2CMV20-00071-01 CSIRT comparte IoC de campañas de phishing con malware

CSIRT comparte una serie de Indicadores de Compromiso (IoC) obtenidos del análisis realizado a múltiples campañas de phishing con archivos adjuntos que contienen malware.

2CMV20-00071-01-2.jpg

Resumen

El Equipo de Respuesta ante Incidentes de Seguridad Informática (CSIRT), comparte una serie de Indicadores de Compromiso (IoC) obtenidos del análisis realizado a múltiples campañas de phishing con archivos adjuntos que contienen malware, los que están circulando en el ciberespacio nacional y representan un riesgo para los sistemas informáticos, así como para los usuarios en general.

CSIRT recomienda a los administradores y usuarios bloquear los hash publicados en este informe, y mantener un permanente monitoreo sobre el resto de los Indicadores de Compromiso.

Observación

Solicitamos tener en consideración las señales de compromiso en su conjunto.

IoC hash

Hash SHA-256

00bbb46d129cb92e21e0dde1e96e2ba6180c6ae00337f2fac9573a7ad52af2c7
085985e9485fb2215e2fb2d51d991590300a8d0ec22025943d8e22cdb4f5d88e
09749409d74889ea294065b2992f83efd93b868a0a8c4e621aa9bec5fdd7ff92
0a8cd64603b9ae74c070d962fb2ad28ba4d047418d5e204a93fb7d9f150aad82
0f33aa6f8d1017fc5ea9d8b1c54da57f5de191198aada4e5a3e20ba283204eb7
11ebddeb37dbe6f6446de6f12c51afe0bb23c6b30eaf73ab5863330113e5d23a
12044c14e75838d73382e1c2b29eb30d24df6c236a65dfdd738ff783fadbc8e9
16a42707dc6924d3f1910892b1b94145aba4ddfe69f2abd5325a14d3fe823819
17c5aeba7a30fe8c764dd7fdc79d633e7fe95754ae796a2803e32ff565be945c
18682da00e4eef83254a0013572555f205b4f24eb149781d13b2d2be9bb4bd77
196110af1272d52e2742f2e02771e76dd13f76ed27217a9e9ef35a9b706fb4fd
1a4dac1622e769fa5c98555dab3b4c552c8ac40ff7097490cdf1b363a899e36a
1c7b67f8fc7ec831b16dabde506788c6709f93db358d6432c9ffbc5bae244f5c
24313cac577c9bcb8280cdbb49da4239bc047a9da38f7e92a6ad9c146015bca6
2cfe7f19203bbe9f371de5990608b54595c083c51fc849009cefe24e54f4a7e8
2f42f540a4219c8f9111de5eecec94a622ce1d97e6eee327dfcf754c0073384f
325097c8fb2716bbcf632a2d7b5d2b16b5873df88236a87762d2d5d18dbe6731
3297dab797abe5ba8541d9bd2081d1cd397420b8aeb1b176655fb4ef3c4b7f29
329d1688743c04146ab3d2688c758270dfdb6ff6753aee76385e5190767ae136
