Conficker Infection Analysis Turns Spotlight on Number of Compromises

執筆者
Brian Prince
Brian Prince
Published: Apr 17, 2009
Updated: Feb 2, 2021
2 minute read
eWeek のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る

Has the number of Conficker infections been overhyped? Not necessarily.

New research by Kaspersky Lab has put the aforementioned question back in the spotlight. While the Conficker worm generated an intense amount of public interest, the number of computers infected with the newest variant of the worm seems to be relatively small.

Kaspersky Lab’s analysis revealed just over 200,000 unique IP addresses were participating in Conficker’s peer-to-peer network (P2P).

“While analysing Kido [Conficker] network behaviour we’ve been able to develop an application that helped us to get an in depth insight into the peer-to-peer network communications of the malware, which have been used to distribute updates over the last week,” blogged Georg Wicherski, a virus analyst at the security company. “Over a 24 hour observation period, we’ve been able to identify 200,652 unique IPs participating in the network, far less then initial estimated Kido infection counts.”

However, Kaspersky Lab Senior Antivirus Researcher Roel Schouwenberg noted this is just the number of computers the company detected participating in the P2P network. The total number of infected machines is still in the millions, Schouwenberg told eWEEK.

At various points, vendors have put the number as high as 9 million, but efforts by the security community such as The Conficker Working Group seem to have paid off. However, the group still puts the current number of unique IPs infected with variants A, B and C at roughly 3.6 million.

Only a fraction of the nodes infected with earlier variants appear to have been updated, according to Wicherski’s blog post. Kaspersky’s analysis also found that the highest concentration of infected machines is in Brazil, China and the eastern part of the United States, which is reminiscent of similar findings from IBM’s X-Force earlier this month.

The latest iteration of the worm has been tied to a scheme to trick users into downloading rogue anti-virus. There are a number of tools available to help victims remove and detect the malware, as well as a patch for the Microsoft vulnerability targeted by multiple versions of the worm.

Brian Prince

Brian Prince

Content Writer
eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。