6.25 DDoS 공격의 하드디스크 파괴 악성코드 상세 분석

2013-06-28 Ahnlab Detailed analysis of hard disk destruction malware in 6.25 DDoS attack

http://asec.ahnlab.com/954

Thumbnail for 6.25 DDoS 공격의 하드디스크 파괴 악성코드 상세 분석

ASEC analyzed malware built to conduct DDoS attacks against South Korean government websites at 10:00 on June 25 and also found related malware designed to destroy hard disks. The RDPSHELLEX.EXE sample checks for prior infection with a mutex, installs as a Windows service under legitimate-looking service names, and can transmit infected-system operating-system details to attacker infrastructure. The destructive component stores trigger data for MBR destruction, password changes, network sessions, and process execution, then stops services, changes user passwords, alters the desktop, and patches disk MBRs through PhysicalDrive writes. The wiper can overwrite disk sectors and delete or corrupt files with web, media, and image extensions, making the incident relevant for both DDoS response and destructive-malware recovery planning.

Related Reports

« Back