Malware City/Blog/

Apr
01
Filed Under:
MISCELLANEOUS

Downadup – The Internet Apocalypse That Won’t Happen

01 April 2009
Six months after the initial Downadup outbreak, the number of infected systems is still growing, while media speculates about a possible collapse of compromised computers around the world on April Fools’ Day.

Downadup (a.k.a. Conficker or Kido) is not the cleverest e-threat ever. It is just a very well-written piece of malware, highly aggressive and resistant. The worm did not the damage other worms have done, but it has great potential though, especially because it can update itself in a smart manner.

The alleged "Internet Apocalypse" is nothing else than a simple speculation. So far, the code analysis of different Downadup variants revealed no other evidence in this respect. The only sure thing by now, other than its high rate of infections, is that the worm was crafted for deploying rogue security software on the compromised machines.

The rumors that media amplified are based on the misunderstanding of an enhanced feature pertaining to the latest variant. Downadup initial versions connected to a limited number of domains in order to update. The current enhancement refers to the generation of 50,000 random domains and the selection of 500 of them that it attempts to randomly connect for the same update purposes, starting April 1st (see full description).

 

Still, the number of the Downadup infected machines around the globe probably equals already that of Belgium's or Netherlands' population, while Q1 infection rates reveal absolutely alarming figures, as you can see below.

 

Top 10 Most Infected Countries

Percentile infections growth in Feb (compared to Jan)

Australia

311.62

China

287.98

Indonesia

256.58

Spain

222.73

Philippines

220.32

India

214.47

Thailand

209.08

Malaysia

183.67

Italy

137.08

France

126.51

 

Top 10 Most Infected Countries

Percentile infections growth in Mar (compared to Jan)

China

683.71

Australia

473.99

Indonesia

339.96

India

316.71

Spain

280.81

Philippines

264.00

Thailand

199.11

Malaysia

193.19

France

164.30

Italy

116.37

 

Top 10 Most Infected Countries

Percentile infections growth in Mar (compared to Feb)

China

237.42

Australia

152.11

India

147.67

Indonesia

132.50

France

129.88

Spain

126.08

Philippines

119.83

Malaysia

105.18

Thailand

95.23

Italy

84.89

 

There is only one point here: Downadup is not a toy or an April Fools' Day joke. It is important that you patch your OS with the latest updates, while also installing and activating a reliable proactive security suite. Remember to scan everything and to trust nobody!

Better safe than sorry!

P.S.: If your system has been infected, there is still hope. Check http://www.bdtools.net/, download the Downadup Removal Tool, follow the instructions and clean your system. Ideally, once you eliminated Downadup from your machine, you should patch your OS with the latest updates, install and activate an antimalware suite.




Balancing the keen and until late in night reading, with Internet "addiction", the genuine zeal for my bright and fervid students with the craze for the latest discoveries in science and technology, I also enjoy taking not very usual ...

Comments:

Mint said on Apr-2-2009 04:46

I live in Thailand it's true, because half the computers on my university's network are infected with Worm, Trojan and other malware. Nobody's going to spend this much time on a virus only for it to be spread as a rumor.

Raveesh Katiyar said on Apr-2-2009 05:01

We have 5 or more system and all connected with LAN,And we have also DSL connection for internet connectivity, But some problem in our network, MSN frequently disconnect wherever internet connectivity proper.

Comment on this

Name:

Email:

Website:

Your email adress will not be published.