![]() |
|
#1
|
||||
|
||||
|
Quote:
|
|
#2
|
|||
|
|||
|
I happened to notice the filename of the image in the article:
During the conficker fiasco, some researchers made a connection between Storm - Waledac - Conficker, based on the prevalence of email spam. REFERENCES New Downad/Conficker variant spreading over P2P http://countermeasures.trendmicro.eu...ding-over-p2p/ Quote:
http://news.zdnet.com/2100-9595_22-292858.html Quote:
http://www.mxlogic.com/itsecurityblo...-Conficker.cfm Quote:
---- rich |
|
#3
|
||||
|
||||
|
Good stuff Rich.
|
|
#4
|
|||
|
|||
|
Thanks, Ron. If their conclusions are correct, that might be a reason why Conficker didn't seem to do much at first -- just biding time waiting for opportunities to distribute malware.
---- rich |
|
#5
|
|||
|
|||
|
Does anyone know where there is a list of the domains used by this worm? I'd like to blackhole DNS for them to help protect my customers in the short term.
Thanks, Henry |
|
#6
|
|||
|
|||
|
Here are a couple of lists. You can search around for others:
Full Waledac Domain Listing http://www.securityzone.org/?p=61 Waledac - New Campaign, New Domains, GeoCities, and SpywareProtect2009 http://www.shadowserver.org/wiki/pmw...endar/20090416 Assuming the Conficker botnet will be involved, it won't be so easy to keep track. To wit: Conficker C Analysis http://mtc.sri.com/Conficker/addendumC/ Quote:
Nonetheless, going back to the original Storm exploits, as domains were taken down, new domains were generated daily. So, we should be prepared for similar activity. Also variants of the trojan payload continally changed, making detection more difficult for anti-malware products. As far as protecting your customers: evidently the initial attack is via email, enticing the victim to click on a link to go to the bad site. ---- rich |
|
#7
|
|||
|
|||
|
Hey Rich, thank you very much, that's exactly what I was looking for!
Henry |
|
#8
|
|||
|
|||
|
You are welcome, and good success to you in protecting your customers!
---- rich |
|
#9
|
|||
|
|||
|
Here is an early example:
Waledac Independence Day Theme - New Campaign In The Wild http://securitylabs.websense.com/con...erts/3431.aspx Quote:
I notice that this is an almost exact copy-cat from last year. See my thread here: http://www.wilderssecurity.com/showthread.php?t=214046 ---- rich |
| « Previous Thread | Next Thread » |
| Thread Tools | Search this Thread |
|
|