Indicators are what attackers leave behind. Stolen credentials are what they arrive with.
TLP:WHITE117 IOCs
From Campus to C2: Tracking a Persistent Chinese Operation Against Vietnamese Universities
OT
ORKL Threat LibraryThreat Actors
Malware Families
Diamond Model
Adversary(3)
Infrastructure(6)
Capability(6)
Victim
Indicators of Compromise
Indicators of Compromise117
| Type | Indicator | Confidence | Score | First Seen |
|---|---|---|---|---|
| IP | 156.59.13.38 malwarenetworkresearch | High | 68 | Oct 9, 26 |
| MD5 | 1415c48ad7d8848191b0cd7a122a7cfb file-hashmalwareresearch | High | 67 | Oct 9, 26 |
| MD5 | 6fe223ce568d919f80bea233738d0628 file-hashmalwareresearch | High | 67 | Oct 9, 26 |
| Domain | e.md c2malwarenetwork | High | 67 | Oct 9, 26 |
| SHA256 | 51c9d895c013a402d42841f52bae0bc5525b085d11ad2934f64068563a719132 file-hashmalwareresearch | High | 67 | Oct 9, 26 |
| MD5 | c82698395e6a30cad74c0bc0a6cd51af file-hashmalwareresearch | High | 67 | Oct 9, 26 |
| MD5 | f5de3ac3f12a2eee62a58d7ec77693dd file-hashmalwareresearch | High | 67 | Oct 9, 26 |
| MD5 | 298f5096cda09151bd6b10ab605f0e7c file-hashmalwareresearch | High | 67 | Oct 9, 26 |
| CVE | CVE-2023-46747 exploitintel-blogloader | High | 59 | Jun 25, 26 |
| MD5 | ceff651b3a7cbb667799510fe1d5d2c3 file-hashmalwareresearch | High | 67 | Oct 9, 26 |
| URL | http://microsoft-symantec.art:8848/sl malwarenetworkresearch | High | 68 | Oct 9, 26 |
| MD5 | 351a765b352730fe5b66baaef6410cbd file-hashmalwareresearch | High | 67 | Oct 9, 26 |
| IP | 221.2.22.145 malwarenetworkresearch | High | 68 | Oct 9, 26 |
| MD5 | 9e0e6f3e82a1a09228987ef496b5b9f3 file-hashmalwareresearch | High | 67 | Oct 9, 26 |
| MD5 | 38ecb8e7ff4a034618082b3bb6116f90 file-hashmalwareresearch | High | 67 | Oct 9, 26 |
| MD5 | 698d51a19d8a121ce581499d7b701668 file-hashmalwareresearch | High | 67 | Oct 9, 26 |
| Domain | catserver.host malwarenetworkresearch | High | 67 | Oct 9, 26 |
| CVE | CVE-2023-36802 c2exploitmalware | High | 67 | Oct 9, 26 |
| IP | 27.210.0.131 malwarenetworkresearch | High | 68 | Oct 9, 26 |
| MD5 | a28ab9f7acdf3ced769ee44f47828504 file-hashmalwareresearch | High | 67 | Oct 9, 26 |
| MD5 | 78b1fa873aabd54c1d73e2f7cd664a31 file-hashmalwareresearch | High | 67 | Oct 9, 26 |
| URL | https://ctrlaltintel.com/research/china-vietnam-campaign/ malwarenetworkrat | High | 67 | Oct 9, 26 |
| Domain | sqlmap.py malwarenetworkrat | High | 67 | Oct 9, 26 |
| URL | http://103.215.77.214:8080/3.asmx exploitmalwarenetwork | High | 68 | Oct 9, 26 |
| MD5 | fd6d0f45fab383257462a2b91fb7b169 file-hashmalwareresearch | High | 67 | Oct 9, 26 |
| Domain | microsoft-defend.club loadermalwarenetwork | High | 68 | Oct 9, 26 |
