<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; downadup</title>
	<atom:link href="http://www.darknet.org.uk/tag/downadup/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Conficker Finally Awakes &amp; Dumps Payload</title>
		<link>http://www.darknet.org.uk/2009/04/conficker-finally-awakes-dumps-payload/</link>
		<comments>http://www.darknet.org.uk/2009/04/conficker-finally-awakes-dumps-payload/#comments</comments>
		<pubDate>Fri, 10 Apr 2009 08:20:09 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[General Hacking]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[conficker]]></category>
		<category><![CDATA[conficker payload]]></category>
		<category><![CDATA[conficker virus]]></category>
		<category><![CDATA[confiicker worm]]></category>
		<category><![CDATA[downadup]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[viruses]]></category>
		<category><![CDATA[waledac]]></category>
		<category><![CDATA[worms]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1697</guid>
		<description><![CDATA[So it seems something big was brewing with Conficker, they just didn&#8217;t want to do what everyone expected and unleash it on April 1st when all eyes were on them. Smart move really, they kept quiet and waited a week or so after before dropping some fairly serious and complex payloads (encrypted rootkits). It seems [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>So it seems something big was brewing with <a href="http://www.darknet.org.uk/tag/conficker/">Conficker</a>, they just didn&#8217;t want to do what everyone expected and unleash it on April 1st when all eyes were on them.</p>
<p>Smart move really, they kept quiet and waited a week or so after before dropping some fairly serious and complex payloads (encrypted rootkits).</p>
<p>It seems like they are going for the old ransom tactic and duping users into buying dodgy anti-virus software.</p>
<blockquote><p>An updated version of the Conficker worm is installing malware that attempts to lure people into buying rogue anti-virus software. Security researchers also say the worm is downloading malware tied to the notorious Waledac botnet.</p>
<p>Conficker&#8217;s latest move may be tied to a scheme to lure users into downloading fake anti-virus software.</p>
<p>Security researchers monitoring the Conficker worm&#8217;s activities say the malware has been observed downloading a file detected by Kaspersky Lab as FraudTool.Win32.SpywareProtect2009.s.</p>
<p>&#8220;Once it&#8217;s run, you see the app interface, which naturally asks if you want to remove the threats it&#8217;s &#8216;detected,&#8217;&#8221; wrote Aleks Gostev on Kaspersky Lab&#8217;s Analyst&#8217;s Diary blog. &#8220;Of course, this service comes at a price—$49.95.&#8221;</p></blockquote>
<p>There is also some links to <a href="http://www.darknet.org.uk/tag/waledac/">Waledac</a> a supposed next-gen botnet for spamming purposes that came shortly after the demise of <a href="http://www.darknet.org.uk/tag/storm/">Storm</a>.</p>
<p>It seems like Conficker is not going to be laying dormant any more, perhaps they weren&#8217;t making enough from renting out sections to spammers and DDoSers &#8211; now they really want to monetize the infected machines they have gathered.</p>
<blockquote><p>In addition to that file, the worm is also now downloading the Waledac malware, which steals passwords and turns computers into bots for spamming operations. Waledac has emerged as a key part of spamming operations over the past several months, and is widely considered a reincarnation of the infamous Storm botnet. </p>
<p>&#8220;Fear is used, universally, as a means to control people,&#8221; said Sendio CTO Tal Golan. &#8220;Governments use it. Large businesses use it. So it should come as no surprise to anyone that &#8216;cyber-bad guys&#8217; use it.&#8221;</p>
<p>At the moment, the rogue anti-virus software comes from sites located in the Ukraine (131-3.elaninet.com.78.26.179.107) although the worm is downloading it from other sites, according to Kaspersky Lab.</p></blockquote>
<p>Unsurprisingly the source for much of the rogue software is in Eastern Europe, a hotspot for cybercrime and hackers skilled in malware and cryptography.</p>
<p>There&#8217;s some updates from F-Secure here:</p>
<p><a href="http://www.f-secure.com/weblog/archives/00001652.html">New Conficker action</a></p>
<p></p>
