facebook rss twitter

Trend Micro detects new activity from Conficker worm

by Scott Bicheno on 9 April 2009, 14:46

Tags: Trend Micro

Quick Link: HEXUS.net/qaruc

Add to My Vault: x

Uh oh

Security software maker Trend Micro publishes a blog in which it gives updates on the latest state of play in the world of malware.

Its latest post concerns the much-feared worm called Conficker (also known as DOWNAD), which had been expected to spring into malevolent life on 1 April. That didn't happen but Trend has recently detected signs of activity from the worm.

"Days after the April 1st activation date of Conficker, nothing interesting was seen so far in our Downad/Conficker monitoring system except the continuous checking of dates and times via Internet sites, checking of updates via HTTP, and the increasing P2P communications from the Conficker peer nodes," opens the post.

"Well that was until last night when we saw a new file (119,296 bytes) in the Windows Temp folder. Checking on the file properties reveals that the file was created exactly on April 7, 2009 at 07:41:21."

Trend goes on to propose that this is a new variant of the worm called WORM_DOWNAD.E. It apparently leaves no trace of itself on the machine after running. The blog concludes by saying "The Conficker/Downad P2P communications is now running in full swing!"

 



HEXUS Forums :: 2 Comments

Login with Forum Account

Don't have an account? Register today!
I'll be watching http://isc.sans.org/diary.html?storyid=6157 closely. I've checked all networks I take care of using nmap and snort and they look to be clean, which is good.
we have seen some activity from this over the last few days.

Popups and error logs filling up due to brute force attempts

“The SAM database was unable to lockout the account of account-name due to a resource error, such as a hard disk write failure (the specific error code is in the error data) . Accounts are locked after a certain number of bad passwords are provided so please consider resetting the password of the account mentioned above.”

this is W32.Downadup.B