<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>CounterMeasures -  A Security Blog  downadup</title>
	<atom:link href="http://countermeasures.trendmicro.eu/tag/downadup/feed/" rel="self" type="application/rss+xml" />
	<link>http://countermeasures.trendmicro.eu</link>
	<description>Trend Micro’s Rik Ferguson blogs about current security issues.</description>
	<lastBuildDate>Wed, 01 Feb 2012 14:48:59 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>History of the botnet &#8211; White Paper</title>
		<link>http://countermeasures.trendmicro.eu/history-of-the-botnet-white-paper/</link>
		<comments>http://countermeasures.trendmicro.eu/history-of-the-botnet-white-paper/#comments</comments>
		<pubDate>Fri, 12 Nov 2010 13:09:08 +0000</pubDate>
		<dc:creator>Rik Ferguson</dc:creator>
				<category><![CDATA[malware]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[downadup]]></category>
		<category><![CDATA[malicious code]]></category>
		<category><![CDATA[waledac]]></category>
		<category><![CDATA[worm_downad]]></category>
		<category><![CDATA[ZeuS]]></category>

		<guid isPermaLink="false">http://countermeasures.trendmicro.eu/?p=2463</guid>
		<description><![CDATA[Just a quick update, the three part series I have blogged here has been published today as a White Paper. If you&#8217;re interested it can be downloaded here as a 13 page PDF.<div class="addthis_toolbox addthis_default_style " addthis:url='http://countermeasures.trendmicro.eu/history-of-the-botnet-white-paper/' addthis:title='History of the botnet &#8211; White Paper '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_button_google_plusone" g:plusone:size="medium"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></description>
			<content:encoded><![CDATA[<p>Just a quick update, the three part series I have blogged here has been published today as a White Paper. If you&#8217;re interested it can be downloaded <a onclick="pageTracker._trackPageview('/go/CMblog/botnetwhitepaper/');" href="http://uk.trendmicro.com/imperia/md/content/uk/trendmicro_the_botnet_chronicles_en.pdf">here</a> as a 13 page PDF.</p>
<div class="addthis_toolbox addthis_default_style " addthis:url='http://countermeasures.trendmicro.eu/history-of-the-botnet-white-paper/' addthis:title='History of the botnet &#8211; White Paper '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_button_google_plusone" g:plusone:size="medium"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></content:encoded>
			<wfw:commentRss>http://countermeasures.trendmicro.eu/history-of-the-botnet-white-paper/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Look Out, Licat!</title>
		<link>http://countermeasures.trendmicro.eu/look-out-licat/</link>
		<comments>http://countermeasures.trendmicro.eu/look-out-licat/#comments</comments>
		<pubDate>Thu, 07 Oct 2010 13:49:18 +0000</pubDate>
		<dc:creator>Rik Ferguson</dc:creator>
				<category><![CDATA[malware]]></category>
		<category><![CDATA[conficker]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[downadup]]></category>
		<category><![CDATA[malicious code]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[worm_downad]]></category>

		<guid isPermaLink="false">http://countermeasures.trendmicro.eu/?p=2368</guid>
		<description><![CDATA[UPDATE: Further research has confirmed that LICAT appears to be very strongly linked to ZeuS possibly in an effort to rebuild or strengthen botnets after recent law enforcement activities ______________________________________________________________________________________ Researchers at TrendLabs have blogged this morning about a new file infector virus known as Licat.a which appears to be be geographically and numerically widespread. [...]<div class="addthis_toolbox addthis_default_style " addthis:url='http://countermeasures.trendmicro.eu/look-out-licat/' addthis:title='Look Out, Licat! '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_button_google_plusone" g:plusone:size="medium"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></description>
			<content:encoded><![CDATA[<p><strong>UPDATE</strong>: <a href="http://blog.trendmicro.com/links-between-pe_licat-and-zeus-confirmed/">Further research</a> has confirmed that LICAT appears to be very strongly linked to ZeuS possibly in an effort to rebuild or strengthen botnets after recent law enforcement activities<br />
______________________________________________________________________________________</p>
<p>Researchers at TrendLabs have <a href="http://blog.trendmicro.com/file-infector-uses-domain-generation-technique-like-downadconficker/">blogged</a> this morning about a new file infector virus known as <a href="http://threatinfo.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=PE_LICAT.A">Licat.a</a> which appears to be be geographically and numerically widespread. Research into the malicious code is ongoing.<br />
  <br />
&nbsp;<br />
<div id="attachment_2372" class="wp-caption alignleft" style="width: 486px"><img class="size-full wp-image-2372" title="Licat Distribution" src="http://countermeasures.trendmicro.eu/wp-content/uploads/2010/10/Licat1.jpg" alt="" width="476" height="190" /><p class="wp-caption-text">Licat Distribution</p></div><br />
&nbsp;<br />