| IP | 74.125.196.113 c2exploitloader | High | 68 | Oct 9, 26 |
| MD5 | fc48ee15a4d16cee6cac9805cf8d0ec4 file-hashmalwareresearch | High | 67 | Oct 9, 26 |
| IP | 27.150.112.38 malwarenetworkresearch | High | 68 | Oct 9, 26 |
| MD5 | 2058842e1799195a2f3c9971e4dea24e file-hashmalwareresearch | High | 67 | Oct 9, 26 |
| MD5 | a11a1d761d757d367146f0f772632d8c file-hashmalwareresearch | High | 67 | Oct 9, 26 |
| SHA256 | f34bd1d485de437fe18360d1e850c3fd64415e49d691e610711d8d232071a0b1 abuseacademic institutionsaerospace & defense | High | 85 | Jul 27, 23 |
| MD5 | ea5705041c355cc87c4aaedca6203840 file-hashmalwareresearch | High | 67 | Oct 9, 26 |
| URL | symantec.art:8848/slt malwarenetworkresearch | High | 67 | Oct 9, 26 |
| Domain | microsoft-symantec.art malwarenetworkresearch | High | 68 | Oct 9, 26 |
| MD5 | ae3e7304122469f2de3ecbd920a768d1 file-hashmalwareresearch | High | 67 | Oct 9, 26 |
| MD5 | c1b11a39ef693fa6bf1bb3282fafb640 file-hashmalwareresearch | High | 67 | Oct 9, 26 |
| MD5 | a65b99553494cd178c72b2bc7ae44554 file-hashmalwareresearch | High | 67 | Oct 9, 26 |
| IP | 103.56.52.61 malwarenetworkransomware | High | 68 | Oct 9, 26 |
| IP | 27.219.79.226 malwarenetworkransomware | High | 68 | Oct 9, 26 |
| MD5 | 0659f21cb8422c830af696a947eeff6c file-hashmalwareresearch | High | 67 | Oct 9, 26 |
| MD5 | 75341ae79be66b2e09d578fcd6fa8441 file-hashmalwareresearch | High | 67 | Oct 9, 26 |
| Domain | gost.x64.so malwarenetworkresearch | High | 67 | Oct 9, 26 |
| URL | http://microsoft-symantec.art:8848/swt malwarenetworkresearch | High | 68 | Oct 9, 26 |
| MD5 | 29efd64dd3c7fe1e2b022b7ad73a1ba5 abuseacademic institutionsactive directory | High | 88 | Mar 29, 23 |
| MD5 | abcf9d28603eee7630ed93ef9f729888 file-hashmalwareresearch | High | 67 | Oct 9, 26 |
| MD5 | f87afacff9c44b94db109e3e956a4b33 file-hashmalwareresearch | High | 67 | Oct 9, 26 |
| MD5 | 6ba0dbcd2db8f44243799c891dbd2a59 file-hashmalwareresearch | High | 67 | Oct 9, 26 |
| MD5 | cbdc6e33deb4daac12bdce086165c8f1 file-hashmalwareresearch | High | 67 | Oct 9, 26 |
| MD5 | eb80f7bddb699784baa9fbf2941eaf4a academic institutionsactive scananydesk | High | 86 | Jan 8, 23 |
| MD5 | ab59a40273401b69d019877be0190fce file-hashmalwareresearch | High | 67 | Oct 9, 26 |
| IP | 38.181.79.15 malwarenetworkransomware | High | 68 | Oct 9, 26 |
| MD5 | 0aa8a3cd0ac247d5eeca2661e88f71b7 file-hashmalwareresearch | High | 67 | Oct 9, 26 |
| IP | 27.150.113.1 malwarenetworkresearch | High | 68 | Oct 9, 26 |
| Domain | cfcert.store c2malwarenetwork | High | 67 | Oct 9, 26 |
| IP | 27.150.114.115 c2malwarenetwork | High | 68 | Oct 9, 26 |
| IP | 123.132.37.188 malwarenetworkresearch | High | 68 | Oct 9, 26 |
