CẢNH BÁO MÃ ĐỘC APT TẤN CÔNG CÓ CHỦ ĐÍCH

2018-07-23 VNCERT Warning: Targeted APT Malware Attack

https://web.archive.org/web/20181205155103/http://www.vncert.gov.vn:80/baiviet.php?id=100

Thumbnail for CẢNH BÁO MÃ ĐỘC APT TẤN CÔNG CÓ CHỦ ĐÍCH

VNCERT issued urgent coordination warning 234/VNCERT-ĐPƯC after observing targeted APT-style malware attacks against Vietnamese banks and nationally important infrastructure organizations in late July 2018. The advisory said attackers used deceptive and advanced technical methods to bypass defenses, take control of user computers and internal systems, and steal important information. VNCERT instructed recipients to block C2 IPs `38.132.124.250` and `89.249.65.220`, scan for `syschk.ps1` and `hs.exe`, verify MD5/SHA-1 hashes, remove malicious processes and persistence artifacts, and report remediation status to VNCERT. The source does not attribute the activity to a named threat actor.

Indicators of Compromise

Type Value First Seen Last Seen
HASH ed7fcb9023d63cd9367a3a455ec9433… 2018-07-23 2019-01-22
HASH 26466867557f84dd4784845280da1f27 2018-07-23 2019-01-22
HASH 9ff715209d99d2e74e64f9db894c114… 2018-07-23 2019-01-13
HASH bda82f0d9e2cb7996d2eefdd1e5b41c4 2018-07-23 2019-01-13
IPv4 89.249.65.220 2018-07-23 2019-01-13
IPv4 38.132.124.250 2018-07-23 2019-01-13

Related Reports

« Back