CẢNH BÁO MÃ ĐỘC APT TẤN CÔNG CÓ CHỦ ĐÍCH
2018-07-23 • VNCERT • Warning: Targeted APT Malware Attack •
https://web.archive.org/web/20181205155103/http://www.vncert.gov.vn:80/baiviet.php?id=100
VNCERT issued urgent coordination warning 234/VNCERT-ĐPƯC after observing targeted APT-style malware attacks against Vietnamese banks and nationally important infrastructure organizations in late July 2018. The advisory said attackers used deceptive and advanced technical methods to bypass defenses, take control of user computers and internal systems, and steal important information. VNCERT instructed recipients to block C2 IPs `38.132.124.250` and `89.249.65.220`, scan for `syschk.ps1` and `hs.exe`, verify MD5/SHA-1 hashes, remove malicious processes and persistence artifacts, and report remediation status to VNCERT. The source does not attribute the activity to a named threat actor.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | ed7fcb9023d63cd9367a3a455ec9433… | 2018-07-23 | 2019-01-22 |
| HASH | 26466867557f84dd4784845280da1f27 | 2018-07-23 | 2019-01-22 |
| HASH | 9ff715209d99d2e74e64f9db894c114… | 2018-07-23 | 2019-01-13 |
| HASH | bda82f0d9e2cb7996d2eefdd1e5b41c4 | 2018-07-23 | 2019-01-13 |
| IPv4 | 89.249.65.220 | 2018-07-23 | 2019-01-13 |
| IPv4 | 38.132.124.250 | 2018-07-23 | 2019-01-13 |