RSS Feed

New MS08-067 Exploit Creeps in During DOWNAD Frenzy

Posted on Friday, April 10, 2009 in Exploits, Malware

A new MS08-067 exploit silently made its entrance as the rest of the world was keeping watch on DOWNAD’s next step last week. In what seems to be a case of “old worm with new tricks,” the worm Neeris which has been active for a few years now was found updated with the now infamous MS08-067 exploit.

Detected by Trend Micro as WORM_NEERIS.A, the number of PCs infected by this variant reportedly spiked almost at the same time that DOWNAD was supposed to do its thing. However, despite similarities between DOWNAD and Neeris, Microsoft reports that no evidence has been found suggesting any connection between the two.

Apart from propagating through the Microsoft Server Service Vulnerability, WORM_NEERIS.A also propagates through removable drives, SQL servers, and through the instant messaging application MSN Messenger. It also drops a rootkit component, detected as RTKT.FARFLI.UW which it uses to hides its processes. This worm also opens the affected system’s port 449 and connects to a certain site where it waits for commands sent by a remote user.

If Neeris would be able to live up to the mark left by DOWNAD is anyone’s guess for now. Sadly, the fact that another threat leveraging on the same vulnerability that had just been on the global spotlight has emerged indicates that there are still users who are unable to see the importance of updating their systems. Users must realize that cyber criminals will continue to strike as long as they keep themselves vulnerable. So please, update your systems here.

via New MS08-067 Exploit Creeps in During DOWNAD Frenzy | Malware Blog | Trend Micro.

About :
  • Share/Save/Bookmark

Bring on the comments

  1. Arianacync says:

    I like your post. Good stuff. Keep them coming :)…

  2. Hi, good post. I have been woondering about this issue,so thanks for posting. I’ll definitely be coming back to your site.

  3. JaneRadriges says:

    Hi, very nice post. I have been wonder’n bout this issue,so thanks for posting

  4. The best information i have found exactly here. Keep going Thank you

  5. GarykPatton says:

    Hi! I like your srticle and I would like very much to read some more information on this issue. Will you post some more?

  6. Hi! I like your srticle and I would like very much to read some more information on this issue. Will you post some more?

  7. The best information i have found exactly here. Keep going Thank you

Leave a Reply