Ten Days of Rain
2011-07-06 • Mcafee •
https://www.mcafee.com/blogs/wp-content/uploads/2011/07/McAfee-Labs-10-Days-of-Rain-July-2011.pdf
Attachments
McAfee observed a March 2011 DDoS operation against South Korean government, military-related targets, and U.S. Forces Korea, launched from compromised hosts in South Korea. The botnet used a multitier command-and-control architecture with first-tier redirector servers distributed across multiple geographies to improve resiliency against takedowns. The malware was configured primarily for DDoS using ICMP, UDP, and HTTP request traffic, with a predefined 10-day operating window and payloads protected by multiple cryptographic algorithms including RC4, AES, RSA, and MD5. At the end of the attack window, infected hosts were designed to self-destruct by deleting and overwriting key files and damaging the master boot record, limiting recovery and forensic analysis. The combination of targeted South Korean and USFK victims, resilient C2, restricted bot functionality, and destructive cleanup made the campaign operationally distinct from typical financially motivated botnets.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 210.0.204.175 | 2011-07-06 | 2011-07-06 |
| IPv4 | 91.74.106.98 | 2011-07-06 | 2011-07-06 |
| IPv4 | 61.91.86.34 | 2011-07-06 | 2011-07-06 |
| IPv4 | 149.156.160.60 | 2011-07-06 | 2011-07-06 |
| IPv4 | 203.186.126.225 | 2011-07-06 | 2011-07-06 |
| IPv4 | 122.176.36.85 | 2011-07-06 | 2011-07-06 |
| IPv4 | 201.168.56.139 | 2011-07-06 | 2011-07-06 |
| IPv4 | 173.11.235.222 | 2011-07-06 | 2011-07-06 |
| IPv4 | 208.36.53.174 | 2011-07-06 | 2011-07-06 |
| IPv4 | 113.53.236.67 | 2011-07-06 | 2011-07-06 |
| IPv4 | 196.23.164.39 | 2011-07-06 | 2011-07-06 |
| IPv4 | 194.90.168.146 | 2011-07-06 | 2011-07-06 |
| IPv4 | 114.167.76.1 | 2011-07-06 | 2011-07-06 |
| IPv4 | 87.22.234.153 | 2011-07-06 | 2011-07-06 |
| IPv4 | 95.9.112.9 | 2011-07-06 | 2011-07-06 |
| IPv4 | 86.62.115.242 | 2011-07-06 | 2011-07-06 |
| IPv4 | 157.161.44.108 | 2011-07-06 | 2011-07-06 |
| HASH | 0a21b996e1f875d740034d250b878884 | 2011-03-07 | 2011-07-06 |
| HASH | a63f4c213e2ae4d6caa85382b65182c8 | 2011-03-07 | 2011-07-06 |
| HASH | c963b7ad7c7aefbe6d2ac14bed316cb8 | 2011-03-07 | 2011-07-06 |
| IPv4 | 120.151.118.10 | 2011-03-07 | 2011-07-06 |
| IPv4 | 212.190.216.147 | 2011-03-07 | 2011-07-06 |
| IPv4 | 119.15.208.97 | 2011-03-07 | 2011-07-06 |
| IPv4 | 208.71.147.242 | 2011-03-07 | 2011-07-06 |
| IPv4 | 212.102.5.42 | 2011-03-07 | 2011-07-06 |
| IPv4 | 147.175.129.216 | 2011-03-07 | 2011-07-06 |
| IPv4 | 41.241.141.76 | 2011-03-07 | 2011-07-06 |
| IPv4 | 206.74.76.243 | 2011-03-07 | 2011-07-06 |
| IPv4 | 59.120.179.11 | 2011-03-07 | 2011-07-06 |
| IPv4 | 63.163.221.71 | 2011-03-07 | 2011-07-06 |
| IPv4 | 88.215.130.6 | 2011-03-07 | 2011-07-06 |
| IPv4 | 212.62.100.211 | 2011-03-07 | 2011-07-06 |
| IPv4 | 32.106.118.196 | 2011-03-07 | 2011-07-06 |
| IPv4 | 203.196.252.244 | 2011-03-07 | 2011-07-06 |
| IPv4 | 59.125.224.43 | 2011-03-07 | 2011-07-06 |
| IPv4 | 212.58.215.77 | 2011-03-07 | 2011-07-06 |