| Domain | edu.vn malwarenetworkresearch | High | 67 | Oct 9, 26 |
| MD5 | 7d372351d7629ab7bf694812d03674c5 file-hashmalwareresearch | High | 67 | Oct 9, 26 |
| MD5 | bed7058beeeefc3efeb8b408ec68e5fa file-hashmalwareresearch | High | 67 | Oct 9, 26 |
| CVE | CVE-2017-0213 c2exploitintel-blog | High | 64 | Oct 9, 26 |
| MD5 | 140a0f81a7b1e76efa914dd688edc5e5 file-hashmalwareresearch | High | 67 | Oct 9, 26 |
| MD5 | 0d4ee255c91405a9f270c94862ea1361 file-hashmalwareresearch | High | 67 | Oct 9, 26 |
| CVE | CVE-2022-39197 exploitmalwarerat | High | 67 | Oct 9, 26 |
| SHA256 | 44cc5d20ba8b692fd10d358aab5694c21caf1c63e7a1ecb0f989010b7dfa830a file-hashmalwareresearch | High | 67 | Oct 9, 26 |
| Domain | id_rsa.pub malwarenetworkresearch | High | 67 | Oct 9, 26 |
| CVE | CVE-2023-28252 c2exploitintel-blog | High | 60 | Oct 9, 26 |
| MD5 | e06aacd6139288d5bea4a676ee0c2404 file-hashloadermalware | High | 86 | Jun 11, 26 |
| MD5 | 895d4e39649399d7e7010510ae17750b file-hashmalwareresearch | High | 67 | Oct 9, 26 |
| MD5 | 1643a53dc2a0117e0a66612bb3f341fe file-hashmalwareresearch | High | 67 | Oct 9, 26 |
| MD5 | 61cd12c70e9b6125a8d8b5784bdefc4b file-hashmalwareresearch | High | 67 | Oct 9, 26 |
| SHA256 | 61c0810a23580cf492a6ba4f7654566108331e7a4134c968c2d6a05261b2d8a1 abuseacademic institutionsaccommodation and food services | High | 88 | Mar 5, 23 |
| URL | http://microsoft-symantec.art:8848/?h=microsoft-symantec.art&p=8848&t=tcp&a=w64&stage=true malwarenetworkresearch | High | 68 | Oct 9, 26 |
| Domain | encoding.default.ge malwarenetworkresearch | High | 67 | Oct 9, 26 |
| MD5 | 69f40aa49b4ac18700c3499f167bd845 file-hashmalwareresearch | High | 67 | Oct 9, 26 |
| IP | 119.165.225.129 malwarenetworkresearch | High | 68 | Oct 9, 26 |
| MD5 | 9b0e4652a0317e6e4da66f29a74b5ad7 file-hashmalwareresearch | High | 67 | Oct 9, 26 |
| MD5 | 650be782605daa164ad7d1f971ef76a3 file-hashmalwareresearch | High | 67 | Oct 9, 26 |
| MD5 | 723d364d402760641ec172e27e9b6a56 file-hashmalwareresearch | High | 67 | Oct 9, 26 |
| URL | http://microsoft-symantec.art:8848/slt malwarenetworkresearch | High | 68 | Oct 9, 26 |
| CVE | CVE-2018-8120 c2exploitmalware | High | 67 | Oct 9, 26 |
| MD5 | 5982a720a2f0834e5d04ea4ad49900dd file-hashmalwareresearch | High | 67 | Oct 9, 26 |
| URL | http://microsoft-symantec.art:8848/?h=microsoft-symantec.art&p=8848&t=tcp&a=w32&stage=true malwarenetworkresearch | High | 68 | Oct 9, 26 |
| CVE | CVE-2024-30088 c2exploitmalware | High | 67 | Oct 9, 26 |
| MD5 | 4facb81f57e515a508040270849bcd35 file-hashmalwareresearch | High | 67 | Oct 9, 26 |
| CVE | CVE-2022-24521 c2exploitmalware | High | 67 | Oct 9, 26 |
