3.3 DDoS Report

2011-03-05 Hauri

https://cppg.or.kr/issue/download.php?bo_table=qna&wr_id=2315&no=0&page=3

Attachments

3.3_DDoS_Report.pdf (2 MB)

The March 2011 South Korea DDoS incident began with compromised web-hard update mechanisms, including Sharebox and later similar file-distribution services such as Bobofile and Filecity, which rapidly pushed malicious update binaries to users. The malware chain downloaded additional components such as SBUpdate.exe, Host.dll, ntcm63.dll, and randomized service DLLs from relay servers, then split functions across modules for host-file tampering, encrypted command communication, DDoS execution, and destructive payloads. Scheduled attacks used UDP, ICMP, and HTTP-style request flooding against South Korean government, military, financial, portal, and security-related sites, while a separate component searched common document formats, compressed filenames into CAB form, and overwrote data with zeros. The report lists hashes and infrastructure including relay IPs such as 209.107.241.247 and 98.21.253.110, and notes structural similarities to the 2009 July 7 DDoS attacks with stronger encryption and continued abuse of web-hard software distribution channels.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN sub.sharebox.co.kr 2011-03-05 2011-03-09
IPv4 173.18.37.158 2011-03-05 2011-03-07
IPv4 78.39.222.97 2011-03-05 2011-03-07
IPv4 82.154.248.137 2011-03-05 2011-03-07
IPv4 207.191.121.170 2011-03-05 2011-03-07
IPv4 209.107.241.247 2011-03-05 2011-03-07
IPv4 212.200.11.82 2011-03-05 2011-03-07
IPv4 200.132.59.120 2011-03-05 2011-03-07
URL http://sub.sharebox.co.kr/Share… 2011-03-05 2011-03-05
URL http://sub.sharebox.co.kr/SBUpd… 2011-03-05 2011-03-05
URL http://webfile.bobofile.co.kr/a… 2011-03-05 2011-03-05
DOMAIN webfile.bobofile.co.kr 2011-03-05 2011-03-05
DOMAIN webfile.filecity.co.kr 2011-03-05 2011-03-05
IPv4 74.39.222.97 2011-03-05 2011-03-05
IPv4 98.21.253.110 2011-03-05 2011-03-05

Related Reports

« Back