A file infector is malware which could be considered the most &#8220;classic&#8221; form of virus, one that seeks out other file types and injects its own code into these victim files. Whenever one of the infected files is opened this causes the malicious code to execute.<br />
&nbsp; <br />
Licat seeks out .EXE files on infected system and modifies those files, adding its malicious routines.<br />
&nbsp; <br />
When an infected file is opened, Licat will generate a series of 800 internet addresses in the format<em> </em>below. The pseudorandom alpha characters are generated using a randomizing function, which is computed from the current UTC system date and time.<br />
&nbsp;<br />
<em>http://{pseudorandom alpha characters}.biz/forum/ </em></p>
<p><em>http://{pseudorandom alpha characters}.org/forum/ </em></p>
<p><em>http://{pseudorandom alpha characters}.info/forum/ </em></p>
<p><em>http://{pseudorandom alpha characters}.net/forum/</em></p>
<p><em>http://{pseudorandom alpha characters}.com/forum/</em>.<br />
 &nbsp;<br />
It will then attempt to connect to each of these destinations to download and execute further components or other payloads. The last time similar behaviour to this was seen was in the infamous <a href="http://countermeasures.trendmicro.eu/downadconficker-whos-the-april-fool/" target="_blank">Conficker </a>botnet<br />
 &nbsp;<br />
Analysis of the mother infector file is ongoing and further details will be posted on the <a href="http://blog.trendmicro.com/file-infector-uses-domain-generation-technique-like-downadconficker/" target="_blank">TrendLabs blog</a>.</p>
<div class="addthis_toolbox addthis_default_style " addthis:url='http://countermeasures.trendmicro.eu/look-out-licat/' addthis:title='Look Out, Licat! '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_button_google_plusone" g:plusone:size="medium"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></content:encoded>
			<wfw:commentRss>http://countermeasures.trendmicro.eu/look-out-licat/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>2010 &#8211; Year of the Zombie Cloud?</title>
		<link>http://countermeasures.trendmicro.eu/2010-year-of-the-zombie-cloud/</link>
		<comments>http://countermeasures.trendmicro.eu/2010-year-of-the-zombie-cloud/#comments</comments>
		<pubDate>Tue, 15 Dec 2009 10:10:26 +0000</pubDate>
		<dc:creator>Rik Ferguson</dc:creator>
				<category><![CDATA[malware]]></category>
		<category><![CDATA[Opinion]]></category>
		<category><![CDATA[Web 2.0]]></category>
		<category><![CDATA[conficker]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[downadup]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[Twitter]]></category>
		<category><![CDATA[web]]></category>

		<guid isPermaLink="false">http://countermeasures.trendmicro.eu/?p=1606</guid>
		<description><![CDATA[  2009 has been a notable year for malware and malicious online activity for a number of reasons and several of them relate to what is known as botnets. A zombie, or a bot, is a PC infected by malware that brings it under the remote control of a criminal. Criminals run networks that can [...]<div class="addthis_toolbox addthis_default_style " addthis:url='http://countermeasures.trendmicro.eu/2010-year-of-the-zombie-cloud/' addthis:title='2010 &#8211; Year of the Zombie Cloud? '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_button_google_plusone" g:plusone:size="medium"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></description>
			<content:encoded><![CDATA[<div id="attachment_1607" class="wp-caption alignleft" style="width: 510px"><a href="http://countermeasures.trendmicro.eu/wp-content/uploads/2009/12/zombiesnolove.jpg"><img class="size-full wp-image-1607" title="zombiesnolove" src="http://countermeasures.trendmicro.eu/wp-content/uploads/2009/12/zombiesnolove.jpg" alt="zombiesnolove" width="500" height="375" /></a><p class="wp-caption-text">How to Survive a Zombie Attack, by Acey Duecy</p></div>
<p> </p>
<p>2009 has been a notable year for malware and malicious online activity for a number of reasons and several of them relate to what is known as <strong><em>botnets</em></strong>. A zombie, or a bot, is a PC infected by malware that brings it under the remote control of a criminal. Criminals run networks that can range from thousands to millions of infected machines and they use them to power most of the cybercrime we see today including spam, DDoS, scareware, phishing, and malicious or illegal website hosting. They have a finger in every cybercriminal pie.</p>
<p> </p>
<p>In the first half of the year, the <a title="Conficker, who's the April fool?" href="http://countermeasures.trendmicro.eu/downadconficker-whos-the-april-fool/" target="_blank"><em>Conficker</em> </a>worm (also known as <em>Downadup</em> or <em>Kido</em>) stole all the headlines in the malware world. Eventually the <em>Conficker</em> botnet was seen to deliver standard cybercriminal payloads, such as spambots and Fake AV (or scareware), much to the disappointment of some of the more hysterical commentators. Just because the outbreak received so much coverage that died away just as rapidly, don’t be fooled into thinking this threat has gone away. The <em>Conficker Working Group</em>, an alliance of security vendors, researchers and other commercial organisations is <a title="Conficker infection tracking" href="http://www.confickerworkinggroup.org/wiki/pmwiki.php/ANY/InfectionTracking" target="_blank">currently showing </a>around 6 million unique IP addresses as appearing to be infected with this malware.</p>
