PULSE NAME
VTA - Chinese 'Gallium' Hackers Using New PingPull Malware in Cyberespionage Attacks
WHITE Superpro 2022-06-14 Modified: 2022-07-14
31
IOCs
MEDIUM VOLUME
A Chinese advanced persistent threat (APT) known as "Gallium" has been observed using a previously undocumented remote access trojan in its espionage attacks targeting companies operating in Southeast Asia, Europe, and Africa. Called PingPull, the "difficult-to-detect" backdoor is notable for its use of the Internet Control Message Protocol (ICMP) for command-and-control (C2) communications. However, PingPull does not only use ICMP, but also HTTPS and TCP for the C2 communications. The malware is a Visual C++-based malware, where it provides a threat actor the ability to access a reverse shell and run arbitrary commands on a compromised host. This encompasses carrying out file operations, enumerating storage volumes, and timestomping files. In all three variants, namely ICMP, HTTPS and TCP, the malware installs itself as a service and has a description simulating a legitimate service, aiming to discourage users from terminating it.
Indicators of Compromise (31)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 1a96767957e193c45b1bf642f3293350 MD5 of b4aabfb8f0327370ce80970c357b84782eaf0aabfc70f5e7340746f25252d541 2022-06-14
FileHash-MD5 7e01d776a0eb044a11bf91f3a68ce6f5 MD5 of fc2147ddd8613f08dd833b6966891de9e5309587a61e4b35408d56f43e72697e 2022-06-14
FileHash-MD5 83f860e22cadb5c3f247ad6dc834059a MD5 of c55ab8fdd060fb532c599ee6647d1d7b52a013e4d8d3223b361db86c1f43e845 2022-06-14
FileHash-MD5 9ad380e7b6d9c83b88ed1b307107912e MD5 of f86ebeb6b3c7f12ae98fe278df707d9ebdc17b19be0c773309f9af599243d0a3 2022-06-14
FileHash-MD5 b4dd22013aefae6f721f0b67be61dc91 MD5 of de14f22c88e552b61c62ab28d27a617fb8c0737350ca7c631de5680850282761 2022-06-14
FileHash-MD5 d58c5fe6a5b5b3d494bae50d1df310f5 MD5 of 8b664300fff1238d6c741ac17294d714098c5653c3ef992907fc498655ff7c20 2022-06-14
FileHash-MD5 e12c09cf7ec74e8dfa412f9fdc8e1ee3 MD5 of 1ce1eb64679689860a1eacb76def7c3e193504be53ebb0588cddcbde9d2b9fe6 2022-06-14
FileHash-SHA1 177f953496b10a4256431166c6247cc5a135e343 SHA1 of de14f22c88e552b61c62ab28d27a617fb8c0737350ca7c631de5680850282761 2022-06-14
FileHash-SHA1 241b74dee500d61bb10ccfca598979499e40fdff SHA1 of c55ab8fdd060fb532c599ee6647d1d7b52a013e4d8d3223b361db86c1f43e845 2022-06-14
FileHash-SHA1 5c37b9701a1944b5df6437f7a76097ee1392b1a7 SHA1 of 8b664300fff1238d6c741ac17294d714098c5653c3ef992907fc498655ff7c20 2022-06-14
FileHash-SHA1 6d4cc7f30e0a67432244d1a3bb7c058be7c1795f SHA1 of f86ebeb6b3c7f12ae98fe278df707d9ebdc17b19be0c773309f9af599243d0a3 2022-06-14
FileHash-SHA1 76efd8ef3f64059820d937fa87acf9369775ecd5 2022-06-14
FileHash-SHA1 97713366202b6914e6defc4dfcbdff430785f407 SHA1 of b4aabfb8f0327370ce80970c357b84782eaf0aabfc70f5e7340746f25252d541 2022-06-14
FileHash-SHA1 98aa72ecd43556837f94208431cb710d7eb803e7 SHA1 of 1ce1eb64679689860a1eacb76def7c3e193504be53ebb0588cddcbde9d2b9fe6 2022-06-14
FileHash-SHA1 a121f00aba46b8c8db956756723f357e9eacb6cc SHA1 of fc2147ddd8613f08dd833b6966891de9e5309587a61e4b35408d56f43e72697e 2022-06-14
FileHash-SHA256 1ce1eb64679689860a1eacb76def7c3e193504be53ebb0588cddcbde9d2b9fe6 2022-06-14
FileHash-SHA256 8b664300fff1238d6c741ac17294d714098c5653c3ef992907fc498655ff7c20 2022-06-14
FileHash-SHA256 b4aabfb8f0327370ce80970c357b84782eaf0aabfc70f5e7340746f25252d541 2022-06-14
FileHash-SHA256 c55ab8fdd060fb532c599ee6647d1d7b52a013e4d8d3223b361db86c1f43e845 2022-06-14
FileHash-SHA256 de14f22c88e552b61c62ab28d27a617fb8c0737350ca7c631de5680850282761 2022-06-14
FileHash-SHA256 f86ebeb6b3c7f12ae98fe278df707d9ebdc17b19be0c773309f9af599243d0a3 2022-06-14
FileHash-SHA256 fc2147ddd8613f08dd833b6966891de9e5309587a61e4b35408d56f43e72697e 2022-06-14
domain hinitial.com 2022-06-14
domain micfkbeljacob.com 2022-06-14
hostname df.micfkbeljacob.com 2022-06-14
hostname jack.micfkbeljacob.com 2022-06-14
hostname t1.hinitial.com 2022-06-14
hostname v2.hinitial.com 2022-06-14
hostname v3.hinitial.com 2022-06-14
hostname v4.hinitial.com 2022-06-14
hostname v5.hinitial.com 2022-06-14