Author Topic: Confick virus!  (Read 6735 times)


Oh hey dudes it wasnt fake. It became conficker.e

It now does this:
   1. (Un)Trigger Date – May 3, 2009, it will stop running
   2. Runs using a random file name and random service name
   3. Deletes this dropped component afterwards
   4. Propagates via MS08-067 to external IPs if Internet is available, if no connections, uses local IPs
   5. Opens port 5114, and serves as an HTTP server by broadcasting via SSDP request
   6. Connects to the following sites:
          * Myspace.com
          * msn.com
          * ebay.com
          * cnn.com
          * aol.com

It also does not leave a trace of itself in the host machine. It runs and deletes all traces, no files, no registries etc.

Another interesting thing we also noticed was that the Downad/Conficker box was trying to access a known Waledac domain (goodnewsdigital(dot)com) and download yet another encrypted file. This coincidentally happened just after the creation of the new Downad/Conficker binary described below (07:41:23):

IP download file

The domain currently resolves to an IP address that is hosting a known Waledac ploy in HTML to download print.exe, which has been verified to be a new Waledac binary.

Two things can be summed up from the events that transpired:

   1. As expected, the P2P communications of the Downad/Conficker botnet may have just been used to serve an update, and not via HTTP. The Conficker/Downad P2P communications is now running in full swing!
   2. Conficker-Waledac connection? Possible, but we still have to dig deeper into this…


http://blog.trendmicro.com/downadconficker-watch-new-variant-in-the-mix/#ixzz0CfVxc5DE


This is real stuff, they showed it on the news and I think most of the border states are infected, good thing I live in nevada!If you cant go to Microsoft.com or any virus removing site, you infected and it was set up by russain and asians who are forgeted up


This is real stuff, they showed it on the news and I think most of the border states are infected, good thing I live in nevada!If you cant go to Microsoft.com or any virus removing site, you infected and it was set up by russain and asians who are forgeted up

Sorry but nevada is infected also.


Sorry but nevada is infected also.

-snip-
But in Reno I can go to Microsoft.com


EDIT: TURN OFF ALL COMPUTERS ON MAY 1st OR IT WILL TRIGGER
« Last Edit: April 14, 2009, 02:53:48 PM by :Blockboy: »

But in Reno I can go to Microsoft.com


EDIT: TURN OFF ALL COMPUTERS ON MAY 1st OR IT WILL TRIGGER

So you dont have it. That does not mean that others do.

Also turning off computers wont help. It will just do what it was programed to do when it is turned on again.

jord, your chart is bullstuff.

Didn't strike me once, won't strike me now, my computer's a complete handicap, but it can defend against viruses :D


Sorry but nevada is infected also.


i heard someone stop the virus. i bet it was castro, after all a little chunk of cuba was infected

i heard someone stop the virus. i bet it was castro, after all a little chunk of cuba was infected
Because Havana is the only place in Cuba that has power most of the day.

Edit: Cuba is too poor and has few computers other than for government use
« Last Edit: April 14, 2009, 05:54:55 PM by Ronin »

Each one of those read spots is the location of an ISP that the above websites at a request to get the date and time and such that resembles what the config virus does. Its not as bad as it looks. probably only one person in cube has the virus.

Each one of those read spots is the location of an ISP that the above websites at a request to get the date and time and such that resembles what the config virus does. Its not as bad as it looks. probably only one person in cube has the virus.

Because the goverment is like hurr we dont use microstuff stuff. we use our modified linux distro but we still dont allow computers.