PULSE NAME
NewPOSThings updated activity
WHITE AlienVault 2015-10-26 Modified: 2016-01-11
11
IOCs
MEDIUM VOLUME
New activity from NewPOSThings and the "You Chung" actor. It is assumed that actors using the malware are targeting small- to medium-sized businesses given the malware’s focus on VNC applications. Small businesses are generally more likely to use remote administration software for their POS terminals so that 3rd parties can manage the terminals.
Indicators of Compromise (2 / 11 total)
All domain FileHash-MD5
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 b6c1d46e25a43d9ae24c85c38c52d6a4 2015-10-26
FileHash-MD5 761d23e1e2f496f1a6a2385808afc6eb 2015-10-26