Showing posts with label Worms. Show all posts
Showing posts with label Worms. Show all posts

Monday, March 30, 2009

Conficker Tools

Felix Leder and Tillmann Werner

The following page contains the tools and analysis results described in our "Know your Enemy" paper "Containing Conficker - To Tame a Malware". The paper is published by the undefinedHoneynet Project and can be downloaded here: todo

All tools are to be considered as proof of concepts. Even though most of them run stable, they are not meant for use in production. They don't come with any warranty.
All tools are available including source code and are licences using GPL.

http://iv.cs.uni-bonn.de/wg/cs/applications/containing-conficker/

Sunday, February 22, 2009

Conficker B++?

"From late November through December 2008 we recorded more than 13,000 Conficker infections within our honeynet, and surveyed more than 1.5 million infected IP addresses from 206 countries. More recently, our cumulative census of Conficker.A indicates that it has affected more than 4.7 million IP addresses, while its successor, Conficker.B, has affected 6.7M IP addresses"

Read more on SRI's Analysis Report

Friday, January 16, 2009

Preemptive Blocklist and More Downadup Numbers

Updated Downadup from F-Secure.

The number of Downadup infections are skyrocketing based on our calculations. From an estimated 2.4 million infected machines to over 8.9 million during the last four days. That's just amazing. Read more...

Friday, January 9, 2009

F-Secure Warns about a new Worm

Downadup uses several different methods to spread. These include using the recently patched vulnerability in Windows Server Service, guessing network passwords and infecting USB sticks. As an end result, once the malware gains access to the inside of a corporate network, it can be unusually hard to eradicate fully.

Typical problems generated by the worm include locking network users out of their accounts. This happens because the worm tries to guess (or brute-force) network passwords, tripping the automatic lock-out of a user who has too many password failures.



more technical details

Hack the Box Blue

https://arcy24.medium.com/hack-the-box-blue-f5ae5b602a5c