3.3 DDoS 악성코드에 대한 분석 보고서
2011-03-07 • ESTSecurity • 3.3 Analysis report on DDoS malware •
ESTsoft analyzed the March 3 DDoS malware incident that disrupted about 40 public-sector, portal, shopping, finance, power, and transport sites in South Korea and abroad. The malware was distributed through compromised update servers at five Korean webhard services, turning users into zombie PCs that launched HTTP, UDP, and ICMP DDoS traffic against configured targets. Compared with the earlier 7.7 DDoS case, the 3.3 malware used obfuscated DAT target files, encrypted server communications, multiple coordinated DLL and DAT components, host-file changes to block antivirus updates, and stronger disk-destruction logic that could overwrite the MBR without the earlier .NET dependency. The report lists many malware hashes and notes downloader, dropper, and backdoor components that contacted suspected C&C infrastructure, exfiltrated host and domain information, and made analysis harder by self-deleting with batch files.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 0a21b996e1f875d740034d250b878884 | 2011-03-07 | 2011-07-06 |
| HASH | a63f4c213e2ae4d6caa85382b65182c8 | 2011-03-07 | 2011-07-06 |
| HASH | c963b7ad7c7aefbe6d2ac14bed316cb8 | 2011-03-07 | 2011-07-06 |
| IPv4 | 120.151.118.10 | 2011-03-07 | 2011-07-06 |
| IPv4 | 212.190.216.147 | 2011-03-07 | 2011-07-06 |
| IPv4 | 119.15.208.97 | 2011-03-07 | 2011-07-06 |
| IPv4 | 208.71.147.242 | 2011-03-07 | 2011-07-06 |
| IPv4 | 212.102.5.42 | 2011-03-07 | 2011-07-06 |
| IPv4 | 147.175.129.216 | 2011-03-07 | 2011-07-06 |
| IPv4 | 41.241.141.76 | 2011-03-07 | 2011-07-06 |
| IPv4 | 206.74.76.243 | 2011-03-07 | 2011-07-06 |
| IPv4 | 59.120.179.11 | 2011-03-07 | 2011-07-06 |
| IPv4 | 63.163.221.71 | 2011-03-07 | 2011-07-06 |
| IPv4 | 88.215.130.6 | 2011-03-07 | 2011-07-06 |
| IPv4 | 212.62.100.211 | 2011-03-07 | 2011-07-06 |
| IPv4 | 32.106.118.196 | 2011-03-07 | 2011-07-06 |
| IPv4 | 203.196.252.244 | 2011-03-07 | 2011-07-06 |
| IPv4 | 59.125.224.43 | 2011-03-07 | 2011-07-06 |
| IPv4 | 212.58.215.77 | 2011-03-07 | 2011-07-06 |
| HASH | 133d384459ed020b4619735ba70fe7b1 | 2011-03-07 | 2011-03-07 |
| HASH | eda2413435eedd080988ad0ba63c7454 | 2011-03-07 | 2011-03-07 |
| HASH | 88e2f0ca1bed4feab764b7bec703c7e8 | 2011-03-07 | 2011-03-07 |
| HASH | ae0d2fa1043770a37df97b94024d6165 | 2011-03-07 | 2011-03-07 |
| HASH | e92d5533b226532f84d8876abfe959fe | 2011-03-07 | 2011-03-07 |
| HASH | d15e188501acc67fd4d0d7699ec7b102 | 2011-03-07 | 2011-03-07 |
| HASH | f1ec5b570351db41f7dd4f925b8c2ba7 | 2011-03-07 | 2011-03-07 |
| HASH | 5ea379f108665421b243a8fdeaab4344 | 2011-03-07 | 2011-03-07 |
| HASH | 1be4cca010ae2d1f6c6926ec623d2c6c | 2011-03-07 | 2011-03-07 |
| HASH | 53b8e4fb77fdb70a4d59ec903c110318 | 2011-03-07 | 2011-03-07 |
| HASH | 0a11609e967857908b0fa285da5a29ef | 2011-03-07 | 2011-03-07 |
| HASH | 561dac7d20a488317c62ed38a6940987 | 2011-03-07 | 2011-03-07 |
| HASH | 13bafd5001aae9b079480d2323403c36 | 2011-03-07 | 2011-03-07 |
| HASH | 556b0f5e9d6e61dcf0914e1b0ce39155 | 2011-03-07 | 2011-03-07 |
| HASH | 64ff3d3c000f657489cc03df13db8366 | 2011-03-07 | 2011-03-07 |
| HASH | 7e22f5347c3f8b424ea49eb40193f865 | 2011-03-07 | 2011-03-07 |
| HASH | de905320da5d260f7bb880d1f7af8cec | 2011-03-07 | 2011-03-07 |
| HASH | d7aee492ac8253dfb05f8dc08c6660f2 | 2011-03-07 | 2011-03-07 |
| HASH | 9ef7c717ba856ec760d6a62ffc05f502 | 2011-03-07 | 2011-03-07 |
| HASH | 534822b4175b99140eee4868dedfbb04 | 2011-03-07 | 2011-03-07 |
| HASH | 6b0d5b1225a6bbba43946734fdd3cc4f | 2011-03-07 | 2011-03-07 |
| HASH | ae1d2cb86364e27a759d0106374ed403 | 2011-03-07 | 2011-03-07 |
| HASH | cf8c47c8970821c9106a131647b08497 | 2011-03-07 | 2011-03-07 |
| HASH | 111401c491c7319005cb3906d298b63b | 2011-03-07 | 2011-03-07 |
| HASH | e8374d1f7944dc56e8d3b6331aed093b | 2011-03-07 | 2011-03-07 |
| HASH | e82313dd99d4aaec6f4dc9db4c7bf6ec | 2011-03-07 | 2011-03-07 |
| HASH | 65334333f65c5297b0e4f06a4b050804 | 2011-03-07 | 2011-03-07 |
| HASH | a411b944af23d28d636a0312b5b705de | 2011-03-07 | 2011-03-07 |
| HASH | 59034bdb4deb4bf2e5d4431383d6e3b6 | 2011-03-07 | 2011-03-07 |
| HASH | 4551cebfd3340e744828eeab9ca076d9 | 2011-03-07 | 2011-03-07 |
| HASH | d1170fe4e3658e95ec04ab9c0a9b5f64 | 2011-03-07 | 2011-03-07 |
| IPv4 | 210.245.87.13 | 2011-03-07 | 2011-03-07 |
| IPv4 | 83.103.52.109 | 2011-03-07 | 2011-03-07 |
| IPv4 | 210.145.163.228 | 2011-03-07 | 2011-03-07 |
| IPv4 | 74.42.253.166 | 2011-03-07 | 2011-03-07 |
| IPv4 | 65.15.100.146 | 2011-03-07 | 2011-03-07 |
| IPv4 | 173.18.37.158 | 2011-03-05 | 2011-03-07 |
| IPv4 | 78.39.222.97 | 2011-03-05 | 2011-03-07 |
| IPv4 | 82.154.248.137 | 2011-03-05 | 2011-03-07 |
| IPv4 | 207.191.121.170 | 2011-03-05 | 2011-03-07 |
| IPv4 | 209.107.241.247 | 2011-03-05 | 2011-03-07 |
| IPv4 | 212.200.11.82 | 2011-03-05 | 2011-03-07 |
| IPv4 | 200.132.59.120 | 2011-03-05 | 2011-03-07 |