Conficker worm wakes up via peer-to-peer sharing
One week after April 1, Conficker got the first move and the infected computer got a new payload via P2P channel.
Researchers are still analyzing the software code installed on the infected computer and suspect it is a keystroke logger (recording the character entered from the keyboard) or a program designed to steal sensitive information. inside the machine.
According to Trend Micro, the worm tries to access sites like MySpace, MSN, eBay, CNN and AOL to check if the computer is connected to the Internet and "timed" to end on 3. / 5.
" After 3/5, Conficker will stop working and not continue to clone, " said Trend Micro representative.
Yesterday, the company discovered a new file in the Windows Temp folder and a large amount of encrypted TCP response from an IP point that shared peer Conficker worm in Korea.
Mafiaboy, hackers attacked a series of popular websites such as CNN, Yahoo, eBay . and caused $ 1 billion in losses in 2000 when he was 15 years old, said Conficker is just like the tip of the iceberg. This case proves that Internet security is currently not improved, even easier to "hit" than 10 years ago because then most still use dial-up connections.
Conficker is a worm that exploited the vulnerability Microsoft patched in October 2008 by Windows. After nearly 6 months, it upgraded to 3 versions and infected millions of computers. The latest version Conficker.c is supposed to update to a new variant from 1/4. However, April Fools Day passes quietly and security experts say Conficker.c will actually only be added a new element.
- Akamai: Conficker worm is still spreading
- Conficker worm still silently grows
- Description of the P2P-Worm.Win32.BlackControl.g template
- 7 things to know to prevent Conficker worm
- China: Millions of computers infected with the Conficker worm
- Passwords are simply 'fat bait' of Conficker worm
- Conficker's victim has reached 7 million
- How to destroy and prevent Conficker
- How to prevent Conficker (Downadup) worm
- The new worm 'digs' a Windows vulnerability
- How to share files online on LicketyLink
- Conficker worm 'terrorizes' US Utal University
- Tool to destroy the Conficker worm variant for free
- Conficker worm still raging in TM Datacenter data center