7.7 DDoS: Unknown Secrets & Botnet Counter Attack
2009-11-08 • Issuemakers Lab •
Attachments
IssuemakersLab's 7.7 DDoS presentation describes a hierarchical botnet used in the July 2009 attacks against South Korean and U.S. government, media, and financial websites. The malware family included file-information stealers, DDoS components, spam components, and an HDD/MBR destroyer, with samples such as msiexec?/ntdll.exe, wmiconf.dll, wmcfg.exe, mstimer.dll, and wversion.exe using custom XOR-based protocols and configuration files. The deck lists C&C IP relay servers and distributed support servers, including flash.gif download locations used by mstimer.dll before wversion.exe executed after midnight on July 10 to overwrite the MBR and damage documents by compressing them with random passwords. The report is useful because it documents both the botnet's command hierarchy and the destructive payload chain behind the 7.7 DDoS incident.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | newrozfm.com | 2009-11-08 | 2009-11-08 |
| URL | http://newrozfm.com/img/glyph/f… | 2009-11-08 | 2009-11-08 |
| URL | http://201.116.58.131/xampp/img… | 2009-11-08 | 2009-11-08 |
| URL | http://122.155.5.196/shop/image… | 2009-11-08 | 2009-11-08 |
| URL | http://75.151.32.182/flash.gif | 2009-11-08 | 2009-11-08 |
| URL | http://202.14.70.116/flash.gif | 2009-11-08 | 2009-11-08 |
| URL | http://163.19.209.22/flash.gif | 2009-11-08 | 2009-11-08 |
| URL | http://92.63.2.118/flash.gif | 2009-11-08 | 2009-11-08 |
| URL | http://200.6.218.194/flash.gif | 2009-11-08 | 2009-11-08 |
| IPv4 | 98.118.201.35 | 2009-11-08 | 2009-11-08 |
| IPv4 | 75.144.115.102 | 2009-11-08 | 2009-11-08 |
| IPv4 | 93.104.211.61 | 2009-11-08 | 2009-11-08 |
| IPv4 | 67.69.18.51 | 2009-11-08 | 2009-11-08 |
| IPv4 | 116.68.144.212 | 2009-11-08 | 2009-11-08 |
| IPv4 | 220.250.64.246 | 2009-11-08 | 2009-11-08 |
| IPv4 | 213.23.243.210 | 2009-07-09 | 2009-11-08 |
| IPv4 | 213.33.116.41 | 2009-07-09 | 2009-11-08 |
| IPv4 | 216.199.83.203 | 2009-07-09 | 2009-11-08 |