Hunter's Malware Blog

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Monday, 11 March 2013

Spotlight On Malware: The Conficker Worm.

Posted on 15:31 by Unknown
By popular request, here is a look at the Conficker Worm. This worm is also known as Downup, Downadup, and Kido.

First, Conficker sounds like a weird name. Where did it come from you ask? The origin of the name is thought to be a portmanteau of the English term configure and the German pejorative term Ficker. Conficker comes in 5 flavors, all of which we will talk about separately. The five flavors have been dubbed A, B, C, D, and E.

The first variant of Conficker (A) was discovered in early November of 2008. It spread through the Internet by exploiting a vulnerability in a network service (specifically MS08-067) on Windows 2000 through Server 2008. Windows 7 could have been affected, but during that time Windows 7 was in beta and the beta was not publicly available until January 2009. Although Microsoft released an emergency patch on November 23, 2008 to patch the vulnerability, a large number of PCs still remained unpatched as of January 2009. The final thing that Conficker A does is update itself to Conficker B, C, or D.

The second variant (B), discovered in December, added the ability to spread over LANs through removable media. The second variant also disabled Windows AutoUpdate and blocked certain DNS lookups. The final thing that Conficker B does is update to Conicker C or D.

The third variant (C) which was discovered in early February 2009 did much of the same stuff as Conficker B did. The final thing that Conficker C did was update itself to Conficker D.

Conficker D is where things get a little more interesting. This variant was discovered in March of 2009. It did what Conficker C did, however, it also added a few extra features such as disabling safe mode, and searching for processes that are related to anti-malware programs and killing them at one second intervals. The final thing that Conficker D did was download and install Conficker E.

Conficker E was discovered 3 days after Conficker D. It protected itself in the same manner as D (disabling anti-malware) and had a very interesting final payload. The final action was downloading and installing a spambot and SpyProtect 2009. Conficker E also removed itself on May 3 of 2009, leaving the copy of Conficker D still on the computer.

That is it for this Spotlight On Malware blog post. Once again, this was by popular request.... Now stop requesting it.
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Posted in Spotlight On Malware, Windows | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • How do I make sure my Antivirus Software is protecting me?
    You are a computer user concerned about malware, you have antivirus software, but you do not know if it is protecting you. What do you do? O...
  • Spotlight on malware: Reveton Trojan
    The Reveton Trojan, also called the FBI MoneyPak Trojan, and the Police Trojan, is a screen locker Trojan that displays a warning from a ...
  • Using Windows XP? Here comes the end.
    OK, a bit over-dramatic with the title, but literary license means I can, so I did. Seriously now, on April 8, 2014, official support for Wi...
  • Malware Spotlight Double Header: Bagle and Netsky.
    For a reader special, we are taking a look at two pieces of malware, both of which are related in a way. Bagle is a mass mailing worm which ...
  • What Does It Mean? Layered Defense
    These days, you can't read, hear. or see anything about computer security without catching the phrase "Layered Defense" or som...

Categories

  • Macs
  • Spotlight On Malware
  • What Does It Mean?
  • What's in a name?
  • Windows

Blog Archive

  • ▼  2013 (19)
    • ►  November (1)
    • ►  April (3)
    • ▼  March (7)
      • Malware Spotlight Double Header: Bagle and Netsky.
      • What Does It Mean? Layered Defense
      • What's In A Name: Rootkits
      • How do I make sure my Antivirus Software is protec...
      • Spotlight On Malware: The Conficker Worm.
      • Where did this whole issue with Malware begin?
      • My Take on Third Party Tech Support.
    • ►  February (6)
    • ►  January (2)
Powered by Blogger.

About Me

Unknown
View my complete profile