6.25 Cyber Attack Analysis Report

2013-06-26 Fireeye

https://www.dailysecu.com/bbs/download.php?table=bbs_10&savefilename=bbs_10_927_2720.pdf&filename=[FireEye]%206.25%20Cyber%20Attack%20Analysis%20Report_ver1.0

Attachments

FireEye_6.25_Cyber_Attack_Analysis_Report_ver1.0.pdf (536 KB)

Thumbnail for 6.25 Cyber Attack Analysis Report

FireEye's 6.25 Cyber Attack Analysis Report describes the June 25, 2013 campaign in which attackers modified a web-hard installer to distribute malware, build a botnet, and trigger DDoS activity at a scheduled time. The report says the malware used Themida packing, anti-VM and anti-debugging techniques, and Tor-based proxying to complicate analysis and follow-on tracing. It identifies SimDiskup.exe as the file created by the tampered installer, c.jpg as a downloaded executable that created Tor-related files such as svchost.exe, thttp.exe/explorer.exe, and config.ini, and a later main dropper that created temporary loaders and service DLLs. The dropper contacted C&C paths at webmail.genesyshost.com/mail/images/ct.jpg and www.hostmypic.net/pictures/e02947e8573918c1d887e04e2e0b1570.jpg before delivering wuauieop.exe, which generated large DNS queries against randomized gcc.go.kr subdomains.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN www.hostmypic.net 2013-06-26 2013-07-09
URL http://webmail.genesyshost.com/… 2013-06-26 2013-07-09
DOMAIN webmail.genesyshost.com 2013-06-26 2013-07-09
URL http://www.hostmypic.net/pictur… 2013-06-26 2013-06-26

Related Reports

« Back