<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>NetworkJew &#187; worm</title>
	<atom:link href="http://networkjew.com/tag/worm/feed/" rel="self" type="application/rss+xml" />
	<link>http://networkjew.com</link>
	<description>Network tips, news and technology.</description>
	<lastBuildDate>Tue, 31 Jan 2012 15:40:26 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Conficker Sells Out!</title>
		<link>http://networkjew.com/2009/04/10/conficker-sells-out/</link>
		<comments>http://networkjew.com/2009/04/10/conficker-sells-out/#comments</comments>
		<pubDate>Fri, 10 Apr 2009 13:46:13 +0000</pubDate>
		<dc:creator>Network Jew</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[conficker]]></category>
		<category><![CDATA[conficker update]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[p2p]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[windows]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://networkjew.com/2009/04/10/conficker-sells-out/</guid>
		<description><![CDATA[<a href="http://networkjew.com/2009/04/10/conficker-sells-out/"><img align="left" hspace="5" width="150" height="150" src="http://networkjew.com/wp-content/plugins/thumbnail-for-excerpts/tfe_no_thumb.png" class="alignleft wp-post-image tfe" alt="" title="" /></a>]]></description>
			<content:encoded><![CDATA[<p>After lying dormant for a week, then mysteriously downloading encrypted content, Conficker is now starting to actually show its true colors. It wants to sell you something. Great.</p>
<p><a href="http://www.f-secure.com/weblog/archives/00001652.html">From F-Secure</a>:</p>
<p># On April 8th a new update was made available to Conficker.C infected machines via the P2P network<br />
# The new file, which we call Conficker.E, is executed and co-exists alongside the old infection<br />
# It re-introduces spreading via the MS08-067 vulnerability. Spreading functionality was removed in Conficker.C and the gang behind this maybe realized they made a mistake and added it again.<br />
# There&#8217;s a possible connection to Waledac, a spambot. Some Conficker.C infected computers connected to a well known Waledac domain and downloaded Waledac from there.<br />
# There&#8217;s also a connection to rogue anti-virus products as we&#8217;ve seen it end up on Conficker.C infected machines. The rogue product was Spyware Guard 2008.<br />
# Conficker.E deletes itself if the date is May 3, 2009 or later.</p>
]]></content:encoded>
			<wfw:commentRss>http://networkjew.com/2009/04/10/conficker-sells-out/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Conficker Update &#8211; It&#8217;s Doing Something</title>
		<link>http://networkjew.com/2009/04/09/conficker-updates-its-doing-something/</link>
		<comments>http://networkjew.com/2009/04/09/conficker-updates-its-doing-something/#comments</comments>
		<pubDate>Thu, 09 Apr 2009 16:04:31 +0000</pubDate>
		<dc:creator>Network Jew</dc:creator>
				<category><![CDATA[Hardware]]></category>
		<category><![CDATA[Home Networking]]></category>
		<category><![CDATA[How-Tos]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security Links]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Top 10]]></category>
		<category><![CDATA[conficker]]></category>
		<category><![CDATA[conficker update]]></category>
		<category><![CDATA[p2p]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://networkjew.com/?p=242</guid>
		<description><![CDATA[<a href="http://networkjew.com/2009/04/09/conficker-updates-its-doing-something/"><img align="left" hspace="5" width="150" src="http://networkjew.com/wp-content/uploads/2009/03/worm-225x157.jpg" class="alignleft wp-post-image tfe" alt="worm" title="worm" /></a>]]></description>
			<content:encoded><![CDATA[<p><a rel="attachment wp-att-217" href="http://networkjew.com/2009/03/31/detect-conficker-worm-with-new-python-tool/worm/"><img class="alignleft size-thumbnail wp-image-217" title="worm" src="http://networkjew.com/wp-content/uploads/2009/03/worm-225x157.jpg" alt="worm 225x157 Conficker Update   Its Doing Something" width="225" height="157" /></a>Well, April 1st came and went without the Internet exploding. All seemed calm on the waters until today when, apparently, infected Conficker PC&#8217;s began downloading new encrypted binaries and checking to see if various websites were up.</p>
<p>According to Trend Micro&#8217;s summary:</p>
<blockquote><p>Two things can be summed up from the events that transpired:</p>
<p>1. As expected, the P2P communications of the Downad/Conficker botnet may have just been used to serve an update, and not via HTTP. The Conficker/Downad P2P communications is now running in full swing!<br />
2. Conficker-Waledac connection? Possible, but we still have to dig deeper into this…</p></blockquote>
