DDOS Madness Continued...

2009-07-11 Fireeye

https://www.fireeye.com/blog/threat-research/2009/07/ddos-madness-climax.html

Attachments

DDOS_Madness_Continued.pdf (626 KB)

FireEye analyzed the July 2009 DDoS activity that disrupted major U.S. and South Korean websites and found destructive malware behavior after the DDoS phase ended. A service component named mstimer.dll triggered wversion.exe after July 10, causing the malware to overwrite disk sectors, erase the MBR, and search fixed and removable drives for common document types. The case shows the campaign combining public-facing DDoS disruption with host-level destructive payloads aimed at damaging infected systems.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 7dee2bd4e317d12c9a2923d05315268… 2009-07-11 2026-04-03
HASH 367f35c24aa276eea7cc07f6abdbaf8… 2009-07-11 2009-07-11
HASH 1c748931f9544992ce211471f97fcb3… 2009-07-11 2009-07-11
HASH fc5fdb124b312954cb3b4d6c4b40819… 2009-07-11 2009-07-11
HASH 4e48da87b815d2a6396a35b39e5f0c0… 2009-07-11 2009-07-11
IPv4 75.151.32.182 2009-07-11 2009-07-11

Related Reports

« Back