Round 4 for Conficker and Twitter attacked
Posted: Tue Apr 14, 2009 2:34 pm
Round 1 was the .A varient, Round 2 was the .B varient, Round 3 was the .C varient (.A and .B upgrading to .C on April 1st 2009), and now it looks like another round of Conficker. The new updated version of the Conficker bot net software circulating now as of last week kicked into action. This new one comes complete with an antivirus scam and got busy over this last week end with sending out 40,000 spam messages from just one infected machine in a 12 hour period (the machine was tracked down by Symantec researchers). A full network infected with this version is estimated to be able to send out 400 Billion spam emails in a single day, and thats just one network. Can you imagine trillions of spam emails sent by multiple networks continually? This version also downloads and launches a fake antivirus program called 'Spyware Protect 2009' (that comes from a site in the Ukraine, but it is also being downloaded from other sites as well.) which claims to identify multiple problematic files and offers to remove them for the convenient fee of $49.95 and of course credit cards are happily accepted. This version will spread as a worm until its due to expire on May 3, 2009. It brings with it a malware package which can both send spam and harvest personal information. It affects networks and non-networked individual computers.
A University of Utah computer network has been infested with this new version, including some machines at its hospitals. Can you imagine what would happen if all of those patient records were compromised by this thing?
Heres some information from the Kaspersky's antivirus blog about the new Conficker thing > http://www.viruslist.com/en/weblog?weblogid=208187654
And on top of the Conficker thing now Twitter has been attacked (not by Conficker) as well and its been traced to a 17 year old kid in Brooklyn New York named Mikeyy Mooney who exploited the Twitter API using Javascript. The script is hosted at a separate site and takes advantage of credentials stored by a browser or other specialized clients to update a Twitter user's profile URL. Once a user viewed that profile the script will be called and for the person that viewed the profile their own profile would be modified in turn. Once modified the profile starts sending out spam on Twitter. This is the very first attack on Twitter and the first time its been hit by malware. According to Mikeyy, he did this 'out of boredom' and wanted to make people aware of security holes and that the spam was an unintended consequence. As soon as the first round of attacks was taken care of by the Twitter people, it started again with a completly different spam message using a script from a different web site, so I guess a new 'pandoras box' was opened and someone else caught on to the script thing and its spreading.
What is this world coming to? Nothing is safe any more I guess. They should drag this Mikeyy twerp out back and beat the crap out of him for doing this stuff. As for the Conficker creators, who ever they may be, I hope there is a special place in hell for them.
A University of Utah computer network has been infested with this new version, including some machines at its hospitals. Can you imagine what would happen if all of those patient records were compromised by this thing?
Heres some information from the Kaspersky's antivirus blog about the new Conficker thing > http://www.viruslist.com/en/weblog?weblogid=208187654
And on top of the Conficker thing now Twitter has been attacked (not by Conficker) as well and its been traced to a 17 year old kid in Brooklyn New York named Mikeyy Mooney who exploited the Twitter API using Javascript. The script is hosted at a separate site and takes advantage of credentials stored by a browser or other specialized clients to update a Twitter user's profile URL. Once a user viewed that profile the script will be called and for the person that viewed the profile their own profile would be modified in turn. Once modified the profile starts sending out spam on Twitter. This is the very first attack on Twitter and the first time its been hit by malware. According to Mikeyy, he did this 'out of boredom' and wanted to make people aware of security holes and that the spam was an unintended consequence. As soon as the first round of attacks was taken care of by the Twitter people, it started again with a completly different spam message using a script from a different web site, so I guess a new 'pandoras box' was opened and someone else caught on to the script thing and its spreading.
What is this world coming to? Nothing is safe any more I guess. They should drag this Mikeyy twerp out back and beat the crap out of him for doing this stuff. As for the Conficker creators, who ever they may be, I hope there is a special place in hell for them.