TF-MAL-js.unidentified_001
📛 Threat Title
Malware family: Unidentified JS 001 (APT32 Profiler)
Description
ThreatFox malware family `js.unidentified_001`. Printable name: Unidentified JS 001 (APT32 Profiler).
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:advisory.eventussecurity.com
The intrusion, suspected to have been active, involved tactics and techniques commonly associated with APT32 /OceanLotus, a group known for targeting individuals and organizations working on Vietnamese-related issues. The intrusion utilized a range of persistence mechanisms and evasion techniques to blend in with legitimate processes.
-
web:attack.mitre.org
APT32 is a suspected Vietnam-based threat group that has been active since at least 2014. The group has targeted multiple private sector industries as well as foreign governments, dissidents, and journalists with a strong focus on Southeast Asian countries like Vietnam, the Philippines, Laos, and Cambodia.
-
web:bazaar.abuse.ch
Using tags, it is easy to navigate through the huge amount of malware samples in the MalwareBazaar corpus. The page below gives you an overview on malware samples that are tagged with APT32 .
-
web:bluecyber.hashnode.dev
I. Over view File nameWelcome to the Darkness.html sha25656e926b816c062078f8acac3bd28e2759447d07d9fb6e1d31d2a032121c110c6 File Size5.01 MB (5256901 bytes) This is an ...
-
web:cyble.com
Cyble decodes APT 3 and its cyber-espionage tactics, tools, and global impact. Learn how Cyble helps detect, defend, and respond to cyber threats.
-
web:github.com
This dataset contains over 3,500 malware samples that are related to 12 APT groups which alledgedly are sponsored by 5 different nation-states. This dataset was used for benchmarking different Machine Learning approaches performing authorship attribution. This dataset can be used for future benchmarks or malware research.
-
web:malpedia.caad.fkie.fraunhofer.de
Details for the Unidentified JS 001 (APT32 Profiler) malware family including references, samples and yara signatures.
-
web:malwareanalysisspace.blogspot.com
OK, let's jump to the first part of malware and extract the TraceIndexer.exe and TTDReplay.dll. The incident summary and detail you can view from China ThreatBook: APT32 Poisoning GitHub, Targeting Chinese Cybersecurity Professionals and Specific Large Enterprises | ThreatBook CTI, Here I'm focused on diving deep into the process of malware analysis, the malicious file .uso, which is from ...
-
web:thehackernews.com
Vietnamese human rights group targeted by APT32 hackers in multi-year campaign. Malware used to compromise systems and steal data.
-
web:www.securityscientist.net
APT32 (G0050), known as OceanLotus, is a Vietnamese APT targeting ASEAN governments, automotive firms, and journalists. Explore their custom malware , DNS C2, macOS tools, and defense strategies.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.