| |
Worm Conficker/Downadup/Kido widely propagating
Date: January 22, 2009
Updated: February 09, 2009; February 18, 2009; February 23, 2009; March 19, 2009; March 31, 2009; April 15, 2009; May 13, 2009
It has been observed that worm Win32/Conficker/Downadup/kido is spreading widely by exploiting a previously reported Server Service vulnerability described in CERT-In vulnerability note CIVN-2008-170
and Microsoft Security Bulletin MS08-067.
Apart from exploiting the said vulnerability, the attack vectors include network shares (ADMINI$ shares with a long list of hard-coded passwords), removable drives (drops a hidden autorun.inf file), scareware (fake security alerts to frighten consumers into purchasing bogus computer security software) and most recently Metasploit payload (the exploitation method derived from the metasploit ms08_067_netapi module to spread itself).
It is reported that this worm is actively infecting Windows systems with specific language operating systems such as English, Chinese, Arabic, Portugese.
It has also been reported that a list of malicious domains (randomly generated by the worm) are hosting the copy of the worm and are requested for further downloading from the infected machine.
The worm can act as a HTTP server listening to a random port between 1024 and 10000 and if the remote machine is exploited successfully, the victim will connect back to the http server and download a variant of the worm.
A new variant, Conficker B++ or C implements a new backdoor with "auto-update" functionality, allowing machines compromised by the new variant to have additional malicious code installed on them. Conficker.C uses robust P2P to distribute cryptographically signed updates to other computers infected with conficker.This P2P functionality contains a UDP P2P discovery routine that sends UDP traffic to lists of generated IPs and ports.
A new polymorphic variant, Conficker.D infects the local computer, terminates services and blocks access to numerous Web sites. This variant does not spread to removable drives or shared folders across a network. Win32/Conficker.D may build 50,000 URLs per day to download files and only visits 500 of the generated URLs within a 24-hour period. After a successful download/execution from a generated URL, Win32/Conficker.D lays dormant for four days before resuming URL monitoring again.
Conficker-E is the latest version of the Conficker worm which ultimately drops conficker.C in the victim system.it downloads W32.Waledac trojan and it may also download rogue security tool Spyware Protect 2009.It Opens port 5114 and serve as HTTP server, by broadcasting via SSDP request. Conficker-E is set to delete itself on the May 3, 2009.
When infected the following symptoms can be observed in the affected machine:
- Blocked access to antivirus-related sites.
- Disabled services such as Windows Automatic Update Service, Windows Security Center, Windows Defender and Windows Error Reporting and Internet connection sharing service.
- Resets System Restore Point.
- High traffic on port 445 in the affected network.
- Hidden files even after changing the ‘Folder Options’.
- Inability to log in using Windows credentials because they are locked out
Note: Users are advised to download Conficker Removal Tools only from the genuine Antivirus Websites. This is because man websites having names related to "Conficker" are being used to serve Conficker Worm in place of genuine Conficker Removal Tools.
A list of possible malicious domains are given here
Countermeasures:
Free Removal Tools:
References
http://www.cert-in.org.in/vulnerability/civn-2008-170.htm
http://www.cert-in.org.in/virus/win32_conficker.htm
http://www.avertlabs.com/research/blog/index.php/2009/01/15/conficker-worm-using-metasploit-
payload-to-spread/
http://blog.trendmicro.com/the-mess-that-is-worm_downad/
http://www.microsoft.com/security/portal/Entry.aspx?Name=Win32%2fConficker
http://www.microsoft.com/security/portal/Entry.aspx?Name=Worm%3aWin32%2f
Conficker.gen!A
http://www.microsoft.com/security/portal/Entry.aspx?Name=Worm%3aWin32%2f
Conficker.A
http://www.securityfocus.com/brief/887
http://www.microsoft.com/security/portal/Entry.aspx?Name=Worm%3aWin32%2f
Conficker.B
http://news.bbc.co.uk/1/hi/technology/7832652.stm
http://voices.washingtonpost.com/securityfix/2009/01/tricky_windows_worm_
wallops_mi.html?
wprss=securityfix
http://support.microsoft.com/kb/962007
http://mtc.sri.com/Conficker
http://www.microsoft.com/security/portal/Entry.aspx?Name=Worm%3aWin32%2f
Conficker.C
http://www.us-cert.gov/current/index.html
http://www.doxpara.com/?p=1285
http://www.skullsecurity.org/blog/?p=209
http://seclists.org/nmap-dev/2009/q1/0869.html
http://honeynet.org/node/388
http://www.mcafee.com/us/threat_center/conficker.html
http://iv.cs.uni-bonn.de/wg/cs/applications/containing-conficker/
http://www.microsoft.com/security/portal/Entry.aspx?name=Worm:Win32/Conficker.E
https://forums2.symantec.com/t5/blogs/blogarticlepage/blog-id/malicious_
code/article-id/262
http://blogs.technet.com/msrc/archive/2009/04/09/conficker-e.asp
|
|