7.7 DDoS: Unknown Secrets & Botnet Counter Attack

2009-11-08 Issuemakers Lab

http://powerofcommunity.net/poc2009/si.pdf

Attachments

7.7_DDoS__Unknown_Secrets__Botnet_Counter_Attack.pdf (2 MB)

Thumbnail for 7.7 DDoS: Unknown Secrets & Botnet Counter Attack

IssuemakersLab's 7.7 DDoS presentation describes a hierarchical botnet used in the July 2009 attacks against South Korean and U.S. government, media, and financial websites. The malware family included file-information stealers, DDoS components, spam components, and an HDD/MBR destroyer, with samples such as msiexec?/ntdll.exe, wmiconf.dll, wmcfg.exe, mstimer.dll, and wversion.exe using custom XOR-based protocols and configuration files. The deck lists C&C IP relay servers and distributed support servers, including flash.gif download locations used by mstimer.dll before wversion.exe executed after midnight on July 10 to overwrite the MBR and damage documents by compressing them with random passwords. The report is useful because it documents both the botnet's command hierarchy and the destructive payload chain behind the 7.7 DDoS incident.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN newrozfm.com 2009-11-08 2009-11-08
URL http://newrozfm.com/img/glyph/f… 2009-11-08 2009-11-08
URL http://201.116.58.131/xampp/img… 2009-11-08 2009-11-08
URL http://122.155.5.196/shop/image… 2009-11-08 2009-11-08
URL http://75.151.32.182/flash.gif 2009-11-08 2009-11-08
URL http://202.14.70.116/flash.gif 2009-11-08 2009-11-08
URL http://163.19.209.22/flash.gif 2009-11-08 2009-11-08
URL http://92.63.2.118/flash.gif 2009-11-08 2009-11-08
URL http://200.6.218.194/flash.gif 2009-11-08 2009-11-08
IPv4 98.118.201.35 2009-11-08 2009-11-08
IPv4 75.144.115.102 2009-11-08 2009-11-08
IPv4 93.104.211.61 2009-11-08 2009-11-08
IPv4 67.69.18.51 2009-11-08 2009-11-08
IPv4 116.68.144.212 2009-11-08 2009-11-08
IPv4 220.250.64.246 2009-11-08 2009-11-08
IPv4 213.23.243.210 2009-07-09 2009-11-08
IPv4 213.33.116.41 2009-07-09 2009-11-08
IPv4 216.199.83.203 2009-07-09 2009-11-08

Related Reports

« Back