32d57980df122e313af05b944fa3c85cbab2e78c40332c0d69b7cbabdaa307d3
3317dc5be83730e3a5981eed31115cfa2b66483e859957b8b89a2390ca7b63c3
363f5afc01b56576215ad33689ce1202a8c9bb6a84582d88eb27c126590391ad
380898df8fb2f0fd23488ab6bc5ad77f1ca61edb73a72c3882c9dc8d61627c2a
3a814c286fe4c85b2947e52b5551940420efc8196bec00d1b5f7dcee3b811885
3ab6b79ee2ac1895d499ef356c908cc897034b98f378ede22d7f4c506c5a934a
3f94ae5489afe555273e78f9a39a080ce93496d263da50632d240d6f6725a684
42d23dfa18dd4ceb8d59bd768a2866fa364d3c6956ce05e8f26a79e552d79fb8
48099ca861d25cbbddab6e7fb08b61b73b37c27001d88dba177c99a08c0c6c46
4cdfcc8639f608e7b8831e47702c36114c95b40a9e4c33eee5bf2bda66e85c96
515f144fb2787dff8e183326779dbe8dfbcb39e0c68d3412b43b387c2d4f67f7
550af7dc6e51fc20d06b338a996880bc84d72c4a135b35ef8f73252839a8341f
69df6645aacc44f45f8c295c247e675e57f5188387138135c927c97defb2c9d9
6b853efc15573665c9fac4d482130b678cc0eafdb0b8a742c57d202ab7c02615
6ebef23be7fd281538fabd7aa2c945911d74855a35da68d1e78d42d63f770eb5
714f70dbf506839f4fd4fd1f062c6da68f65bb8523009a5b9e1e8a4c59126a14
72b942dd9ea9a72dd6387c5815a9c03516e3988b0c3477f3a3b9035812bed550
768439330ed94b4a26cf73f164473a1f50b2d96400c5521a3f4b84c6822afdc3
78172f621816e82f9fcef792ab7deb7ce740acdbe4bfc9c84abf786d6c60a804
7a5d1eea4f59c4fc7fcf96f488480c5480682cfdc41d0726894b37b3bbfab988
7c93d3ea6aa980f0109a9cf438d0578a9c7eddb29b62a84f16d34272f3ea8599
7d206452247f03da0873bd8f6197b3cfa160fb68e7ea0d5bc39bbfae71979416
7e4c8619c8d1b503ba9feea05a0cebc4616edd6dba4a8484243b5f6b3ae01fe4
8063a2c617da4d4da2745b20516de01443851d4915022af960958a7d79abc197
8281cd4c2d7a7a8fc832fabba5d970710000c97606262e5d98ce4c3bc3a44a3c
85ecd3a5a3ddc993ba98fa6de72bb17e146c063449229a6d54522341460f2611
86c45c27dd0a9e6188a97bf9df7709166d18ddf21a429b3b1baede8cf1c7fd18
8b81793a9208e59123733d44c31e992e32ebdd5d4700d05c14c4982395b44486
8c82cc623cd4d4ec151a35f4d3fa75035dad8085385bcad2e3394b9cf9fcf29f
9914ae78b914ae2e3f68a6d91fec5e579594a421faae725c0eb83a8c911b2503
99ff40e2f955801b8a5a16e43b66ddae8bf0f11594b651868fd7c35ee32854bb
9c54d9e594dca4040765401d50baf0546055d5654edbd3c24458741133a77af8
9fee57918672137160499dcd1a099670ef8f9a787f3a1ad6d8123df26cddbc3b
