Witty Worm - "Patient zero" Analysis of First PCs attacked
A recent study was completed related to the Witty worm, which represents one of the most sophisticated attacks using a few vulnerability in the Black Ice Firewall system. The randomized IP generation and destructive disk algorithms used by Witty are detailed in the Long Version of the Slide show below.
Internet Storm Center
http://isc.sans.org/diary.php?date=2005-05-26
Security Focus Article
http://www.securityfocus.com/news/11235
Article - Outwitting the Witty Worm
http://www.cc.gatech.edu/~akumar/witty.html
Slide Show - Long Version
(esp. pages 11-17, 41-42)
http://www.cc.gatech.edu/%7Eakumar/witty_slides.pdf
Slide Show - Short Version
http://www.cc.gatech.edu/%7Eakumar/wisp.pdf
Reflections on Witty: Analyzing the Attacker
http://www.icsi.berkeley.edu/%7Enweaver/login_witty.txt