PULSE NAME
The Naikon APT and the MsnMM Campaigns
WHITE Naikon AlienVault 2015-05-21 Modified: 2017-03-07
80
IOCs
HIGH VOLUME
For over half a decade, the Naikon APT waged multiple attack campaigns on sensitive targets throughout South-eastern Asia and around the South China Sea. It maintained a heavy offensive focus on Myanmar, Vietnam, Singapore, the Philippines, Malaysia, and Laos. Targets and victims included ASEAN governmental agencies and government departments, investment enterprises, military, law enforcement and border control organizations, embassies, university faculties and others.
Indicators of Compromise (80)
All domain URL hostname FileHash-MD5 CVE
TYPEINDICATORDESCRIPTIONCREATED
domain stonehoof.com 2015-05-21
URL frankhere.oicp.net:443 2015-05-21
URL goihang.vicp.net:443 2015-05-21
URL us.googlereader.pw:443 2015-05-21
hostname mncgn.51vip.biz 2015-05-21
hostname thailand.vicp.net 2015-05-21
hostname frankhere.oicp.net 2015-05-21
hostname phsenator.vicp.net 2015-05-21
hostname bkav.imshop.in 2015-05-21
hostname ubaoyouxiang.gicp.net 2015-05-21
hostname googlemm.vicp.net 2015-05-21
hostname ttteco.vicp.net 2015-05-21
hostname goihang.vicp.net 2015-05-21
hostname myanmartech.vicp.net 2015-05-21
hostname mmkcg.uicp.net 2015-05-21
hostname xl.findmy.pw 2015-05-21
hostname ahzx.eicp.net 2015-05-21
hostname us.googlereader.pw 2015-05-21
hostname vietnam.gnway.net 2015-05-21
FileHash-MD5 4972c7205e3279322637f609b9199e97 2015-05-21
FileHash-MD5 ceb6e4499cfd8650f3e94fbcf7de48f6 2015-05-21
FileHash-MD5 9f23c0aed27f0874308bbd5f173ed85b 2015-05-21
FileHash-MD5 5c04904a50f0285851fb7292c13858ec 2015-05-21
FileHash-MD5 f14c42765f130ee6dec3a87dc50a47e1 2015-05-21
FileHash-MD5 3bed6788753690762c7d15a3247d8301 2015-05-21
FileHash-MD5 469ca0c73398903908babcad14300d8d 2015-05-21
FileHash-MD5 800116c4fe842768a0e1acbc72c8cd62 2015-05-21
FileHash-MD5 b6424852dd0187ea554a1cbc4e3490f3 2015-05-21
FileHash-MD5 a5721c5e7f2b49df82595819b5a49c0c 2015-05-21
FileHash-MD5 7a9712cbb3e340e577ce0320cceeb05f 2015-05-21
FileHash-MD5 1d6258bc3688226e7cb56fb821215a8b 2015-05-21
FileHash-MD5 48c2d02c443d70fe004a2d6fb9439f76 2015-05-21
FileHash-MD5 1b37457632840b04bf03e0745e51e573 2015-05-21
FileHash-MD5 5de5aa40eb3d30df2053a38bc26963b5 2015-05-21
FileHash-MD5 c8ed40879e1e3352692fe8c765294955 2015-05-21
FileHash-MD5 748c4761822dc7076399922df58551ae 2015-05-21
FileHash-MD5 cb72e70378755f1e8ab744a5b5e692bd 2015-05-21
FileHash-MD5 6758fc7e483ad9cd6280bcc3f4d85222 2015-05-21
FileHash-MD5 33d388c6e841ede3920f79516b5da032 2015-05-21
FileHash-MD5 b049fdeeb707e86e5e334f72cd50ffd8 2015-05-21
FileHash-MD5 21119ddd01694bb9181286b52cf1203c 2015-05-21
FileHash-MD5 113822c9bfeed38c099ae9004f1d8404 2015-05-21
FileHash-MD5 9883abc829870478ce6f3cfddbcbbaf2 2015-05-21
FileHash-MD5 448cd7c3ae0ae445d805a4849fe5e120 2015-05-21
FileHash-MD5 7b1199523a662a3844ba590f83b56dae 2015-05-21
FileHash-MD5 27ed7c7dd840ff7936418cf029d56603 2015-05-21
FileHash-MD5 6f9b6adbb33b7c8912aa2e5ae1c39f7a 2015-05-21
FileHash-MD5 03a3251bde74df30ab5bf0b730e08c8d 2015-05-21
FileHash-MD5 7f422b43eeb93b230ff7553c841c4785 2015-05-21
FileHash-MD5 b295274423c91ad9e254475bf8edd459 2015-05-21
FileHash-MD5 d57a7369d79467d7c768bb08febcc6a2 2015-05-21
FileHash-MD5 40138f3db14e6e137f8d0bdcbb5851d8 2015-05-21
FileHash-MD5 4299846c34fddda2f5a75239f8aca424 2015-05-21
FileHash-MD5 79de618615e139053ad92ca1e7bb7456 2015-05-21
FileHash-MD5 6cbc73fae7118dbd0fae328ce8ee6050 2015-05-21
FileHash-MD5 6803bd509d36d2b99049fcc9d975a21c 2015-05-21
FileHash-MD5 55b8b8779001b7e78a6adc55fb546401 2015-05-21
FileHash-MD5 416e6c9105139080310984ed06f6a57b 2015-05-21
FileHash-MD5 55048b78e9549c462c1463f7648454a5 2015-05-21
FileHash-MD5 bf6d3f52ab8176122be858ddccc22148 2015-05-21
FileHash-MD5 041436594c1ce9e99c569fb7402fe0c7 2015-05-21
FileHash-MD5 7c0676d950a1443e98b7d5b4727923ea 2015-05-21
FileHash-MD5 ab0185f3dc730af754559297f6f47492 2015-05-21
FileHash-MD5 d86106faaa398b8d83437176bf5e39c4 2015-05-21
FileHash-MD5 48fb78e8ba531505e246760c0d02d6b0 2015-05-21
FileHash-MD5 6a82c153bd370250cc2fed89f1bb5c91 2015-05-21
FileHash-MD5 90e9bdfc1fc6fe5999b047880c7445ae 2015-05-21
FileHash-MD5 c58df5892700ac3f467524f86bf325c0 2015-05-21
FileHash-MD5 dabba458b13cb676406c2bb219af9f81 2015-05-21
FileHash-MD5 5f1f6fb3cea3e9c3bd84909b7d37aa8d 2015-05-21
FileHash-MD5 516f64dd4fce3b9a325ea8501f97a88a 2015-05-21
FileHash-MD5 c8c81cca4645e71213f2310cec6c277d 2015-05-21
FileHash-MD5 95c4a236faa65b75dbb0076d8248584c 2015-05-21
FileHash-MD5 a3b3a32b6f67e4629133cc4578230efe 2015-05-21
FileHash-MD5 638c119a82a1b1d470e42e2e9712f3fb 2015-05-21
FileHash-MD5 c334737ea5e8f74567bfdc2fce6717b9 2015-05-21
FileHash-MD5 8660193a90e70f19a4419ae09306761f 2015-05-21
CVE CVE-2012-0158 2015-05-21
CVE CVE-2010-3333 2015-05-21
CVE CVE-2012-1856 2015-05-21