a0daf55a85c41cbda5582b932a8fd770f00bff28d136baf5204db6057bec314a
a505fb064720437d8d61098a84db6ed6330d1772af31f1af6ada1b56812b0ba1
a701e219d3e1936d127e74fbaa5b74e5cbb40d6b5fb6bdfe2a93052c1e5c719e
a7a315d63857365a81ad842fc0e5a317ee2904ba6cddec5ca074b3fd65b4eba1
aafae3b48f23c0cc27cfe185ec661d239b62e1cd0602d2a3657873805cb7d709
b251ab2cf211dcd50d42f0093a81adca760195647d5346cdd9c0889811b4dd7f
ba9bfb0d60c82a7089416526c12c14a7bb094918d3b1238ff7ef84871168308e
bd6c0614c2067e0cccd3d863d3721392c95a08e15e4602e9a36de9a1cfde4abd
bdf730859a96fcc2d53cf167a0f055805cee05d7a2ff3d15a83b56f6246ec62d
be2466fc811cf92f9cb4d8e4d0544f787a92fe45952795ab9ecba9efc2f9d6da
bf6e5ae0de368c999c3e21c95ddcf574066d2f67534636f61896876172fa3cee
c2e11dda09e051595e47d1dc5152ec2dd98b4688134424ab193851006db2a957
ca705ab3ba45902c24cdf0c3178ed891ba1746849c932a4027296042b3e6cf5d
cdc131531529cac19de749d4016dd319c652b023f1c2cfab93c41e46aed8b536
d00a08229e5a41018bbab3309e559e26de9e4e14ba58ad334c5f9d669c957255
d18e5559004807ca15aa90239b41d5c77c9bf707f9b5672fcabf9b63a5ace78e
d268cec7cab09077037ec3169a29adcad007c5f649640046b76d0208806ff266
d57c3d6e33edb58a5552013f71e76758f25f690e62707ebb26a9e34159269cfc
d57cc31ecbd752009d3f6b6268f98d0be6a4027543a5e1678fe6ff9a433d63e2
dddcc2de7f959374d4e4903e1f99b03c17d19d919ad7820212aa7af012199e0a
df327bad984ccd24518787010789914ff3d39360177f0d4c84cfbf445f01513d
e00c5e351edfd9c27080244a22f112590a83e51222298066d5e0297c07dc2f8d
e21cc23207ea788779739f436bd0f28515cfe5519e5cb0b9d9d36516f41abf85
e4e678e0a158761b1924c737a2fe1c291e057587c80feb59acfa9c4eb2a87945
e6ba6403690e08d6e9206411ce7240ff65682fbae782cf2011c96418218d6bd7
e7d33f88e5cacc8b3e69da5c7c753b8e87f1a9ddfbe0649726b7d00708e88d05
ea72c4a852dea910097c6ccb723730a2a3e9fd765d1637c5f619f701b7757979
f179610576760e21a037458c30e42c05245d489835bd73a3f80a7a7a8f2ca8aa
f5e5906c1a4ad79dcd40bc428ea6799adb64cf252d2c6972f0eec37249b7801f
f818e8fef554c517419f895ad76a028094435fe5f415a9a109d6de854ccd0f69
f88f33ca7ce9dfded7062bd7d9a4e8552b19ee55bf23e84fdbf9f94c89d72d79
f8a72d19ac8c459714d53872a63deb4bc1fd98bf3a7c9377dfa236d1f6acf4f6
fc445fe8be324d90d4fc3fb4163ae847440b9ab5a6fed82933f18fc0e51d7ed7

