6月25日と7月1日に発生した韓国へのサイバー攻撃をまとめてみた

2013-06-26 piyokango A summary of the cyber attacks on South Korea that occurred on June 25th and July 1st.

http://d.hatena.ne.jp/Kango/20130626/1372257887

Thumbnail for 6月25日と7月1日に発生した韓国へのサイバー攻撃をまとめてみた

The excerpt describes a June 2013 incident wave in South Korea that disrupted government, political, military, and media sites, including outages, defacements, and publication of personal data allegedly taken from government-related systems. It reports that 16 organizations were affected, 131 servers went down, and several websites were defaced with Anonymous or High Anonymous-themed messages, while South Korean authorities raised the cyber crisis alert level and began a joint investigation. Technical details include a compromised SimDisk update mechanism, malware delivered from legitimate infrastructure, C&C-directed activity against target sites, Themida packing, password changes to "highanon2013," desktop image changes, destructive wiping behavior stronger than the earlier March 20 wiper, and Tor-based component retrieval. The excerpt lists infrastructure such as simdisk.co.kr, habang.co.kr, webmail.genesyshost.com, and 211.196.153.24, plus multiple hashes, but it presents attribution around Anonymous, High Anonymous, and OpNorthKorea as contested or suspected rather than conclusive.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN webmail.genesyshost.com 2013-06-26 2013-07-09
HASH 98e0daafceb50d04828790cc344881d9 2013-06-26 2013-06-26
HASH 0708a979a5c7c3a0450b7ddc37faead7 2013-06-26 2013-06-26
HASH 27838d9f0f1befd7af151f1b73ad7720 2013-06-26 2013-06-26
HASH 0ff67e022fa9ce7056316ceff82a80a8 2013-06-26 2013-06-26
HASH 13b4617013f22f9eba25be0b6ab2a7a8 2013-06-26 2013-06-26
HASH d9e211d1e05b50e1021e55110298dff5 2013-06-26 2013-06-26
HASH f60935e852d0c7bcffaa54dda15d009a 2013-06-26 2013-06-26
HASH d97aef01ac94d2c7654033caa707a59f 2013-06-26 2013-06-26
URL http://www.edream.ac.kr 2013-06-26 2013-06-26
URL http://www.sekwang.co.kr 2013-06-26 2013-06-26
URL http://www.jungbo.net 2013-06-26 2013-06-26
URL http://www.dsimall.com 2013-06-26 2013-06-26
URL http://www.cakecall.com 2013-06-26 2013-06-26
URL http://www.yeongnam.com 2013-06-26 2013-06-26
URL http://www.nw119.com 2013-06-26 2013-06-26
URL http://www.cybertokdo.com 2013-06-26 2013-06-26
URL http://www.scco.co.kr 2013-06-26 2013-06-26
URL http://www.youngheungdo.com 2013-06-26 2013-06-26
URL http://www.gnnews.co.kr 2013-06-26 2013-06-26
IPv4 211.196.153.24 2013-06-26 2013-06-26

Related Reports

« Back