<p><a href="http://blog.trendmicro.com/downadconficker-watch-new-variant-in-the-mix/#ixzz0CCEjrkH5">Here&#8217;s a link to more information from Trend Micro</a></p>
<p>Here&#8217;s a link to the conficker &#8220;eye test&#8221; &#8211; it&#8217;ll let you know if your machine is infected or not.</p>
<p>http://www.talkbiz.com/confickertest/</p>
]]></content:encoded>
			<wfw:commentRss>http://networkjew.com/2009/04/09/conficker-updates-its-doing-something/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Detect Conficker Worm with new Python Tool</title>
		<link>http://networkjew.com/2009/03/31/detect-conficker-worm-with-new-python-tool/</link>
		<comments>http://networkjew.com/2009/03/31/detect-conficker-worm-with-new-python-tool/#comments</comments>
		<pubDate>Tue, 31 Mar 2009 14:22:37 +0000</pubDate>
		<dc:creator>Network Jew</dc:creator>
				<category><![CDATA[Scripting]]></category>
		<category><![CDATA[Security Links]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[conficker]]></category>
		<category><![CDATA[python]]></category>
		<category><![CDATA[tool]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://networkjew.com/?p=216</guid>
		<description><![CDATA[<a href="http://networkjew.com/2009/03/31/detect-conficker-worm-with-new-python-tool/"><img align="left" hspace="5" width="150" src="http://networkjew.com/wp-content/uploads/2009/03/worm-300x210.jpg" class="alignleft wp-post-image tfe" alt="worm" title="worm" /></a>]]></description>
			<content:encoded><![CDATA[<p>I<a rel="attachment wp-att-217" href="http://networkjew.com/2009/03/31/detect-conficker-worm-with-new-python-tool/worm/"><img class="alignleft size-medium wp-image-217" title="worm" src="http://networkjew.com/wp-content/uploads/2009/03/worm-300x210.jpg" alt="worm 300x210 Detect Conficker Worm with new Python Tool" width="300" height="210" /></a>f you haven&#8217;t heard already, you soon will hear about the &#8220;Conficker&#8221; worm. It&#8217;s a computer &#8220;worm&#8221; that is estimated to have infected up to 15 million computers worldwide, including those used by the Houston Municipal Courts, the UK Ministry of Defence, and the British House of Commons. Its so bad that last month Microsoft issued a $250,000 bounty for information leading to the arrest and conviction of those behind Conficker.</p>
<p>From Microsoft: Conficker infects other computers across a network by exploiting a vulnerability in the Windows Server service (SVCHOST.EXE). If the vulnerability is successfully exploited, it could allow remote code execution when file sharing is enabled. It may also spread via removable drives and weak administrator passwords. It disables several important system services and security products.</p>
<p>Once your computer is infected, it is now &#8220;owned&#8221; by the Conficker worm and its creators. It becomes one of millions of infected PC&#8217;s making up a massive &#8220;army&#8221; of infected machines that could possibly be used to implement the author&#8217;s bidding at any time.  Here&#8217;s the scary part- all these infected machines ( or &#8220;bots&#8221;) are currently programmed to &#8220;check in&#8221; with their master on April 1st to get new instructions. No one knows exactly what will happen on that day.</p>
<p>Pundits have speculated a variety of different malicious deeds this massive bot army could undertake on 4/1. One possibility is that the author&#8217;s will grab sensitive personal data off all these machines. Another thought is that they will launch massive denial of service attacks on major websites.  Still others believe that this bot army will be sold off for the purposes of sending out Spam worldwide.  No one, except the authors knows for sure.</p>
<p>Regardless, make sure your machines have AntiVirus software, and that its up-to-date. If you&#8217;ve just recently installed AntiVirus, make sure you do a full system scan. Make sure Automatic Updates are turned on.</p>
<p>The Honeynet project just released a new python script you can run to scan your network for infected machines. Here&#8217;s a link to it:</p>
<p>http://honeynet.org/node/388</p>
<p>For more info about this worm you can check out any of the following links:</p>
<p>http://en.wikipedia.org/wiki/Conficker</p>
<p>http://vil.nai.com/vil/content/v_153464.htm</p>
<p>This one&#8217;s REAL technical but a great read if you have the time:</p>
<p>http://mtc.sri.com/Conficker/addendumC/</p>
<p>Let&#8217;s be careful out there&#8230;.</p>
]]></content:encoded>
			<wfw:commentRss>http://networkjew.com/2009/03/31/detect-conficker-worm-with-new-python-tool/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

