Downad.KK/Conficker.C p2p Port Generation Code Exposed

Yes, we didn’t want to hear any more about this either, but this is actually interesting. In the process of investigating the WORM_DOWNAD.KK peer-to-peer (P2P) protocol communications, Trend Micro threat researchers have discovered – with the assistance of some external resources – some interesting code which indicates that the basic code functionality has been [...]

A Look Inside Conficker P2P Traffic

Visualizations can often show researchers details that would otherwise take hours of staring at raw data to find. WORM_DOWNAD.KK has plenty to show us if we look in the right places. This post focuses on the various P2P channels. The first set of graphs map each IP address (source and destination) found in the [...]

PowerPoint Hit with Zero-Day Attacks

Malicious PowerPoint files (.ppt) are currently being used to exploit a newly reported security hole in the Office app. The isn’t yet any patch available for the zero-day flaw, but Microsoft says the attacks are currently limited and targeted.

Read entire article