6.25 DNS DDoS 공격 악성코드 분석
2013-07-19 • HNS • 6.25 DNS DDoS attack malware analysis •
Attachments
HNS-WI-13-025.pdf (654 KB)
The 6.25 DNS DDoS malware used compromised Simdisk distribution infrastructure to infect PCs and redirect DNS amplification traffic toward South Korean government DNS servers. The report, based on Fortinet's analysis, says the SimDisk_setup.exe package dropped SimDiskup.exe and downloaded c.jpg from the compromised server path /images/korea.c.jpg; that payload became simdisk.exe and unpacked alg.exe, explorer.exe, and config.ini. The malware used Tor 0.2.3.25 components and multiple hardcoded .onion URLs to retrieve the DDoS payload, then checked file-mapping objects and system architecture before dropping a service-loaded DLL and the Themida-packed wuauieop.exe. After the hardcoded 25 June 10:00 trigger, the payload launched DNS amplification by sending roughly 20,000 randomized DNS queries whose responses were directed at ns.gcc.go.kr and ns2.gcc.go.kr, and the timing and execution logic resembled elements seen in the 3.20 cyber attacks.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | http://snij5xfzt2qspxj2.onion/e… | 2013-07-19 | 2013-07-19 |
| URL | http://u6irlnorfxnn7cqs.onion/e… | 2013-07-19 | 2013-07-19 |
| URL | http://et53n5fxxmjukgki.onion/e… | 2013-07-19 | 2013-07-19 |
| URL | http://rns3d52wyctfktcb.onion/e… | 2013-07-19 | 2013-07-19 |
| URL | http://vtyee6ev7gki7qxf.onion/e… | 2013-07-19 | 2013-07-19 |
| URL | http://7odyldjmpzjrhsye.onion/e… | 2013-07-19 | 2013-07-19 |
| URL | http://swe4ta6k64m7vguk.onion/e… | 2013-07-19 | 2013-07-19 |
| URL | http://p4dxzhnlukvh6p4a.onion/e… | 2013-07-19 | 2013-07-19 |
| URL | http://n3fwfxcdjfv4zxpa.onion/e… | 2013-07-19 | 2013-07-19 |
| URL | http://hfc4z2pxfdmsfczp.onion/e… | 2013-07-19 | 2013-07-19 |
| DOMAIN | simdisk.co.kr | 2013-06-25 | 2013-07-19 |
| IPv4 | 152.99.200.6 | 2013-06-25 | 2013-07-19 |
| IPv4 | 152.99.1.10 | 2013-06-25 | 2013-07-19 |