Ten Days of Rain

2011-07-06 Mcafee

https://www.mcafee.com/blogs/wp-content/uploads/2011/07/McAfee-Labs-10-Days-of-Rain-July-2011.pdf

Attachments

McAfee-Labs-10-Days-of-Rain-July-2011.pdf (980 KB)

McAfee observed a March 2011 DDoS operation against South Korean government, military-related targets, and U.S. Forces Korea, launched from compromised hosts in South Korea. The botnet used a multitier command-and-control architecture with first-tier redirector servers distributed across multiple geographies to improve resiliency against takedowns. The malware was configured primarily for DDoS using ICMP, UDP, and HTTP request traffic, with a predefined 10-day operating window and payloads protected by multiple cryptographic algorithms including RC4, AES, RSA, and MD5. At the end of the attack window, infected hosts were designed to self-destruct by deleting and overwriting key files and damaging the master boot record, limiting recovery and forensic analysis. The combination of targeted South Korean and USFK victims, resilient C2, restricted bot functionality, and destructive cleanup made the campaign operationally distinct from typical financially motivated botnets.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 210.0.204.175 2011-07-06 2011-07-06
IPv4 91.74.106.98 2011-07-06 2011-07-06
IPv4 61.91.86.34 2011-07-06 2011-07-06
IPv4 149.156.160.60 2011-07-06 2011-07-06
IPv4 203.186.126.225 2011-07-06 2011-07-06
IPv4 122.176.36.85 2011-07-06 2011-07-06
IPv4 201.168.56.139 2011-07-06 2011-07-06
IPv4 173.11.235.222 2011-07-06 2011-07-06
IPv4 208.36.53.174 2011-07-06 2011-07-06
IPv4 113.53.236.67 2011-07-06 2011-07-06
IPv4 196.23.164.39 2011-07-06 2011-07-06
IPv4 194.90.168.146 2011-07-06 2011-07-06
IPv4 114.167.76.1 2011-07-06 2011-07-06
IPv4 87.22.234.153 2011-07-06 2011-07-06
IPv4 95.9.112.9 2011-07-06 2011-07-06
IPv4 86.62.115.242 2011-07-06 2011-07-06
IPv4 157.161.44.108 2011-07-06 2011-07-06
HASH 0a21b996e1f875d740034d250b878884 2011-03-07 2011-07-06
HASH a63f4c213e2ae4d6caa85382b65182c8 2011-03-07 2011-07-06
HASH c963b7ad7c7aefbe6d2ac14bed316cb8 2011-03-07 2011-07-06
IPv4 120.151.118.10 2011-03-07 2011-07-06
IPv4 212.190.216.147 2011-03-07 2011-07-06
IPv4 119.15.208.97 2011-03-07 2011-07-06
IPv4 208.71.147.242 2011-03-07 2011-07-06
IPv4 212.102.5.42 2011-03-07 2011-07-06
IPv4 147.175.129.216 2011-03-07 2011-07-06
IPv4 41.241.141.76 2011-03-07 2011-07-06
IPv4 206.74.76.243 2011-03-07 2011-07-06
IPv4 59.120.179.11 2011-03-07 2011-07-06
IPv4 63.163.221.71 2011-03-07 2011-07-06
IPv4 88.215.130.6 2011-03-07 2011-07-06
IPv4 212.62.100.211 2011-03-07 2011-07-06
IPv4 32.106.118.196 2011-03-07 2011-07-06
IPv4 203.196.252.244 2011-03-07 2011-07-06
IPv4 59.125.224.43 2011-03-07 2011-07-06
IPv4 212.58.215.77 2011-03-07 2011-07-06

Related Reports

« Back