Welcome, Guest. Please login or register.
November 08, 2009, 05:13:10 PM

Login with username, password and session length

333400 Posts
36825 Topics
83519 Members

Latest Member: Gemo66

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Learn about Computer Security and Interact with Security Experts
| |-+  General Security Questions and Comments (not product related)
| | |-+  Urgent-Massive DDOS Attack!
« previous next »
Pages: [1] Go Down Print
Author Topic: Urgent-Massive DDOS Attack!  (Read 2426 times)
Creasy
Product Translator
Comodo's Hero
*****
Offline Offline

Posts: 691


I'm watching you.


« on: July 07, 2009, 10:30:16 PM »

DDOS attack files.
Known as Mutated Mydoom+Downloader.

filename: msiexec2.exe
size:33,841 bytes
When msiexec2.exe being excuted, it creates 'uregvs.nis' file.
There are many target addresses inside of msiexec2.exe code.

Following files attack those web sites.

filename:perfvwr.dll
size: 65,536 bytes

filename: wmiconf.dll
size: 67,072 bytes

some evidences about this attack.

1. attacker's IPs came from China.
2. Using Botnet.
3. Using Zombie PC.
4. spreaded by internet.
5. it changes it's code automatically.
6. addresses can be changed by attackers.

It has following Target Addresses.
Following addresses are related with South Korea gov and USA gov.
The attacker's IPs came from China.
But the origin of attacker's IPs came from North Korea.

[Target addresses]
Some of websites still can't be connected or slow.

<Korea>
banking.nonghyup.com - bank
blog.naver.com -portal
ebank.keb.co.kr - bank
ezbank.shinhan.com  -bank
mail.naver.com  -mail service
www.assembly.go.kr -gov
www.auction.co.kr
www.chosun.com -journal
www.hannara.or.kr -a political party
www.mnd.go.kr -gov
www.mofat.go.kr -gov
www.president.go.kr -gov
www.usfk.mil -US military website in korea

<USA>
finance.yahoo.com -portal
travel.state.gov -gov
www.amazon.com
www.dhs.gov -gov
www.dot.gov -gov
www.faa.gov -gov
www.ftc.gov -gov
www.nasdaq.com -stocks
www.nsa.gov -gov
www.nyse.com -gov
www.state.gov -gov
www.usbank.com -bank
www.usps.gov -US postal service
www.ustreas.gov -gov
www.voa.gov -voice of america
www.voanews.com
www.whitehouse.gov -gov
www.yahoo.com -portal
www.washingtonpost.com -journal
www.usauctionslive.com
www.defenselink.mil -military
www.marketwatch.com -stocks
www.site-by-site.com


« Last Edit: July 08, 2009, 10:38:18 PM by Creasy » Logged

Wrong messages are dangerous, but wrong interpretation of correct messages is even more dangerous.-Andre Kostolany-
I'm a MAN!!
I'm not a girl!
OmeletGuy
Good gamer, Omelet Chef, Rogue AV hater!
Global Moderator
Comodo's Hero
*****
Online Online

Posts: 1328


The only thing i ask for are eggs.


WWW
« Reply #1 on: July 07, 2009, 10:38:55 PM »

I know South Korea Websites are under Attack, they dont know who is attacking, but i hear this on the BBC once today. Had no idea US Gov was being DDOS also, they probably dont even feel it. LOL

And yesterday a website that host Malware for IT's was DDOS also. (Most of there attacking IP's where form Russia and Ukrain) I Get the feeling that it was a test drive for a upcomming DDOS attack.

« Last Edit: July 07, 2009, 10:41:30 PM by OmeletGuy » Logged

What you see isn’t what you always get!
Creasy
Product Translator
Comodo's Hero
*****
Offline Offline

Posts: 691


I'm watching you.


« Reply #2 on: July 07, 2009, 10:46:07 PM »

I know South Korea Websites are under Attack, they dont know who is attacking, but i hear this on the BBC once today. Had no idea US Gov was being DDOS also, they probably dont even feel it. LOL

And yesterday a website that host Malware for IT's was DDOS also.


They know where this attack came from. It's from China.
Also US gov knows where this attack came from. It's from China.
Some of attack informations have been identified.

But I think crazy North Korea is doing this attack.
Or China.
« Last Edit: July 07, 2009, 10:49:16 PM by Creasy » Logged

Wrong messages are dangerous, but wrong interpretation of correct messages is even more dangerous.-Andre Kostolany-
I'm a MAN!!
I'm not a girl!
Monkey_Boy=)
Product Translator
Comodo's Hero
*****
Offline Offline

Posts: 1154


^^^^


« Reply #3 on: July 07, 2009, 11:02:26 PM »

dang.. They should have killed twitter instead of those sites.. =/
Logged
OmeletGuy
Good gamer, Omelet Chef, Rogue AV hater!
Global Moderator
Comodo's Hero
*****
Online Online

Posts: 1328


The only thing i ask for are eggs.


