Skip to main content

Conficker goes B++

posted onFebruary 24, 2009
by hitbsecnews

Malware writers have created a new version of the Conficker worm that no longer needs to phone home to download its malware package.

Dubbed Conficker B++, the new strain opens a backdoor on the infected machine allowing hackers to push out updates directly to the worm, without it needing to contact a remote server first.

Or in the words of Microsoft's advisory: "We've discovered that the new variant no longer patches netapi32.dll against all attempts to exploit it. Instead, it now checks for a specific
pattern in the incoming shellcode and for a URL to an updated payload."

Source

Tags

Viruses & Malware

You May Also Like

Recent News

Friday, November 29th

Tuesday, November 19th

Friday, November 8th

Friday, November 1st

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th