Tuesday, March 31, 2009 9:51 AM
cmosby
Feeling Conflicted about Conficker? – SANS Internet Storm
digg_url = 'http://isc.sans.org/diary.html?storyid=6103&rss';
digg_title = 'Feeling Conflicted about Conficker?';
digg_skin='compact';
digg_topic = 'security';
In just a few minutes it will be April 1st at the International Date Line. Over the next 24 hours Conficker will change the way it communicates, but we don't expect much of anything else to happen. There has been quite a bit of media hype about Conficker, and we've seen dozens of new domain names registered to "help" those who are confused. There are also several reports of malicious software masquerading as detection and cleaning tools for Conficker-infected computers. Our official Conficker page is at http://www.dshield.org/conficker, that's where we have links to all of the software and analysis that we know is trustworthy.
As always, we want to remind our readers that if you are doing what everybody considers to be best business practices (firewalls, unneeded services turned off, systems patched, current antivirus software, user education and awareness, good policies, an incident detection and response mechanism, etc.) then you have very little to worry about.
If you detect anything NEW with respect to Conficker over the next 24 hours please let us know via our contact page. We'll sound the alarm should something bad happen. Otherwise, back to work and Happy April Fool's Day!!
Marcus H. Sachs
Director, SANS Internet Storm Center