Trend Micro Facebook TrendLabs Twitter Malware Blog RSS Feed You Tube - Trend Micro
Search our blog:

  • Recent Posts

  • Calendar

    May 2012
    S M T W T F S
    « Apr    
     12345
    6789101112
    13141516171819
    20212223242526
    2728293031  
  • About Us
    Malware Blog > DOWNAD/Conficker Watch: New Variant in The Mix?

    Days after the April 1st activation date of Conficker, nothing interesting was seen so far in our Downad/Conficker monitoring system except the continuous checking of dates and times via Internet sites, checking of updates via HTTP, and the increasing P2P communications from the Conficker peer nodes.

    Well that was until last night when we saw a new file (119,296 bytes) in the Windows Temp folder. Checking on the file properties reveals that the file was created exactly on April 7, 2009 at 07:41:21.

    Checking also on traffic captures show that there was no HTTP download that occurred somewhere around that time frame, which was from April 7, 2009 at 07:40:00 up to April 7, 2009 at 07:42:00. However, we noticed a huge encrypted TCP response (134,880 bytes) from a known Conficker P2P IP node (verified by other independent sources), which was hosted somewhere in Korea.

    The size of the encrypted TCP blob pretty much matches the size of the binary that got created in the aforementioned folder. There are some additional bytes, which could be the headers and keys that Conficker/Downadup has been known to use.

    Trend now detects this new Conficker variant as WORM_DOWNAD.E. Some interesting things (well at least in our perspective) found are:

    1. (Un)Trigger Date – May 3, 2009, it will stop running
    2. Runs using a random file name and random service name
    3. Deletes this dropped component afterwards
    4. Propagates via MS08-067 to external IPs if Internet is available, if no connections, uses local IPs
    5. Opens port 5114, and serves as an HTTP server by broadcasting via SSDP request
    6. Connects to the following sites:
      • Myspace.com
      • msn.com
      • ebay.com
      • cnn.com
      • aol.com

    It also does not leave a trace of itself in the host machine. It runs and deletes all traces, no files, no registries etc.

    Another interesting thing we also noticed was that the Downad/Conficker box was trying to access a known Waledac domain (goodnewsdigital(dot)com) and download yet another encrypted file. This coincidentally happened just after the creation of the new Downad/Conficker binary described below (07:41:23):

    IP download file

    The domain currently resolves to an IP address that is hosting a known Waledac ploy in HTML to download print.exe, which has been verified to be a new Waledac binary.

    Two things can be summed up from the events that transpired:

    1. As expected, the P2P communications of the Downad/Conficker botnet may have just been used to serve an update, and not via HTTP. The Conficker/Downad P2P communications is now running in full swing!
    2. Conficker-Waledac connection? Possible, but we still have to dig deeper into this…

    Research and collaboration is currently ongoing in our own labs, as well as within the Conficker Working Group, and will update this blog post for new findings.

    Thanks to Joseph Cepe and Paul Ferguson for working on additional information for this entry.


    UPDATE: 10:50 PDT, 9 April 2009:

    Having followed the activities of Eastern European online cyber crime for several years, there is one thing we are certain about — these criminals are motivated by one thing: money.

    How was Downad/Conficker helping them meet their goals? It wasn’t. A very large botnet of compromised computers doesn’t make money if it justs “sits there” doing nothing.

    So now we saw — as described above — that the Downad/Conficker botnet has awakened, and perhaps their desire to monetizing their efforts is becoming more clear.

    In the latest activity, we see infected Downad.KK/Conficker.C nodes pulling down new Waledac binaries (perhaps for spamming, as Waledac has been known to do)from a fast-flux domain infrastructure, but also now it is also installing Fake/Rogue AntiVirus  (AV) malware, too. See screenshot below:

    FAKEAV screenshot

    As we have seen, the ongoing Rogue AV efforts by this criminal organization has been widespread, pernicious, unabated, and obviously profitable.

    Stay tuned — this situation is still unravelling.

