List of US, South Korean sites targeted in ongoing DDOS
Wed, 2009-07-08 07:19

My colleague, Martyn Williams, forwarded me this link to a Korean blogger who has published an analysis of the malware used in an ongoing DDOS attack against government and business sites in the U.S. and South Korea.

The list is in line with sites that have been reported to me by security researchers studying this attack, but it is far more comprehensive than anything I've yet seen published.

Who is doing this? An angry teenager? Surely North Korea would be able to come up with a more prominent US bank to hit than US Bank? Then again, maybe not.

Korean police are reportedly investigating the incident. The FBI had no comment Tuesday.

[Attack site list]
Cheong Wa Dae, the Ministry of National Defense, Foreign Affairs and Trade, Republic of Korea National Assembly, U.S. forces in Korea, Naver blog, Naver mail, bank, internet banking, internet banking, Shinhan Bank, Korea Exchange Bank, internet banking, the Grand National Party, the Chosun Ilbo, the auction

Banking.nonghyup.com (bank, internet banking)
Blog.naver.com (Naver blog)
Ebank.keb.co.kr (Korea Exchange Bank Internet Banking)
Ezbank.shinhan.com (Shinhan Bank, Internet Banking)
Mail.naver.com (Naver Mail)
Www.assembly.go.kr (Republic of Korea National Assembly)
Www.auction.co.kr (auction)
Www.chosun.com (Chosun Ilbo)
Www.hannara.or.kr (GNP)
Www.mnd.go.kr (Defense)
Www.mofat.go.kr (Foreign Minister)
Www.president.go.kr (Blue House)
Www.usfk.mil (USFK)

(Transformation may vary depending on the attack website)

Finance.yahoo.com
Travel.state.gov
Www.amazon.com
Www.dhs.gov
Www.dot.gov
Www.faa.gov
Www.ftc.gov
Www.nasdaq.com
Www.nsa.gov
Www.nyse.co
Www.state.gov
Www.usbank.com
Www.usps.gov
Www.ustreas.gov
Www.voa.gov
Www.voanews.com
Www.whitehouse.gov
Www.yahoo.com
Www.washingtonpost.com
Www.usauctionslive.com
Www.defenselink.mil
Www.marketwatch.com
Www.site-by-site.com

Reader Feedback
Thu, 2009-07-09 13:56
Akamai
By Anonymous

It looks like all the US Govt sites that stayed up were on Akamai, just check out their DNS records (nslookup or dig www.whitehouse.gov). I noticed that DOT wasn't at first when they went down, but was when they came back up. Seems like if you want to sustain a DDoS, you need to be calling those guys.

Post new comment

The content of this field is kept private and will not be shown publicly.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.
* Denotes a required field
VIRTUAL CONFERENCE
Security Directions: A Virtual Conference

Security Directions Available On Demand Sept. 30 - Dec. 30

Join us for a virtual event with candid, expert information on top security challenges and issues - all from the comfort of your desktop.

» Register Now

WEBCAST
Protecting PII: How to Work with IT to Manage Risk

Compuware Understand the critical nature of the test data privacy problem and get tips on how to work with IT to implement a test data privacy program.

» View this Webcast