<p> </p>
<p>An unrelated, but important trend in 2009 was the exponential increase in the abuse of social networking providers for malicious purposes. The enormous active user populations on sites like <em>Facebook</em>, <em>Twitter</em> and <em>MySpace</em> prove a very attractive lure to organised online crime and its attendant money-making, bot recruitment and Fake AV pushing scams. <em>Facebook</em> has been <a title="Two more rogue Facebook apps" href="http://countermeasures.trendmicro.eu/two-more-rogue-facebook-apps-linked-to-fucabook-scam/" target="_blank">abused by rogue Apps</a>, designed to fool users into clicking links that reward the creator through pay-per-click affiliate advertising networks. It has also been used to spread malware through many means; malicious links in wall posts and messages, malware designed specifically to <a title="Koobface abuses Google Reader pages" href="http://blog.trendmicro.com/koobface-abuses-google-reader-pages/" target="_blank">hijack accounts</a> and by <a title="Hacked Facebook applications reach out to exploit sites in Russia" href="http://thompson.blog.avg.com/2009/10/hacked-facebook-applications-reach-out-to-exploit-sites-in-russia.html" target="_blank">external compromise </a>of legitimate Facebook Apps. The <em>Koobface</em> family of malware (also a botnet) has evolved over the course of 2009; it was initially spread through malicious messages and wall posts with links to fake <em>YouTube</em> sites punting a supposed codec in order to view the video. The codec of course was nothing of the sort and led to infection and account hijacking. <em>Koobface</em> now though has evolved to the point where it is fully <a title="New Koobface Component Imitates Facebook User" href="http://blog.trendmicro.com/new-koobface-component-imitates-facebook-user/" target="_blank">capable of creating its own fake <em>Facebook</em> profile </a>pages, complete with confirmed <em>Gmail</em> address, photo and biographical data. These fake accounts then set about joining networks and sending friend requests again all in a completely automated fashion.</p>
<p> </p>
<p>Here’s where it gets interesting, in addition to spamming and malware, web 2.0 sites have been abused in new and concerning ways over the course of 2009. <em>Twitter</em> and <em>Google Reader</em> have been <a title="Job Spam uses Twitter" href="http://blog.trendmicro.com/job-spam-uses-twitter/" target="_blank">used as the landing page</a> in spam campaigns, to attempt to overcome URL filtering in email messages. In recent months <em><a title="Twitter based botnet commend channel" href="http://asert.arbornetworks.com/2009/08/twitter-based-botnet-command-channel/">Twitter</a>, <a title="What is your bot Facebook status today?" href="http://www.symantec.com/connect/blogs/trojanwhitewell-what-s-your-bot-facebook-status-today" target="_self">Facebook</a>, <a title="Pastebin botnets" href="http://blog.spywareguide.com/2009/06/pastebin-botnets.html" target="_blank">Pastebin</a>, <a title="Botnet C&amp;C on Google Groups" href="http://news.softpedia.com/news/Botnet-C-C-Server-Hosted-on-Google-Groups-121576.shtml" target="_blank">Google Groups</a></em> and a <a title="Botnet Command and Control Server Hosted on Google App Engine" href="http://news.softpedia.com/news/Botnet-Command-and-Control-Server-Hosted-on-Google-App-Engine-126559.shtml" target="_blank"><em>Google AppEngine</em> </a>have all been used as surrogate Command &amp; Control servers for botnets, and just last week <a title="Zeus crimeware using Amazon's EC2 as command and control server" href="http://blogs.zdnet.com/security/?p=5110" target="_blank">it was reported</a> that a Zeus botnet was leveraging compromised servers inside Amazon’s EC2 cloud for command and contro. These public forums have been configured to issue obfuscated commands to globally distributed botnets, these commands often contain further URLs which the bot then accesses to download commands or components.</p>
<p> </p>
<p>The attraction with these sites and services lies in the fact that they offer a public, open, scalable, highly-available and relatively anonymous means of maintaining a command and control infrastructure, which at the same time further reduces the chance of detection by traditional technologies. Whilst network content inspection solutions could reasonably be expected to pick up on compromised endpoints that are communicating with known-bad sites (command &amp; control servers), or over suspicious or unwanted channels such as IRC; it has been historically safe to assume that a PC making a standard HTTP GET request, over port 80 to a content provider such as Facebook, Google or Twitter, even several times every day, is as acting entirely normally. However, as botnet owners and criminal outfits seek to further dissipate their command and control infrastructure and blend into the general white noise of the internet, <strong>that is no longer the case</strong>.</p>
<p> </p>
