Neeris : The downadup replica

With Conficker issue not yet over , a replica of it is out in the “market” . Recently reported by Microsoft as a replica of Downadup, the worm is detected to be Win32/Neeris.gen!C. Microsoft calls it a “copycat” of downadup.

This latest variant of Neeris , which has been in existence since 2005 , seems to mimick all of Conficker’s spreading techniques, including the exploitation of MS08-067 and the AutoRun spreading tactic . The worm author has however created it to be an easily spotted malware with extensions like .exe or .scr , extensions that could easily be doubted by an average Internet user.

These worms are now rapidly spreading through Internet Messengers like MSN !

MS malware protection center report on Neeris could be found here .


Leave a Reply

Fill in your details below or click an icon to log in: Logo

You are commenting using your account. Log Out /  Change )

Google+ photo

You are commenting using your Google+ account. Log Out /  Change )

Twitter picture

You are commenting using your Twitter account. Log Out /  Change )

Facebook photo

You are commenting using your Facebook account. Log Out /  Change )


Connecting to %s