ioc-collection/Philippine-Navy-Certificate
avast-ti 4b16028e37
Add files via upload
2022-03-28 12:31:12 +02:00
..
README.md Add files via upload 2022-03-28 12:31:12 +02:00
network.txt Add files via upload 2022-03-28 12:22:42 +02:00
samples.md5 Add files via upload 2022-03-28 12:22:42 +02:00
samples.sha1 Add files via upload 2022-03-28 12:22:42 +02:00
samples.sha256 Add files via upload 2022-03-28 12:22:42 +02:00

IoC for Compromised Philippine Navy Certificate

Malware analysis and more technical informations at https://decoded.avast.io/threatintel/avast-finds-compromised-philippine-navy-certificate-used-in-remote-access-tool/

Table of Contents

Samples (SHA-256)

85FA43C3F84B31FBE34BF078AF5A614612D32282D7B14523610A13944AADAACB - C:\Windows\System32\wlbsctrl.dll

Network indicators

C&C servers

dost[.]igov-service[.]net:8443

File names

C:\Windows\System32\wlbsctrl.dll

Mutex

t7As7y9I6EGwJOQkJz1oRvPUFx1CJTsjzgDlm0CxIa4=