6月25日と7月1日に発生した韓国へのサイバー攻撃をまとめてみた
2013-06-26 • piyokango • A summary of the cyber attacks on South Korea that occurred on June 25th and July 1st. •
The excerpt describes a June 2013 incident wave in South Korea that disrupted government, political, military, and media sites, including outages, defacements, and publication of personal data allegedly taken from government-related systems. It reports that 16 organizations were affected, 131 servers went down, and several websites were defaced with Anonymous or High Anonymous-themed messages, while South Korean authorities raised the cyber crisis alert level and began a joint investigation. Technical details include a compromised SimDisk update mechanism, malware delivered from legitimate infrastructure, C&C-directed activity against target sites, Themida packing, password changes to "highanon2013," desktop image changes, destructive wiping behavior stronger than the earlier March 20 wiper, and Tor-based component retrieval. The excerpt lists infrastructure such as simdisk.co.kr, habang.co.kr, webmail.genesyshost.com, and 211.196.153.24, plus multiple hashes, but it presents attribution around Anonymous, High Anonymous, and OpNorthKorea as contested or suspected rather than conclusive.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | webmail.genesyshost.com | 2013-06-26 | 2013-07-09 |
| HASH | 98e0daafceb50d04828790cc344881d9 | 2013-06-26 | 2013-06-26 |
| HASH | 0708a979a5c7c3a0450b7ddc37faead7 | 2013-06-26 | 2013-06-26 |
| HASH | 27838d9f0f1befd7af151f1b73ad7720 | 2013-06-26 | 2013-06-26 |
| HASH | 0ff67e022fa9ce7056316ceff82a80a8 | 2013-06-26 | 2013-06-26 |
| HASH | 13b4617013f22f9eba25be0b6ab2a7a8 | 2013-06-26 | 2013-06-26 |
| HASH | d9e211d1e05b50e1021e55110298dff5 | 2013-06-26 | 2013-06-26 |
| HASH | f60935e852d0c7bcffaa54dda15d009a | 2013-06-26 | 2013-06-26 |
| HASH | d97aef01ac94d2c7654033caa707a59f | 2013-06-26 | 2013-06-26 |
| URL | http://www.edream.ac.kr | 2013-06-26 | 2013-06-26 |
| URL | http://www.sekwang.co.kr | 2013-06-26 | 2013-06-26 |
| URL | http://www.jungbo.net | 2013-06-26 | 2013-06-26 |
| URL | http://www.dsimall.com | 2013-06-26 | 2013-06-26 |
| URL | http://www.cakecall.com | 2013-06-26 | 2013-06-26 |
| URL | http://www.yeongnam.com | 2013-06-26 | 2013-06-26 |
| URL | http://www.nw119.com | 2013-06-26 | 2013-06-26 |
| URL | http://www.cybertokdo.com | 2013-06-26 | 2013-06-26 |
| URL | http://www.scco.co.kr | 2013-06-26 | 2013-06-26 |
| URL | http://www.youngheungdo.com | 2013-06-26 | 2013-06-26 |
| URL | http://www.gnnews.co.kr | 2013-06-26 | 2013-06-26 |
| IPv4 | 211.196.153.24 | 2013-06-26 | 2013-06-26 |