TrendLabs researcher Ivan Macalintal has this evening discovered a new variant of Downad/Conficker called WORM_DOWNAD.E spreading over the peer-to-peer functionality of the previous version of this now infamous worm.

As well as reactivating the original propogation functionality, this new variant sheds some extra light on possible links with other malware and origins of the worm. This new Downad/Conficker variant is talking to a server which is known already for being associated with the Waledac family of malware, in order to download further malicious components. These components have so far been missing, but could this finally be the “other boot dropping” that we have all been waiting for?
Waledac has, for a while now, been suspected to be the latest offering from the people behind the Storm botnet. Could it be that Downad/Conficker, Waledac and Storm all originate from the same cybercriminal gang?
Please read the TrendLabs Malware blog for a detailed breakdown.

Pingback: The ultimate guide to scareware protection « AES IT Security
Pingback: Conficker acorda e instala conteúdo desconhecido nos micros infectados | Tumulto
Pingback: Heise Meldung: Conficker-Wurm lädt jetzt doch nach
Pingback: Trend Micro: Conficker się obudził i instaluje spyware | covalic ...bo grafika jest dla ludzi
Pingback: Conficker disparará novos ataques em 3 de maio
Pingback: Conficker: Neue Variante sorgt für neue Panik
Pingback: Conficker wakes up, updates via P2P, drops payload | Cyberphunkz Tech Blog
Pingback: File Extension Torrent | Gadgets & Tech
Pingback: Top 10 Websites To Learn The Art Of Being A Fashionista | Classics Blog
Pingback: blog.grospolina.net
Pingback: El nuevo Conficker ya no se conecta a dominios | Shadow Security
Pingback: Conficker si è svegliato, altro che pesce d’aprile - The New Blog Times
Pingback: New Downad/Conficker variant spreading over P2P » Counter Measures | thepostingsecrets
Pingback: .:: Securnetwork.net Blog - Massimo Rabbi ::. » Conficker ora si aggiorna!
Pingback: Conficker deve tentar novo ataque em maio « 1security’s Blog
Pingback: Dennison Technology Group Inc. » The Conficker worm is finally active.
Pingback: Conficker.E: Aufgewacht und »Ready to Rock!« - The Inquirer DE
Pingback: Conficker wakes up, updates, drops payload | The IT Security Attaché
Pingback: Conficker alive and well with new variant update via P2P
Pingback: Conficker botnet stirs to distribute update payload - Computer Forums
Pingback: Conficker wakes up, updates, drops payload | Between the Lines | ZDNet.com
Pingback: Trend Micro entdeckt neue Conficker-Variante - Security | News | ZDNet.de
Pingback: Cloud Computing Adoption Comes Down To Trust and Openness | Tek Tips Blogs
Pingback: Conficker wakes up, updates via P2P, drops payload | NJN Network
Pingback: TECHGEEK.com.au : Trend Micro : New variant of Conficker in the wild
Pingback: Malware Diaries » Blog Archive » Conficker alive and well with new variant update via P2P
Pingback: Kaspersky Labs USA » Conficker wakes up, updates via P2P, drops payload