Threat Database Trojans TROJ_DIDKR.A

TROJ_DIDKR.A

By Sumo3000 in Trojans

Threat Scorecard

Threat Level: 90 % (High)
Infected Computers: 4
First Seen: July 1, 2013
Last Seen: September 23, 2021
OS(es) Affected: Windows

TROJ_DIDKR.A is a Trojan that affects DNS servers of the South Korean government. TROJ_DIDKR.A performs DDoS attacks at particular websites. TROJ_DIDKR.A is set to download the DDoS-capable component into corrupted PCs on or after 10 AM of June 25. This ticking 'time bomb' shows the huge influence represented by time-triggered attacks, specifying big effects in a short period of time. The DDoS attack, which is connected with TROJ_DIDKR.A is performed by continuously sending rather large DNS packets, more than one kilobyte, to two IP addresses. These affected IP addresses are the primary and secondary DNS name servers of record for numerous South Korean government websites. The attack strives to knock all of these websites offline indirectly: computer users who don't have a DNS record cached for these URLs would need to use DNS to translate the URL to the IP address, but because the name servers for these web addresses are offline, they would be unable to do so. By affecting a single point of failure, cybercrooks are able to hijack numerous websites using only one attack.

Trending

Most Viewed

Loading...