3.3 DDoS 악성코드에 대한 분석 보고서

2011-03-07 ESTSecurity 3.3 Analysis report on DDoS malware

http://blog.estsoft.co.kr/65

ESTsoft analyzed the March 3 DDoS malware incident that disrupted about 40 public-sector, portal, shopping, finance, power, and transport sites in South Korea and abroad. The malware was distributed through compromised update servers at five Korean webhard services, turning users into zombie PCs that launched HTTP, UDP, and ICMP DDoS traffic against configured targets. Compared with the earlier 7.7 DDoS case, the 3.3 malware used obfuscated DAT target files, encrypted server communications, multiple coordinated DLL and DAT components, host-file changes to block antivirus updates, and stronger disk-destruction logic that could overwrite the MBR without the earlier .NET dependency. The report lists many malware hashes and notes downloader, dropper, and backdoor components that contacted suspected C&C infrastructure, exfiltrated host and domain information, and made analysis harder by self-deleting with batch files.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 0a21b996e1f875d740034d250b878884 2011-03-07 2011-07-06
HASH a63f4c213e2ae4d6caa85382b65182c8 2011-03-07 2011-07-06
HASH c963b7ad7c7aefbe6d2ac14bed316cb8 2011-03-07 2011-07-06
IPv4 120.151.118.10 2011-03-07 2011-07-06
IPv4 212.190.216.147 2011-03-07 2011-07-06
IPv4 119.15.208.97 2011-03-07 2011-07-06
IPv4 208.71.147.242 2011-03-07 2011-07-06
IPv4 212.102.5.42 2011-03-07 2011-07-06
IPv4 147.175.129.216 2011-03-07 2011-07-06
IPv4 41.241.141.76 2011-03-07 2011-07-06
IPv4 206.74.76.243 2011-03-07 2011-07-06
IPv4 59.120.179.11 2011-03-07 2011-07-06
IPv4 63.163.221.71 2011-03-07 2011-07-06
IPv4 88.215.130.6 2011-03-07 2011-07-06
IPv4 212.62.100.211 2011-03-07 2011-07-06
IPv4 32.106.118.196 2011-03-07 2011-07-06
IPv4 203.196.252.244 2011-03-07 2011-07-06
IPv4 59.125.224.43 2011-03-07 2011-07-06
IPv4 212.58.215.77 2011-03-07 2011-07-06
HASH 133d384459ed020b4619735ba70fe7b1 2011-03-07 2011-03-07
HASH eda2413435eedd080988ad0ba63c7454 2011-03-07 2011-03-07
HASH 88e2f0ca1bed4feab764b7bec703c7e8 2011-03-07 2011-03-07
HASH ae0d2fa1043770a37df97b94024d6165 2011-03-07 2011-03-07
HASH e92d5533b226532f84d8876abfe959fe 2011-03-07 2011-03-07
HASH d15e188501acc67fd4d0d7699ec7b102 2011-03-07 2011-03-07
HASH f1ec5b570351db41f7dd4f925b8c2ba7 2011-03-07 2011-03-07
HASH 5ea379f108665421b243a8fdeaab4344 2011-03-07 2011-03-07
HASH 1be4cca010ae2d1f6c6926ec623d2c6c 2011-03-07 2011-03-07
HASH 53b8e4fb77fdb70a4d59ec903c110318 2011-03-07 2011-03-07
HASH 0a11609e967857908b0fa285da5a29ef 2011-03-07 2011-03-07
HASH 561dac7d20a488317c62ed38a6940987 2011-03-07 2011-03-07
HASH 13bafd5001aae9b079480d2323403c36 2011-03-07 2011-03-07
HASH 556b0f5e9d6e61dcf0914e1b0ce39155 2011-03-07 2011-03-07
HASH 64ff3d3c000f657489cc03df13db8366 2011-03-07 2011-03-07
HASH 7e22f5347c3f8b424ea49eb40193f865 2011-03-07 2011-03-07
HASH de905320da5d260f7bb880d1f7af8cec 2011-03-07 2011-03-07
HASH d7aee492ac8253dfb05f8dc08c6660f2 2011-03-07 2011-03-07
HASH 9ef7c717ba856ec760d6a62ffc05f502 2011-03-07 2011-03-07
HASH 534822b4175b99140eee4868dedfbb04 2011-03-07 2011-03-07
HASH 6b0d5b1225a6bbba43946734fdd3cc4f 2011-03-07 2011-03-07
HASH ae1d2cb86364e27a759d0106374ed403 2011-03-07 2011-03-07
HASH cf8c47c8970821c9106a131647b08497 2011-03-07 2011-03-07
HASH 111401c491c7319005cb3906d298b63b 2011-03-07 2011-03-07
HASH e8374d1f7944dc56e8d3b6331aed093b 2011-03-07 2011-03-07
HASH e82313dd99d4aaec6f4dc9db4c7bf6ec 2011-03-07 2011-03-07
HASH 65334333f65c5297b0e4f06a4b050804 2011-03-07 2011-03-07
HASH a411b944af23d28d636a0312b5b705de 2011-03-07 2011-03-07
HASH 59034bdb4deb4bf2e5d4431383d6e3b6 2011-03-07 2011-03-07
HASH 4551cebfd3340e744828eeab9ca076d9 2011-03-07 2011-03-07
HASH d1170fe4e3658e95ec04ab9c0a9b5f64 2011-03-07 2011-03-07
IPv4 210.245.87.13 2011-03-07 2011-03-07
IPv4 83.103.52.109 2011-03-07 2011-03-07
IPv4 210.145.163.228 2011-03-07 2011-03-07
IPv4 74.42.253.166 2011-03-07 2011-03-07
IPv4 65.15.100.146 2011-03-07 2011-03-07
IPv4 173.18.37.158 2011-03-05 2011-03-07
IPv4 78.39.222.97 2011-03-05 2011-03-07
IPv4 82.154.248.137 2011-03-05 2011-03-07
IPv4 207.191.121.170 2011-03-05 2011-03-07
IPv4 209.107.241.247 2011-03-05 2011-03-07
IPv4 212.200.11.82 2011-03-05 2011-03-07
IPv4 200.132.59.120 2011-03-05 2011-03-07

Related Reports

« Back