Conficker, also known as Downadup and Kido, is a Windows network worm first identified in 2008 that caused millions of infections globally, particularly affecting unpatched and legacy Windows environments. Its principal propagation vector was exploitation of MS08-067, a remote code-execution vulnerability in the Windows Server service reachable over SMB/RPC. Variants also spread by brute-forcing weak credentials on SMB shares and by infecting removable media, enabling broad autonomous propagation within enterprise networks.
Conficker establishes persistence through Windows service and autorun mechanisms, modifies system and network settings, and can inject into Windows processes. It employs polymorphism, obfuscation, anti-analysis, anti-sandbox, and anti-virtualization measures, and has interfered with security products, update-related services, and security-related DNS resolution. The worm uses a domain-generation algorithm for command-and-control resilience; some variants additionally used peer-to-peer communications to receive updates and download further malware. Conficker is not reliably attributable to a publicly identified threat actor.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
...MS08-067 (CVE-2008-4250), which was a propagation vector of the infamous Conficker worm. | So exploit variants or encrypted exploits can be generated for many RPC vulnerabilities – such as MS08-067 (CVE-2008-4250), which was a propagation vector of the infamous Conficker worm.
27 distinct techniques documented for this family, organized by ATT&CK tactic.
ADVSTORESHELL is capable of setting and deleting Registry values. Agent Tesla can achieve persistence by modifying Registry key entries. APT41 used a malware variant called GOODLUCK to modify the registry in order to steal credentials.
when it guesses the right password, it writes the payload to the remote share and runs it by creating a remote service
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
Let’s look at one case across many families: Code Injection ... OpenProcess() on the target process ... VirtualAllocEx() ... WriteProcessMemory() ... CreateRemoteThread()
The signatures folder contains YARA rules to detect unpacked variants of the worm in memory and Snort rules to detect exploitation attempts in a network.
when it guesses the right password, it writes the payload to the remote share and runs it by creating a remote service
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
it contains polymorphism, obfuscation and anti-analysis tricks
今回のようにサーバサイド側でダウンロードさせるマルウェアを多様に変化(ポリモーフィズム)させ、同一URLから異なる検体が時折またはアクセスする度にダウンロードされる仕組みを「サーバサイドポリモーフィズム」と呼びます。
Let’s look at one case across many families: Code Injection ... OpenProcess() on the target process ... VirtualAllocEx() ... WriteProcessMemory() ... CreateRemoteThread()
The second line executes the other file using Rundll32.exe which invokes a gibberish export function
Probes for live hosts in the internal network by trying to connect to their SMB share
The content repeatedly describes malware and threat actors collecting the current date, time, or time zone from victim systems, including examples such as "The net time command can be used... to determine the local or remote system time" and commands like "net time \\hostname" and "w32tm /tz".
EternalBlue required zero user interaction and zero authentication, allowing it to spread laterally across networks at machine speed. The article also recommends restricting internal SMB traffic to limit the blast radius of lateral movement.
The worm spreads itself by 3 mechanisms: By Infecting DOKs and removable drives.
Another way in which the worm replicates itself over the network exploits a vulnerability in Window Spooler (MS10-061)... The worm is also capable of distributing itself over the network through shared folders... Stuxnet’s exploitation of the MS08-67 vulnerability to propagate itself through the network is comparable to the use of the same vulnerability by the network worm Conficker.
During the night of 8th/9th April, computers infected with Trojan-Downloader.Win32.Kido (aka Conficker.c) contacted each other over P2P, telling infected machines to download new malicious files, thus activating the Kido botnet.
Akira will delete system volume shadow copies via PowerShell commands. Avaddon deletes backups and shadow copies using native system tools. Babuk has the ability to delete shadow volumes using vssadmin.exe delete shadows /all /quiet. BlackCat can delete shadow copies using vssadmin.exe delete shadows /all /quiet and wmic.exe Shadowcopy Delete; it can also modify the boot loader using bcdedit /set {default} recoveryenabled No.
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
113 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A worm that propagated through the MS08-067 Windows Server service vulnerability, infecting millions of systems globally.
A historically cited wormable malware example associated with exploitation of RPC vulnerabilities.
Referenced as a historical worm outbreak used for comparison with the proposed Intelligent Worm model.
Conficker is referenced as a major historical worm threat from an earlier era of cybersecurity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.