6.25 사이버테러 분석 보고서

2013-07-09 Ahnlab 6.25 Cyber ​​Terror Analysis Report

http://download.ahnlab.com/kr/site/magazineAhn/ahn_201307.pdf

Attachments

ahn_201307.pdf (10 MB)

Thumbnail for 6.25 사이버테러 분석 보고서

AhnLab’s analysis of the June 25, 2013 cyberattack describes DDoS activity against South Korean government and media-related targets beginning at 10:00 local time. One attack path used malware distributed through modified webhard installer and update files to turn user PCs into bots, then used C&C instructions to direct traffic at DNS servers supporting government websites. A second path used malicious scripts injected into websites so visitors generated attack traffic while browsing, and the report also notes Apache Range DoS activity against selected media, political-party, and related domains. The excerpt includes malware staging details such as service-style DLL execution, creation of wuauieop.exe, and downloads from webmail.genesyshost.com and hostmypic.net, giving defenders concrete host and network behaviors to validate.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 152.99.200.6 2013-06-25 2013-07-19
IPv4 152.99.1.10 2013-06-25 2013-07-19
URL http://www.hostmypic.net/pictur… 2013-07-09 2013-07-09
URL https://dorumugs-tools.googleco… 2013-07-09 2013-07-09
DOMAIN mail.intercity.com 2013-07-09 2013-07-09
DOMAIN dorumugs-tools.googlecode.com 2013-07-09 2013-07-09
DOMAIN mail.pensys.com 2013-07-09 2013-07-09
IPv4 112.217.190.218 2013-07-09 2013-07-09
IPv4 210.127.39.29 2013-07-09 2013-07-09
IPv4 20.20.9.21 2013-07-09 2013-07-09
URL http://webmail.genesyshost.com/… 2013-06-26 2013-07-09
DOMAIN webmail.genesyshost.com 2013-06-26 2013-07-09

Related Reports

« Back