Alert: Worm infects 3.5 million Windows PCs worldwide
Alert: Worm infects 3.5 million Windows PCs worldwide
By Victor Ng | Jan 15, 2009
The computer worm that exploits a month-old Windows bug has infected more than a million PCs in the last 24 hours.
F-Secure estimated that 3.5 million PCs worldwide have been compromised by the "Downadup" worm, an increase of more than 1.1 million new infections since Wednesday, 14 January 2009.
Chia Wing Fei, Security Response Manager at F-Secure, said, “They do this by trying to connect to various Web addresses. And if the worm finds an active Web server at one of these domains, it will download and run a particular executable..."
This gives the malware gang a free hand to do whatever they want with all of the infected machines. "They could build a large botnet, for example. The framework is in place.”
Normally, malware uses only one or maybe a handful of websites. Such sites are generally easy to locate and shut down.
Then there is Downadup.
It uses a complicated algorithm that changes daily and is based on timestamps from public websites such as Google.com and Baidu.com. With this algorithm, the worm generates many possible domain names every day, such as: qimkwaify .ws, mphtfrxs .net, gxjofpj .ws, imctaef .cc, and hcweu .org.


0 comments
Facebook
LinkedIn
Digg

