162
Nart Villeneuve and Masashi Crete-Nishihata
attribute the attacks to these aliases, since it is possible the attackers could be using
someone else ’ s tools.
Where the attackers downloaded the Trojan programs they used in the attack
revealed further evidence. The attackers downloaded c99shell and pBot from two
separate locations. The version of c99shell at both locations was identical. The pBot
was functionally identical, but the connection information in the pBot confi guration
fi le was different. Attacker 1 and Attacker 3 both made attempts to download the same
instance of c99shell from a compromised server. However, only Attacker 2 was able
to successfully download c99shell from the Web site 0verkill.co.cc and upload it to
the Mizzima Web server.
Attacker 2 made attempts to download an instance of c99shell as well as another
fi le, an instance of pBot, from 0verkill.co.cc . 0verkill.co.cc was registered to “ Charlie
Root ” with the e-mail address ir00t3r@gmail.com. It was registered from an IP address
in Burma.
43
The pBot that Attacker 1 attempted to download from 0verkill.co.cc was confi gured
to connect to an IRC server, overkill.myanmarchat.org (with the prefi x “ vesali ” ) to
IRC channel “ #jail. ” The pBot that Attackers 2 and 3 attempted to download from a
compromised server, videovideo.it, was confi gured to connect to an IRC server at
64.18.129.9 with the prefi x “ soul ” ( fi gure 8.3 ).
To collect further information we attempted to connect to 64.18.129.9, but were
unable to obtain access. We were able to briefl y connect to the overkill.myanmarchat.
org IRC server until we were kicked out and banned. The “ overkill ” subdomain was
subsequently removed and failed to resolve. When connecting to the overkill.myanmarchat.org IRC server, the network names “ irc.doscoder.org ” and “ irc.vesali.net ” were
displayed. Only one user was seen on the server:
[xer0] (~xero@overkill.name): xero
[xer0] @#jail
[xer0] irc.doscoder.org :Over Kill Over The WorlD
[xer0] is a Network Administrator
[xer0] is available for help.
The IRC server information indicated that there was some still-unknown relationship
between “ doscoder ” and “ 0verkill. ” It is important to recall that modifi cations were
made to c99shell by doscoder — a member of the “ oGc Security Team ” and the “ #cyberw0rm ” channel on the oGc IRC network. Now, “ doscoder ” emerged as the host name
for the overkill.myanmarchat.org IRC server. A Web search turned up a relationship
between the fi le name and location path of the c99shell at now defunct locations on
doscoder.t35.com . In addition, much of the code in the defacement page posted on the
Mizzima News Web servers was similar to the code in another unrelated defacement by
doscoder. However, no further information was found concerning the doscoder alias.
Nart Villeneuve and Masashi Crete-Nishihata
attribute the attacks to these aliases, since it is possible the attackers could be using
someone else ’ s tools.
Where the attackers downloaded the Trojan programs they used in the attack
revealed further evidence. The attackers downloaded c99shell and pBot from two
separate locations. The version of c99shell at both locations was identical. The pBot
was functionally identical, but the connection information in the pBot confi guration
fi le was different. Attacker 1 and Attacker 3 both made attempts to download the same
instance of c99shell from a compromised server. However, only Attacker 2 was able
to successfully download c99shell from the Web site 0verkill.co.cc and upload it to
the Mizzima Web server.
Attacker 2 made attempts to download an instance of c99shell as well as another
fi le, an instance of pBot, from 0verkill.co.cc . 0verkill.co.cc was registered to “ Charlie
Root ” with the e-mail address ir00t3r@gmail.com. It was registered from an IP address
in Burma.
43
The pBot that Attacker 1 attempted to download from 0verkill.co.cc was confi gured
to connect to an IRC server, overkill.myanmarchat.org (with the prefi x “ vesali ” ) to
IRC channel “ #jail. ” The pBot that Attackers 2 and 3 attempted to download from a
compromised server, videovideo.it, was confi gured to connect to an IRC server at
64.18.129.9 with the prefi x “ soul ” ( fi gure 8.3 ).
To collect further information we attempted to connect to 64.18.129.9, but were
unable to obtain access. We were able to briefl y connect to the overkill.myanmarchat.
org IRC server until we were kicked out and banned. The “ overkill ” subdomain was
subsequently removed and failed to resolve. When connecting to the overkill.myanmarchat.org IRC server, the network names “ irc.doscoder.org ” and “ irc.vesali.net ” were
displayed. Only one user was seen on the server:
[xer0] (~xero@overkill.name): xero
[xer0] @#jail
[xer0] irc.doscoder.org :Over Kill Over The WorlD
[xer0] is a Network Administrator
[xer0] is available for help.
The IRC server information indicated that there was some still-unknown relationship
between “ doscoder ” and “ 0verkill. ” It is important to recall that modifi cations were
made to c99shell by doscoder — a member of the “ oGc Security Team ” and the “ #cyberw0rm ” channel on the oGc IRC network. Now, “ doscoder ” emerged as the host name
for the overkill.myanmarchat.org IRC server. A Web search turned up a relationship
between the fi le name and location path of the c99shell at now defunct locations on
doscoder.t35.com . In addition, much of the code in the defacement page posted on the
Mizzima News Web servers was similar to the code in another unrelated defacement by
doscoder. However, no further information was found concerning the doscoder alias.