<p>It is no coincidence that much the innovation in 2009 has been around command &amp; control systems for botnets. The vast majority of old-school IRC controlled botnets are shut down within 24 hours and peer-to-peer bots often leave visible signatures too, leading to their neutralisation at machine level. One factor of web 2.0 botnet controls that I would expect cybercriminals to be currently evaluating is the single point of failure represented by relying on a single provider such as Facebook or Google–shut down the malicious Facebook page and you disable the botnet. Botnet creators have invested significant amounts of time and code in distributing their management infrastructure, in fast-flux and in peer-to-peer protocols. We can fully expect them to carry these lessons learned into the newer “cloud-enabled” botnet. It is entirely possible that the capability of the latest Koobface variant to create multiple automated profiles could be leveraged to mitigate against the single point of failure inherent in using a single Facebook or Twitter profile as a covert channel.</p>
<p>When it comes to botnets it would be really nice to be able to say “it’s getting better”.  <strong>It’s not</strong>.  <a title="The Internet Infestation, How Bad Is It Really?" href="http://blog.trendmicro.com/the-internet-infestation-how-bad-is-it-really/" target="_blank">More and more computers are being infected, and they are staying infected for longer</a>.</p>
<div class="addthis_toolbox addthis_default_style " addthis:url='http://countermeasures.trendmicro.eu/2010-year-of-the-zombie-cloud/' addthis:title='2010 &#8211; Year of the Zombie Cloud? '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_button_google_plusone" g:plusone:size="medium"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></content:encoded>
			<wfw:commentRss>http://countermeasures.trendmicro.eu/2010-year-of-the-zombie-cloud/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>New Downad/Conficker variant spreading over P2P</title>
		<link>http://countermeasures.trendmicro.eu/new-downadconficker-variant-spreading-over-p2p/</link>
		<comments>http://countermeasures.trendmicro.eu/new-downadconficker-variant-spreading-over-p2p/#comments</comments>
		<pubDate>Wed, 08 Apr 2009 19:21:14 +0000</pubDate>
		<dc:creator>Rik Ferguson</dc:creator>
				<category><![CDATA[malware]]></category>
		<category><![CDATA[conficker]]></category>
		<category><![CDATA[downadup]]></category>
		<category><![CDATA[malicious code]]></category>
		<category><![CDATA[waledac]]></category>
		<category><![CDATA[worm_downad]]></category>

		<guid isPermaLink="false">http://countermeasures.trendmicro.eu/?p=453</guid>
		<description><![CDATA[TrendLabs researcher Ivan Macalintal has this evening discovered a new variant of Downad/Conficker called WORM_DOWNAD.E spreading over the peer-to-peer functionality of the previous version of this now infamous worm.   As well as reactivating the original propogation functionality, this new variant sheds some extra light on possible links with other malware and origins of the worm. This [...]<div class="addthis_toolbox addthis_default_style " addthis:url='http://countermeasures.trendmicro.eu/new-downadconficker-variant-spreading-over-p2p/' addthis:title='New Downad/Conficker variant spreading over P2P '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_button_google_plusone" g:plusone:size="medium"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></description>
			<content:encoded><![CDATA[<p>TrendLabs researcher Ivan Macalintal has this evening discovered a new variant of Downad/Conficker called <a href="http://threatinfo.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM%5FDOWNAD%2EE&amp;VSect=P" target="_blank">WORM_DOWNAD.E</a> spreading over the peer-to-peer functionality of the previous version of this now infamous worm.</p>
<p><img class="alignleft size-full wp-image-458" title="worm_downad_e_bd" src="http://countermeasures.trendmicro.eu/wp-content/uploads/2009/04/worm_downad_e_bd.gif" alt="worm_downad_e_bd" width="490" height="591" /></p>
<p> </p>
<p>As well as reactivating the original propogation functionality, this new variant sheds some extra light on possible links with other malware and origins of the worm. This new Downad/Conficker variant is talking to a server which is known already for being associated with the Waledac family of malware, in order to download further malicious components. These components have so far been missing, but could this finally be the &#8220;other boot dropping&#8221; that we have all been waiting for?</p>
<p> </p>
<p>Waledac has, for a while now, been suspected to be the latest offering from the people behind the Storm botnet. Could it be that Downad/Conficker, Waledac and Storm all originate from the same cybercriminal gang?</p>
<p> </p>
<p>Please read the <a href="http://blog.trendmicro.com/downadconficker-watch-new-variant-in-the-mix/" target="_self">TrendLabs Malware blog </a>for a detailed breakdown.</p>
<div class="addthis_toolbox addthis_default_style " addthis:url='http://countermeasures.trendmicro.eu/new-downadconficker-variant-spreading-over-p2p/' addthis:title='New Downad/Conficker variant spreading over P2P '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_button_google_plusone" g:plusone:size="medium"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></content:encoded>
			<wfw:commentRss>http://countermeasures.trendmicro.eu/new-downadconficker-variant-spreading-over-p2p/feed/</wfw:commentRss>