<p>Source: <a href="http://www.eweek.com/c/a/Security/Updated-Conficker-Ropes-Victims-into-Rogue-Antivirus-Scam-376657/?kc=rss">eWeek</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Conficker+Finally+Awakes+%26+Dumps+Payload+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D1697+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2009/04/conficker-finally-awakes-dumps-payload/&amp;t=Conficker+Finally+Awakes+%26+Dumps+Payload" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2009/04/conficker-finally-awakes-dumps-payload/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2009/04/conficker-finally-awakes-dumps-payload/&amp;title=Conficker+Finally+Awakes+%26+Dumps+Payload" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2009/04/conficker-finally-awakes-dumps-payload/&amp;title=Conficker+Finally+Awakes+%26+Dumps+Payload" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2009/04/conficker-finally-awakes-dumps-payload/&amp;title=Conficker+Finally+Awakes+%26+Dumps+Payload" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2009/04/conficker-finally-awakes-dumps-payload/&amp;title=Conficker+Finally+Awakes+%26+Dumps+Payload" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2009%2F04%2Fconficker-finally-awakes-dumps-payload%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2009/04/conficker-finally-awakes-dumps-payload/feed/</wfw:commentRss>
		<slash:comments>12</slash:comments>
		</item>
		<item>
		<title>Conficker Day &#8211; April 1st &#8211; Uneventful</title>
		<link>http://www.darknet.org.uk/2009/04/conficker-day-april-1st-uneventful/</link>
		<comments>http://www.darknet.org.uk/2009/04/conficker-day-april-1st-uneventful/#comments</comments>
		<pubDate>Thu, 02 Apr 2009 08:37:07 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[General News]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[april 1st]]></category>
		<category><![CDATA[botnets]]></category>
		<category><![CDATA[conficker]]></category>
		<category><![CDATA[conficker day]]></category>
		<category><![CDATA[downadup]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[viruses]]></category>
		<category><![CDATA[worms]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1669</guid>
		<description><![CDATA[So the big Conficker scare of April 1st has passed without any real events, no major sites taken down, no major online terror campaigns spawned. Just a new more sophisticated, harder to stop version of Conficker updating from a longer list of domains. It seems like this malware might be here to stay and infecting [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>So the big <a href="http://www.darknet.org.uk/tag/conficker/">Conficker</a> scare of April 1st has passed without any real events, no major sites taken down, no major online terror campaigns spawned.</p>
<p>Just a new more sophisticated, harder to stop version of Conficker updating from a longer list of domains.</p>
<p>It seems like this malware might be here to stay and infecting more and more computers building a formidable network of zombies.</p>
<blockquote><p>April 1 has come and gone in some parts of the world, and the Conficker worm is still here. While the day in security passed by relatively uneventfully, there are still people at risk.</p>
<p>The doomsday some were predicting the Conficker worm to bring had not materialized as of the evening of April 1. But that hardly means Conficker is a bust.</p>
<p>In short, the Conficker worm did what was expected—generate 50,000 domain names and begin contacting them. According to BKIS, the Bach Khoa Internetwork Security center, 1.1 million PCs in Europe, Asia and a part of America infected with Conficker have already &#8220;called home.&#8221;</p>
<p>But even though nothing dramatic happened, AVG Technologies Chief Research Officer Roger Thompson warned against blowing the worm off. </p></blockquote>
<p>It seems like the confirmed infection rate is sitting at just above 1 million, far less than the <a href="http://www.darknet.org.uk/2009/01/conficker-aka-downadup-or-kido-infections-skyrocket-to-an-estimate-9-million/">previously estimated 9 million</a>.</p>
<p>But still 1 million is a formidable arsenal of spam sending machines, or a deadly <a href="http://www.darknet.org.uk/tag/ddos/">DDoS</a> network.</p>
<blockquote><p>There is also the possibility of selling Conficker&#8217;s army of infected computers, but that could prove problematic due to the amount of attention it generated. Right now, countless members of the security community, including the Conficker Cabal—formally known as the Conficker Working Group—are keeping tabs on the worm. Even with 50,000 domains in question, those domains are being closely monitored and any malicious servers will likely be noticed before long.</p>
<p>&#8220;Given the profile of Conficker, I think it&#8217;s rather unlikely that the botnet is up for sale,&#8221; said Roel Schouwenberg, senior anti-virus researcher at Kaspersky Lab Americas. &#8220;Not a lot of people out there would like to handle such hot property, as the botnet is being watched by a lot of people. However, leasing [parts of] the botnet is a different story. That way the leasers would get the advantage of the power of the botnet, but the owners would still be running the risk.&#8221;</p></blockquote>
<p>I think the assumption is fine, they won&#8217;t plan on selling the botnet &#8211; they will just keep increasing its size and potential and then lease out chunks of it for DDoS attacks and sending spam e-mails.</p>
