Born on the 4th of July

2009-07-09 Symantec

https://www.symantec.com/connect/blogs/born-4th-july

Thumbnail for Born on the 4th of July

Symantec reported that several U.S. and South Korean government, financial, and media websites were taken offline around July 4 by coordinated DDoS activity. The malware chain involved W32.Dozer, Trojan.Dozer, W32.Mydoom.A@mm, and W32.Mytob!gen: Mytob gathered email addresses and mailed the Dozer dropper, which installed Trojan.Dozer and Mydoom components on compromised systems. Trojan.Dozer functioned as a backdoor, contacted hardcoded IP addresses over TCP ports 53, 80, and 443, and could receive commands to update itself, report DDoS status, or launch HTTP GET/POST, UDP, ICMP, TCP ACK, and TCP SYN flood attacks against predetermined targets. The report recommends keeping security software current, filtering email attachments, and blocking the observed command-and-control IP addresses to reduce the impact of the Mydoom/Dozer activity.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 213.23.243.210 2009-07-09 2009-11-08
IPv4 213.33.116.41 2009-07-09 2009-11-08
IPv4 216.199.83.203 2009-07-09 2009-11-08

Related Reports

« Back