6.25 DNS DDoS 공격 악성코드 분석

2013-07-19 HNS 6.25 DNS DDoS attack malware analysis

https://www.dailysecu.com/bbs/download.php?table=bbs_10&savefilename=bbs_10_981_2774.pdf&filename=HNS-WI-13-025.pdf

Attachments

HNS-WI-13-025.pdf (654 KB)

Thumbnail for 6.25 DNS DDoS 공격 악성코드 분석

The 6.25 DNS DDoS malware used compromised Simdisk distribution infrastructure to infect PCs and redirect DNS amplification traffic toward South Korean government DNS servers. The report, based on Fortinet's analysis, says the SimDisk_setup.exe package dropped SimDiskup.exe and downloaded c.jpg from the compromised server path /images/korea.c.jpg; that payload became simdisk.exe and unpacked alg.exe, explorer.exe, and config.ini. The malware used Tor 0.2.3.25 components and multiple hardcoded .onion URLs to retrieve the DDoS payload, then checked file-mapping objects and system architecture before dropping a service-loaded DLL and the Themida-packed wuauieop.exe. After the hardcoded 25 June 10:00 trigger, the payload launched DNS amplification by sending roughly 20,000 randomized DNS queries whose responses were directed at ns.gcc.go.kr and ns2.gcc.go.kr, and the timing and execution logic resembled elements seen in the 3.20 cyber attacks.

Indicators of Compromise

Type Value First Seen Last Seen
URL http://snij5xfzt2qspxj2.onion/e… 2013-07-19 2013-07-19
URL http://u6irlnorfxnn7cqs.onion/e… 2013-07-19 2013-07-19
URL http://et53n5fxxmjukgki.onion/e… 2013-07-19 2013-07-19
URL http://rns3d52wyctfktcb.onion/e… 2013-07-19 2013-07-19
URL http://vtyee6ev7gki7qxf.onion/e… 2013-07-19 2013-07-19
URL http://7odyldjmpzjrhsye.onion/e… 2013-07-19 2013-07-19
URL http://swe4ta6k64m7vguk.onion/e… 2013-07-19 2013-07-19
URL http://p4dxzhnlukvh6p4a.onion/e… 2013-07-19 2013-07-19
URL http://n3fwfxcdjfv4zxpa.onion/e… 2013-07-19 2013-07-19
URL http://hfc4z2pxfdmsfczp.onion/e… 2013-07-19 2013-07-19
DOMAIN simdisk.co.kr 2013-06-25 2013-07-19
IPv4 152.99.200.6 2013-06-25 2013-07-19
IPv4 152.99.1.10 2013-06-25 2013-07-19

Related Reports

« Back