Conficker

S0608

Malware.View on attack.mitre.org

About this malware

Conficker is a computer worm first detected in October 2008 that targeted Microsoft Windows using the MS08-067 Windows vulnerability to spread. In 2016, a variant of Conficker made its way on computers and removable disk drives belonging to a nuclear power plant.

Techniques used13

Procedure examples13

TechniqueProcedure example
T1021.002
SMB/Windows Admin Shares

Conficker variants spread through NetBIOS share propagation.

T1027
Obfuscated Files or Information

Conficker has obfuscated its code to prevent its removal from host machines.

T1046
Network Service Discovery

Conficker scans for other machines to infect.

T1091
Replication Through Removable Media

Conficker variants used the Windows AUTORUN feature to spread through USB propagation.

T1105
Ingress Tool Transfer

Conficker downloads an HTTP server to the infected machine.

T1112
Modify Registry

Conficker adds keys to the Registry at HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services and various other Registry locations.

T1124
System Time Discovery

Conficker uses the current UTC victim system date for domain generation and connects to time servers to determine the current date.

T1210
Exploitation of Remote Services

Conficker exploited the MS08-067 Windows vulnerability for remote code execution through a crafted RPC request.

T1490
Inhibit System Recovery

Conficker resets system restore points and deletes backup files.

T1543.003
Windows Service

Conficker copies itself into the %systemroot%\system32 directory and registers as a service.

T1547.001
Registry Run Keys / Startup Folder

Conficker adds Registry Run keys to establish persistence.

T1568.002
Domain Generation Algorithms

Conficker has used a DGA that seeds with the current UTC victim system date to generate domains.

T1685
Disable or Modify Tools

Conficker terminates various services related to system security and Windows.

Groups that use it0

None recorded.

Campaigns0

None recorded.

References2

  1. Conficker Nuclear Power Plant Open source
    Cimpanu, C. (2016, April 26). Malware Shuts Down German Nuclear Power Plant on Chernobyl's 30th Anniversary. Retrieved February 18, 2021.
  2. SANS Conficker Open source
    Burton, K. (n.d.). The Conficker Worm. Retrieved February 18, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.