Join us for the Honeynet Workshop 2024: May 27th–29th, Copenhagen, Denmark

Simple Conficker Scanner v2

15 Apr 2009 Tillmann Werner conficker detection network scan
Today we released version 2 of our Simple Conficker Scanner (SCSv2). It contains a new scanning method which allows for detection of machines infected with the recent Conficker version (D or E, depending on the naming scheme - the tool calls it D). Although the patch to the vulnerable function NetpwPathCanonicalize() was updated in the new variant, the RPC response codes for specially crafted requests are still different for infected machines.