Conficker, also known as Downadup and Kido, is a Windows network worm that caused one of the largest global malware outbreaks of the late 2000s. It primarily targeted Windows systems, especially poorly patched and legacy environments, and spread aggressively through multiple mechanisms including exploitation of the MS08-067 Windows Server service vulnerability, brute forcing of SMB-accessible shares with password lists, and infection of removable media through autorun-based propagation. Some variants also used peer-to-peer communications and domain generation for resilience and update distribution.
On infected hosts, Conficker established persistence through Registry autorun entries and service registration, including copying itself into system directories and registering as a Windows service. It modified Registry locations associated with services and startup, altered TCP-related settings to support propagation activity, and interfered with security controls and system recovery features. Reported behaviors include disabling or disrupting protective services, deleting restore points, and using anti-analysis, anti-sandbox, obfuscation, and polymorphic techniques. Conficker has also been associated with hiding components using NTFS Alternate Data Streams and with process injection into common Windows processes.
Conficker incorporated command-and-control resilience features that included a domain generation algorithm based on the victim system date and, in some variants, peer-to-peer update mechanisms. It also performed time-related checks to support domain generation. Successful lateral movement via SMB could result in remote service creation and execution on other hosts. Later activity linked to Conficker variants included downloading additional malware, and the botnet was notable enough to prompt coordinated international disruption efforts such as the Conficker Working Group.
Conficker is widely recognized as a worm rather than a conventional trojan or loader because self-propagation was central to its design and operational impact. Its outbreak remains a canonical example of how unpatched Windows vulnerabilities, weak passwords, and removable-media exposure can combine to produce rapid enterprise-scale compromise.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
...MS08-067 (CVE-2008-4250), which was a propagation vector of the infamous Conficker worm. | So exploit variants or encrypted exploits can be generated for many RPC vulnerabilities – such as MS08-067 (CVE-2008-4250), which was a propagation vector of the infamous Conficker worm.
27 distinct techniques documented for this family, organized by ATT&CK tactic.
ADVSTORESHELL is capable of setting and deleting Registry values. Agent Tesla can achieve persistence by modifying Registry key entries. APT41 used a malware variant called GOODLUCK to modify the registry in order to steal credentials.
when it guesses the right password, it writes the payload to the remote share and runs it by creating a remote service
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
Let’s look at one case across many families: Code Injection ... OpenProcess() on the target process ... VirtualAllocEx() ... WriteProcessMemory() ... CreateRemoteThread()
The signatures folder contains YARA rules to detect unpacked variants of the worm in memory and Snort rules to detect exploitation attempts in a network.
when it guesses the right password, it writes the payload to the remote share and runs it by creating a remote service
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
it contains polymorphism, obfuscation and anti-analysis tricks
今回のようにサーバサイド側でダウンロードさせるマルウェアを多様に変化(ポリモーフィズム)させ、同一URLから異なる検体が時折またはアクセスする度にダウンロードされる仕組みを「サーバサイドポリモーフィズム」と呼びます。
Let’s look at one case across many families: Code Injection ... OpenProcess() on the target process ... VirtualAllocEx() ... WriteProcessMemory() ... CreateRemoteThread()
The second line executes the other file using Rundll32.exe which invokes a gibberish export function
Probes for live hosts in the internal network by trying to connect to their SMB share
The content repeatedly describes malware and threat actors collecting the current date, time, or time zone from victim systems, including examples such as "The net time command can be used... to determine the local or remote system time" and commands like "net time \\hostname" and "w32tm /tz".
During the night of 8th/9th April, computers infected with Trojan-Downloader.Win32.Kido (aka Conficker.c) contacted each other over P2P, telling infected machines to download new malicious files, thus activating the Kido botnet.
Akira will delete system volume shadow copies via PowerShell commands. Avaddon deletes backups and shadow copies using native system tools. Babuk has the ability to delete shadow volumes using vssadmin.exe delete shadows /all /quiet. BlackCat can delete shadow copies using vssadmin.exe delete shadows /all /quiet and wmic.exe Shadowcopy Delete; it can also modify the boot loader using bcdedit /set {default} recoveryenabled No.
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
111 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a historical worm outbreak used for comparison with the proposed Intelligent Worm model.
Conficker is referenced as a major historical worm threat from an earlier era of cybersecurity.
Conficker is referenced only as part of an Nmap host script check for signs of Conficker.C infection; the scan result indicates the host is clean or ports are blocked.
A worm/botnet referenced as a historical example of large-scale DGA-based command-and-control resilience.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.