Breaking News

SAMA introduces L70 AIO Liquid Cooler Crucial Unleashes Its Most Powerful Gaming Memory Yet: DDR5 Pro OC 6400 CL32 RICOH announces GR IV Monochrome and GR IV HDF High-end Compact Digital Cameras CORSAIR Launches the Revolutionary AIR 5400 Triple-Chamber Mid Tower to Redefine Performance ASUS TUF Gaming Unveils Call of Duty Black Ops 7 Edition AMD Radeon RX 9070 XT

logo

  • Share Us
    • Facebook
    • Twitter
  • Home
  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map

Search form

DDoS Attacking US and South Korea Government Sites

DDoS Attacking US and South Korea Government Sites

Enterprise & IT Jul 9,2009 0

There is currently a DDoS attack against a number of websites, most of them belong to US and South Korea goverment sites. The malware involved in the attack has been detected as W32/Mydoom.HN. The worm reportedly may be received as an email attachment.

Once executed, the worm drops the following files, according to Symantec:

* %System%\[RANDOM CHARACTERS].nls
* %System%\wmcfg.exe (detected as W32.Mydoom.A@mm)
* %System%\wmiconf.dll (detected as Trojan.Dozer)
* %System%\dllcache\npptools.dll
* %System%\drivers\npf.sys
* %System%\npptools.dll
* %System%\Packet.dll
* %System%\WanPacket.dll
* %System%\wpcap.dll

The worm creates the following registry entry, so that it runs every time Windows starts:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows
NT\CurrentVersion\SvcHost\"wmiconf" = "WmiConfig"

It creates a new service with the following characteristics:

Service name: WmiConfig service
Display name: WmiConfig service
Startup Type: Automatic

The worm creates the service by adding entries to the following registry subkeys:

* HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WmiConfig
* HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WmiConfig

The worm drops Trojan.Dozer, a distributed denial of service (DDoS) Trojan, and W32.Mydoom.A@mm, the component that sends out the emails with W32.Dozer attached. All of these components work together to perform the DDoS attacks and spread through email.

South Korea's spy agency suspects North Korea is behind the series of attacks that have triggered Web site outages in South Korea and the United States.

Tags: Virus
Previous Post
NXP and TSMC Deliver First 45nm Single-Chip Digital TV Platform
Next Post
Nokia Introduces the Nokia 3720 Classic

Related Posts

  • Samsung Laptop Full of Notorious Malware Is On Sale For $1.2M

  • Cisco Identifies Virus That Kills Off PCs

  • Researchers Identify iOS Espionage App

  • Researchers Identify New iOS Vulnerability

  • Dropbox, WordPress Used To Spread Malware

  • Microsoft Says Viruses Are Back On The Rise

  • First Targeted Attack Utilising Malware for Android Devices Reported

  • Cyber Attack Targets Nato, Government Websites

Latest News

SAMA introduces L70 AIO Liquid Cooler
Cooling Systems

SAMA introduces L70 AIO Liquid Cooler

Crucial Unleashes Its Most Powerful Gaming Memory Yet: DDR5 Pro OC 6400 CL32
PC components

Crucial Unleashes Its Most Powerful Gaming Memory Yet: DDR5 Pro OC 6400 CL32

RICOH announces GR IV Monochrome and GR IV HDF High-end Compact Digital Cameras
Cameras

RICOH announces GR IV Monochrome and GR IV HDF High-end Compact Digital Cameras

CORSAIR Launches the Revolutionary AIR 5400 Triple-Chamber Mid Tower to Redefine Performance
Cooling Systems

CORSAIR Launches the Revolutionary AIR 5400 Triple-Chamber Mid Tower to Redefine Performance

ASUS TUF Gaming Unveils Call of Duty Black Ops 7 Edition AMD Radeon RX 9070 XT
GPUs

ASUS TUF Gaming Unveils Call of Duty Black Ops 7 Edition AMD Radeon RX 9070 XT

Popular Reviews

be quiet! Dark Mount Keyboard

be quiet! Dark Mount Keyboard

Terramaster F8-SSD

Terramaster F8-SSD

be quiet! Light Mount Keyboard

be quiet! Light Mount Keyboard

be quiet! Pure Base 501

be quiet! Pure Base 501

Soundpeats Pop Clip

Soundpeats Pop Clip

Akaso 360 Action camera

Akaso 360 Action camera

Dragon Touch Digital Calendar

Dragon Touch Digital Calendar

Noctua NF-A12x25 G2 fans

Noctua NF-A12x25 G2 fans

Main menu

  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map
  • About
  • Privacy
  • Contact Us
  • Promotional Opportunities @ CdrInfo.com
  • Advertise on out site
  • Submit your News to our site
  • RSS Feed