A Technical Analysis of ISAACWiper
ID: 7dee9aab-d3f5-5caf-adcb-b697b0ed59fb
STIX ID: report--7dee9aab-d3f5-5caf-adcb-b697b0ed59fb
Feed Name: WatchGuard Secplicity Blog
### Executive summary: This report provides a detailed reverse-engineering analysis of ISAACWiper, a 32-bit Windows DLL wiper discovered on Ukrainian networks immediately prior to the 24 February 2022 invasion and attributed to Russia’s GRU (Sandworm). The analysis covers file metadata and hashes, imported APIs, exported entrypoints, use of GetTickCount-seeded Mersenne Twister PRNG to generate overwrite data, techniques to lock volumes and destroy the MBR by writing the first 10,000 bytes of physical drives, iterative file/directory overwrites, logging behavior, and observable indicators that caused systems to fail and force reboots.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
