to that file, the worm is also now downloading the Waledac malware, which steals passwords and turns computers into bots for spamming operations. Waledac has emerged as a key part of spamming operations over the past several months, and is widely considered a reincarnation of the infamous Storm botnet. </p>
<p>&#8220;Fear is used, universally, as a means to control people,&#8221; said Sendio CTO Tal Golan. &#8220;Governments use it. Large businesses use it. So it should come as no surprise to anyone that &#8216;cyber-bad guys&#8217; use it.&#8221;</p>
<p>At the moment, the rogue anti-virus software comes from sites located in the Ukraine (131-3.elaninet.com.78.26.179.107) although the worm is downloading it from other sites, according to Kaspersky Lab.</p></blockquote>
<p>Unsurprisingly the source for much of the rogue software is in Eastern Europe, a hotspot for cybercrime and hackers skilled in malware and cryptography.</p>
<p>There&#8217;s some updates from F-Secure here:</p>
<p><a href="http://www.f-secure.com/weblog/archives/00001652.html">New Conficker action</a></p>
<p></p>
<p>Source: <a href="http://www.eweek.com/c/a/Security/Updated-Conficker-Ropes-Victims-into-Rogue-Antivirus-Scam-376657/?kc=rss">eWeek</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Conficker+Finally+Awakes+%26+Dumps+Payload+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D1697+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2009/04/conficker-finally-awakes-dumps-payload/&amp;t=Conficker+Finally+Awakes+%26+Dumps+Payload" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2009/04/conficker-finally-awakes-dumps-payload/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2009/04/conficker-finally-awakes-dumps-payload/&amp;title=Conficker+Finally+Awakes+%26+Dumps+Payload" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2009/04/conficker-finally-awakes-dumps-payload/&amp;title=Conficker+Finally+Awakes+%26+Dumps+Payload" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2009/04/conficker-finally-awakes-dumps-payload/&amp;title=Conficker+Finally+Awakes+%26+Dumps+Payload" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2009/04/conficker-finally-awakes-dumps-payload/&amp;title=Conficker+Finally+Awakes+%26+Dumps+Payload" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2009%2F04%2Fconficker-finally-awakes-dumps-payload%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2009/04/conficker-finally-awakes-dumps-payload/feed/</wfw:commentRss>
		<slash:comments>12</slash:comments>
		</item>
	</channel>
</rss>

