A brief outline of the story so far with WORM_DOWNAD and some thoughts about the April 1st “activation date”.

 

 

“This could well be very big, but it will also be very quiet.”

I’m beginning to get a little exercised by many of the verbs I am seeing attached to this malware in recent commentary; words like “virus set to explode”, “erupt”, “blow up” or “will infect 12m computers on April 1st”. I put the following information together to try to clarify exactly what will be “activated” on April the 1st and bring some rationality to the debate.

 

First Variant

In November 2008, Downad/Conficker was seen for the first time. This first variant was the most simple; it spread by exploiting a vulnerability (MS08-67) that was actually patched by Microsoft back in October of 2008. This variant actively avoided infecting systems that were configured to use a Ukrainian keyboard layout or had IP addresses registered to the Ukraine (which may give some clue as to its origins). This original variant, once it had infected a machine would firstly randomly generate IP addresses and use those to search for new victims to infect and then go on to attempt to download some rogue antivirus “scareware” as a one-time event. From that point on, it would generate a daily list of 250 pseudo-random domain names using the top level domain suffixes com, .net, .org, .info, and .biz and attempt to connect out to those servers and download further malicious content.

worm_downad_a1

 

Second Variant

January 2009 saw the second Downad/Conficker variant, which was largely a rewrite of the first; it no longer excluded Ukrainian systems and did not try to download the “scareware” as the first variant did. It also used several more mechanisms through which to spread. In addition to exploiting the Microsoft vulnerability, it also spread by writing to any removable drives plugged into infected systems, any shared network drives currently attached and additionally searched for machines on the same network against which it would attempt a brute force password attack using a list of over 240 predefined common passwords. This second variant also attempted to disable many well known anti-virus programs, blocks access to security related web sites, and disabled key Microsoft security services such as Windows Automatic Update. These additional methods of self-propagation are though to have contributed to the worm’s success at infecting large numbers of machines.

 

This second variant also generates a daily list of 250 domains to try to connect to this time using more top level domain suffixes com, .net, .org, .info, .biz, and adding .ws, .wn and .cc  The domains generated by the two versions do not overlap.

 downad_1

 

Third Variant

In March 2009, a significant third Downad/Conficker variant surfaced. This new version appears to have been spread by an update pushed out to machines previously infected with the second variant. This new version now generates a daily list of 50,000 Internet domain names instead of the 250 generated previously and rather than the 5 or 8 top level domains used by the first two variants, this version uses 110 different top level domains. Only 500 of these generated domains are queried, and only once per day. It is this mechanism that is coded to begin on 1st April, and the sheer numbers of domain names involved render redundant the blocking mechanisms used so far to combat the worm.

 

In addition to this already established HTTP Command & Control infrastructure, this new variant also introduced Peer to Peer communications capabilities between infected hosts, presumably in an effort to get around the security and internet industries attempts to shut down the HTTP connection mechanism.

 

In this third update, the propagation methods present in the first and second variants have been removed and the stance of the infection has shifted to a more defensive one. This signals perhaps that the cybercriminals behind this feel they have infected enough machines to turn this into a “simple” botnet for distributing whichever malicious code they see fit. Remember though, the propagation functionality could just as easily be switched on again as required by the authors.

 

It’s really anyone’s guess what the infected hosts will be used for if the command & control infrastructure goes live on April 1st. Pushing rogue AV? Sending Spam? Carrying out Denial of Service attacks on other servers and Internet infrastructure? Hosting Malware and Phishing sites? Or simply creating a very large asset pool of infected PCs for the owners to rent out for cash? Personally I don’t buy into the mass attack scenario, the motivator for mainstream cybercrime is still cash generation, and “bringing down the Internet” wouldn’t be much of an earner. The people behind this piece of code are very skilled, very well informed and resourced. They have invested much time and effort in the creation of this botnet, and will be aiming to see some return on that investment. Making so much noise that every victim knows they’re infected will have entirely the opposite effect. This could well be very big, but it will also be very quiet.

 

If you believe your system may be infected by Downad/Conficker, then online scanners and tools almost certainly won’t be of any use to you, because the websites will be blocked by the infection. I would recommend you download SysClean, a free tool from Trend Micro to remove any infection.

 

For a great in-depth analysis of Downad/Conficker, please have a look at the Research Paper written by SRI International


Bookmark
| More
This entry was posted on Wednesday, 25. March 2009 and is filed under "malware". You can follow any responses to this entry with RSS 2.0. You can leave a response here, or send a trackback from your own site.

13 Comments to "Downad/Conficker, who’s the April Fool?"

Tech Whiz Underground » Cool down on Conflicker panic, say experts:
Friday, 27. March 2009 um 12:33 am

[...] in the creation of this botnet, and will be aiming to see some return on that investment,” wrote Trend Micro senior security advisor Rik [...]

conficker virus:
Friday, 27. March 2009 um 7:31 pm

[...] see some return on that investment,” wrote Trend Micro senior security advisor Rik Ferguson in a blog post. Source: [...]