		<slash:comments>27</slash:comments>
		</item>
		<item>
		<title>Restore Access to Blocked Sites on Conficked Systems</title>
		<link>http://countermeasures.trendmicro.eu/restore-access-to-blocked-sites-on-conficked-systems/</link>
		<comments>http://countermeasures.trendmicro.eu/restore-access-to-blocked-sites-on-conficked-systems/#comments</comments>
		<pubDate>Tue, 31 Mar 2009 21:29:45 +0000</pubDate>
		<dc:creator>Rik Ferguson</dc:creator>
				<category><![CDATA[malware]]></category>
		<category><![CDATA[conficker]]></category>
		<category><![CDATA[downadup]]></category>
		<category><![CDATA[worm_downad]]></category>

		<guid isPermaLink="false">http://countermeasures.trendmicro.eu/?p=397</guid>
		<description><![CDATA[As has been previously noted on this blog and many others over the past few weeks. A machine infected with Downad/Conficker will not be able to access many of the domains which can assist in the cleanup of the infection.   So in anticipation of the &#8220;Impending Technological Apocalypse™&#8220;. Trend Micro is pleased to bring [...]<div class="addthis_toolbox addthis_default_style " addthis:url='http://countermeasures.trendmicro.eu/restore-access-to-blocked-sites-on-conficked-systems/' addthis:title='Restore Access to Blocked Sites on Conficked Systems '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_button_google_plusone" g:plusone:size="medium"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></description>
			<content:encoded><![CDATA[<p>As has been previously noted on this blog and many others over the past few weeks. A machine infected with Downad/Conficker will not be able to access many of the domains which can assist in the cleanup of the infection.</p>
<p> </p>
<p>So in anticipation of the &#8220;Impending Technological Apocalypse<span style="font-size: medium;">™</span>&#8220;. Trend Micro is pleased to bring you a method to outsmart the worm and restore access to those blocked web sites on your infected machines.</p>
<p> </p>
<p>1 -In the <strong>Start</strong> menu, choose <strong>Run</strong>. (If you cannot see the <strong>Run </strong>choice in your Start menu you may need to add it. It can be added as follows: Right mouse click the <strong>Start</strong> button and choose <strong>Properties</strong>. Hit the <strong>Customise</strong> button and choose <strong>Advanced</strong>. In the <strong>Start Menu Items </strong>section, scroll down until you see the check box for <strong>Run Command</strong>, check that box as below, and hit <strong>OK</strong>).</p>
<p><img class="alignleft size-full wp-image-399" title="startmen" src="http://countermeasures.trendmicro.eu/wp-content/uploads/2009/03/startmen.png" alt="startmen" width="403" height="423" /></p>
<p> </p>
<p> </p>
<p>2- Alright, so now you can hit the <strong>Start</strong> button and choose <strong>Run</strong>. In the Run window that appears, type <em><strong>cmd</strong></em> as below and hit <strong>OK</strong>.</p>
<p><img class="alignleft size-full wp-image-400" title="runcmd" src="http://countermeasures.trendmicro.eu/wp-content/uploads/2009/03/runcmd.png" alt="runcmd" width="347" height="186" /></p>
<p> </p>
<p>3 -In the window that appears, type the command <strong><em>net stop dnscache</em></strong>, and hit Enter, then type <em><strong>exit</strong></em> and hit Enter again. It should appear exactly as show below.</p>
<p><img class="alignleft size-full wp-image-403" title="dosbox" src="http://countermeasures.trendmicro.eu/wp-content/uploads/2009/03/dosbox.png" alt="dosbox" width="669" height="338" /></p>
<p> </p>
<p>4 &#8211; Right, we&#8217;re almost done, just a belt-and-braces check to do now. Again click <strong>Start</strong> and choose <strong>Run</strong>. This time type <em><strong>services.msc</strong></em> in the Run box and click <strong>OK</strong>. It brings up a window as shown below</p>
<p><img class="alignleft size-full wp-image-407" title="services" src="http://countermeasures.trendmicro.eu/wp-content/uploads/2009/03/services.png" alt="services" width="701" height="526" /></p>
<p> </p>
<p>5 &#8211; Double-click the <strong>DNS Client</strong> entry in the list, and if it is not already stopped, hit the <strong>Stop</strong> button.</p>
<p> </p>
<p>Hey presto! You should now be able to access all of those previously blocked sites, of course including the excellent <a href="http://housecall.trendmicro.com/uk/" target="_blank">HouseCall </a>for all your cleanup needs.</p>
<p> </p>
<p>This service has been brought to you by a large Indian meal, a very long day and a well-known Tennesee Sippin&#8217; Whiskey</p>
<div class="addthis_toolbox addthis_default_style " addthis:url='http://countermeasures.trendmicro.eu/restore-access-to-blocked-sites-on-conficked-systems/' addthis:title='Restore Access to Blocked Sites on Conficked Systems '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_button_google_plusone" g:plusone:size="medium"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></content:encoded>
			<wfw:commentRss>http://countermeasures.trendmicro.eu/restore-access-to-blocked-sites-on-conficked-systems/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Poisoned Downad/Conficker Removal Searches&#8230;</title>
		<link>http://countermeasures.trendmicro.eu/poisoned-downadconficker-removal-searches/</link>
