News & Information for Technology Purchasers
NewsFactor Network Sites:   NewsFactor.com Security CRM Business Sci-Tech Newsletters XML/RSS Feed  
   
Home Enterprise I.T. Hardware Software Communications More Topics...
Computing
Average Rating:
Rate this article:  
Conficker Worm Will Call Home on April Fools Conficker Worm Will Call Home on April Fools' Day
By Patricia Resende
March 26, 2009 2:26PM

    Bookmark and Share
Security experts around the world will be watching on April 1, when the widespread Conficker worm is scheduled to call home to mystery domains. The creators of Conficker, also known as Downadup, are playing a cat-and-mouse game with the security posse organized by Microsoft. The April 1 date could even be a Conficker distraction.
 



April 1 brings on the age-old tradition of jokes and pranks. But this year, April 1 will be more than just April Fools' Day.

The first day of April 2009 is when security analysts around the world will watch to see what happens to thousands of computers because of the Conficker worm, a family of malware that is now widespread and affecting 10 million computers.

Conficker, also known as Downadup, is spread in three ways, including via exploit, weak passwords, and the use of autorun.inf files which are copied to USB drives.

Cat and Mouse

Graham Cluley, a security analyst with Sophos, said it's not possible for analysts to figure out what the payload could be because it's not yet present in the Conficker code.

"Some people have got rather confused as to what the April 1st deadline really means," Cluley said in an official blog post. "The truth is that Conficker is not set to activate a specific payload on April 1st. Rather, on April 1st Conficker will begin to attempt to contact the 50,000-a-day potential call-home Web servers from which it may receive updates."

Beyond that, Cluley said there's no guarantee the download will even occur on the first day of April. It all depends on when the authors of the malicious code choose to register a domain out of the 50,000 listed each day.

Jart Armin, a security expert with HostExploit, agrees. "The April 1st date would appear to be speculation; in the four or so worm variations seen so far, all have had various 'call home for an update' dates, times and varying locations," Armin said. "Conficker remains a dangerous threat, but its masters are obviously playing a cat-and-mouse game with the community, constantly matching any publicized anti-measures, and it's normal business as usual for malware in general."

Armin warned that the authors of the code may be using April Fools' Day to distract people while they commit other attacks. "It is important to remember, when observing illusionists as in this case, to also watch what the other hand is being used for," he said.

Bounty Still Out

While the Conficker masters iron out details, businesses are planning countermeasures to fight the virus.

In February, Microsoft Relevant Products/Services announced a collaboration Relevant Products/Services dubbed the Conficker Cabal with other industry leaders, including AOL, F-Secure, Arbor Networks, and VeriSign, to put together a coordinated response to the worm.

The software giant has been working with the Internet Corporation of Assigned Names and Numbers (ICANN) and operators of Domain Name Systems to find a way to disable the domains targeted by Conficker. Microsoft has also posted a $250,000 bounty for information that results in the arrest and conviction of those responsible for launching the malicious code.
 

Tell Us What You Think
Your Comment:



Advertisement


 Computing
1.   Nvidia Auto-Switches Notebook GPU
2.   MS: Windows 7 Doesn't Hurt Battery
3.   Tips for More Windows 7 Productivity
4.   The Pros and Cons of Apple's iPad
5.   IBM Power7 Server Takes on Big Load


advertisement
EPIC Objects To Google-NSA TiesEPIC Objects To Google-NSA Ties
Cyberattack meant to rattle Google?
Average Rating:
Symbian 3 Is Now Fully Open SourceSymbian 3 Is Now Fully Open Source
But mobile OS remains linked to Nokia.
Average Rating:
Google Attack Highlights Black MarketGoogle Attack Highlights Black Market
Paying for bug info is hotly debated.
Average Rating:
Product Information and Resources for Technology You Can Use To Boost Your Business

Enterprise Hardware Spotlight
Nvidia Auto-Switches Notebook GPU To Save Battery Life
Nvidia has taken the wraps off a notebook technology that chooses the best graphics processor for any given application and automatically routes the workload to Nvidia or Intel processors.
 
Microsoft Says Battery Woes Not Caused By Windows 7
Battery problems on Windows 7 machines are not caused by the operating system. That's the position of Stephen Sinofsky, head of the Windows division, in a long posting on the Windows engineering blog.
 
IBM's New POWER7 Servers Save Energy with Big Loads
IBM has unveiled high-capacity servers that are the first to be based on its new, multi-core POWER7 chip. It said the new line is designed "to manage the most demanding emerging applications."
 

Enterprise Technology Spotlight
Google May Add Facebook, Twitter Links to Gmail
Google will reportedly roll more social-networking features into Gmail, the fastest-growing e-mail service. The new features could save users the trouble of switching to Facebook or Twitter.
 
IBM's New POWER7 Servers Save Energy with Big Loads
IBM has unveiled high-capacity servers that are the first to be based on its new, multi-core POWER7 chip. It said the new line is designed "to manage the most demanding emerging applications."
 
IBM Opens Eco-Friendly, Cloud-Focused Data Center
IBM has opened its latest data center in North Carolina. Big Blue said the $362 million facility in Research Triangle Park is designed to support cloud computing and other new computing models.
 

Navigation
NewsFactor Network
Home/Top News | Enterprise I.T. | Hardware | Software | Communications | Network Security | Wireless Tech | Linux/Open Source
Apple/Macintosh | Microsoft/Windows | World Wide Web | Data Storage | E-Commerce | Personal Tech | Tech Trends | Press Releases
NewsFactor Network Enterprise I.T. Sites
NewsFactor Technology News | Enterprise Security Today | CRM Daily

NewsFactor Business and Innovation Sites
Sci-Tech Today | NewsFactor Business Report

NewsFactor Services
FreeNewsFeed | Free Newsletters | Free Whitepapers | XML/RSS Feed

About NewsFactor Network | How To Contact Us | Article Reprints | Careers @ NewsFactor | Services for PR Pros | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2010 NewsFactor Network. All rights reserved. Article rating technology by Blogowogo.