    - Paul Ferguson, Threat Reasearch

    To have a view of past WALEDAC activity, you may visit the following links below:

     • DOWNAD/Conficker Watch: New Variant in The Mix?
     • Waledac Spamming Image Hosting and Italian Job Offers
     • WALEDAC Spamming Madness
     • Waledac Localizes Social Engineering
     • WALEDAC Spreads More Malware Love
     • What is Old is New Again: Malicious New Year e-Card Spam
     • Fake Obama News Sites Abound
     • WALEDAC Loves (to Spam) You!
     • Just Got Unlucky: Part 3

    FAKEAV variants have also been making the rounds since early this year, as can be seen on the following posts:

     • What Will Go DOWNAD on April 1?
     • Crack Sites Distribute VIRUX and FakeAV
     • Gmail Downtime Exposes Ad-Rigged Site
     • Cybercrooks Handing Out Malware
     • Bogus LinkedIn Profiles Harbor Malicious Content





    Share this article
    Get the latest on malware protection from TrendLabs
    Email this story to a friend   Technorati   NewsVine   MySpace   Google   Live   del.icio.us   StumbleUpon




    113 Responses to “DOWNAD/Conficker Watch: New Variant in The Mix?”

    1. madaco Says:

      is it at all possible that waledak may be made by one group, and to help spread their thing, they are using how many box’s with conficker on them, pretending to be an updated conficker version, so that it will be “updated” to waledak’s version, which will install the normal waledak and then later dlete the conficker E/waledak version. please note thati am a noob, so i dont really know what im talking about in regard to malware, but could someone tell me if what I am saying is not completly ridiculas?