| MD5 | 64aa88125366a1787919b5ec61befa1d file-hashmalwareresearch | High | 67 | Oct 9, 26 |
| MD5 | 809f3a686c379e3567db71585b169d4d file-hashmalwareresearch | High | 67 | Oct 9, 26 |
| IP | 27.199.77.113 malwarenetworkresearch | High | 68 | Oct 9, 26 |
| MD5 | 875cd28cf7b4fa7abd0d4e079a13bf26 file-hashmalwareresearch | High | 67 | Oct 9, 26 |
| URL | http://victm.edu.vn/3.asmx/Tas9er malwarenetworkresearch | High | 68 | Oct 9, 26 |
| MD5 | a39696e95a34a017be1435db7ff139d5 file-hashmalwareresearch | High | 67 | Oct 9, 26 |
| CVE | CVE-2019-18935 exploitintel-blogmalware | High | 60 | Sep 28, 26 |
| MD5 | 8bc54a3ae402e1c3e158010169e97c38 file-hashmalwareresearch | High | 67 | Oct 9, 26 |
| CVE | CVE-2020-0796 c2exploitmalware | High | 67 | Oct 9, 26 |
| SHA256 | bf7120a63483a2e4300a4d1405ac7525f11dd1f6d6a7120767bc42566da35891 file-hashmalwareresearch | High | 67 | Oct 9, 26 |
| IP | 103.56.52.142 malwarenetworkransomware | High | 68 | Oct 9, 26 |
| IP | 148.66.16.226 malwarenetworkrecon | High | 68 | Oct 9, 26 |
| MD5 | bb7326689f40a1190676770dd59a3ca9 abuseacademic institutionsactive scanning | High | 67 | Aug 29, 25 |
| URL | edu.vn:80/ malwarenetworkrat | High | 67 | Oct 9, 26 |
| MD5 | ec76edde147207156f6de31f6ecc5bef file-hashmalwareresearch | High | 67 | Oct 9, 26 |
| IP | 27.150.113.183 malwarenetworkresearch | High | 68 | Oct 9, 26 |
| MD5 | 5d882e918248790794a07cabe72cf2b1 file-hashmalwareresearch | High | 67 | Oct 9, 26 |
| Domain | catserver.properties c2malwarenetwork | High | 67 | Oct 9, 26 |
| MD5 | f91cc2b904a778d77da1ca2f0772c1b1 file-hashmalwareresearch | High | 67 | Oct 9, 26 |
| URL | http://baidu.com malwarenetworkproxy | High | 67 | Oct 9, 26 |
| MD5 | 3fed1004befb9834b699a88ccdce757e file-hashmalwareresearch | High | 67 | Oct 9, 26 |
| IP | 27.210.226.254 malwarenetworkresearch | High | 68 | Oct 9, 26 |
| Domain | catserver.store malwarenetworkresearch | High | 67 | Oct 9, 26 |
| IP | 39.85.164.6 malwarenetworkransomware | High | 68 | Oct 9, 26 |
| IP | 103.215.77.214 c2malwarenetwork | High | 68 | Oct 9, 26 |
| MD5 | 3388b033f6a92e22f47f094b3c38df4f file-hashmalwareresearch | High | 67 | Oct 9, 26 |
| MD5 | 40b96d9df310d5f448c0908c3231ff4e file-hashmalwareresearch | High | 67 | Oct 9, 26 |
| Domain | micrcs.microsoft-defend.club loadermalwarenetwork | High | 68 | Oct 9, 26 |
| MD5 | 0b2e3a199df127abba4e1f468d674cbe file-hashmalwareresearch | High | 67 | Oct 9, 26 |
| MD5 | 5c106ea9a277b8489be3059750c3f6ec file-hashmalwareresearch | High | 67 | Oct 9, 26 |
| MD5 | 131e9c99a7be59afb2f8763e07963c69 file-hashmalwareresearch | High | 67 | Oct 9, 26 |
IOC Relationship Graph
IOC Relationship Graph117 total IOCs
IPMD5DomainSHA256CVEURL