P. Porras, H. Saidi, V. Yegneswaran
This new, self-refreshing worm appeared and spread on the internet
in November 2008, then infected a serious number of systems successfully
in a short period of time. The worm attacked windows based systems
(Win2K, WinXP, Win 2003, Vista, Win 2008 etc.) with the help of
specifically compounded RPC requests. Although Microsoft published the
fix on October 23rd, 2008, it seems that
numerous systems didn't get these updates.
At the peak of the
infection, based on the measured data, we can talk about
4.7 million
infected IPs in 206 countries, but this data may mean a lot more
computers. Later, more variants of the virus appeared, among which a
few are still active based on network analysis systems. In the
article below, a very detailed analysis can be read about the
structure and operation of the worm.
Original title: An Analysis of Conficker's Logic and Rendezvous Points