IoC Descarga malware Urls

hxxp://odytravelgear[.]com/tsaapprovedluggagelocks/bl_uh_t32c/
hxxp://broganfamily[.]org/images/s_w6_h2gc/
hxxp://chromaccess[.]com/attachments/o_wle6_cyuobdkxwm/
hxxp://sitebilisim[.]com/cgi-bin/f9mr_wgobf_x5/
hxxp://www.nfis[.]com/accounts/h_d7c10_dnl/
hxxps://renatocoto[.]com/wp-includes/3wh_3d6w_6cub3u/

IoC nombre de archivo

 Nombres de Archivos con Malware

Form.doc XPV-080120 CYQ-080620.doc
M83 invoicing.doc CSO-080120 BWL-080620.doc
GYY-080120 SWV-080620.doc NJ4039762427PN.doc
list of our new purchase order.zip SY9526361258BS.doc
CONTRACT Scan 000029900 003999000 -pdf.gz FYT-080120 NGP-080620.doc
Form - Aug 06, 2020.doc BL2861788338NW.doc
LK4514177313IL.doc KOJ-080120 PBE-080620.doc
INSTRUCTIONS COPY.zip JB6590502069PH.doc
invoice #9379.doc OT0873316487DH.doc
QZP-080120 NON-080620.doc DK5827888875NF.doc
PO# 08062020Ex.doc OZ4670034071XE.doc
QZ8541633169WX.doc AG7840035918RF.doc
PVH-080120 JNW-080620.doc HK5530240294FT.doc
DC1398476232OT.doc VRP-080120 WOQ-080520.doc
PO# 08062020.doc IXU-080120 MLU-080620.doc
INV_16303.doc Form - Aug 05, 2020.doc
JTH-080120 ZWB-080620.doc GS4177847732DO.doc
JKO-080120 ZWN-080620.doc PO# 08052020.doc
KO0077220464IR.doc DownloadTrackingRefrence03.08.20.pdf.Gz
DNT-080120 BJE-080620.doc ICO-080120 UYU-080520.doc
WK5989895660XH.doc LMN-080120 SFF-080520.doc
Packing List.pdf.z FQC-080120 QCS-080520.doc
Urgent Order.r00 YQ7217511006QV.doc
KB2440808638UD.doc RFQ.iso
Electronic form.doc RFQ.zip
IOG-080120 JKI-080620.doc MAJDALANI INOX SA Pedido.r11
ZKG-080120 LYM-080620.doc Download_Tracking_Refrence.03.08.2020.pdf.Gz
ZDB-080120 ECT-080620.doc #reference.exe
IR3938409211CN.doc SOLICITUD DE OFERTA 05-08-2020·pdf
RZV-080120 SBJ-080620.doc 08.zip
LXX-080120 DLW-080620.doc PO 2005072 INTECSA INARSA.cab
Download_Tracking_Refrence.29.07.2020.pdf.Gz Shipment Documents.ace
KD8929060662YA.doc Ordine  MRP001094.iso
FJA-080120 EPY-080620.doc Scan_Docs #INV 300489739-04-08-2020 Amended.r00
Urgent PO.pdf.z New Order pdf 7Z.rar
RJ0545609363BT.doc New order 090FjEl5Bj836ZH.zip
SFJ-080120 MID-080620.doc FACTURA_E-4672393.doc
AMZ-080120 ZRU-080620.doc Image001.gz
VG8289277607JH.doc
FXY-080120 EBY-080620.doc
QWC-080120 KJJ-080620.doc
BNW-080120 ZRJ-080620.doc
ES0820976543AT.doc
VWX-080120 XQI-080620.doc

