6.25 사이버테러 분석 보고서
2013-07-09 • Ahnlab • 6.25 Cyber Terror Analysis Report •
http://download.ahnlab.com/kr/site/magazineAhn/ahn_201307.pdf
Attachments
ahn_201307.pdf (10 MB)
AhnLab’s analysis of the June 25, 2013 cyberattack describes DDoS activity against South Korean government and media-related targets beginning at 10:00 local time. One attack path used malware distributed through modified webhard installer and update files to turn user PCs into bots, then used C&C instructions to direct traffic at DNS servers supporting government websites. A second path used malicious scripts injected into websites so visitors generated attack traffic while browsing, and the report also notes Apache Range DoS activity against selected media, political-party, and related domains. The excerpt includes malware staging details such as service-style DLL execution, creation of wuauieop.exe, and downloads from webmail.genesyshost.com and hostmypic.net, giving defenders concrete host and network behaviors to validate.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 152.99.200.6 | 2013-06-25 | 2013-07-19 |
| IPv4 | 152.99.1.10 | 2013-06-25 | 2013-07-19 |
| URL | http://www.hostmypic.net/pictur… | 2013-07-09 | 2013-07-09 |
| URL | https://dorumugs-tools.googleco… | 2013-07-09 | 2013-07-09 |
| DOMAIN | mail.intercity.com | 2013-07-09 | 2013-07-09 |
| DOMAIN | dorumugs-tools.googlecode.com | 2013-07-09 | 2013-07-09 |
| DOMAIN | mail.pensys.com | 2013-07-09 | 2013-07-09 |
| IPv4 | 112.217.190.218 | 2013-07-09 | 2013-07-09 |
| IPv4 | 210.127.39.29 | 2013-07-09 | 2013-07-09 |
| IPv4 | 20.20.9.21 | 2013-07-09 | 2013-07-09 |
| URL | http://webmail.genesyshost.com/… | 2013-06-26 | 2013-07-09 |
| DOMAIN | webmail.genesyshost.com | 2013-06-26 | 2013-07-09 |