WWW
« Reply #4 on: July 07, 2009, 11:04:21 PM »

dang.. They should have killed twitter instead of those sites.. =/

lol they may, if Twitter is using one of those server or is on a line that is being used to DDOS.
Logged

What you see isn’t what you always get!
OmeletGuy
Good gamer, Omelet Chef, Rogue AV hater!
Global Moderator
Comodo's Hero
*****
Online Online

Posts: 1328


The only thing i ask for are eggs.


WWW
« Reply #5 on: July 08, 2009, 12:12:15 AM »

HACKERS ATTACK SOUTH KOREAN GOVT, PRIVATE WEB SITES:
http://www.tmcnet.com/usubmit/-hackers-attack-south-korean-govt-private-web-sites-/2009/07/07/4262004.htm
Quote
SEOUL, Jul 08, 2009 (AsiaPulse via COMTEX) -- A series of cyber attacks disrupted the Web sites of South Korea's presidential office, government agencies and private firms, but no serious damage was reported, officials said Wednesday.

The so-called distributed denial-of-service (DDoS) attacks against 11 domestic Internet sites started at around 6:00 p.m.

on Tuesday, shutting them down for hours, said the government-run Korea Information Security Agency (KISA).

Hackers disrupted the Web sites of the presidential office Cheong Wa Dae, the National Assembly and the Ministry of Defense, it said.

Among private sites infiltrated were major lenders Shinhan Bank and Korea Exchange Bank.
The cyber attacks also affected the country's No. 1 portal Naver's e-mail service and online auctioneer eBay's South Korean site Auction.com, the agency said.

A DDoS attack involves sending large amounts of data that renders Web servers unusable by obstructing communication between the intended server and the target. The attacks generally use multiple personal computers infected by a hacker, allowing the individual to drive more traffic to the target.

KISA officials said most sites returned to normal as of 10:00 p.m. on Tuesday, though some sites remained unable to get access.

Online attack hits US government Web sites: http://www.networkworld.com/news/2009/070809-online-attack-hits-us-government.html
Quote
A botnet comprised of about 50,000 infected computers has been waging a war against U.S. government Web sites and causing headaches for businesses in the U.S. and South Korea.

The attack started Saturday, and security experts have credited it with knocking the U.S. Federal TradeCommission's (FTC's) Web site offline for parts of Monday and Tuesday. Several other government Web sites have also been targeted, including the U.S. Department of Transportation (DOT).

Any change you could upload those files to VT and post links?
and also PM them to Melih or Umesh (head of AV)
« Last Edit: July 08, 2009, 12:30:52 AM by OmeletGuy » Logged

What you see isn’t what you always get!
Creasy
Product Translator
Comodo's Hero
*****
Offline Offline

Posts: 691


I'm watching you.


« Reply #6 on: July 08, 2009, 12:55:19 AM »

Any change you could upload those files to VT and post links?
and also PM them to Melih or Umesh (head of AV)

I think COMODO already knows.
Logged

Wrong messages are dangerous, but wrong interpretation of correct messages is even more dangerous.-Andre Kostolany-
I'm a MAN!!
I'm not a girl!
OmeletGuy
Good gamer, Omelet Chef, Rogue AV hater!
Global Moderator
Comodo's Hero
*****
Online Online

Posts: 1328


The only thing i ask for are eggs.


WWW
« Reply #7 on: July 08, 2009, 04:05:35 PM »

Updated MyDoom responsible for DDOS attacks, says AhnLab.
http://www.networkworld.com/news/2009/070809-updated-mydoom-responsible-for-ddos.html
Quote
An updated version of the MyDoom virus is responsible for a large DDOS (distributed denial of service) attack that took down major U.S. Web sites over the weekend and South Korean Web sites on Wednesday, according to Korean computer security company AhnLab.

When it was discovered in January 2004, MyDoom quickly became the fastest-spreading e-mail worm in Internet history. Once a PC was infected with MyDoom, it would harvest e-mail addresses and e-mails itself out repeatedly. Early variants MyDoom were coded to conduct DDOS attacks against other Web sites within certain time periods.


White House, Pentagon websites targeted by cyberattack
http://www.theprovince.com/Technology/White+House+Pentagon+websites+targeted+cyberattack/1771439/story.html

Cyberattacks Hit U.S. and South Korean Web Sites
http://www.nytimes.com/2009/07/09/technology/09cyber.html
Quote
SEOUL, South Korea — Cyberattacks that have crippled the Web sites of several major American and South Korean government agencies since the July 4th holiday weekend appear to have been launched by a hostile group or government, South Korea’s main government spy agency said on Wednesday.
Logged

What you see isn’t what you always get!
Tags:
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.055 seconds with 17 queries.
Powered by SMF 1.1.10 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com