You are here: silicon.com > Software > Malware

Malware

Conficker wakes up with payload for the infected

The worm that turned to P2P

Tags: payload, p2p, worm, conficker

By Elinor Mills

Published: 9 April 2009 16:04 GMT

The Conficker worm started to update itself on Wednesday via peer-to-peer, and dropped a payload on infected computers, according to Trend Micro.

At the time of writing researchers were analysing the code of the software that had been dropped onto infected computers. The researchers suspected that it was a keystroke logger, or some other data-stealing program, said David Perry, global director of security education at Trend Micro.

Researchers for Trend Micro said that the software appeared to be a .sys component hiding behind a rootkit, which is software that is designed to hide the fact that a computer has been compromised. The software was heavily encrypted, which made code analysis difficult, the researchers said.

The update appeared to be attempting to access the Waledac domain, according to a post on the TrendLabs Malware Blog on Wednesday. W32.Waledac steals sensitive information, turns computers into spam zombies, and establishes a back door remote access.

The worm also tried to connect to MySpace.com, MSN.com, eBay.com, CNN.com and AOL.com, to test if the computer had internet connectivity. It then deleted all traces of itself in the host machine, and was set to shut down on 3 May, according to the TrendLabs Malware Blog.

Infected computers are receiving the new component in a staggered manner rather than all at once, so there should be no disruption to the websites the computers visit, said Paul Ferguson, advanced threats researcher for Trend Micro.

On Tuesday night Trend Micro researchers noticed a new file in the Windows Temp folder and a huge encrypted TCP response from a known Conficker P2P IP node hosted in Korea.

"As expected, the P2P communications of the Downad/Conficker botnet may have just been used to serve an update, and not via HTTP," the blog post says. "The Conficker/Downad P2P communications is now running in full swing!"

A previous variant, Conficker.C, failed to make a splash a week ago despite the fact that it was programmed to activate on 1 April. It has infected between three million and 12 million computers, according to Perry.

Initially, researchers thought they were seeing a new variant of the Conficker worm, but now they believe it is merely a new component of the worm.

Security company Symantec said on Thursday that the update was for machines infected with the first variant of the worm, Conficker.A.

The worm spreads via a hole in Windows that Microsoft patched in October, as well as through removable storage devices and network shares with weak passwords. The worm disables security software and blocks access to security websites.

Tom Espiner from ZDNet UK contributed to this article

Original article: Conficker wakes up, updates via P2P, drops payload from CNET News.com

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Tim Ferguson Exclusive: Former MySQL boss Marten Mickos talks open source Why Microsoft could become one of the "biggest friends of open source" and why Oracle getting its hands on MySQL could be "one of the biggest open source coups ever"...

Naked CIO Naked CIO: Cloud computing more expensive than we thought? Smart IT leaders will examine the impact of how they pay for tech


  • Jobs
Software/Web Developer - North-west - Permanent - c28k-34k

The systems development team is responsible for a variety of existing internal and external Websites and systems that are under a rolling program of ...

Business Analyst - Oxfordhsire

Person specification This role gives the opportunity for the post holder to work with the senior management team with exposure to all the component ...

Electronics Engineer

This will include:Concept generation Analysis and development of system architectures Analogue, digital and power electronics design Working closely ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: