Downadup Worm Hits Over 3.5 Million Computers

January 16, 2009 by John Messina Windows bulletin MS08-067

(PhysOrg.com) -- Security firm F-Secure has advised that the Downadup worm has spread to more than 3.5 million computers by exploiting a vulnerability Microsoft patched last October. This is achieved by trying to connect to various Web addresses. The worm then looks for an active Web server at one of these domains and downloads and runs a particular executable file. This allows the malware to do whatever it wants with all of the infected computers.

The Downadup uses a complicated algorithm which changes daily and is based on timestamps from public websites such as Google.com and Baidu.com. The worm then generates many possible domain names every day.

Names such as: qimkwaify .ws, mphtfrxs .net, gxjofpj .ws, imctaef .cc, and hcweu .org. It would be impossible to shut them all down because there's just too many and most of them aren't even registered. The bad guys running the show only need to register one domain for the day, register it, and set up a website. From there they can gain access to all of the infected machines.

In order for the F-Secure Response Team to determine just how many machines are infected, they will register some of the possible domains and connect to the infected machines.

Right now the Response Team is seeing hundreds of thousands of unique IP addresses connecting to the domains they have registered. A large portion of that traffic is coming from corporate networks, through firewalls, proxies, and NAT routers. This clearly shows that one unique IP address can be connected to thousands of corporate machines.

All this could have been avoided if more users had patched the vulnerability in how Windows processes remote procedure call (RPC) requests by the Windows Server service. Microsoft issued a critical out-of-band patch, bulletin MS08-067, to fix this problem.

Microsoft Security Bulletin MS08-067: http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx

© 2009 PhysOrg.com


print this article email this article download pdf blog this article bookmark this article     Stumble it Digg this share on Facebook retweet share on Reddit add to delicious
Rate this story - 3.8 /5 (4 votes)


January 16, 2009 all stories

Comments: 0

3.8 /5 (4 votes)
  • Stumble this up

  • Digg this

  • share this

  • hide
  • Related Stories

  • Worms infesting computers worldwide: Microsoft
    created Nov 02, 2009 | popularity not rated yet | comments 0
  • Microsoft warns of serious computer security hole
    created Jul 06, 2009 | popularity not rated yet | comments 0
  • Conficker worm hits hospital devices
    created Apr 30, 2009 | popularity not rated yet | comments 0
  • Conficker worm dabbling with mischief
    created Apr 28, 2009 | popularity not rated yet | comments 0
  • Huge computer worm Conficker stirring to life
    created Apr 09, 2009 | popularity not rated yet | comments 0



  • hide
  • Relevant PhysicsForums posts

  • Control System
    created Nov 24, 2009
  • Base Isolation Systems in Skyscrapers?
    created Nov 23, 2009
  • Need to interview a Computer Hardware Engineer for school project
    created Nov 23, 2009
  • transient heat transfer
    created Nov 23, 2009
  • More from Physics Forums - General Engineering

Other News

Design chosen for British 1,000 mph car

Design chosen for British 1,000 mph car (w/ Video)

Technology / Engineering

created 5 hours ago | popularity 5 / 5 (2) | comments 1

(PhysOrg.com) -- A British team hoping to be the first to get a car to 1,000 mph (1,610 km/h) has made its final design selection. The six-tonne car, known as the Bloodhound, will be powered by a Eurofighter ...


EU assembly adopts Internet, phone user rights

Technology / Telecom

created 1hour ago | popularity not rated yet | comments 0

(AP) -- The European Parliament has endorsed new telecom rules that would give phone and Internet users more rights and allow them to appeal to national courts if they are cut off for illegal file-sharing.


Magic box for mission impossible

Technology / Telecom

created 2 hours ago | popularity not rated yet | comments 0

On September 11, firefighters, police officers and ambulance workers faced a terrifying rescue effort in the World Trade Center complex. They battled to save people from the collapsing Twin Towers, searched for survivors, ...


Taking the drudgery out of software development

Taking the drudgery out of software development

Technology / Software

created 19 hours ago | popularity 3.6 / 5 (10) | comments 7

(PhysOrg.com) -- Software developers will no longer have to reinvent the wheel when writing new programs and applications thanks to a clever new set of tools and a central repository of 'building blocks'.


Selling chip makers on optical computing

Selling chip makers on optical computing

Technology / Semiconductors

created 22 hours ago | popularity 4.7 / 5 (9) | comments 1

(PhysOrg.com) -- Computer chips that transmit data with light instead of electricity consume much less power than conventional chips, but so far, they've remained laboratory curiosities. Professors Vladimir ...