Conficker variant dispenses with need to phone home
Stealth variant Sidesteps MS-led takedown effort
Virus authors have released a new variant of the infamous Conficker (Downadup) worm with enhanced auto-update features.
The changes in the new strain of the malware, dubbed Conficker B++, make it possible for malware authors to push out new code without publishing it on pre-programmed sites, as with earlier variants. The earlier approach has been frustrated by the recent formation of an alliance led by Microsoft geared up to block and take down sites associated with the worm.
"Perhaps as one response to the cabal's action, or simply to produce a more efficient push-based updating service, the Conficker authors have released a variant of Conficker B, which significantly upgrades their ability to flash Conficker drones with Win32 binaries from any address on the Internet," explains an analysis by security firm SRI International.
Conficker B++ is somewhat similar to Conficker B, with 294 of 297 sub-routines the same and 39 additional subroutines. The latest variant, first spotted on 16 February, is even more sneaky than its previous incarnations, SRI explains.
Conficker B++ is no longer limited to reinfection by similarly structured Conficker DLLs, but can now push new self-contained Win32 applications. These executables can infiltrate the host using methods that are not detected by the latest anti-Conficker security applications.
The malware also creates an additional backdoor on compromise machines to create an altogether trickier infectious agent, SRI explains.
In Conficker A and B, there appeared only one method to submit Win32 binaries to the digital signature validation path, and ultimately to the CreateProcess API call. This path required the use of the Internet rendezvous point to download the binary through an HTTP transaction.Under Conficker B++, two new paths to binary validation and execution have been introduced to Conficker drones, both of which bypass the use of Internet Rendezvous points: an extension to the netapi32.dll patch and the new named pipe backdoor. These changes suggest a desire by the Conficker's authors to move away from a reliance on Internet rendezvous points to support binary update, and toward a more direct flash approach.
SRI reckons that Conficker-A has infected 4.7m machines, at one time or another, while Conficker-B has hit 6.7m IP addresses. These figures, as with previous estimates, come from an analysis of the number of machines that have ever tried to call into malware update sites. The actual number of infected hosts at any one time is lower than that. SRI estimates the botnet controlled by Conficker-A and Conficker-B is around 1m and 3m hosts, respectively, or a third of the raw estimate.
SRI's detailed analysis of Conficker, which includes flow charts illustrating the viral and detailed technical analysis, can be found here. ®
Regcast training : Hyper-V 3.0, VM high availability and disaster recovery
COMMENTS
@ Rob Crawford
WTF? I mean, seriously?
"But hey yeah lets blame microsoft it's easier than actually doing anuthing."
Doing things... like wasting my time disabling the extension hiding, autorun and al. stupid "options" that MS forces on my lusers and which tricks them into being even more stupid than they would have been naturally? Something like that?
Also, the warning box: " are you sure you want to run this .exe knowing that this OS is full of holes allowing privilege escalation. Click yes now." needs to be replaced by "Sorry you don't have the right to install this shit you just received by e-mail. Contact your sysadmin if you're craving LART", which takes time.
"machines"? please be more specific!
Dear Reg,
Can you at least, of all the IT mags/rags out there, stop calling them "machines"? I own 3, and administer 4 more, and none of them -- even if they are put on the internet as is, will get infected.
Please, pretty please with bells on, call them what they are: "Windows PCs."
And to those who said MS is "doing something", yes they are. By co-opting half of the internet to form a "posse", they made you think it's not their fault. (Why in blazes does a USB stick need autorun, FFS!!!)
@Pierre
You have unusually high expectations off the average user.
Having been in the IT industry since the early 80s I can assure that the average user is the laziest and most facile creature on earth.
They want everything done for them.
But hey yeah lets blame microsoft it's easier than actually doing anuthing.

IT infrastructure monitoring strategies
What you need to know about cloud backup
Agentless Backup is Not a Myth
Top 10 SIEM Implementer’s Checklist
Steps to Take Before Choosing a Business Continuity Partner