+ Reply to Thread
Results 1 to 3 of 3

Thread: Conflicker update......

  1. #1
    The Voice of Experience ElderGeek's Avatar
    Join Date
    Jul 2007
    Location
    In front of a monitor....
    Posts
    2,113

    Default Conflicker update......

    Copy/pasted from eWeek.com


    Updated Conficker Ropes Victims into Rogue Anti-virus Scam
    By Brian Prince
    2009-04-09


    An updated version of the Conficker worm is installing malware that attempts to lure people into buying rogue anti-virus software. Security researchers also say the worm is downloading malware tied to the notorious Waledac botnet.


    Conficker's latest move may be tied to a scheme to lure users into downloading fake anti-virus software.

    Security researchers monitoring the Conficker worm's activities say the malware has been observed downloading a file detected by Kaspersky Lab as FraudTool.Win32.SpywareProtect2009.s.

    "Once it's run, you see the app interface, which naturally asks if you want to remove the threats it's 'detected,'" wrote Aleks Gostev on Kaspersky Lab's Analyst's Diary blog. "Of course, this service comes at a price—$49.95."


    In addition to that file, the worm is also now downloading the Waledac malware, which steals passwords and turns computers into bots for spamming operations. Waledac has emerged as a key part of spamming operations over the past several months, and is widely considered a reincarnation of the infamous Storm botnet.

    Tricking users into installing rogue software isn't new for the worm, which tried the same thing when it first appeared in 2008. The move also represents another example of attackers cashing in on rogueware. Finjan recently issued a report about a rogueware affiliate network that pulled in an average of $10,800 a day. According to Microsoft's latest Security Intelligence Report, two rogue families, Win32/FakeXPA and Win32/FakeSecSen, were detected on more than 1.5 million computers by Microsoft software.

    "Fear is used, universally, as a means to control people," said Sendio CTO Tal Golan. "Governments use it. Large businesses use it. So it should come as no surprise to anyone that 'cyber-bad guys' use it."

    At the moment, the rogue anti-virus software comes from sites located in the Ukraine (131-3.elaninet.com.78.26.179.107) although the worm is downloading it from other sites, according to Kaspersky Lab.

    There are numerous tools for disinfecting systems hit by Conficker, some of which are linked to here. The worm spreads by exploiting a patched Microsoft vulnerability as well as via network shares by logging in to machines with weak passwords. It also spreads through removable media. Network administrators are advised to deploy MS08-067 if they have not already done so, as well as to follow best practices regarding passwords.


    Stay alert.....
    ...

    I'll be at Camp2........ Next Season........

    ATG-Arizona Technology Group, Inc.

  2. #2
    Senior Member panici33's Avatar
    Join Date
    Jul 2007
    Location
    Illinois
    Posts
    549

    Default

    Damn Ukrainians!

  3. #3
    Senior Member Taylor_01's Avatar
    Join Date
    Jun 2008
    Location
    Mesa,AZ
    Posts
    162

    Default

    Quote Originally Posted by panici33 View Post
    Damn Ukrainians!
    Lets not forget the Nigerians.
    XX ARMY Racing

+ Reply to Thread

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts