<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; virus outbreak</title>
	<atom:link href="http://www.darknet.org.uk/tag/virus-outbreak/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Conficker (AKA Downadup or Kido) Infections Skyrocket To An Estimate 9 Million</title>
		<link>http://www.darknet.org.uk/2009/01/conficker-aka-downadup-or-kido-infections-skyrocket-to-an-estimate-9-million/</link>
		<comments>http://www.darknet.org.uk/2009/01/conficker-aka-downadup-or-kido-infections-skyrocket-to-an-estimate-9-million/#comments</comments>
		<pubDate>Mon, 19 Jan 2009 16:34:00 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[conficker]]></category>
		<category><![CDATA[conficker virus]]></category>
		<category><![CDATA[downadup]]></category>
		<category><![CDATA[kido]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[malware infections]]></category>
		<category><![CDATA[malware outbreak]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[virus infection]]></category>
		<category><![CDATA[virus outbreak]]></category>
		<category><![CDATA[viruses]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1417</guid>
		<description><![CDATA[There hasn&#8217;t been a viral outbreak of this scale for quite some time, Conficker or Downadup as it&#8217;s known was only fairly recently discovered (Oct 2008) and has already infected an estimated 9 million machines! It&#8217;s spreading fast though and it auto-updates itself via downloads from random domains making it almost impossible to stop as [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>There hasn&#8217;t been a viral outbreak of this scale for quite some time, Conficker or Downadup as it&#8217;s known was only fairly recently discovered (Oct 2008) and has already infected an estimated 9 million machines!</p>
<p>It&#8217;s spreading fast though and it auto-updates itself via downloads from random domains making it almost impossible to stop as whatever countermeasures come out, it can just download itself the latest version and bypass them.</p>
<p>It also has multiple infection vectors including traveling via USB drives.</p>
<blockquote><p>Infections of a worm that spreads through low security networks, memory sticks, and PCs without the latest security updates is &#8220;skyrocketing&#8221;.</p>
<p>The malicious program, known as Conficker, Downadup, or Kido was first discovered in October 2008. Anti-virus firm F-Secure estimates there are now 8.9m machines infected.  Experts warn this figure could be far higher and say users should have up-to-date anti-virus software and install Microsoft&#8217;s MS08-067 patch.  In its security blog, F-Secure said that the number of infections based on its calculations was &#8220;skyrocketing&#8221; and that the situation was &#8220;getting worse&#8221;.</p>
<p>Speaking to the BBC, Graham Cluley, senior technology consultant with anti-virus firm Sophos, said the outbreak was of a scale they had not seen for some time.</p></blockquote>
<p>The virus targets the services.exe process (Server service) by exploiting the vulnerability associated with the <a href="http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx">MS08-067</a> patch.</p>
<p>This was a serious remote execution flaw carried out by making a malformed RPC request, apparently it was reported &#8216;privately&#8217;. But now it seems that perhaps the details of the exploit weren&#8217;t that private after all.</p>
<blockquote><p>According to Microsoft, the worm works by searching for a Windows executable file called &#8220;services.exe&#8221; and then becomes part of that code.</p>
<p>It then copies itself into the Windows system folder as a random file of a type known as a &#8220;dll&#8221;. It gives itself a 5-8 character name, such as piftoc.dll, and then modifies the Registry, which lists key Windows settings, to run the infected dll file as a service.</p>
<p>Once the worm is up and running, it creates an HTTP server, resets a machine&#8217;s System Restore point (making it far harder to recover the infected system) and then downloads files from the hacker&#8217;s web site. Most malware uses one of a handful of sites to download files from, making them fairly easy to locate, target, and shut down. But Conficker does things differently. </p></blockquote>
<p>It quite advanced even taking system restore out of the picture and downloading new files to update itself and to infect the machine further. It&#8217;s sneaky as it downloads from a bunch of seemingly randomly generated URLs making it very difficult to track and stop.</p>
<p>Many machines are infected in China, Brazil, Russia, and India &#8211; personally I think this is because piracy is rife in these areas and Microsoft doesn&#8217;t allow pirated copies of Windows to use Windows Update (especially with the WGA tool or Windows Genuine Advantage).</p>
<p></p>
<p>Source: <a href="http://news.bbc.co.uk/2/hi/technology/7832652.stm">BBC News</a> (<em>Thanks Navin</em>)</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Conficker+%28AKA+Downadup+or+Kido%29+Infections+Skyrocket+To+An+Estimate+9+Million+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D1417+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2009/01/conficker-aka-downadup-or-kido-infections-skyrocket-to-an-estimate-9-million/&amp;t=Conficker+%28AKA+Downadup+or+Kido%29+Infections+Skyrocket+To+An+Estimate+9+Million" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2009/01/conficker-aka-downadup-or-kido-infections-skyrocket-to-an-estimate-9-million/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2009/01/conficker-aka-downadup-or-kido-infections-skyrocket-to-an-estimate-9-million/&amp;title=Conficker+%28AKA+Downadup+or+Kido%29+Infections+Skyrocket+To+An+Estimate+9+Million" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2009/01/conficker-aka-downadup-or-kido-infections-skyrocket-to-an-estimate-9-million/&amp;title=Conficker+%28AKA+Downadup+or+Kido%29+Infections+Skyrocket+To+An+Estimate+9+Million" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2009/01/conficker-aka-downadup-or-kido-infections-skyrocket-to-an-estimate-9-million/&amp;title=Conficker+%28AKA+Downadup+or+Kido%29+Infections+Skyrocket+To+An+Estimate+9+Million" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2009/01/conficker-aka-downadup-or-kido-infections-skyrocket-to-an-estimate-9-million/&amp;title=Conficker+%28AKA+Downadup+or+Kido%29+Infections+Skyrocket+To+An+Estimate+9+Million" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2009%2F01%2Fconficker-aka-downadup-or-kido-infections-skyrocket-to-an-estimate-9-million%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2009/01/conficker-aka-downadup-or-kido-infections-skyrocket-to-an-estimate-9-million/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
	</channel>
</rss>

