On CHOW: Turkey recipes
BNET Business Network:
BNET
TechRepublic
ZDNet

November 26th, 2008

New worm exploiting MS08-067 flaw spotted in the wild

Posted by Dancho Danchev @ 10:21 am

Categories: Anti Virus, Arbitrary Code Execution, Botnets, Exploit code, Hackers, Malware, Microsoft, Passwords, Patch Watch, Pen testing, Viruses and Worms, Vulnerability research

Tags: Security, MS08-067, Remote Code Execution, Network Worm, RPC Worm, Dancho Danchev

MS08-067’s W32/Conficker.worm WormMicrosoft’s Security Response Center and McAfee are warning on increased network scanning activity during the last couple of days courtesy of the very latest W32/Conficker.worm exploiting the already patched MS08-067 vulnerability. What’s particularly interesting in the latest wave of copycat worms is that W32/Conficker.worm is patching the infected host in order to ensure that competing malicious parties wouldn’t be able to get in using it. How nice of them.

“This malware mostly spreads within corporations but also was reported by several hundred home users. It opens a random port between port 1024 and 10000 and acts like a web server. It propagates to random computers on the network by exploiting MS08-067. Once the remote computer is exploited, that computer will download a copy of the worm via HTTP using the random port opened by the worm. The worm often uses a .JPG extension when copied over and then it is saved to the local system folder as a random named dll. It is also interesting to note that the worm patches the vulnerable API in memory so the machine will not be vulnerable anymore. It is not that the malware authors care so much about the computer as they want to make sure that other malware will not take it over too.”

MS08-067’s W32/Conficker.worm WormThe public release of the proof of concept code in September, prompted an immediate reaction by international underground communities releasing several different modifications of the exploit, with the Chinese to be first to release a do-it-yourself tool allowing subnet scanning and automatic exposure to malware hosted on a third-party server. At first, the tool was released with commercial intentions with its authors charging $37.80, however, just like the majority of proprietary web malware exploitation kits, several days later the tool leaked to the general public. From a strategic perspective, whereas such DIY tools indeed empower low-profile cybercriminals, the real danger comes from scanning modules introduced within larger botnets.

Dancho DanchevDancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, malware and cybercrime incident response. He's been an active security blogger since 2007, and maintains a popular security blog. See his full profile and disclosure of his industry affiliations.

Email Dancho Danchev

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 3 Talkback(s)
More Windows exploits
Windows is constantly riddled with exploits. Is this because of faulty code or because it's a higher target? Personally I believe it's a combination of both. But, consider the alternatives that rul... (Read the rest)
Posted by: apexwebmaster Posted on: 03/30/09 You are currently: a Guest | | Terms of Use
Exploit code in September??  PB_z | 11/26/08
RE: New worm exploiting MS08-067 flaw spotted in the wild  Secure.me | 11/27/08
More Windows exploits  apexwebmaster | 03/30/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement
Click Here

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

Enterprise Applications

  • Check out some of the easiest and most powerful ways to boost productivity while saving money on your application infrastructure. See ZDNet's comprehensive Enterprise Application resource center, now!
  • New Online Dashboard
  • Read about top issues IT decision-makers face every day, plus get cost effective solutions to real life IT problems. Oracle Topline