This is no April Fools’ joke. The Conficker botnet is alive and well, and is using its peer-to-peer communications system to update itself as it downloads fake antivirus programs to millions of Windows machines previously infected with the virus.
The Conficker worm, also known as Downadup, raced across the Internet in January with tricks to spread undetected. Millions of computers were infected in just a four-day period. There are several different variants running wild already and the latest variant, Conficker.E, is now on the loose. On Wednesday, Symantec discovered a new sample that is a slightly modified version of the original worm.
“We’ve detected a slightly modified version of Downadup which we’re calling variant E. This new variant is similar to previous variants. It has the ability to spread itself as we saw in variant A and it exploits a Microsoft vulnerability like was seen in variant B,” said Orla Cox, security operations manager for Symantec Security Response. “However, it drops the C variant, which didn’t have the ability to propagate.”
Symantec Observes Waledac
According to Symantec, the new sample reintroduces the MS08-067 exploit vector, which was removed in the C variant. It includes a previously unseen self-removal functionality to remove itself from an infected host on May 3.
The new sample includes a slightly different list of URLs to obtain the IP address of the infected host and also reaches out to a new list of high-profile domains to confirm the current date. When reaching out to these domains, the worm is not exploiting any weaknesses nor downloading any code.
Symantec has also observed a possible connection to W32.Waledac, one of the most active spam bots. W32.Waledac steals sensitive information, turns computers into spam zombies, and establishes a backdoor remote access. “We’re seeing a connection with Downadup and Waledac in that Downadup could…