		<comments>http://countermeasures.trendmicro.eu/poisoned-downadconficker-removal-searches/#comments</comments>
		<pubDate>Mon, 30 Mar 2009 21:12:04 +0000</pubDate>
		<dc:creator>Rik Ferguson</dc:creator>
				<category><![CDATA[malware]]></category>
		<category><![CDATA[SEO]]></category>
		<category><![CDATA[conficker]]></category>
		<category><![CDATA[downadup]]></category>
		<category><![CDATA[malicious code]]></category>
		<category><![CDATA[worm_downad]]></category>

		<guid isPermaLink="false">http://countermeasures.trendmicro.eu/?p=373</guid>
		<description><![CDATA[Reminder: For a FREE tool to remove Conficker (and every other malware in the current pattern file) use Trend Micro&#8217;s SysClean available here. As soon as the good news breaks that it is possible to use tools such as the network scanning tool nmap to search for machines infected by Downad/Conficker, then the malicious SEO work starts. [...]<div class="addthis_toolbox addthis_default_style " addthis:url='http://countermeasures.trendmicro.eu/poisoned-downadconficker-removal-searches/' addthis:title='Poisoned Downad/Conficker Removal Searches&#8230; '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_button_google_plusone" g:plusone:size="medium"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></description>
			<content:encoded><![CDATA[<p><strong>Reminder</strong>: For a <strong><span style="color: #800000;">FREE </span></strong>tool to remove Conficker (and every other malware in the current pattern file) use Trend Micro&#8217;s SysClean available <a href="http://www.trendmicro.com/download/dcs.asp" target="_blank">here</a>.</p>
<p>As soon as the <a href="http://www.theregister.co.uk/2009/03/30/conficker_signature_discovery/" target="_blank">good news breaks</a> that it is possible to use tools such as the network scanning tool <a href="http://nmap.org/" target="_blank">nmap </a>to search for machines infected by Downad/Conficker, then the malicious SEO work starts.</p>
<p><img class="alignleft size-full wp-image-375" title="nmapconresult1" src="http://countermeasures.trendmicro.eu/wp-content/uploads/2009/03/nmapconresult1.png" alt="nmapconresult1" width="560" height="323" /></p>
<p>If you need malware removal tools type the URL of your vendor of choice directly into the browser bar and use links on their website. Do not rely on Google search results at this time, as they may have been &#8220;optimised&#8221;.</p>
<p>Careful what you click on, these Google results are loaded!</p>
<div class="addthis_toolbox addthis_default_style " addthis:url='http://countermeasures.trendmicro.eu/poisoned-downadconficker-removal-searches/' addthis:title='Poisoned Downad/Conficker Removal Searches&#8230; '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_button_google_plusone" g:plusone:size="medium"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></content:encoded>
			<wfw:commentRss>http://countermeasures.trendmicro.eu/poisoned-downadconficker-removal-searches/feed/</wfw:commentRss>
		<slash:comments>14</slash:comments>
		</item>
		<item>
		<title>Downad/Conficker, who&#8217;s the April Fool?</title>
		<link>http://countermeasures.trendmicro.eu/downadconficker-whos-the-april-fool/</link>
		<comments>http://countermeasures.trendmicro.eu/downadconficker-whos-the-april-fool/#comments</comments>
		<pubDate>Wed, 25 Mar 2009 17:52:47 +0000</pubDate>
		<dc:creator>Rik Ferguson</dc:creator>
				<category><![CDATA[malware]]></category>
		<category><![CDATA[conficker]]></category>
		<category><![CDATA[downadup]]></category>
		<category><![CDATA[worm_downad]]></category>

		<guid isPermaLink="false">http://countermeasures.trendmicro.eu/?p=311</guid>
		<description><![CDATA[A brief outline of the story so far with WORM_DOWNAD and some thoughts about the April 1st &#8220;activation date&#8221;.     &#8220;This could well be very big, but it will also be very quiet.&#8221; I&#8217;m beginning to get a little exercised by many of the verbs I am seeing attached to this malware in recent commentary; words like [...]<div class="addthis_toolbox addthis_default_style " addthis:url='http://countermeasures.trendmicro.eu/downadconficker-whos-the-april-fool/' addthis:title='Downad/Conficker, who&#8217;s the April Fool? '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_button_google_plusone" g:plusone:size="medium"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></description>
			<content:encoded><![CDATA[<p class="MsoNormal"><span style="font-size: x-small; color: #000080; font-family: Arial;"><span style="font-weight: bold; font-size: 10pt; color: navy; font-family: Arial;"><span style="color: #888888;">A brief outline of the story so far with </span><a href="http://www.trendmicro.com/vinfo/virusencyclo/default2.asp?m=q&amp;virus=DOWNAD&amp;alt=DOWNAD" target="_blank"><span style="color: #888888;">WORM_DOWNAD</span></a><span style="color: #888888;"> and some thoughts about the April 1st &#8220;activation date&#8221;.</span></span></span></p>
<p class="MsoNormal"> </p>
<p class="MsoNormal"><span style="color: #888888;"> </span></p>
<p class="MsoNormal"><span style="font-size: x-small; color: #000080; font-family: Arial;"><span style="font-weight: bold; font-size: 10pt; font-family: Arial;"><span style="color: #888888;">&#8220;This could well be very big, but it will also be very quiet.&#8221;</span></span></span></p>
