SRI undresses Conficker

Researchers at SRI International have published a complete breakdown of the inner workings of the Conficker malware. What their analysis reveals is that Conficker is a best-of-breed piece of malware that uses cutting edge cryptography, pushes the envelope on abusing the DNS system for "meeting point" style communications, implements a sophisticated peer-to-peer command and control structure, and works very hard to escape detection and prevent its removal. You can find the SRI analysis at http://mtc.sri.com/Conficker/addendumC/