<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>CounterMeasures -  A Security Blog » waledac</title>
	<atom:link href="http://countermeasures.trendmicro.eu/tag/waledac/feed/" rel="self" type="application/rss+xml" />
	<link>http://countermeasures.trendmicro.eu</link>
	<description>Trend Microâ€™s Rik Ferguson blogs about current security issues.</description>
	<lastBuildDate>Wed, 01 Feb 2012 14:48:59 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>History of the botnet &#8211; White Paper</title>
		<link>http://countermeasures.trendmicro.eu/history-of-the-botnet-white-paper/</link>
		<comments>http://countermeasures.trendmicro.eu/history-of-the-botnet-white-paper/#comments</comments>
		<pubDate>Fri, 12 Nov 2010 13:09:08 +0000</pubDate>
		<dc:creator>Rik Ferguson</dc:creator>
				<category><![CDATA[malware]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[downadup]]></category>
		<category><![CDATA[malicious code]]></category>
		<category><![CDATA[waledac]]></category>
		<category><![CDATA[worm_downad]]></category>
		<category><![CDATA[ZeuS]]></category>

		<guid isPermaLink="false">http://countermeasures.trendmicro.eu/?p=2463</guid>
		<description><![CDATA[Just a quick update, the three part series I have blogged here has been published today as a White Paper. If you&#8217;re interested it can be downloaded here as a 13 page PDF.<div class="addthis_toolbox addthis_default_style " addthis:url='http://countermeasures.trendmicro.eu/history-of-the-botnet-white-paper/' addthis:title='History of the botnet &#8211; White Paper '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_button_google_plusone" g:plusone:size="medium"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></description>
			<content:encoded><![CDATA[<p>Just a quick update, the three part series I have blogged here has been published today as a White Paper. If you&#8217;re interested it can be downloaded <a onclick="pageTracker._trackPageview('/go/CMblog/botnetwhitepaper/');" href="http://uk.trendmicro.com/imperia/md/content/uk/trendmicro_the_botnet_chronicles_en.pdf">here</a> as a 13 page PDF.</p>
<div class="addthis_toolbox addthis_default_style " addthis:url='http://countermeasures.trendmicro.eu/history-of-the-botnet-white-paper/' addthis:title='History of the botnet &#8211; White Paper '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_button_google_plusone" g:plusone:size="medium"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></content:encoded>
			<wfw:commentRss>http://countermeasures.trendmicro.eu/history-of-the-botnet-white-paper/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>New Downad/Conficker variant spreading over P2P</title>
		<link>http://countermeasures.trendmicro.eu/new-downadconficker-variant-spreading-over-p2p/</link>
		<comments>http://countermeasures.trendmicro.eu/new-downadconficker-variant-spreading-over-p2p/#comments</comments>
		<pubDate>Wed, 08 Apr 2009 19:21:14 +0000</pubDate>
		<dc:creator>Rik Ferguson</dc:creator>
				<category><![CDATA[malware]]></category>
		<category><![CDATA[conficker]]></category>
		<category><![CDATA[downadup]]></category>
		<category><![CDATA[malicious code]]></category>
		<category><![CDATA[waledac]]></category>
		<category><![CDATA[worm_downad]]></category>

		<guid isPermaLink="false">http://countermeasures.trendmicro.eu/?p=453</guid>
		<description><![CDATA[TrendLabs researcher Ivan Macalintal has this evening discovered a new variant of Downad/Conficker called WORM_DOWNAD.E spreading over the peer-to-peer functionality of the previous version of this now infamous worm. Â  As well asÂ reactivating the originalÂ propogation functionality, this new variant sheds some extra light on possible links with other malware and origins of the worm. This [...]<div class="addthis_toolbox addthis_default_style " addthis:url='http://countermeasures.trendmicro.eu/new-downadconficker-variant-spreading-over-p2p/' addthis:title='New Downad/Conficker variant spreading over P2P '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_button_google_plusone" g:plusone:size="medium"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></description>
			<content:encoded><![CDATA[<p>TrendLabs researcher Ivan Macalintal has this evening discovered a new variant of Downad/Conficker called <a href="http://threatinfo.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM%5FDOWNAD%2EE&amp;VSect=P" target="_blank">WORM_DOWNAD.E</a> spreading over the peer-to-peer functionality of the previous version of this now infamous worm.</p>
<p><img class="alignleft size-full wp-image-458" title="worm_downad_e_bd" src="http://countermeasures.trendmicro.eu/wp-content/uploads/2009/04/worm_downad_e_bd.gif" alt="worm_downad_e_bd" width="490" height="591" /></p>
<p>Â </p>
<p>As well asÂ reactivating the originalÂ propogation functionality, this new variant sheds some extra light on possible links with other malware and origins of the worm. This new Downad/Conficker variant is talking to a server which is known already for being associated with the Waledac family of malware, in order to download further malicious components. These components have so far been missing, but could this finally be the &#8220;other boot dropping&#8221; that we have all been waiting for?</p>
<p>Â </p>
<p>Waledac has,Â for a while now, beenÂ suspected to be the latest offering from the people behind the Storm botnet. Could it be that Downad/Conficker, Waledac and Storm all originate from the same cybercriminal gang?</p>
<p>Â </p>
<p>Please read the <a href="http://blog.trendmicro.com/downadconficker-watch-new-variant-in-the-mix/" target="_self">TrendLabs Malware blog </a>for a detailed breakdown.</p>
<div class="addthis_toolbox addthis_default_style " addthis:url='http://countermeasures.trendmicro.eu/new-downadconficker-variant-spreading-over-p2p/' addthis:title='New Downad/Conficker variant spreading over P2P '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_button_google_plusone" g:plusone:size="medium"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></content:encoded>
			<wfw:commentRss>http://countermeasures.trendmicro.eu/new-downadconficker-variant-spreading-over-p2p/feed/</wfw:commentRss>
		<slash:comments>27</slash:comments>
		</item>
		<item>
		<title>Waledac: Reuters Video News Social Engineering</title>
		<link>http://countermeasures.trendmicro.eu/waledac-reuters-video-news-social-engineering/</link>
		<comments>http://countermeasures.trendmicro.eu/waledac-reuters-video-news-social-engineering/#comments</comments>
		<pubDate>Mon, 16 Mar 2009 08:32:59 +0000</pubDate>
		<dc:creator>Rik Ferguson</dc:creator>
				<category><![CDATA[malware]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[waledac]]></category>