Conficker with 10M victims, April 1 update soon | EC-Comp.com:
Saturday, 28. March 2009 um 6:47 am

[...] “The Conficker worm is going to change its operation a bit, but that’s unlikely to cause anything visible on 1 April,” F-Secure said. The company also noted that only the latest version of the malware, known as ‘Conficker C’, which constitutes a small percentage of total infections, would be carrying out any instructions on 1 April. “The truth is that Conficker is not set to activate a specific payload on 1 April. Rather, Conficker will begin to attempt to contact the 50,000-a-day potential call-home web servers from which it may receive updates.”  Malware creation has evolved into a lucrative business since Melissa, and most experts believe that Conficker’s update will be the first step in a spam run or other money-making activity, rather than an old-fashioned attempt at internet mayhem. “The people behind this piece of code are very skilled, very well informed and resourced. They have invested much time and effort in the creation of this botnet, and will be aiming to see some return on that investment,” wrote Trend Micro senior security advisor Rik Ferguson in a blog post. [...]

What Will Go DOWNAD on April 1?:
Monday, 30. March 2009 um 11:21 am

[...] Downad/Conficker, who’s the April Fool? [...]

Latest Antivirus Updates » What Will Go DOWNAD on April 1?:
Monday, 30. March 2009 um 12:59 pm

[...] Downad/Conficker, who’s the April Fool? [...]

Robert Burntwing:
Tuesday, 31. March 2009 um 12:53 pm

If the virus is blocking AV sites, how would one download the sysclean tool from trend micro?

Rik Ferguson:
Tuesday, 31. March 2009 um 1:34 pm

Hi Robert,

Yes, this is absolutely a recurring problem. If you have a machine that is infected, then in most cases it will not be possible to use that particular machine to download repair tools from most domains associated with security. The best course of action is to use a machine that is not infected to make the download, then use some kind of removable media to get the fix tools to the infected machine. Make sure that removable media is write-protected before you put it into the infected machine.

joey:
Wednesday, 1. April 2009 um 3:45 pm

okay I also will Say this The Person who made is Is almost 85% sure using a IRC infection meted.. that sends cmds to a irc server.. by the maker … IF its a private IRC then noone can find the orignal maker. of it.. No Matter what.. about the Data sending i don’t think there will be.. maybe Just websites and a few others things to send the virus out to more people but thats about it..

And also it can be someone also on there pc like me .. typing away there life.. on a computer.. and Using there internet to connect to the victoms but most worms use IRC …. Newer ones.. so Yeah…

thanks for reading

joey

Twitter Trackbacks for Downad/Conficker, who’s the April Fool? » CounterMeasures [trendmicro.eu] on Topsy.com:
Monday, 24. August 2009 um 8:30 am

[...] Downad/Conficker, who’s the April Fool? » CounterMeasures countermeasures.trendmicro.eu/downadconficker-whos-the-april-fool – view page – cached A Trend Micro Blog. Rik Ferguson and others blog about security related issues — From the page [...]

60 Minutes Conficker and Malware Report | Software News Daily:
Wednesday, 16. September 2009 um 6:49 pm

[...] up harmful links that will in fact deliver the worm to the very people looking to remove it. In its detailed report of the different instances of Conficker, Trend Micro states that internet based virus scans will [...]

ReleaseTest » Conficker with 10M victims, April 1 update soon:
Monday, 12. October 2009 um 5:00 am

[...] “The Conficker worm is going to change its operation a bit, but that’s unlikely to cause anything visible on 1 April,” F-Secure said. The company also noted that only the latest version of the malware, known as ‘Conficker C’, which constitutes a small percentage of total infections, would be carrying out any instructions on 1 April. “The truth is that Conficker is not set to activate a specific payload on 1 April. Rather, Conficker will begin to attempt to contact the 50,000-a-day potential call-home web servers from which it may receive updates.”  Malware creation has evolved into a lucrative business since Melissa, and most experts believe that Conficker’s update will be the first step in a spam run or other money-making activity, rather than an old-fashioned attempt at internet mayhem. “The people behind this piece of code are very skilled, very well informed and resourced. They have invested much time and effort in the creation of this botnet, and will be aiming to see some return on that investment,” wrote Trend Micro senior security advisor Rik Ferguson in a blog post. [...]

2010 – Year Of The Zombie Cloud? | Business Computing World:
Wednesday, 16. December 2009 um 10:41 am

[...] the first half of the year, the Conficker worm (also known as Downadup or Kido) stole all the headlines in the malware world. Eventually the [...]

bodo unger:
Friday, 8. January 2010 um 3:17 am

The writer of the conficker virus is Mario Fiege a German in the Philippines. he is working with glavmed.com.stimul-cash.com , rx-promotion.com , spamit.com. He is pretending to be a russian in the internet while hacking domains,,hijacking forums and sending millions of email spam out of malware ghettos like asian.
He is using proxyway.com


Name:

E-Mail (not published)

Website:


Spam protection


© Copyright 2010 Trend Micro Inc. All rights reserved.
Legal Notice | Disclaimer