    Trackbacks

    1. New Downad/Conficker variant spreading over P2P » Counter Measures
    2. Neue Conficker-Version, P2P Download und das Waledac Botnetz | Netzhappen
    3. Kaspersky Labs USA » Conficker wakes up, updates via P2P, drops payload
    4. Conficker wakes up, updates via P2P, drops payload | NJN Network
    5. 7 Days Later : Confiker.C Wakes Up | Scam Types dot Com
    6. cybasurfa (cybasurfa)
    7. BayAreaJinWoo (BayAreaJinWoo)
    8. kkaspar (Kimberly Kaspar)
    9. 0.2 » TrendMicro scopre la nuova variante Conficker.E
    10. beseKUre (beseKUre)
    11. Conficker wakes up, updates, drops payload | Between the Lines | ZDNet.com
    12. wingfeichia (Wing Fei Chia)
    13. Conficker wakes up « The big WARCZYK: Piotr Piwowarczyk’s Blog
    14. O noua varianta de Conficker | Devirusare.com
    15. Conficker alive and well with new variant update via P2P
    16.   Conficker’d Machines Are All Doing… Something [Uh Oh] by Techno News Feed
    17. From the Mind of Marc... · Conficker is alive.
    18. Conficker-Wurm lädt jetzt doch nach « Computerhilfe u. Info Blog
    19. talk2jorgelopez (talk2jorgelopez)
    20. Conficker’d Machines Are All Doing… Something [Uh Oh] | FocuSoft Tech Blog
    21. Conficker.E: Aufgewacht und »Ready to Rock!« - The Inquirer DE
    22. Conficker stirs, begins sharing a payload
    23. Fake "Conficker Infection Alert" spam campaign circulating | Zero Day | ZDNet.com
    24. Conficker wieder aktiv: Wurm Conficker.C läd Updates nach | www.tutsi.de
    25. guiambros (Gui Ambros)
    26. Conficker.E - P2P Updates Have Started for new variant - Harry Waldron - Corporate and Home Security
    27. Conficker Ariseth - Rears Ugly Head, Drops Files…
    28. SecurityOrb Blog Station » Blog Archive » Conficker.D Downad.E
    29. conficker live and lurking | hestonk.com
    30. Conficker May Actually Be Doing Something Very Evil As We Speak « The IT Nerd
    31. Conficker Update - It’s Doing Something | NetworkJew
    32. Conficker Using MySpace, eBay As A Clock - News: Everything-e
    33. Conficker deve tentar novo ataque em maio « 1security’s Blog
    34. Conficker C: Tres millones de infecciones y contando… - Cybernauta
    35. [news] Sercurity update: Conflicker is on the move
    36. It’s Alive! Conficker Wakes Up - And Now It Has a Business Model | Technology News
    37. It’s Alive! Conficker Wakes Up - And Now It Has a Business Model | Web News Aggregation
    38. It’s Alive! Conficker Wakes Up - And Now It Has a Business Model | aerobicswebhost
    39. .:: Securnetwork.net Blog - Massimo Rabbi ::. » Conficker ora si aggiorna!
    40. The Angry Jew » Have You Got Worms?
    41. teppo (Teppo Kotirinta)
    42. thierryzoller (thierryzoller)
    43. Pametniji crv Conficker - Download.hr Forum
    44. hermoton (Anne)
    45. Mechanical Mongeese » Blog Archive » Conficker is finally doing something!?
    46. Conficker si è svegliato, altro che pesce d’aprile - The New Blog Times
    47. COMPUTERWOCHE (COMPUTERWOCHE)
    48. databeast (databeast)
    49. tamonten (Channon Powell)
    50. b3tafx (b3tafx)
    51. TheKissCool (KissCool)
    52. oncertification (Timothy Warner)
    53. leemathews (Lee Mathews)
    54. t_matthews (Thomas Matthews)
    55. magic7502 (Mary)
    56. El nuevo Conficker ya no se conecta a dominios | Shadow Security
    57. MBragg (Margaret Bragg )
    58. Conficker finally on the move - Offtopicz
    59. TechFugaLatest (TechFugaLatest)
    60. powellempire (Cullen Powell)
    61. shugh8 (Scott Hughes)
    62. Clipse (Philip)
    63. Conficker Using MySpace, eBay As A Clock : virtual gambling
    64. di6 (di6)
    65. jcung (jcung)
    66. ArticleSave :: Uncategorized :: It’s Alive! Conficker Wakes Up - And Now It Has a Business Model
    67. hmatlock (Heath Matlock)
    68. Conficker Installing Rogue Software - Spyware Protect 2009 « Geeks to Go! - Tech experts answer your questions
    69. bernieadams (✰ Bernie Adams ✰)
    70. L'avanzata del Conficker non si ferma, dalla rete p2p arriva WORM_DOWNAD.E | WindowSolution
    71. derekw (derek)
    72. jcmendez_us (Juan Carlos Méndez)
    73. mytechnewsinfo (mytechnews.info)
    74. emeixeira (Emma)
    75. Malware Conficker: Neue Wurm-Variante aufgetaucht im Windowsblog | Am Puls der Microsoft Betriebssysteme
    76. Conficker wakes up, updates via P2P, drops payload | Cyberphunkz Tech Blog
    77. Conficker: Neue Variante sorgt für neue Panik
    78. Heatherbelle28 (Heather Saker)
    79. tripnotics (Charlie Wickenden)
    80. samtwentyfour (Sam Twentyfour)
    81. TECHGEEK.com.au : Conficker brings up fake antivirus software
    82. Conficker E Detected on April 7
    83. Conficker ahora instala un software antivirus falso | Historias De Queso
    84. it_info (IT.com.mk)
    85. Virus: Conficker si sveglia, vuole soldi « Paoblog’s Weblog
    86. » Conficker torna ad aggiornarsi
    87. Conficker/DOWNAD/Kido Si evolve ancora e rivela un legame con una vecchia conoscenza: Waledac | Bleakants.com
    88. Conficker also installs fake antivirus software « CKSAlerts von CyberK Systems
    89. IT Security News: So much to tell, yet so little time | IT Security | TechRepublic.com
    90. Conficker and Spyware Protect 2009 « What’s On My PC
    91. Security Tip: Conficker creating Windows TEMP files - Use Clean Up utility software « BlueCollarPCNet Weblog
    92. Conficker torna ad aggiornarsi | Cicoira.it
    93. Conficker Is Up And Kicking! | Rated: SAWJ!
    94. Conficker sa začal aktualizovať na novú verziu | Slowo.sk
    95. DownAD Worm (a.k.a. Conficker) - Gehts es jetzt los? | DS-Websolutions
    96. Conficker Using MySpace, eBay As A Clock | Best financial-place
    97. Conficker Using MySpace, eBay As A Clock | SEO Backlinking - SEO and Online Reputation Management Blog
    98. Conficker’s New Motive - Scareware
    99. Computer Security Research - McAfee Avert Labs Blog
    100. Heise Meldung: Conficker-Wurm lädt jetzt doch nach
    101. nitinvala (niTin vaLa)
    102. Conficker and Spyware Protect 2009 | file an extension
    103. Stature Software Blog » Conficker Worm On The Move, Silently Updating
    104. Le Monde Informatique » Le mystère Conficker continue d’intriguer les spécialistes
    105. Conficker.E-Wurm installiert Scareware und wird am 3. Mai abgeschaltet – oder auch nicht | Basic Thinking Blog
    106. Maverick Computer Services » Conficker Worm is back in action!!
    107. Conficker acorda e instala conteúdo desconhecido nos micros infectados | Tumulto
    108. Topics about Top-trends » DOWNAD/Conficker Watch: New Variant in The Mix?
    109. Who » Conficker torna ad aggiornarsi
    110. Conficter dan Scan Virus secara Manual | Bakawan Web Design
    111. „Conficker“ strikes again | sudskivjestak-ikt.com
    112. DOWNAD/Conficker Turns 1 | Malware Blog | Trend Micro


     

    © Copyright 2011 Trend Micro Inc. All rights reserved. Legal Notice