Warning: Detecting a campaign to spread malicious code GandCrab 5.2 into Vietnam via fake email of the Ministry of Public Security
Today (March 15), the Vietnam Computer Emergency Response Center (VNCERT) has sent a dispatch to member units to announce that there is a campaign to distribute malicious code GandCrab 5.2. into Vietnam and Southeast Asian countries.
The campaign to spread malicious code GandCrab 5.2 when entering Vietnam spread via phishing email Vietnam Ministry of Public Security with the title 'Go in Vietnam' has attached the file 'documents.rar'.
TipsMake.com's email containing the malicious code GandCrab received.
.Rar file attached to the end of the email
For over a year, GandCrab extortion code has spread globally. GandCrab 5.2 is a new version of this dangerous extortion family.
VNCERT once discovered that version 1.0 and 2.0 of malicious code GandCrab attacked Vietnam in April 2018 and issued a command to coordinate requests of agencies, units and enterprises to prevent malicious server connection GandCrab. Currently, VNCERT is still supporting decoding GandCrab version 5.1 and earlier.
If the user opens the mail, unzip and open the malicious attachment that will be activated. It will encrypt the entire user's data and a new file will be generated and instruct the user to pay the ransom to decrypt the data. The ransom is paid via electronic currency and is priced from 400 USD - 1,000 USD.
Malware to extort GandCrab 5.2 is distributed via fake email of the Ministry of Public Security of Vietnam.(Photo: VNCERT).
In the new command of coordinated fire rescue coordination, VNCERT Center requires the management units to monitor and prevent connections to servers that control the extortion of GandCrab malicious code and update the systems. Protection systems such as IDS / IPS, Firewall . according to the identification information in the table below to prevent and prevent the attack of malicious code GandCrab 5.2 in Vietnam.
List of servers controlling GandCrab 5.2 extortion code and list of hash codes to monitor and prevent connections.
The dispatch also stated that if detected, it is necessary to quickly isolate the detected area / machine.
In order to prevent malicious code GandCrab 5.2, users need to improve their vigilance. Do not open and click links, .doc, .pdf, .zip, rar . attachments in emails sent from strangers or emails with strange titles sent from acquaintances. If detected or in doubt, please notify the system administration department.
You should read it
- Warning: Dangerous new malicious code spills over to Vietnam
- The official GandCrab 5.2 decoder was released, ending a bad nightmare called GandCrab Ransomeware
- Lukitus Guide to preventing extortion malicious code
- Shade ransomware, the nightmare of 5 years ago is showing signs of returning
- GandCrab blackmail extinguished after earning $ 2.5 billion worldwide
- GIBON extortion code spread through spam
- How to handle the emergency WannaCry malicious code from the National Information Security Department
- Appearing dangerous Android malicious code specializing in stealing chat content on Facebook Messenger, Skype ...
May be interested
- FBI released the key decryption key for GandCrab Ransomwarethe fbi has officially released decryption keys for blackmailing gandcrab ransomware versions 4, 5, 5.0.4, 5.1 and 5.2.
- In 2020, Vietnam will popularize 500,000 VND smartphones to 100% of the populationin the morning of march 2 in hanoi, the ministry of information and communications said that, together with the policy of turning off the 2g signal, the ministry will work with all departments to develop a program to produce vietnamese smartphones that cost only 500,000 vnd to reach 100. % of people, creating conditions for implementing e-government.
- Warning: New extortion code GandCrab is attacking Vietnamese Internet usersyesterday afternoon (december 11), bkav issued a warning about a fifth generation variant of gandcrab extortion code that was attacking vietnamese internet users on a large scale.
- Fake courier service to spread viruseshacker hides e-mail carriers to trick users. there have been 7,500 computers in vietnam infected with this virus.
- There were 4,035 cyber attacks on Vietnam in the first 5 months of the yearrepresentative of vietnam computer emergency response center (vncert, under the ministry of information and communications) published statistics on the network attack incident in vietnam in 2018.
- GandCrab blackmail extinguished after earning $ 2.5 billion worldwideafter nearly a year and a half of 'storming', the people behind gandcrab ransomware claimed that the malware stopped working and at the same time urged their malicious 'branches' to stop distributing this extortion code. .
- Microsoft urgently warns about a phishing campaign that uses malicious Excel macros to hack PCssecurity team with microsoft's security intelligence has issued an urgent warning about a massive fraud campaign.
- Hacker exploited three vulnerabilities in Microsoft Office to spread Zyklon malwaresecurity researchers have discovered a botnet spread of malware through at least three new vulnerabilities published in microsoft office.
- 5 websites to help 'prank' your friends with fake emailsif you want to send fake emails to prank your friends and family, there are a number of online services worth exploring.
- The fake IE 7 virus appearsif you receive an email asking you to download internet explorer 7 beta 2, delete it immediately. because it was just a virus that appeared and spread by forging the latest version of microsoft's browser test.