<p>All this dodgy stuff is big business now, and sadly there doesn&#8217;t seem to be anything we can do about it.</p>
<p>Of course we can personally make sure no-one we know gets infected with Conficker, and if they do we can clean it up. But other than that, just observe the fun right?</p>
<p></p>
<p>Source: <a href="http://www.eweek.com/c/a/Security/Confickers-Big-Day-Passes-Quietly-But-Was-it-Really-a-Bust402276/?kc=rss">eWeek</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Conficker+Day+%E2%80%93+April+1st+%E2%80%93+Uneventful+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D1669+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2009/04/conficker-day-april-1st-uneventful/&amp;t=Conficker+Day+%E2%80%93+April+1st+%E2%80%93+Uneventful" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2009/04/conficker-day-april-1st-uneventful/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2009/04/conficker-day-april-1st-uneventful/&amp;title=Conficker+Day+%E2%80%93+April+1st+%E2%80%93+Uneventful" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2009/04/conficker-day-april-1st-uneventful/&amp;title=Conficker+Day+%E2%80%93+April+1st+%E2%80%93+Uneventful" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2009/04/conficker-day-april-1st-uneventful/&amp;title=Conficker+Day+%E2%80%93+April+1st+%E2%80%93+Uneventful" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2009/04/conficker-day-april-1st-uneventful/&amp;title=Conficker+Day+%E2%80%93+April+1st+%E2%80%93+Uneventful" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2009%2F04%2Fconficker-day-april-1st-uneventful%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2009/04/conficker-day-april-1st-uneventful/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>New Conficker Variant More Aggressive</title>
		<link>http://www.darknet.org.uk/2009/03/new-conficker-variant-more-aggressive/</link>
		<comments>http://www.darknet.org.uk/2009/03/new-conficker-variant-more-aggressive/#comments</comments>
		<pubDate>Wed, 18 Mar 2009 09:38:15 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Spammers & Scammers]]></category>
		<category><![CDATA[bitdefender]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[conficker]]></category>
		<category><![CDATA[downadup]]></category>
		<category><![CDATA[enigma software]]></category>
		<category><![CDATA[kido]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[symantec]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[worm]]></category>
		<category><![CDATA[worms]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1605</guid>
		<description><![CDATA[Conficker has gotten quite a lot of news recently with it growing so fast and Microsoft offering a bounty for the authors. It seems like the Conficker authors are really serious about retaining control of their botnet and expanding it further without hindrance from the companies trying to stop them. It&#8217;s quite likely they are [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p><a href="http://www.darknet.org.uk/tag/conficker/">Conficker</a> has gotten quite a lot of news recently with it <a href="http://www.darknet.org.uk/2009/01/conficker-aka-downadup-or-kido-infections-skyrocket-to-an-estimate-9-million/">growing so fast</a> and <a href="http://www.darknet.org.uk/2009/02/microsoft-offers-250k-bounty-for-conficker-author/">Microsoft offering a bounty for the authors</a>.</p>
<p>It seems like the Conficker authors are really serious about retaining control of their botnet and expanding it further without hindrance from the companies trying to stop them.</p>
<p>It&#8217;s quite likely they are netting some serious cash from the network of infected computers, with estimates at over 10 million now that&#8217;s a large collection of computers for brute forcing, e-mail spam or DDoS attacks.</p>
<blockquote><p>The authors of the latest variant of the Conficker worm are upping the ante against security vendors who are working to stop the spread and threat of the persistent program.</p>
<p>Conficker.C shuts down security services, blocks computers from connecting to security Web sites, and downloads a Trojan. It also is programmed to begin connecting to 50,000 different domains on April 1 to receive updated copies or other malware, as opposed to connecting to 250 domains a day as previous versions are doing, Ben Greenbaum, senior research manager for Symantec Security Response, said on Friday.</p>
<p>The authors of the code are &#8220;strengthening their hold on their collection of infected machines at the same time they are attempting to strengthen their ability to control those machines by moving to 50,000 domains,&#8221; he said.</p>
<p>A self-described &#8220;cabal&#8221; of companies, including Microsoft, Symantec, and a host of domain registration providers, have been trying to thwart the efforts of Conficker by pre-registering and locking up the domain names being used by the worm to distribute updates.</p></blockquote>