IoC servidor smtp

81.88.40.215 104.47.32.58 212.227.17.13 203.78.107.66 52.151.49.60
62.149.156.165 37.48.85.246 81.24.163.10 95.60.240.140 103.27.72.14
37.75.10.194 31.170.120.152 50.28.36.67 210.145.113.121 206.75.213.45
119.82.249.8 66.96.190.9 118.23.163.148 23.83.209.30 81.169.174.116
58.64.198.26 103.35.65.189 196.25.69.222 23.83.209.13 138.128.162.18
202.172.25.34 171.244.140.109 186.202.137.99 212.227.17.10 202.162.238.89
185.95.3.90 66.96.189.10 154.0.167.162 217.72.192.75 88.80.33.71
66.96.186.6 196.37.111.115 154.0.171.138 212.76.85.78 198.187.29.17
185.29.25.171 202.146.193.141 77.105.37.159 67.225.224.4 104.168.169.134
64.188.23.72 66.96.185.8 172.104.61.201 52.28.59.28 67.214.175.86
190.226.41.75 66.96.185.3 177.185.203.51 202.22.199.150 40.92.20.77
190.226.40.76 222.255.178.21 119.92.204.165 41.215.35.42 40.92.19.59
202.22.199.150 202.162.241.67 170.249.205.42 202.53.23.226 218.102.62.197
134.119.217.179 198.23.53.40 175.107.240.15 222.255.178.21 131.153.51.122
212.76.85.78 66.96.190.5 217.76.145.174 213.19.161.153 59.160.116.25
74.208.166.166 23.83.214.8 217.76.145.174 190.226.40.72 61.112.5.67
95.211.208.49 164.160.94.132 162.246.59.201 103.3.168.13 67.222.38.55
203.175.174.32 195.250.10.4 209.182.192.35 103.3.168.14 23.83.222.29
188.164.194.18 103.15.48.89 23.83.209.30 103.239.139.144 120.136.10.19
31.186.28.30 210.122.9.33 23.83.209.13 115.186.57.132 172.245.159.42
212.40.133.3 183.178.36.239 202.162.246.189 80.74.176.113 162.248.246.98
31.197.243.158 103.230.124.228 202.162.246.186 210.1.224.91 64.182.105.8
200.80.43.3 81.88.40.215 104.47.36.52 200.14.114.13 210.2.86.102
190.202.150.26 124.146.200.2 202.162.241.211 208.60.28.22 192.185.144.96
162.214.25.85 66.96.185.1 95.110.189.247 185.30.48.30 192.185.51.253
23.83.208.37 210.2.130.150 185.128.81.59 200.85.163.70 192.185.149.13
103.15.48.142 190.226.41.9 150.95.33.7 202.162.241.211 192.185.50.141
95.110.189.247 203.84.156.154 186.167.5.226 116.58.56.122 108.166.43.64
84.233.228.144 202.55.81.9 175.29.177.83 198.38.94.253 69.73.154.77
3.1.110.166 196.15.196.92 42.117.1.120 212.76.85.54 197.211.212.116
190.226.40.79 103.252.255.21 60.43.143.56 103.13.122.86 123.30.109.114
208.117.55.132 202.53.23.226 41.79.189.134 202.55.81.9 45.137.22.43
202.162.246.189 123.30.249.16 101.0.86.206 108.163.186.82 193.8.195.28
202.162.246.186 80.74.176.117 200.35.156.43 153.126.208.138 45.143.223.126
202.162.241.211 209.182.192.35 95.128.74.222 131.196.180.13 185.58.73.74
103.15.48.230 104.247.73.20 190.196.6.54 54.37.255.108 45.95.169.243
139.99.246.167 156.54.133.144 116.12.51.19 212.73.86.34 111.118.214.86
139.99.246.170 185.116.213.241 66.228.55.251 113.193.1.42 138.68.68.170
182.239.43.61 66.96.186.7 103.15.48.110 103.27.236.14 195.219.57.207
185.14.148.44 190.114.205.130 122.155.169.156 218.102.62.196 185.222.58.146
45.117.80.75 103.93.17.134 103.15.48.248 117.55.192.9 23.106.223.209
148.244.114.30 66.96.184.4 213.229.190.239 45.35.48.105 80.85.157.189
200.71.154.150 190.226.40.202 217.118.113.119 202.162.246.189 125.227.165.208
198.38.86.146 66.96.185.2 190.196.12.54 203.167.127.19 185.222.57.165
212.89.6.11 125.214.77.1 64.188.23.72 188.191.157.133
24.232.0.83 197.211.215.18 194.25.134.81 202.142.166.70

IoC Correo Electrónico

[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected] [email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]

Recomendaciones        

  • No abrir correos ni mensajes de dudosa procedencia.
  • Desconfiar de los enlaces y archivos en los mensajes o correo.
  • Mantener actualizadas sus plataformas (Office, Windows, Adobe Acrobat, Oracle Java y otras).
  • Ser escépticos frente ofertas, promociones o premios increíbles que se ofrecen por internet.
  • Prestar atención en los detalles de los mensajes o redes sociales.
  • Evaluar el bloqueo preventivo de los indicadores de compromisos.
  • Mantener actualizadas todas las plataformas de tecnologías y de detección de amenazas.
  • Revisar los controles de seguridad de los AntiSpam y SandBoxing.
  • Realizar concientización permanente para los usuarios sobre este tipo de amenazas.
  • Visualizar los sitios web que se ingresen sean los oficiales.

Informe

El informe oficial publicado por el CSIRT del Gobierno de Chile está disponible en el siguiente enlace: 2CMV20-00071-01