
A picture is worth a thousand words…
First let me say, “PATCH your systems” if you have not done so already!
Seriously, you and your machines are sitting ducks for attacks such as MS08-067, which we learned about from Microsoft last month. This type of attack is especially dangerous if your Windows Updates or security products are not up to date. Microsoft released its out-of-cycle emergency patch on the 23rd of October–more than one month ago–so you have no excuse today for being at risk!
At McAfee Avert Labs we have seen a few proof-of-concept binaries using the exploit code that was released into the wild to attack this Windows Server Service vulnerability; the latest is W32/Conficker.worm. According to the description in our Virus Information Library, W32/Conficker.worm decides how it will load itself as a Windows Service depending on whether the compromised version of Windows is Windows 2000.
Once loaded in the service space, the worm attempts to download files from the Internet–specifically, further malware from trafficconverter.biz and data files from maxmind.com.
The worm continues by setting up an HTTP server that listens on a random port on the victim’s system while hosting a copy of the worm. It then scans for new vulnerable victims to exploit, at which point the new victim will download the worm from the previous victim and so on.
To recap McAfee’s coverage and protection for this vulnerability, please check here. We have increased coverage in today’s DATs (Version 5445) to protect against this, and future variants, of the W32/Conficker.worm.
For more information on the Microsoft vulnerability, refer to their security bulletin.
As many of us enter the holiday season of Thanksgiving it’s vital to ensure your systems are patched and up to date while you’re enjoying your time off. Malware doesn’t break for holidays! ![]()

November 26th, 2008 at 4:17 am
Can you share packet captures and more information about the webserver used on infected systems for further compromise/infection?
-Daniel Clemens
Also - for a brief writeup on the chinese based worm that was running around earlier this month..
http://www.packetninjas.net/?p=73
November 27th, 2008 at 1:35 pm
Hi,
Refering your site http://vil.nai.com/vil/content/v_153464.htm I have some extra information. This worm also copies 2 or more jpg files with the same size of the dll in the folder “document and settings\default user\.
Please write it on your site.
November 29th, 2008 at 5:30 am
[…] New malware using an ms08-067 exploit gained momentum http://blogs.technet.com/mmpc/archive/2008/11/25/more-ms08-067-exploits.aspxhttp://www.avertlabs.com/research/blog/index.php/2008/11/25/further-067-woes/http://blog.trendmicro.com/ms08-067-vulnerability-botnets-reloaded/http://isc.sans.org/diary.html?storyid=5401 […]