<p>They are getting sneaky now, targeting security software and services on an infected PC and blocking it from accessing related sites that could help a user fix the infection.</p>
<p>Plus they have expanded their &#8216;update&#8217; domains to 50,000 &#8211; which will take a huge effort to get all of the domains blocked.</p>
<p>I wonder what the next step will be in protecting again this?</p>
<blockquote><p>Now that Conficker.C is targeting 50,000 domains, the group has its work cut out for it, Greenbaum said. Regardless, &#8220;it&#8217;s unknown at this point whether (boosting the domains) is an effective sidestep around the cabal&#8217;s actions,&#8221; he said.</p>
<p>The worm, also called Kido or Downadup, was first detected in November and is believed to have infected more than 10,000 computers. The first two versions exploit a vulnerability that Microsoft patched in October.</p>
<p>The second variant, Conficker.B, was detected last month. It added the ability to spread through network shares and via removable storage devices, like USB drives, through the AutoRun function in Windows.</p>
<p>Among the domains targeted by Conficker was that of Southwest Airlines, which was expected to see an increase in traffic from the botnet on Friday, Sophos said last week. However, a Southwest spokesman said there had been no impact to the site from any additional traffic as a result of Conficker. </p></blockquote>
<p>I hope this stays as just Conficker, if there&#8217;s another large scale breakout we might be in trouble again. There is a way to remove it though, so if you know anyone that has managed to get themselves infected you can give them the below links:</p>
<ul>
<li><a href="http://www.enigmasoftware.com/support/conficker-removal/">Enigma Software Group Conficker Removal Tool</a></li>
<li><a href="http://www.downadup.org/">BitDefender Conficker Removal Tool</a></li>
</ul>
<p></p>
<p>Source: <a href="http://news.cnet.com/8301-1009_3-10196122-83.html">Cnet</a> (<em>Thanks Navin</em>)</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=New+Conficker+Variant+More+Aggressive+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D1605+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2009/03/new-conficker-variant-more-aggressive/&amp;t=New+Conficker+Variant+More+Aggressive" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2009/03/new-conficker-variant-more-aggressive/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2009/03/new-conficker-variant-more-aggressive/&amp;title=New+Conficker+Variant+More+Aggressive" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2009/03/new-conficker-variant-more-aggressive/&amp;title=New+Conficker+Variant+More+Aggressive" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2009/03/new-conficker-variant-more-aggressive/&amp;title=New+Conficker+Variant+More+Aggressive" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2009/03/new-conficker-variant-more-aggressive/&amp;title=New+Conficker+Variant+More+Aggressive" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2009%2F03%2Fnew-conficker-variant-more-aggressive%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2009/03/new-conficker-variant-more-aggressive/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Conficker (AKA Downadup or Kido) Infections Skyrocket To An Estimate 9 Million</title>
		<link>http://www.darknet.org.uk/2009/01/conficker-aka-downadup-or-kido-infections-skyrocket-to-an-estimate-9-million/</link>
		<comments>http://www.darknet.org.uk/2009/01/conficker-aka-downadup-or-kido-infections-skyrocket-to-an-estimate-9-million/#comments</comments>
		<pubDate>Mon, 19 Jan 2009 16:34:00 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[conficker]]></category>
		<category><![CDATA[conficker virus]]></category>
		<category><![CDATA[downadup]]></category>
		<category><![CDATA[kido]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[malware infections]]></category>
		<category><![CDATA[malware outbreak]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[virus infection]]></category>
		<category><![CDATA[virus outbreak]]></category>
		<category><![CDATA[viruses]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1417</guid>
		<description><![CDATA[There hasn&#8217;t been a viral outbreak of this scale for quite some time, Conficker or Downadup as it&#8217;s known was only fairly recently discovered (Oct 2008) and has already infected an estimated 9 million machines! It&#8217;s spreading fast though and it auto-updates itself via downloads from random domains making it almost impossible to stop as [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>There hasn&#8217;t been a viral outbreak of this scale for quite some time, Conficker or Downadup as it&#8217;s known was only fairly recently discovered (Oct 2008) and has already infected an estimated 9 million machines!</p>