		<guid isPermaLink="false">http://countermeasures.trendmicro.eu/?p=216</guid>
		<description><![CDATA[This attack is covered in detail over on the TrendLabs Malware Blog Â  Coupons &#38; Barack ObamaÂ in January, Valentines in February and now video news in March. Waledac has once again reinvented itself. The creators have moved on from their coupon related campaign and are now using fake big news events with associated video content [...]<div class="addthis_toolbox addthis_default_style " addthis:url='http://countermeasures.trendmicro.eu/waledac-reuters-video-news-social-engineering/' addthis:title='Waledac: Reuters Video News Social Engineering '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_button_google_plusone" g:plusone:size="medium"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></description>
			<content:encoded><![CDATA[<p>This attack is covered in detail over on the <a href="http://blog.trendmicro.com/waledac-localizes-social-engineering/" target="_blank">TrendLabs Malware Blog</a></p>
<p>Â </p>
<p>Coupons &amp; Barack ObamaÂ in January, Valentines in February and now video news in March. Waledac has once again reinvented itself. The creators have moved on from their coupon related campaign and are now using fake big news events with associated video content to fool the user into downloading &#8220;the latest Flash Player&#8221; to view it. &#8220;The latest Flash Player&#8221; is of course the newest variant of the <a title="Waledac Worm variants" href="http://www.trendmicro.com/vinfo/virusencyclo/general.asp?vname=WALEDAC&amp;type=MALWARE/GRAYWARE&amp;trigger=overall" target="_blank">Waledac worm</a></p>
<p>This is what the spam messageÂ leads you to if you live in San Jose</p>
<p>Â </p>
<p>Â </p>
<p>Â </p>
<p>Â </p>
<p><img class="size-full wp-image-217 alignnone" title="waledac_reuters" src="http://countermeasures.trendmicro.eu/wp-content/uploads/2009/03/waledac_reuters.png" alt="waledac_reuters" width="536" height="651" /></p>
<p>Â </p>
<p>Don&#8217;t be fooled by the location though, the site is running a couple of clever scripts, one of them will detect the location of your IP address and vary the location of the disaster accordingly; the other will vary the name of the downloaded file (news.exe, save.exe. run.exe etc.). Trend Micro detects the malicious file as <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_WALEDAC.NYS" target="_blank">WORM_WALEDAC.NYS</a> and blocks the malicious domains.</p>
<p>Â </p>
<p>Further evidence, asÂ if any were needed that the botnet creators are still actively filling the void left behind by various event os last year, such as the dismantling of theÂ  <a title="TrendLabs Storm blog posting" href="http://blog.trendmicro.com/storm-uses-old-bait/" target="_blank">Storm </a>botnet and the takedown of <a title="TrendLabs blog posting on McColo" href="http://blog.trendmicro.com/spam-volume-plummets-as-isps-pull-the-plug-on-mccolo/" target="_blank">McColo</a>.</p>
<div class="addthis_toolbox addthis_default_style " addthis:url='http://countermeasures.trendmicro.eu/waledac-reuters-video-news-social-engineering/' addthis:title='Waledac: Reuters Video News Social Engineering '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_button_google_plusone" g:plusone:size="medium"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></content:encoded>
			<wfw:commentRss>http://countermeasures.trendmicro.eu/waledac-reuters-video-news-social-engineering/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

