On The Insider: Trial Set for Anna Nicole Smith Case
BNET Business Network:
BNET
TechRepublic
ZDNet

April 7th, 2009

Conficker worm's copycat Neeris spreading over IM

Posted by Dancho Danchev @ 1:19 pm

Categories: Anti Virus, Botnets, Browsers, Exploit code, Hackers, Malware, Passwords

Tags: IM, Malware, Dancho Danchev, MS08-067, Win32/Neeris, Conficker, Cyberthreats, Spyware, Adware & Malware, Viruses And Worms, Security

Imitation has always been a form of flattery, and that’s particularly true for the cybercrime ecosystem. From the lone Chinese cybercriminals releasing DIY tools for generating malware actively exploiting the MS08-067 flaw, followed by the original Conficker worm, Microsoft’s MMPC (Malware Protection Center) is reporting on a currently spreading Conficker copycat detected as Worm:Win32/Neeris.gen!C.

The latest variant of Neeris which has been in the wild since 2005, is mimicking all of Conficker’s spreading techniques, including the exploitation of MS08-067 and the AutoRun spreading tactic, but is continuing to propagate through its original method - sending links over MSN. With the Neeris copycat now in the game, what are the chances that it would steal some of Conficker’s market share? Pretty pessimistic.

The Neeris author also attempted to launch the campaign beneath the radar with Microsoft’s MMPC pointing out that the peak of the campaign took place on late March 31st and during April 1st, Conficker’s largely overhyped update activation date. However, this tactic is not going to compensate for some of the obvious mistakes that the author made in the form of using bogus time stamps for the malware, and the use of easily spotted as malicious attachments (.exe;.scr) even by the average Internet user.

Copycats don’t just share the same propagation/infection vectors, they also share the same mitigation ones.

Dancho DanchevDancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, malware and cybercrime incident response. He's been an active security blogger since 2007, and maintains a popular security blog. See his full profile and disclosure of his industry affiliations.

Email Dancho Danchev

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 36 Talkback(s)
you are overstating apple's market share by 100%
Apple's share of U.S. PC market jumps to 6.1 percent That was a headline from AppleInsider which means prior to the fiscal period that covered, it was much less. 10% - 12% indeed! As to the validity... (Read the rest)
Posted by: jhand47201 Posted on: 04/12/09 You are currently: a Guest | | Terms of Use
Do you think a Dean of Computer Science could write a dll?  BALTHOR | 04/07/09
S/He'd better be able to  stefanis | 04/08/09
No problem  epcraig | 04/07/09
Nope  wolf_z | 04/08/09
95%...  Queue | 04/08/09
Re;- regardless of OS - are because of stupid users.  hkommedal | 04/08/09
Pointless post  Crestview | 04/08/09
RE: Conficker worm's copycat Neeris spreading over IM  mike acker | 04/08/09
A sandbox?  wolf_z | 04/08/09
RE: ... not just .exe and .scr stuff  GreyGeek77 | 04/09/09
RE: No problem  pubmonster | 04/08/09
MAC RULES!!!  gantoris | 04/08/09
in jobbs wallet  spinin | 04/08/09
Rules what?  Crestview | 04/08/09
I'm with you, no flaming  Crestview | 04/08/09
RE: I'm with you, no flaming..  GreyGeek77 | 04/09/09
And Apples's Safari represents...  ShadowGIATL | 04/09/09
RE: Conficker worm's copycat Neeris spreading over IM  VitaSigns_CSI@... | 04/08/09
Mac's UNIX is no hole-riddled Windows  StevenOz | 04/08/09
prove it  pillbox1234567 | 04/08/09
for every virus the operating system is to blame......  cymru999 | 04/08/09
problem with your argument  tmsbrdrs | 04/08/09
In actuality...  ShadowGIATL | 04/09/09
Couldn't agree more...  deedleedee | 04/08/09
Thanks for a truly sane answer!  jhand47201 | 04/12/09
You zealots never learn  Crestview | 04/08/09
re: you  vilppuu@... | 04/10/09
True, true...  jhand47201 | 04/12/09
@ CSI  brian ansorge | 04/08/09
RE: I CAN'T WAIT UNTIL MAC GET A BETTER SHARE  GreyGeek77 | 04/09/09
GreyGeek Get Real  Rich_F | 04/09/09
you are overstating apple's market share by 100%  jhand47201 | 04/12/09
OMG!  QueenMama | 04/08/09
Yeah  Zach S | 04/08/09
RE: Conficker worm's copycat Neeris spreading over IM  GreyGeek77 | 04/09/09
RE: Conficker worm's copycat Neeris spreading over IM  jhand47201 | 04/12/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement
Click Here

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here