Fast Moving Variant Aimed at Windows RPC Bug

Fast Moving Variant Aimed at Windows RPC Bug

Written By
Matthew Hines
Matthew Hines
Jan 9, 2009
2 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Attackers are still working hard to launch threats that seek to exploit Windows users who remain vulnerable to the Microsoft Windows Server Service RPC Handling Remote Code Execution Vulnerability first reported in late 2008, with Symantec reporting the discovery of a new threat Friday that uses a different propagation pattern than earlier attacks aimed at the same vulnerability.

Dubbed W32.Downadup.B, the researchers said that the attack first appeared on December 30th and can not only propagate itself by exploiting the Microsoft Windows Server Service RPC vulnerability, but also by spreading itself through corporate networks by infecting USB sticks and accessing weak passwords.

“These propagation methods are nothing new; W32.Spybot, W32.Randex, and W32.Mytob variants all use almost identical methods to spread, but this variant requires more effort to protect corporate networks,” researchers said.

“W32.Downadup.B creates an autorun.inf file on all mapped drives so that the threat automatically executes when the drive is accessed. The threat then monitors for drives that are connected to the compromised computer in order to create an autorun.inf file as soon as the drive becomes accessible. The worm also monitors DNS requests to domains containing certain strings and blocks access to those domains so that it will appear that the network request timed out. This means infected users may not be able to update their security software from those websites. This can be problematic as worm authors generally dish out new variants constantly,” the company said.

Symantec researchers reported that they are seeing heavy volumes of both known variants of W32.Downadup, versions A and B.

Matt Hines has been following the IT industry for over a decade as a reporter and blogger, and has been specifically focused on the security space since 2003, including a previous stint writing for eWeek and contributing to the Security Watch blog. Hines is currently employed as marketing communications manager at Core Security Technologies, a Boston-based maker of security testing software. The views expressed herein do not necessarily represent the views of Core Security, and neither the company, nor its products and services will be actively discussed in the blog. Please send news, research or tips to SecurityWatchBlog@gmail.com.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.