Sony/Destover: mystery North Korean actor’s destructive and past network activity

2014-12-04 Kaspersky

https://securelist.com/destover/67985/

Thumbnail for Sony/Destover: mystery North Korean actor’s destructive and past network activity

Destover malware used in the Sony Pictures Entertainment attack was described as a destructive Windows wiper capable of overwriting disk data and the MBR. The droppers installed EldoS RawDisk drivers as a USB 3.0 Host Controller service to bypass NTFS protections, while separate execution switches handled MBR overwrite, file overwrite and deletion, and a local web server that displayed attacker content. The malware created a “Backup and Restore Management” service, dropped multiple copies of itself, attempted connections to several IP addresses, and rebooted the system after destructive actions. The analysis compares Destover with Shamoon and DarkSeoul, noting shared use of destructive drivers, MBR wiping, encoded political-style messages, and tight compile-to-deployment windows while cautioning that these overlaps do not prove a shared operator. The report includes callback IPs and MD5 hashes for Destover components and EldoS drivers for validation.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 760c35a80d758f032d02cf4db12d3e55 2014-12-04 2023-05-02
HASH e904bf93403c0fb08b9683a9e858c73e 2014-12-04 2018-11-01
HASH 2618dd3e5c59ca851f03df12c0cab3b8 2014-12-04 2014-12-28
HASH e1864a55d5ccb76af4bf7a0ae16279ba 2014-12-04 2014-12-28
HASH 6aeac618e29980b69721158044c2e544 2014-12-04 2014-12-28
HASH 86e212b7fc20fc406c692400294073ff 2014-12-04 2014-12-28
HASH b80aa583591eaf758fd95ab4ea7afe39 2014-12-04 2014-12-28
HASH d1c27ee7ce18675974edf42d4eea25c6 2014-12-04 2014-12-28
IPv4 208.105.226.235 2014-12-04 2014-12-28
IPv4 58.185.154.99 2014-12-04 2014-12-28
IPv4 212.31.102.100 2014-12-04 2014-12-28
IPv4 217.96.33.164 2014-12-04 2014-12-28
IPv4 200.87.126.116 2014-12-04 2014-12-28
IPv4 203.131.222.102 2014-12-04 2014-12-28
IPv4 88.53.215.64 2014-12-04 2014-12-28
HASH 2c545b89acdb9877da5cbb96653b1491 2014-12-04 2014-12-04
HASH a3fa8c7eb4f061ab8b9f7829c6741593 2014-12-04 2014-12-04
DOMAIN eldos.com 2014-12-04 2014-12-04

Related Reports

« Back