What Was Conficker? Fifty Thousand Addresses a Day

Microsoft shipped the patch on 23 October 2008, out of band, on a Thursday. That does not happen for ordinary bugs. MS08-067 closed a hole in the Windows Server service that let one crafted RPC request run code on a machine with nobody logged in, and Microsoft had already seen it being used.

The worm was found on 21 November. The patch was four weeks old.

Everyone remembers Conficker as the worm that infected ten million machines and then did nothing. That is roughly half right, and the half that is wrong is the interesting half.

What was Conficker?

A Windows worm, also catalogued as Downadup and Kido, that went through the MS08-067 hole and later through weak administrative passwords and infected USB drives. Five variants between November 2008 and April 2009, each one fixing what the defenders had learned to exploit in the last.

By January 2009 estimates of the infected population ran from nine million to fifteen million machines. The French navy grounded aircraft because flight plans could not be downloaded. Manchester City Council put its cleanup cost at £1.5 million. The German Bundeswehr, the UK Ministry of Defence, hospitals in Sheffield, the Houston municipal court system. It was in everything, and it was patient.

The five variants

  • A — 21 November 2008. MS08-067 only. Generated 250 domains a day across five top-level domains. It checked the keyboard layout and refused to infect a machine set to Ukrainian, which is the kind of detail investigators write down.
  • B — 29 December 2008. Added two new ways in: a dictionary of roughly 240 weak passwords against administrative network shares, and USB drives carrying an autorun.inf whose menu entry was disguised as the ordinary Open folder to view files option. Also 250 domains a day, across eight TLDs.
  • C — 20 February 2009. Added peer-to-peer command distribution, so the domains were no longer the only way to reach it.
  • D — 4 March 2009. The one most reporting calls Conficker.C. Generated 50,000 domains a day across 110 TLDs and tried 500 of them. Disabled Windows Update, Windows Defender and a long list of security tools by name.
  • E — 7 April 2009. Delivered by peer-to-peer to the existing population. Installed the Waledac spam bot and a fake antivirus called SpyProtect 2009, then removed itself on 3 May.

The cryptography is the part practitioners still bring up. The update mechanism verified its payloads with RSA-4096 and, from variant B, hashed with MD6, which Ron Rivest had published only weeks earlier. When a buffer overflow was found in the MD6 reference implementation in early 2009, the next Conficker variant had already fixed it. Somebody on the other side was reading the cryptography mailing lists.

It closed the hole behind itself

The first thing Conficker.B did after arriving through MS08-067 was patch MS08-067. Not on disk; in memory. It hooked the vulnerable function so that the same exploit, arriving later from a competitor or from a copy of itself, would be recognised and handled rather than allowed through. The hole stayed closed to everyone except Conficker, which kept a private door.

That is not a detail; it is the design philosophy. The worm was built by someone who assumed other people would want the machines too, and who treated the vulnerability as property to be defended once taken. Most worms of the previous decade behaved like weather. This one behaved like a landlord.

Fifty thousand addresses a day

A botnet needs to receive orders, and the way it receives them is the way it dies. Point every bot at one domain and the domain gets seized. Point them at a list and the list gets seized.

Conficker pointed them at an algorithm. Every day, each infected machine took the date, ran it through a function, and produced a list of domain names. It tried some of them. If the authors had registered one, the bot got its update. If not, it tried again tomorrow with a new list. The defenders could not block a domain that did not exist yet, and the authors needed to register only one.

The date itself was fetched from public websites rather than from the machine's clock, so that a defender could not confuse it by changing the system time. The jump from 250 names a day to 50,000 was a direct response to what the defenders had done with 250.

The registrars got there first

The answer to a domain generation algorithm is to run the algorithm yourself, faster, and buy everything it produces before the other side can. At 250 a day across a handful of registries, a few companies managed it informally. At 50,000 a day across 110 top-level domains, it needed something that had not existed before.

The Conficker Working Group formed on 12 February 2009: Microsoft, ICANN, Symantec, F-Secure, Verisign, Neustar, Afilias, a list of registries and researchers that ran to dozens of organisations, including the operators of national domains in countries that did not otherwise talk to each other about anything. Every day it generated the day's list and pre-registered, blocked or sinkholed every name, in every registry, on a schedule that could not be missed once, because one missed day was one day the authors could push an update.

Microsoft put up $250,000 the same week for information leading to a conviction. Nobody has ever collected it.

The working group's own later review described the effort as having kept the worm in check rather than dealt it a fatal blow. That is an honest assessment. It was containment, not a cure, and it worked because it never stopped. It also produced the model every DGA takedown since has copied: predict the names, pre-register them, sinkhole them, count what connects.

1 April 2009

The March variant carried a date. On 1 April 2009 its domain-checking logic would switch on, and because the press had learned the date, the first of April became a countdown. Television news ran segments on what would happen when Conficker woke up. 60 Minutes ran a piece the Sunday before.

What happened was that the bots began checking 500 of 50,000 domains, as coded, and the working group had already dealt with the names. A week later the botnet quietly received an update through its peer-to-peer channel, which the domain system had never been the only way to reach. The update, Conficker.E, installed the Waledac spam bot and a fake antivirus product for a few weeks and then removed itself in May.

That is the whole visible payload of the largest worm infection since Slammer: a spam relay and a scareware trial, for a month. Everything else it was capable of, it never did.

The apocalypse that never came, and why that is the wrong lesson

It is tempting to file Conficker beside Y2K, as a panic that fizzled. The comparison fails because Y2K fizzled through effort and Conficker fizzled through choice. Nobody made the authors stand down. The botnet was intact, updated, and reachable over peer-to-peer at any point they wanted it. They simply did not appear to want it for anything, and nobody knows why. The leading theory is that it grew far larger and far more visible than intended, and that the attention made it worthless; a botnet every government on earth is watching is not one you can rent out quietly.

The machines stayed infected. Roughly 1.7 million were still detected a year and a half later. Around 400,000 in 2015. Around half a million in 2019, by one estimate, most of them embedded systems and medical devices running a version of Windows that will never be patched. Seventeen years on, a few hundred thousand machines still generate the day's list every morning and ask for a name that nobody is going to answer.

Further reading

  • The Conficker Working Group — Lessons Learned, January 2011.
  • Phillip Porras, Hassen Saïdi, Vinod Yegneswaran, SRI International — An Analysis of Conficker's Logic and Rendezvous Points, February 2009, and Conficker C Analysis, March 2009.
  • ICANN — Conficker Summary and Review, May 2010.
  • Mark Bowden — Worm: The First Digital World War, Atlantic Monthly Press, 2011.
  • Microsoft Security Bulletin MS08-067, 23 October 2008.

EXHIBIT 0028 — CONFICKER

We put it on a shirt. A wall of small numbered brass post-office boxes, drawn as an engraving, rows and columns of identical little doors with combination dials, one door standing open and empty.

Callouts: THE PATCH WAS FOUR WEEKS OLD. 50,000 DOMAINS A DAY, 110 TLDS. THE REGISTRARS GOT THERE FIRST. IT CLOSED THE HOLE BEHIND ITSELF.

Fifty thousand addresses a day. They bought every one.

That's the whole idea.

View the Conficker shirt — EXHIBIT 0028

Back to blog

Leave a comment

Please note, comments need to be approved before they are published.