<p class="MsoNormal"><span style="font-size: x-small; color: #000080; font-family: Arial;"><span style="font-size: 10pt; color: navy; font-family: Arial;"><span style="color: #888888;">I&#8217;m beginning to get a little exercised by many of the verbs I am seeing attached to this malware in recent commentary; words like &#8220;virus set to explode&#8221;, &#8220;erupt&#8221;, &#8220;blow up&#8221; or &#8220;will infect 12m computers on April 1st&#8221;. I put the following information together to try to clarify exactly what will be &#8220;activated&#8221; on April the 1st and bring some rationality to the debate.</span></span></span></p>
<p class="MsoNormal"><span style="color: #888888;"> </span></p>
<p class="MsoNormal"><strong><span style="font-size: x-small; color: #000080; font-family: Arial;"><span style="font-weight: bold; font-size: 10pt; font-family: Arial;"><span style="color: #888888;">First Variant</span></span></span></strong></p>
<p class="MsoNormal"><span style="font-size: x-small; color: #000080; font-family: Arial;"><span style="font-size: 10pt; color: navy; font-family: Arial;"><span style="color: #888888;">In November 2008, Downad/Conficker was seen for the first time. This first variant was the most simple; it spread by exploiting a vulnerability (</span><a href="http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx" target="_blank"><span style="color: #888888;">MS08-67</span></a><span style="color: #888888;">) that was actually patched by Microsoft back in October of 2008. This variant actively avoided infecting systems that were configured to use a Ukrainian keyboard layout or had IP addresses registered to the Ukraine (which may give some clue as to its origins). This original variant, once it had infected a machine would firstly randomly generate IP addresses and use those to search for new victims to infect and then go on to attempt to download some rogue antivirus “scareware” as a one-time event. From that point on, it would generate a daily list of 250 pseudo-random domain names using the top level domain suffixes com, .net, .org, .info, and .biz and attempt to connect out to those servers and download further malicious content.</span></span></span></p>
<p class="MsoNormal"><span style="font-size: x-small; color: #000080; font-family: Arial;"><span style="font-size: 10pt; font-family: Arial;"><span style="color: #888888;"><img class="alignleft size-full wp-image-313" title="worm_downad_a1" src="http://countermeasures.trendmicro.eu/wp-content/uploads/2009/03/worm_downad_a1.gif" alt="worm_downad_a1" width="450" height="475" /></span></span></span></p>
<p class="MsoNormal"><span style="color: #888888;"> </span></p>
<p class="MsoNormal"><strong><span style="font-size: x-small; color: #000080; font-family: Arial;"><span style="font-weight: bold; font-size: 10pt; font-family: Arial;"><span style="color: #888888;">Second Variant</span></span></span></strong></p>
<p class="MsoNormal"><span style="font-size: x-small; color: #000080; font-family: Arial;"><span style="font-size: 10pt; font-family: Arial;"><span style="color: #888888;">January 2009 saw the second Downad/Conficker variant, which was largely a rewrite of the first; it no longer excluded Ukrainian systems and did not try to download the “scareware” as the first variant did. It also used several more mechanisms through which to spread. In addition to exploiting the Microsoft vulnerability, it also spread by writing to any removable drives plugged into infected systems, any shared network drives currently attached and additionally searched for machines on the same network against which it would attempt a brute force password attack using a list of over 240 predefined common passwords. This second variant also attempted to disable many well known anti-virus programs, blocks access to security related web sites, and disabled key Microsoft security services such as Windows Automatic Update. These additional methods of self-propagation are though to have contributed to the worm’s success at infecting large numbers of machines.</span></span></span></p>
<p class="MsoNormal"><span style="font-size: x-small; color: #000080; font-family: Arial;"><span style="font-size: 10pt; font-family: Arial;"><span style="color: #888888;"> </span></span></span></p>
<p class="MsoNormal"><span style="font-size: x-small; color: #000080; font-family: Arial;"><span style="font-size: 10pt; font-family: Arial;"><span style="color: #888888;">This second variant also generates a daily list of 250 domains to try to connect to this time using more top level domain suffixes com, .net, .org, .info, .biz, and adding .ws, .wn and .cc  The domains generated by the two versions do not overlap.</span></span></span></p>
<p class="MsoNormal"><span style="color: #888888;"> <img class="alignleft size-full wp-image-314" title="downad_1" src="http://countermeasures.trendmicro.eu/wp-content/uploads/2009/03/downad_1.jpg" alt="downad_1" width="448" height="448" /></span></p>
<p class="MsoNormal"><span style="color: #888888;"> </span></p>
<p class="MsoNormal"><strong><span style="font-size: x-small; color: #000080; font-family: Arial;"><span style="font-weight: bold; font-size: 10pt; font-family: Arial;"><span style="color: #888888;">Third Variant</span></span></span></strong></p>
