PULSE NAME
Chinese Cyber Espionage Group Attacking Asia
WHITE PKPLUG AlienVault 2019-10-04 Modified: 2019-10-04
531
IOCs
HIGH VOLUME
For three years, Unit 42 has tracked a set of cyber espionage attack campaigns across Asia, which used a mix of publicly available and custom malware. Unit 42 created the moniker “PKPLUG” for the threat actor group, or groups, behind these and other documented attacks referenced later in this report. We say group or groups as our current visibility doesn’t allow us to determine with high confidence if this is the work of one group, or more than one group which uses the same tools and has the same tasking. The name comes from the tactic of delivering PlugX malware inside ZIP archive files as part of a DLL side-loading package. The ZIP file format contains the ASCII magic-bytes “PK” in its header, hence PKPLUG.
Indicators of Compromise (42 / 531 total)
All URL hostname FileHash-SHA256 domain FileHash-MD5
TYPEINDICATORDESCRIPTIONCREATED
hostname info.csip6.biz 2019-10-04
hostname www.logitechwkgame.com 2019-10-04
hostname www.adminloader.com 2019-10-04
hostname update.adminloader.com 2019-10-04
hostname mail.adminloader.com 2019-10-04
hostname re.adminloader.com 2019-10-04
hostname info.linkdatax.com 2019-10-04
hostname update.linkdatax.com 2019-10-04
hostname cm.appupdatemoremagic.com 2019-10-04
hostname update.microsoftserve.com 2019-10-04
hostname update.tcpdo.net 2019-10-04
hostname up.outhmail.com 2019-10-04
hostname hwmt10.w3.ezua.com 2019-10-04
hostname app.newfacebk.com 2019-10-04
hostname workwifi.andphocen.com 2019-10-04
hostname info.adminsysteminfo.com 2019-10-04
hostname mail.queryurl.com 2019-10-04
hostname admin.nslookupdns.com 2019-10-04
hostname w3.changeip.org 2019-10-04
hostname md.sony36.com 2019-10-04
hostname 3w.tcpdo.net 2019-10-04
hostname lala513.gicp.net 2019-10-04
hostname update.queryurl.com 2019-10-04
hostname jackhex.md5c.net 2019-10-04
hostname w3.ezua.com 2019-10-04
hostname webserver.servehttp.com 2019-10-04
hostname work.andphocen.com 2019-10-04
hostname www5.zyns.com 2019-10-04
hostname netvovo.windowsnetwork.org 2019-10-04
hostname imw100pass.imwork.net 2019-10-04
hostname news.tibetgroupworks.com 2019-10-04
hostname jackhex.md5c.com 2019-10-04
hostname www.lzsps.ml 2019-10-04
hostname yl.andphocen.com 2019-10-04
hostname re.queryurl.com 2019-10-04
hostname web.microsoftdefence.com 2019-10-04
hostname www3.mefound.com 2019-10-04
hostname update.newfacebk.com 2019-10-04
hostname ppt.bodologetee.com 2019-10-04
hostname web.outlooksysm.net 2019-10-04
hostname dns.cdncool.com 2019-10-04
hostname sm.umtt.com 2019-10-04