DDoS Trojan Spread from Domestic Source
DDoS Trojan Spread from Domestic Source
  • Staff
  • 승인 2009.07.28 10:53
  • 댓글 0
이 기사를 공유합니다

What is now being called the 7.7 DDoS Attack, which paralyzed major websites in Korea on July 7, is confirmed to have spread from two domestic online storage services, called "webhards," in Seoul and Busan. The command and control servers for the attack, which are believed to have given attack and suicide orders, were found to be based overseas.

According to a communication by the National Police Agency's counter-cyberterrorism response center on July 27, the attackers initially hacked two webhard sites in Seoul and Busan and infected their programs with a malicious trojan. Users of the webhard service then had the trojan downloaded to their computers, where it waited for further instructions.  Computers that had been infected with the malicious virus turned into zombies that carried out C&C's attack and suicide orders.

A total of nine C&C servers in six countries including Germany, the United States and Thailand were found to give instructions to zombie computers. Police found out that out of 55,596 worldwide zombie computers that had transmitted systems information to the server in Germany alone, 54,628, or 98 percent, turned out to be based in Korea.


댓글삭제
삭제한 댓글은 다시 복구할 수 없습니다.
그래도 삭제하시겠습니까?
댓글 0
댓글쓰기
계정을 선택하시면 로그인·계정인증을 통해
댓글을 남기실 수 있습니다.

  • ABOUT
  • CONTACT US
  • SIGN UP MEMBERSHIP
  • RSS
  • 2-D 678, National Assembly-daero, 36-gil, Yeongdeungpo-gu, Seoul, Korea (Postal code: 07257)
  • URL: www.koreaittimes.com | Editorial Div: 82-2-578- 0434 / 82-10-2442-9446 | North America Dept: 070-7008-0005 | Email: info@koreaittimes.com
  • Publisher and Editor in Chief: Monica Younsoo Chung | Chief Editorial Writer: Hyoung Joong Kim | Editor: Yeon Jin Jung
  • Juvenile Protection Manager: Choul Woong Yeon
  • Masthead: Korea IT Times. Copyright(C) Korea IT Times, All rights reserved.
ND소프트