<p class="MsoNormal"><span style="font-size: x-small; color: #000080; font-family: Arial;"><span style="font-size: 10pt; font-family: Arial;"><span style="color: #888888;">In March 2009, a significant third Downad/Conficker variant surfaced. This new version appears to have been spread by an update pushed out to machines previously infected with the second variant. This new version now generates a daily list of 50,000 Internet domain names instead of the 250 generated previously and rather than the 5 or 8 top level domains used by the first two variants, this version uses 110 different top level domains. Only 500 of these generated domains are queried, and only once per day. It is this mechanism that is coded to begin on 1<sup>st</sup> April, and the sheer numbers of domain names involved render redundant the blocking mechanisms used so far to combat the worm.</span></span></span></p>
<p class="MsoNormal"><span style="color: #888888;"> </span></p>
<p class="MsoNormal"><span style="font-size: x-small; color: #000080; font-family: Arial;"><span style="font-size: 10pt; font-family: Arial;"><span style="color: #888888;">In addition to this already established HTTP Command &amp; Control infrastructure, this new variant also introduced Peer to Peer communications capabilities between infected hosts, presumably in an effort to get around the security and internet industries attempts to shut down the HTTP connection mechanism.</span></span></span></p>
<p class="MsoNormal"><span style="color: #888888;"> </span></p>
<p class="MsoNormal"><span style="font-size: x-small; color: #000080; font-family: Arial;"><span style="font-size: 10pt; font-family: Arial;"><span style="color: #888888;">In this third update, the propagation methods present in the first and second variants have been removed and the stance of the infection has shifted to a more defensive one. This signals perhaps that the cybercriminals behind this feel they have infected enough machines to turn this into a “simple” botnet for distributing whichever malicious code they see fit. Remember though, the propagation functionality could just as easily be switched on again as required by the authors.</span></span></span></p>
<p class="MsoNormal"><span style="color: #888888;"> </span></p>
<p class="MsoNormal"><span style="font-size: x-small; color: #000080; font-family: Arial;"><span style="font-size: 10pt; font-family: Arial;"><span style="color: #888888;">It&#8217;s really anyone&#8217;s guess what the infected hosts will be used for if the command &amp; control infrastructure goes live on April 1st. Pushing rogue AV? Sending Spam? Carrying out Denial of Service attacks on other servers and Internet infrastructure? Hosting Malware and Phishing sites? Or simply creating a very large asset pool of infected PCs for the owners to rent out for cash? Personally I don&#8217;t buy into the mass attack scenario, the motivator for mainstream cybercrime is still cash generation, and &#8220;bringing down the Internet&#8221; wouldn&#8217;t be much of an earner. The people behind this piece of code are very skilled, very well informed and resourced. They have invested much time and effort in the creation of this botnet, and will be aiming to see some return on that investment. Making so much noise that every victim knows they&#8217;re infected will have entirely the opposite effect. This could well be very big, but it will also be very quiet.</span></span></span></p>
<p class="MsoNormal"><span style="color: #888888;"> </span></p>
<p class="MsoNormal"><span style="font-size: x-small; color: #000080; font-family: Arial;"><span style="font-size: 10pt; color: navy; font-family: Arial;"><span style="color: #888888;">If you believe your system may be infected by Downad/Conficker, then online scanners and tools almost certainly won&#8217;t be of any use to you, because the websites will be blocked by the infection. I would recommend you download </span><a href="http://www.trendmicro.com/download/dcs.asp" target="_blank"><span style="color: #888888;">SysClean</span></a><span style="color: #888888;">, a free tool from Trend Micro to remove any infection.</span></span></span></p>
<p class="MsoNormal"><span style="color: #888888;"> </span></p>
<p class="MsoNormal"><span style="font-size: x-small; color: #000080; font-family: Arial;"><span style="font-size: 10pt; color: navy; font-family: Arial;"><span style="color: #888888;">For a great in-depth analysis of Downad/Conficker, please have a look at the </span><a href="http://mtc.sri.com/Conficker/" target="_blank"><span style="color: #888888;">Research Paper</span></a><span style="color: #888888;"> written by SRI International</span></span></span></p>
<div class="addthis_toolbox addthis_default_style " addthis:url='http://countermeasures.trendmicro.eu/downadconficker-whos-the-april-fool/' addthis:title='Downad/Conficker, who&#8217;s the April Fool? '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_button_google_plusone" g:plusone:size="medium"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></content:encoded>
			<wfw:commentRss>http://countermeasures.trendmicro.eu/downadconficker-whos-the-april-fool/feed/</wfw:commentRss>
		<slash:comments>14</slash:comments>
		</item>
	</channel>
</rss>

