2009 | Print this page |
The size of botnet not seen by Antivirus vendors in some time; specialists at ESET devoting utmost attention to the threat.
The new variant of the dangerous worm Conficker is rapidly spreading through the Internet. The malware‘s variants, which appeared previously have succeeded in shutting down thousands of PCs worldwide. Computer security experts agree that Win32/Conficker.X, (also dubbed by some vendors as Conficker.C or Conficker.D) poses even a greater threat than its predecessors.
The danger is in that it is perfectly poised for a massive attack against computer infrastructure and/or perpetration of a mass-scale data-theft.The authors of the worm have programmed it to spread not only via the internet by exploiting vulnerabilities in the Windows OS, but also to propagate via exchangeable media. The worm is programmed in such a way as to be remotely controllable, once infected PCs become a part of a large botnet – a network of PCs used to send spam and/or other dangerous forms of malware.
The new variant of Conficker is unique in that it is programmed to radically increase the number of internet domains the worm checks in to for instructions come April 1st. While the existing variants of the worm check in to domains numbering in the hundreds a day, after April 1st, this number is expected to climb dramatically to as much as 50, 000 a day. As yet, computer security experts do not have a clear idea as to the nature of the command for those PCs, which have already been infiltrated. Speculations abound that the action will come in the form of a devastating attack against the Internet infrastructure itself.
"ESET is concentrating fully on monitoring the spread of this worm and is planning an upsurge in staffing of its Virus lab as April 1st approaches. ESET solutions were successful in identifying the new variants of Conficker by deploying proactive detection methods, extending 100% protection to our clients," states Juraj Malcho, the Head of ESET Virus Lab.
In the history of computer threats, Conficker ranks among the most dangerous, given its capacity to reach vast numbers of PCs simultaneously. "The main goal of the authors of the worm is to construct and consolidate a botnet of unprecedented proportions that can be exploited for a massive attack against the internet infrastructure or for a mass-scale espionage,“ adds Malcho.
Win32/Conficker.X performs the following changes to infected workstations:
How to protect yourself?