<p>It&#8217;s spreading fast though and it auto-updates itself via downloads from random domains making it almost impossible to stop as whatever countermeasures come out, it can just download itself the latest version and bypass them.</p>
<p>It also has multiple infection vectors including traveling via USB drives.</p>
<blockquote><p>Infections of a worm that spreads through low security networks, memory sticks, and PCs without the latest security updates is &#8220;skyrocketing&#8221;.</p>
<p>The malicious program, known as Conficker, Downadup, or Kido was first discovered in October 2008. Anti-virus firm F-Secure estimates there are now 8.9m machines infected.  Experts warn this figure could be far higher and say users should have up-to-date anti-virus software and install Microsoft&#8217;s MS08-067 patch.  In its security blog, F-Secure said that the number of infections based on its calculations was &#8220;skyrocketing&#8221; and that the situation was &#8220;getting worse&#8221;.</p>
<p>Speaking to the BBC, Graham Cluley, senior technology consultant with anti-virus firm Sophos, said the outbreak was of a scale they had not seen for some time.</p></blockquote>
<p>The virus targets the services.exe process (Server service) by exploiting the vulnerability associated with the <a href="http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx">MS08-067</a> patch.</p>
<p>This was a serious remote execution flaw carried out by making a malformed RPC request, apparently it was reported &#8216;privately&#8217;. But now it seems that perhaps the details of the exploit weren&#8217;t that private after all.</p>
<blockquote><p>According to Microsoft, the worm works by searching for a Windows executable file called &#8220;services.exe&#8221; and then becomes part of that code.</p>
<p>It then copies itself into the Windows system folder as a random file of a type known as a &#8220;dll&#8221;. It gives itself a 5-8 character name, such as piftoc.dll, and then modifies the Registry, which lists key Windows settings, to run the infected dll file as a service.</p>
<p>Once the worm is up and running, it creates an HTTP server, resets a machine&#8217;s System Restore point (making it far harder to recover the infected system) and then downloads files from the hacker&#8217;s web site. Most malware uses one of a handful of sites to download files from, making them fairly easy to locate, target, and shut down. But Conficker does things differently. </p></blockquote>
<p>It quite advanced even taking system restore out of the picture and downloading new files to update itself and to infect the machine further. It&#8217;s sneaky as it downloads from a bunch of seemingly randomly generated URLs making it very difficult to track and stop.</p>
<p>Many machines are infected in China, Brazil, Russia, and India &#8211; personally I think this is because piracy is rife in these areas and Microsoft doesn&#8217;t allow pirated copies of Windows to use Windows Update (especially with the WGA tool or Windows Genuine Advantage).</p>
<p></p>
<p>Source: <a href="http://news.bbc.co.uk/2/hi/technology/7832652.stm">BBC News</a> (<em>Thanks Navin</em>)</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Conficker+%28AKA+Downadup+or+Kido%29+Infections+Skyrocket+To+An+Estimate+9+Million+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D1417+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2009/01/conficker-aka-downadup-or-kido-infections-skyrocket-to-an-estimate-9-million/&amp;t=Conficker+%28AKA+Downadup+or+Kido%29+Infections+Skyrocket+To+An+Estimate+9+Million" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2009/01/conficker-aka-downadup-or-kido-infections-skyrocket-to-an-estimate-9-million/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2009/01/conficker-aka-downadup-or-kido-infections-skyrocket-to-an-estimate-9-million/&amp;title=Conficker+%28AKA+Downadup+or+Kido%29+Infections+Skyrocket+To+An+Estimate+9+Million" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2009/01/conficker-aka-downadup-or-kido-infections-skyrocket-to-an-estimate-9-million/&amp;title=Conficker+%28AKA+Downadup+or+Kido%29+Infections+Skyrocket+To+An+Estimate+9+Million" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2009/01/conficker-aka-downadup-or-kido-infections-skyrocket-to-an-estimate-9-million/&amp;title=Conficker+%28AKA+Downadup+or+Kido%29+Infections+Skyrocket+To+An+Estimate+9+Million" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2009/01/conficker-aka-downadup-or-kido-infections-skyrocket-to-an-estimate-9-million/&amp;title=Conficker+%28AKA+Downadup+or+Kido%29+Infections+Skyrocket+To+An+Estimate+9+Million" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2009%2F01%2Fconficker-aka-downadup-or-kido-infections-skyrocket-to-an-estimate-9-million%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2009/01/conficker-aka-downadup-or-kido-infections-skyrocket-to-an-estimate-9-million/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
	</channel>
</rss>

