Common Tasks

Recent Posts

Community

Email Notifications

Personal Links

Archives

Security Protection - Harry Waldron (CS)

Security Best Practices, Breaking News, & Updates

SRI Report - Excellent indepth Analysis of Conficker

Idea This is a highly technical and detailed analysis of how the Conficker attacks work 

SRI Report - Excellent indepth Analysis of Conficker
http://mtc.sri.com/Conficker/

QUOTE: In this paper, we crack open the Conficker A and B binaries, and analyze many aspects of their internal logic. Some important aspects of this logic include its mechanisms for computing a daily list of new domains, a function that in both Conficker variants, laid dormant during their early propagation stages until November 26 and January 1, respectively. Conficker drones use these daily computed domain names to seek out Internet rendezvous points that may be established by the malware authors whenever they wish to census their drones or upload new binary payloads to them.  This binary update service essentially replaces the classic command and control functions that allow botnets to operate as a collective.