Join us for the Honeynet Workshop 2024: May 27th–29th, Copenhagen, Denmark

Detecting Conficker

30 Mar 2009 Tillmann Werner conficker detection downadup scanner signature
As you know, bad things are going to happen on April 1st: people will be sending out emails to their friends, telling silly jokes and putting MTAs under a higher load. Besides that (but not quite that bad), Conficker will activate its domain name generation routine to contact command-and-control servers. We have been researching this piece of malware recently, with a focus on how to detect Conficker-infected machines. Felix and I had a discussion with Dan Kaminsky about the possibilities to actively detect Conficker and wrote a scanner for this task.