Sony/Destover: mystery North Korean actor’s destructive and past network activity
2014-12-04 • Kaspersky •
Destover malware used in the Sony Pictures Entertainment attack was described as a destructive Windows wiper capable of overwriting disk data and the MBR. The droppers installed EldoS RawDisk drivers as a USB 3.0 Host Controller service to bypass NTFS protections, while separate execution switches handled MBR overwrite, file overwrite and deletion, and a local web server that displayed attacker content. The malware created a “Backup and Restore Management” service, dropped multiple copies of itself, attempted connections to several IP addresses, and rebooted the system after destructive actions. The analysis compares Destover with Shamoon and DarkSeoul, noting shared use of destructive drivers, MBR wiping, encoded political-style messages, and tight compile-to-deployment windows while cautioning that these overlaps do not prove a shared operator. The report includes callback IPs and MD5 hashes for Destover components and EldoS drivers for validation.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 760c35a80d758f032d02cf4db12d3e55 | 2014-12-04 | 2023-05-02 |
| HASH | e904bf93403c0fb08b9683a9e858c73e | 2014-12-04 | 2018-11-01 |
| HASH | 2618dd3e5c59ca851f03df12c0cab3b8 | 2014-12-04 | 2014-12-28 |
| HASH | e1864a55d5ccb76af4bf7a0ae16279ba | 2014-12-04 | 2014-12-28 |
| HASH | 6aeac618e29980b69721158044c2e544 | 2014-12-04 | 2014-12-28 |
| HASH | 86e212b7fc20fc406c692400294073ff | 2014-12-04 | 2014-12-28 |
| HASH | b80aa583591eaf758fd95ab4ea7afe39 | 2014-12-04 | 2014-12-28 |
| HASH | d1c27ee7ce18675974edf42d4eea25c6 | 2014-12-04 | 2014-12-28 |
| IPv4 | 208.105.226.235 | 2014-12-04 | 2014-12-28 |
| IPv4 | 58.185.154.99 | 2014-12-04 | 2014-12-28 |
| IPv4 | 212.31.102.100 | 2014-12-04 | 2014-12-28 |
| IPv4 | 217.96.33.164 | 2014-12-04 | 2014-12-28 |
| IPv4 | 200.87.126.116 | 2014-12-04 | 2014-12-28 |
| IPv4 | 203.131.222.102 | 2014-12-04 | 2014-12-28 |
| IPv4 | 88.53.215.64 | 2014-12-04 | 2014-12-28 |
| HASH | 2c545b89acdb9877da5cbb96653b1491 | 2014-12-04 | 2014-12-04 |
| HASH | a3fa8c7eb4f061ab8b9f7829c6741593 | 2014-12-04 | 2014-12-04 |
| DOMAIN | eldos.com | 2014-12-04 | 2014-12-04 |